CtrlK
BlogDocsLog inGet started
Tessl Logo

fortify

Fortify integration. Manage data, records, and automate workflows. Use when the user wants to interact with Fortify data.

56

Quality

65%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/fortify/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a strong, executable integration guide: concrete Membrane CLI commands cover the full lifecycle and the connection workflow includes a polling feedback loop and error branch. It loses points mainly for a redundant introductory concept explanation, a numbering inconsistency, and content density that could be split into a reference file.

DimensionReasoningScore

Conciseness

Largely lean command-driven content, but the opening paragraph explains what Fortify is (a concept Claude already knows) and the clientAction state-transition detail is somewhat verbose.

4 / 5

Actionability

Provides fully executable, copy-paste-ready commands with realistic flags across install, auth, connection, action search/run, and proxy, plus a concrete options table covering the common cases.

5 / 5

Workflow Clarity

The connect workflow has a clear sequence with an explicit polling feedback loop and an error/state-decision branch, but lacks explicit validation checkpoints for destructive proxy operations and has a numbering drift ("Step 2" vs "1b").

4 / 5

Progressive Disclosure

Well-organized into clear sections with no nested references, but content is consolidated in a single file with an inlined clientAction spec and full proxy options table that could live in a reference file.

4 / 5

Total

17

/

20

Passed

Description

48%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description correctly pairs a what and a when clause and names a distinct niche (Fortify), but the capability wording is generic boilerplate ("Manage data, records, and automate workflows") rather than concrete Fortify actions, and it omits the natural trigger terms users would say. Specificity and trigger coverage are the weakest areas.

Suggestions

Replace generic verbs with concrete Fortify operations, e.g. "Scan source code for vulnerabilities, audit findings, and triage remediation priorities".

Add natural user trigger terms such as "scan", "vulnerability", "security findings", and "SAST" so the skill matches how users phrase the request.

Tighten the "when" clause to be Fortify-specific, e.g. "Use when the user wants to scan code for security vulnerabilities or work with Fortify findings, projects, or reports."

DimensionReasoningScore

Specificity

Names the Fortify domain but the actions ("Manage data, records, and automate workflows") are generic rather than concrete Fortify-specific operations like scan, audit, or triage vulnerabilities.

2 / 5

Completeness

Both a "what" and an explicit "when" are present, but the "what" is vague/generic which drags it below the level where both are clearly and concretely stated.

3 / 5

Trigger Term Quality

Includes a "Use when..." clause and the keyword "Fortify data", but lacks the natural terms users actually say (scan, vulnerability, security findings, audit).

3 / 5

Distinctiveness Conflict Risk

The named tool "Fortify" gives it a clear niche with minimal conflict risk, though the generic data-management action language creates minor overlap with other data skills.

4 / 5

Total

12

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.