CtrlK
BlogDocsLog inGet started
Tessl Logo

dopesecurity

Dope.security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Dope.security data.

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/dopesecurity/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a well-organized, command-driven integration guide with executable examples, a clear stateful connection workflow, and useful best practices. Its main limitations are minor over-explanation in the intro, placeholder-substitution gaps in examples, and slightly inconsistent step numbering rather than a fully copy-paste-ready end-to-end flow.

Suggestions

Trim the opening paragraph that explains what Dope.security is — Claude can treat the product name as given and the detail adds tokens without adding actionability.

Add one complete end-to-end example with real-looking values (connection id, an action id, a sample --input) so a user can copy-paste a working flow.

Normalize the connection workflow step numbering (Step 1, 1b, Step 2) into a single consistent sequence to remove the navigation ambiguity.

DimensionReasoningScore

Conciseness

The body is mostly lean command examples and flag tables with only minor over-explanation (the opening platform-description paragraph and agent-types note could be trimmed), matching 'efficient; minor instances of over-explanation that could be trimmed.'

4 / 5

Actionability

It provides concrete, executable commands throughout (install, login, connection ensure/get, action list/run, request) plus a flags table, fitting 'mostly executable guidance; concrete code or commands with minor gaps' — placeholders like CONNECTION_ID and QUERY still require substitution and no single end-to-end runnable example is given.

4 / 5

Workflow Clarity

The connection flow is clearly sequenced with state-based checkpoints (READY/BUILDING/CLIENT_ACTION_REQUIRED/CONFIGURATION_ERROR) and a re-poll feedback loop after the user acts, matching 'clear sequence with most checkpoints present; minor validation gaps' — the slightly inconsistent step numbering ('Step 2', '1b') keeps it below a 5.

4 / 5

Progressive Disclosure

No bundle files exist, so the single self-contained SKILL.md is evaluated on its own organization; it has well-structured sections (overview, install, auth, connecting, actions, proxy, best practices) with no nested references, fitting 'good structure; most content appropriately placed; minor organization gaps' — some inlined detail (clientAction sub-fields, proxy flags table) could live in separate references but none are provided.

4 / 5

Total

16

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description correctly pairs a what and an explicit use-when trigger anchored on a distinct product name, but its capability list is generic rather than concrete. It is functional and clear yet lacks the specific actions and richer trigger vocabulary of the best examples.

Suggestions

Replace generic verbs with concrete capabilities, e.g. 'Manage policies, events, users, destinations, lists, and alerts' instead of 'Manage data, records, and automate workflows'.

Expand trigger terms to cover natural phrasings users might say, such as 'browser security policies', 'Dope.security alerts', or 'web activity events'.

Make the 'when' clause more specific about the data scope, e.g. 'Use when the user wants to query or manage Dope.security policies, events, or alerts.'

DimensionReasoningScore

Specificity

Names the domain ('Dope.security integration') but the actions ('Manage data, records, and automate workflows') are generic and minimal rather than concrete capabilities, matching the 'names the domain but actions are minimal or generic' anchor.

2 / 5

Completeness

Both a 'what' ('Manage data, records, and automate workflows') and an explicit 'when' ('Use when the user wants to interact with Dope.security data') are present; the 'when' is explicit though the 'what' is somewhat generic, so it sits at 'has both what and when; when could be more specific' rather than a 5.

4 / 5

Trigger Term Quality

Includes the natural product keyword 'Dope.security' and 'data', but lacks common variations or synonyms a user might say, fitting 'some relevant keywords but missing common variations or synonyms.'

3 / 5

Distinctiveness Conflict Risk

The named product 'Dope.security' gives it a clear niche with minimal conflict risk, but the generic 'data/records/workflows' phrasing keeps it just below the fully-distinct anchor at 5.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.