CtrlK
BlogDocsLog inGet started
Tessl Logo

nessus

Nessus integration. Manage data, records, and automate workflows. Use when the user wants to interact with Nessus data.

55

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/nessus/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a well-structured, actionable guide built around concrete Membrane CLI commands with a clear state-polling connection workflow. Trimming the introductory concept explanation and the duplicated action-list section, plus fixing the inconsistent step numbering, would improve it.

Suggestions

Remove or shorten the opening paragraph explaining what Nessus is, since Claude already knows this; lead with the integration mechanics instead.

Consolidate the duplicated action-discovery commands ("Searching for actions" and "Popular actions") into a single section.

Reconcile the "Step 2" and "1b" references with actual section headers, or relabel sections as explicit numbered steps for a cleaner sequence.

DimensionReasoningScore

Conciseness

The body is mostly efficient command-driven guidance, but the opening paragraph explains what Nessus is (a concept Claude already knows) and the action-list command appears redundantly in two sections.

3 / 5

Actionability

It provides concrete, copy-paste-ready membrane commands with flags for login, connection, action discovery, action execution, and proxying, with only minor gaps like generic input placeholders and no Nessus-specific action example.

4 / 5

Workflow Clarity

The connection flow has clear state-based branching (READY, CLIENT_ACTION_REQUIRED, CONFIGURATION_ERROR) with a re-poll feedback loop, but cross-references like "Step 2" and "1b" are inconsistently labeled relative to the actual section headers.

4 / 5

Progressive Disclosure

No bundle files exist, but the single file is well-organized into clear sections (overview, install, auth, connecting, actions, proxy, best practices) with only minor redundancy that could be tightened.

4 / 5

Total

15

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly identifies the Nessus niche and includes an explicit use-when trigger, but the capability description relies on generic verbs rather than concrete vulnerability-management actions. Adding specific actions and trigger synonyms would raise specificity and trigger quality.

Suggestions

Replace generic verbs with concrete Nessus actions, e.g. "Launch vulnerability scans, review scan results, and manage scan configurations."

Add natural trigger synonyms users would say, such as "vulnerability scan," "security scan," "Tenable," or "scan results."

Make the "Use when" clause more specific, e.g. "Use when the user wants to run or review Nessus vulnerability scans."

DimensionReasoningScore

Specificity

The description names the Nessus domain but the actions ("Manage data, records, and automate workflows") are generic rather than concrete operations like scanning or reporting, matching the anchor for minimal/generic actions.

2 / 5

Completeness

Both a "what" (Nessus integration, manage data/records/workflows) and an explicit "Use when the user wants to interact with Nessus data" trigger are present, though neither is highly specific.

4 / 5

Trigger Term Quality

"Nessus" is a strong domain keyword and "interact with Nessus data" is a usable phrase, but common synonyms like vulnerability scanning, security scans, or Tenable are missing.

3 / 5

Distinctiveness Conflict Risk

"Nessus" is a distinct named product giving a clear niche with minimal conflict risk, though the generic "manage data, records" phrasing creates slight overlap with other data skills.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.