CtrlK
BlogDocsLog inGet started
Tessl Logo

rapid7-insight-platform

Rapid7 Insight Platform integration. Manage Users, Roles, Organizations, Assets, Vulnerabilities, Findings and more. Use when the user wants to interact with Rapid7 Insight Platform data.

65

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/rapid7-insight-platform/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced integration guide anchored in executable Membrane CLI commands with strong connection-state feedback loops. Its main weaknesses are inlined reference-grade detail that should be split out and the absence of explicit post-action verification for destructive operations.

Suggestions

Move the proxy flags table and connection state-machine detail into reference files (e.g., REFERENCE.md) referenced one level deep from the overview.

Add an explicit verification step after running actions (e.g., check the response status/output before declaring success), especially for destructive or batch operations.

Trim the overview paragraph and de-duplicate the action-list command between 'Searching for actions' and 'Popular actions'.

DimensionReasoningScore

Conciseness

Largely operational and command-driven with only minor padding (the platform overview paragraph, the 'Popular actions' section restating the search command, and light marketing phrasing in best practices).

4 / 5

Actionability

Provides copy-paste-ready, fully executable commands throughout (install, login, connection ensure/get with --wait, action list/run with --input, request with a full flags table), covering the common cases with concrete placeholders.

5 / 5

Workflow Clarity

Clear sequence from install through login, connection ensure, state polling with explicit feedback loops (READY/CLIENT_ACTION_REQUIRED/CONFIGURATION_ERROR), and action discovery/run; the only gap is a lack of explicit result-verification after running potentially destructive actions.

4 / 5

Progressive Disclosure

The body is well-sectioned but inlines substantial reference-grade detail (the connection state machine, the proxy flags table, auth variants) that, for a skill this long, would be better split into one-level-deep reference files; no reference structure exists.

3 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid, third-person description that names the product, lists concrete managed objects, and includes an explicit 'Use when' clause. It is held back from the top by a generic trigger phrase and the open-ended 'and more' hedge.

Suggestions

Replace 'and more' with a few more concrete managed objects or drop the hedge to strengthen specificity.

Expand the 'Use when' clause with concrete trigger phrases (e.g., 'when the user mentions Rapid7, InsightVM, vulnerabilities, or findings').

Add common synonyms/extensions like 'InsightVM' to broaden natural trigger coverage.

DimensionReasoningScore

Specificity

Lists several concrete capabilities ('Manage Users, Roles, Organizations, Assets, Vulnerabilities, Findings') but relies on a single verb ('Manage') plus an open-ended 'and more' hedge, leaving minor coverage gaps that keep it just below comprehensive.

4 / 5

Completeness

Explicitly answers both 'what' (manage the listed platform objects) and 'when' ('Use when the user wants to interact with Rapid7 Insight Platform data'), but the trigger clause is somewhat generic rather than enumerating concrete trigger phrases.

4 / 5

Trigger Term Quality

Includes the natural product name 'Rapid7 Insight Platform' and domain terms (Vulnerabilities, Findings, Assets) users would say, but omits common synonyms like 'InsightVM' or 'vulnerability management'.

4 / 5

Distinctiveness Conflict Risk

Targets a clearly named, niche commercial product ('Rapid7 Insight Platform') with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.