CtrlK
BlogDocsLog inGet started
Tessl Logo

lastpass-enterprise-api

LastPass Enterprise API integration. Manage data, records, and automate workflows. Use when the user wants to interact with LastPass Enterprise API data.

56

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/lastpass-enterprise-api/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is actionable and well-structured with strong command examples, but it carries marketing fluff and lacks validation/verification checkpoints for the destructive action-running and proxy operations.

Suggestions

Remove the marketing intro and tighten best-practices prose (e.g. drop "improve their overall security posture" and "burn less tokens") to respect the token budget.

Add an explicit verification step after running actions or proxy requests (e.g. check the `output`/response status and confirm destructive changes before proceeding), and label the referenced "Step 2" section.

De-duplicate the action-discovery guidance between "Searching for actions" and "Popular actions", or split the detailed flag reference into a separate reference file.

DimensionReasoningScore

Conciseness

Most of the body is efficient command examples and a flag table, but the opening marketing paragraph ("helps businesses streamline access management and improve their overall security posture") and padded best-practices phrasing ("burn less tokens and make communication more secure") are unnecessary explanation Claude does not need.

3 / 5

Actionability

Concrete, copy-paste-ready commands cover the core workflow (install, login, connection ensure, action list/run, request) with a flag table, leaving only minor placeholder gaps (CONNECTION_ID, actionId).

4 / 5

Workflow Clarity

The connection-readiness flow has good polling checkpoints, but the destructive action-running and proxy (POST/DELETE) flows lack any verification step, which caps workflow clarity at 3; additionally "Step 2" is referenced but never labeled as a section.

3 / 5

Progressive Disclosure

The single-file body is well organized with clear section headers and no bundle files, but it is longer than a lean overview and contains minor redundancy between "Searching for actions" and "Popular actions".

4 / 5

Total

14

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is third-person, has an explicit "Use when…" trigger, and names a clearly distinct niche, but its action vocabulary is generic and it omits natural synonyms users would say for a password-management/SSO API.

Suggestions

Replace generic verbs ("Manage data, records") with concrete LastPass actions such as "provision users, manage password policies, and configure shared folders".

Add natural trigger synonyms to the "Use when" clause, e.g. "password management, single sign-on (SSO), user provisioning, or shared folder administration".

Tighten the when-clause to enumerate the specific Enterprise API tasks that should trigger the skill.

DimensionReasoningScore

Specificity

Names the domain (LastPass Enterprise API) and a few action categories ("Manage data, records, and automate workflows"), but the action terms are generic rather than concrete, falling between anchor 2 (minimal/generic actions) and anchor 4 (several specific actions).

3 / 5

Completeness

Both "what" (integration that manages data/records and automates workflows) and an explicit "Use when…" trigger are present, but the when clause is narrow and lacks the richer concrete trigger phrases that anchor 5 requires.

4 / 5

Trigger Term Quality

It includes relevant keywords ("LastPass Enterprise API", "interact with LastPass Enterprise API data") but misses common natural synonyms a user would say such as password management, SSO, single sign-on, or user provisioning.

3 / 5

Distinctiveness Conflict Risk

It names a specific commercial product/API (LastPass Enterprise API) with a distinct trigger ("interact with LastPass Enterprise API data"), giving it a clear niche with minimal conflict risk against other skills.

5 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.