CtrlK
BlogDocsLog inGet started
Tessl Logo

ibm-x-force-exchange

IBM X-Force Exchange integration. Manage data, records, and automate workflows. Use when the user wants to interact with IBM X-Force Exchange data.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/ibm-x-force-exchange/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, highly actionable guide to driving IBM X-Force Exchange through the Membrane CLI, with real commands, a feedback-looped connection-readiness workflow, and a useful actions table. Its main weaknesses are minor over-explanation and an unlabeled 'Step 2' that slightly muddies the workflow sequence.

Suggestions

Relabel or remove the dangling 'skip to Step 2' references — either add an explicit 'Step 2: Search for actions' heading or change the wording to point at the 'Searching for actions' section.

Trim the product-definition opener and editorial asides ('This is the fastest way to get a connection') to tighten token use.

Consider moving the full popular-actions table and proxy flag reference into a REFERENCES.md so the overview stays lean, signaling it with a one-level link.

DimensionReasoningScore

Conciseness

The body is mostly lean — commands, tables, and flag lists with little padding — though the opening 'IBM X-Force Exchange is a threat intelligence platform where users can research...' and some explanatory asides (e.g. 'This is the fastest way to get a connection') could be trimmed, fitting 'efficient; minor instances of over-explanation' above the score-3 anchor.

4 / 5

Actionability

It supplies copy-paste-ready commands for the full lifecycle — install, login, connection ensure/get, action list/run, and request with flags — plus a populated popular-actions table, matching 'fully executable; copy-paste ready code or commands; specific examples cover the common cases.'

5 / 5

Workflow Clarity

There is a clear install→auth→connect→search→run sequence with explicit validation checkpoints (poll until state READY, handle CLIENT_ACTION_REQUIRED, CONFIGURATION_ERROR/SETUP_FAILED, re-poll after user action), but the 'skip to Step 2' references point to no labeled Step 2 and the connection/search/run steps live under separate headers rather than one numbered flow, so it fits 'clear sequence with most checkpoints present; minor validation gaps' below the score-5 anchor.

4 / 5

Progressive Disclosure

No bundle files exist and the single SKILL.md is organized into well-labeled sections (Install, Auth, Connecting, Searching, Running, Proxy, Best practices) with no nested references, fitting 'good structure; most content appropriately placed'; the popular-actions table and proxy-flag table could arguably be split out, keeping it just below the score-5 anchor.

4 / 5

Total

17

/

20

Passed

Description

41%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description correctly names the product and includes a Use-when trigger, but its capability language is generic and it omits the concrete threat-intel actions and natural analyst keywords that would make it sharply triggerable. It is distinct yet under-specified.

Suggestions

Replace generic verbs with concrete operations, e.g. 'Look up IP/URL reputation, search CVEs, get malware reports, and resolve DNS/WHOIS via IBM X-Force Exchange.'

Add natural trigger phrases a security analyst would actually say, such as 'threat intelligence', 'IP reputation', 'CVE lookup', or 'malware hash'.

Tighten the 'when' clause to specific intents: 'Use when the user wants to research a threat, check IP/URL reputation, or look up a vulnerability in IBM X-Force Exchange.'

DimensionReasoningScore

Specificity

The description names the domain ("IBM X-Force Exchange") but the only actions given are generic — "Manage data, records, and automate workflows" — with no concrete threat-intel operations like IP/URL reputation, vulnerability lookup, or malware search, matching the 'names the domain but actions are minimal or generic' anchor and falling below the score-3 anchor which requires concrete actions.

2 / 5

Completeness

It provides an explicit "Use when the user wants to interact with IBM X-Force Exchange data" trigger (so it clears the missing-trigger cap of 3), but the 'what' is vague ("Manage data, records, and automate workflows"), keeping it at the score-3 anchor rather than score 4 whose example pairs a clear what with a Use-when clause.

3 / 5

Trigger Term Quality

The only natural keyword is the product name "IBM X-Force Exchange"; common analyst phrases like "threat intelligence", "IP reputation", "look up a CVE", or "check this URL" are absent, so it sits at 'one or two generic keywords; missing the natural phrases users say' rather than the score-3 anchor which expects relevant domain keywords.

2 / 5

Distinctiveness Conflict Risk

Naming the specific commercial product "IBM X-Force Exchange" gives it a clear niche with low overlap risk, but the generic trigger phrasing ("interact with IBM X-Force Exchange data") leaves minor ambiguity versus a sibling threat-intel skill, so it fits 'mostly distinct; minor overlap risk' rather than the fully-distinct score-5 anchor.

4 / 5

Total

11

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.