CtrlK
BlogDocsLog inGet started
Tessl Logo

duo-security

Duo Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Duo Security data.

55

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/duo-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a concrete, executable CLI integration guide with a well-sequenced connection workflow and state feedback loops. Its main weaknesses are some padded introductory explanation, broken step cross-references, and a 'Popular actions' section that under-delivers on its heading.

Suggestions

Tighten the intro: drop or compress the paragraph explaining what Duo Security is, and remove or flesh out the sparse 'Duo Security Overview' list so every line earns its place.

Fix the broken cross-references: define 'Step 1/1a' and 'Step 2' headings that the 'skip to Step 2' and '1b' references actually point to.

Make 'Popular actions' deliver: list 3-5 concrete Duo actions (e.g. get users, list factors, enumerate phones) with example run commands, instead of only repeating the discovery command.

DimensionReasoningScore

Conciseness

The body is mostly concrete commands, but the opening paragraph ('Duo Security is a SaaS platform that provides multi-factor authentication...') explains the product's general purpose, and the sparse 'Duo Security Overview' list ('User / Factor / Phone' plus 'Use action names and parameters as needed.') adds little value. It is mostly efficient with some unnecessary explanation that could be trimmed, fitting score 3 rather than the leaner score 4.

3 / 5

Actionability

It provides many copy-paste-ready commands (login, connection ensure, action list/run, request) with flags and JSON examples, but the 'Popular actions' section promises actions and instead only repeats a discovery command, and no real Duo-specific action is shown with concrete parameters. These minor gaps keep it at score 4 rather than the fully-covered score 5.

4 / 5

Workflow Clarity

The connect→wait→search→run sequence is clear and includes a strong feedback loop for connection states (READY/BUILDING/CLIENT_ACTION_REQUIRED/CONFIGURATION_ERROR with re-polling). However, cross-references are broken ('skip to Step 2' and '#### 1b' with no Step 2 or 1a defined), which is a minor clarity gap holding it below score 5.

4 / 5

Progressive Disclosure

As a single-file CLI guide with no bundle files, it is well-organized into clear sections (Install, Authentication, Connecting, Searching, Running, Proxy, Best practices) with content appropriately inline. It is not score 5 because the low-value 'Overview' list and the underdeveloped 'Popular actions' section are minor organization gaps.

4 / 5

Total

15

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has an explicit when-trigger and a distinct product name, but its stated capabilities are generic and omit Duo's actual domain (MFA/access management) and the natural terms users say. It is a passable but under-specific trigger description.

Suggestions

Replace generic verbs with Duo-specific actions, e.g. 'Manage Duo users, factors, phones, and authentication policies; automate access-management workflows.'

Add natural trigger terms users actually say: 'Use when the user wants to manage Duo Security users, factors, or phones, or work with multi-factor authentication (MFA/2FA) and access policies.'

Mention the core Duo concepts (users, factors, phones, authentication) so the description reads as Duo-specific rather than a generic integration template.

DimensionReasoningScore

Specificity

The description names the domain ('Duo Security integration') but the actions are minimal and generic — 'Manage data, records, and automate workflows' describes no Duo-specific capability (no mention of MFA, users, factors, or access management). It matches the 'Names the domain but actions are minimal or generic' anchor and falls short of score 3, which requires 1-2 concrete actions.

2 / 5

Completeness

It answers both what ('Manage data, records, and automate workflows') and when ('Use when the user wants to interact with Duo Security data') with an explicit, specific trigger clause, so it clears the score-3 cap. It is not score 5 because the 'what' is generic rather than concrete trigger phrases.

4 / 5

Trigger Term Quality

'Duo Security' and 'interact with Duo Security data' are relevant natural keywords, but common variations users would actually say — multi-factor authentication, MFA, 2FA, Duo users, Duo factors — are entirely missing. This is 'some relevant keywords but missing common variations or synonyms', not yet score 4's good coverage.

3 / 5

Distinctiveness Conflict Risk

'Duo Security' is a specific named SaaS product giving it a clear niche and distinct trigger, but the generic action phrasing ('manage data, records, automate workflows') creates minor overlap risk with other Membrane integration skills that share the same verb template. Not score 5 because the actions lack Duo-specific distinctiveness.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.