CtrlK
BlogDocsLog inGet started
Tessl Logo

qualys

Qualys integration. Manage data, records, and automate workflows. Use when the user wants to interact with Qualys data.

64

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/qualys/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with executable commands and a sensible validated connection workflow. The main weaknesses are minor over-explanation of background concepts and a couple of inconsistent step references.

Suggestions

Remove or condense the introductory paragraph defining what Qualys is, since Claude already knows this.

Fix the step numbering: label the 'Step 2' target referenced after a READY connection, and add a '1a' or renumber the '1b. Wait for the connection' heading.

Add a brief validation note for destructive proxy methods (POST/PUT/DELETE), e.g. confirming the target resource before non-GET requests.

DimensionReasoningScore

Conciseness

The body is mostly lean executable commands, but the opening paragraph explains what Qualys is ('Qualys is a cloud-based platform for IT, security, and compliance solutions...'), which Claude already knows and could be trimmed.

4 / 5

Actionability

Copy-paste-ready commands throughout (membrane login, connection ensure, action list/run, request) plus a flags table cover the common cases fully.

5 / 5

Workflow Clarity

A clear install → auth → connect → discover → run sequence includes a polling/state feedback loop (READY/BUILDING/CLIENT_ACTION_REQUIRED), but the body references an unlabeled 'Step 2' and a '1b' with no '1a', leaving minor structural gaps.

4 / 5

Progressive Disclosure

No bundle files are present, but the single file is well-organized with clear ## sections and nothing that clearly demands separation; structure is good with only minor organization gaps.

4 / 5

Total

17

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly names the Qualys domain and includes an explicit 'Use when' trigger, with strong distinctiveness. It is held back from the top tier by generic action language and limited trigger-term variation.

Suggestions

Replace generic verbs with concrete Qualys actions, e.g. 'Query VM detections, pull asset details, and manage remediation tickets'.

Expand the 'when' clause to list natural trigger phrases users would say, such as 'Use when the user wants to query Qualys vulnerabilities, assets, detections, remediations, or tickets'.

Add common synonyms/file artifacts users mention (e.g. 'Qualys VM', 'Qualys assets', 'QID') to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

Names the Qualys domain and a couple of actions ('Manage data, records, and automate workflows'), but the actions are generic rather than the several specific concrete actions required for a 4.

3 / 5

Completeness

Both 'what' (Qualys integration managing data/records and automating workflows) and an explicit 'when' ('Use when the user wants to interact with Qualys data') are present, though the 'when' could name specific Qualys workflows to reach a 5.

4 / 5

Trigger Term Quality

'Qualys' and 'interact with Qualys data' give good keyword coverage with a natural trigger phrase, but coverage stops short of the comprehensive synonyms/extensions needed for a 5.

4 / 5

Distinctiveness Conflict Risk

'Qualys' is a clear, narrow niche with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.