CtrlK
BlogDocsLog inGet started
Tessl Logo

pangea

Pangea integration. Manage data, records, and automate workflows. Use when the user wants to interact with Pangea data.

61

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/pangea/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with copy-paste-ready CLI commands, a clear sequenced workflow, and built-in validation/polling checkpoints; its main weaknesses are minor verbosity in the intro and service catalog and an unlabeled "Step 2" reference.

Suggestions

Label the post-connection section explicitly as "Step 2" (or renumber consistently) so the "skip to Step 2" reference resolves to a real heading.

Trim the opening "Pangea is a security platform for developers..." sentence and consider moving the exhaustive service catalog into a separate reference file referenced from the overview.

Add an explicit verification checkpoint after `membrane action run` (e.g. checking the `output` field for errors) to close the run-action feedback loop.

DimensionReasoningScore

Conciseness

The body is mostly lean and command-focused, assuming Claude's competence, with only minor over-explanation (the opening "Pangea is a security platform for developers..." sentence and the exhaustive inline service catalog) that could be trimmed, fitting the efficient-with-minor-padding anchor.

4 / 5

Actionability

It provides fully executable, copy-paste-ready commands for every common case (install, login, connection ensure/get, action list/run, request proxy) plus a concrete flags table, matching the anchor for fully executable guidance covering common cases.

5 / 5

Workflow Clarity

The sequence (install → authenticate → connect → poll until ready → search → run → proxy fallback) is clear with validation checkpoints and a feedback loop (re-poll after CLIENT_ACTION_REQUIRED, error handling for CONFIGURATION_ERROR/SETUP_FAILED), but the "skip to Step 2" reference points to an unlabeled section, a minor gap fitting the clear-sequence-with-most-checkpoints anchor.

4 / 5

Progressive Disclosure

No bundle files exist, so this scores the single-file structure: content is well-organized into clear sections with good navigation, though the inline service catalog and flags reference could arguably live in separate files, fitting the good-structure-with-minor-organization-gaps anchor.

4 / 5

Total

17

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description correctly answers both what and when with an explicit "Use when" trigger and is anchored to a distinct branded platform, but its action verbs are generic and the trigger phrasing lacks concrete synonyms or variations.

Suggestions

Replace generic verbs ("Manage data, records, and automate workflows") with concrete Pangea-specific actions such as audit logging, secret vaulting, redaction, or intel lookups.

Expand the "Use when" clause with concrete trigger phrases users would actually say, e.g. "Use when the user wants to audit events, store secrets in a vault, redact text, or look up reputation for IPs, URLs, domains, or files."

Add common synonyms and the service family names so the trigger covers natural variations users might request.

DimensionReasoningScore

Specificity

It names the domain ("Pangea integration") and lists several actions ("Manage data, records, and automate workflows"), but the verbs are generic rather than concrete, fitting the anchor that names a domain with a few non-comprehensive actions.

3 / 5

Completeness

Both "what" ("Manage data, records, and automate workflows") and "when" ("Use when the user wants to interact with Pangea data") are explicitly present, but the "when" clause is fairly generic rather than listing concrete trigger phrases, fitting the anchor where both exist yet "when" could be more specific.

4 / 5

Trigger Term Quality

The natural trigger is essentially the brand name plus "interact with Pangea data"; there is some relevant keyword coverage but no synonyms or variations beyond the brand, matching the anchor with relevant-but-limited keywords.

3 / 5

Distinctiveness Conflict Risk

The branded "Pangea" name gives it a clear niche with low conflict risk, but the generic action language ("manage data, records, automate workflows") creates minor overlap with broad data-management skills, fitting the "mostly distinct; minor overlap risk" anchor.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.