CtrlK
BlogDocsLog inGet started
Tessl Logo

jupiterone

JupiterOne integration. Manage data, records, and automate workflows. Use when the user wants to interact with JupiterOne data.

57

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/jupiterone/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, command-driven guide with strong actionability and clear connection-state validation/feedback loops. Main weaknesses are mild verbosity in the intro/overview prose, inconsistent step numbering, and a duplicated action-discovery command.

Suggestions

Trim the marketing-style intro paragraph and remove the vague 'JupiterOne Overview' bullets plus the filler line 'Use action names and parameters as needed.'

Fix step numbering so referenced anchors ('Step 2', a '1a' before '1b') actually exist and are labeled consistently.

Deduplicate the action-discovery command shown in both 'Searching for actions' and 'Popular actions', keeping one canonical example.

DimensionReasoningScore

Conciseness

Most sections are lean command blocks, but there are several instances of tightening needed: the marketing-style intro ("cybersecurity asset management platform that helps organizations understand and manage their cyber assets"), the vague "JupiterOne Overview" bullets, filler ("Use action names and parameters as needed"), and a repeated action-list command; this matches 'mostly efficient but includes some unnecessary explanation,' not a 4 because the padding is more than minor.

3 / 5

Actionability

Concrete executable commands throughout ("npm install -g @membranehq/cli@latest", "membrane connection ensure", "membrane action run", "membrane request") plus a full proxy-options table give mostly copy-paste-ready guidance with placeholder gaps; not a 5 because examples don't walk through a complete common case end-to-end (e.g., a sample query run with real output).

4 / 5

Workflow Clarity

There is a clear sequence (install -> authenticate -> connect -> poll for READY -> search actions -> run) with explicit validation checkpoints (state polling via --wait, CLIENT_ACTION_REQUIRED handling, CONFIGURATION_ERROR/SETUP_FAILED error paths); not a 5 because step numbering is inconsistent (a "1b" with no 1a, references to an unlabeled "Step 2"), leaving minor sequencing gaps.

4 / 5

Progressive Disclosure

No bundle files exist and the single ~140-line SKILL.md is organized with clear section headers (Install, Authentication, Connecting, Searching, Popular actions, Best practices) and one-level navigation; not a 5 because some inline material (the proxy options table, the duplicated action-discovery block) could be tightened or split, and not a 3 because structure is genuinely good rather than merely present.

4 / 5

Total

15

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description answers both 'what' and 'when' with an explicit 'Use when...' clause and names a distinct product niche, keeping conflict risk low. Weaknesses are generic action verbs ('manage data/records') and thin trigger-term coverage beyond the product name.

Suggestions

Replace generic verbs with specific capabilities, e.g. "Query cyber assets and relationships, run saved searches, and automate compliance workflows."

Broaden trigger terms to natural user phrasings like "cyber assets, asset relationships, security compliance, or JupiterOne queries."

DimensionReasoningScore

Specificity

Quotes "Manage data, records, and automate workflows" name the JupiterOne domain plus 1-2 concrete-but-generic actions, matching the anchor for domain + 1-2 actions without comprehensive coverage; not a 2 because actions are named beyond the bare domain, not a 4 because "manage data/records" is too generic to count as several specific actions.

3 / 5

Completeness

"Manage data, records, and automate workflows" answers 'what' and "Use when the user wants to interact with JupiterOne data" answers 'when', matching the anchor with both present but 'when' somewhat generic; the 'Use when...' clause is explicit so it is not capped at 3, and not a 5 because the trigger phrasing lacks concrete concrete trigger examples.

4 / 5

Trigger Term Quality

The phrase "Use when the user wants to interact with JupiterOne data" surfaces the natural product keyword "JupiterOne" but misses common variations, synonyms, or asset-management phrasings users might say; not a 2 because a real natural term is present, not a 4 because coverage is thin beyond the product name.

3 / 5

Distinctiveness Conflict Risk

JupiterOne is a specific named cybersecurity asset-management product, giving a clear niche with distinct triggers and minimal conflict risk, matching the highest anchor; voice is third person ("Manage", "Use when the user wants") so no voice penalty applies.

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.