CtrlK
BlogDocsLog inGet started
Tessl Logo

imperva

Imperva integration. Manage data, records, and automate workflows. Use when the user wants to interact with Imperva data.

52

Quality

59%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/imperva/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a largely actionable integration guide built around concrete Membrane CLI commands and useful connection-state guidance. Its weaknesses are concept-padding in the intro, an undefined "Step 2" reference, and missing validation/feedback loops for destructive proxy operations.

Suggestions

Remove the opening paragraph defining what Imperva is and the filler line "Use action names and parameters as needed"; merge the redundant "Popular actions" section into "Searching for actions".

Define the repeatedly-referenced "Step 2" (or reword the "skip to Step 2" jumps) so the connection→action flow is coherent.

Add a validation/verify step after `membrane action run` and before destructive proxy calls (e.g., check the `output`/error fields, confirm before `--method DELETE`) to establish a feedback loop.

DimensionReasoningScore

Conciseness

The bulk is efficient concrete CLI commands, but the opening paragraph explaining what Imperva is, the filler "Use action names and parameters as needed", and the duplicated "Popular actions" section add unnecessary explanation that could be trimmed.

3 / 5

Actionability

Copy-paste-ready commands cover the common cases (login, connection ensure, connection get --wait, action list, action run, request proxy) with a flags table, but placeholders like CONNECTION_ID and the bare proxy example leave minor gaps.

4 / 5

Workflow Clarity

The install→authenticate→connect→poll→search→run flow is sequenced with connection-state checkpoints, but destructive-capable proxy requests (DELETE/PUT) lack validation steps and the document repeatedly references an undefined "Step 2", so it cannot exceed the validation cap of 3.

3 / 5

Progressive Disclosure

The single file is well-sectioned with clear headers and no nested references, and no bundle files exist to verify; minor gaps (the redundant Popular actions section and the absent Step 2) keep it just below the top anchor.

4 / 5

Total

14

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description correctly pairs a "Use when…" trigger with a stated purpose and leans on a distinct product name for low conflict risk. Its main weakness is generic action language ("manage data, records, automate workflows") that lacks concrete capabilities.

Suggestions

Replace "Manage data, records, and automate workflows" with 2-3 concrete Imperva actions (e.g., "view security events, inspect WAF attack analytics, update bot protection rules").

Expand the trigger clause with natural synonyms users might say (e.g., "Use when the user mentions Imperva, Incapsula, WAF events, or attack analytics").

Add a file-type or entity cue (e.g., sites, security events) to sharpen distinctiveness against generic data skills.

DimensionReasoningScore

Specificity

The description names the Imperva domain but its actions are generic ("Manage data, records, and automate workflows") rather than concrete operations, matching the anchor for naming a domain with minimal/generic actions.

2 / 5

Completeness

Both a "what" (Imperva integration; manage data, records, automate workflows) and an explicit "when" ("Use when the user wants to interact with Imperva data") are present, but the "what" is generic rather than concrete, so it sits just below the top anchor.

4 / 5

Trigger Term Quality

"Use when the user wants to interact with Imperva data" includes the natural keyword "Imperva", but coverage is thin with no synonyms or common variations, fitting the anchor for some relevant keywords missing variations.

3 / 5

Distinctiveness Conflict Risk

Imperva is a specific named product giving a clear niche and distinct trigger, but the generic "manage data, records" phrasing carries minor overlap risk with other data-management skills.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.