CtrlK
BlogDocsLog inGet started
Tessl Logo

safebase

SafeBase integration. Manage data, records, and automate workflows. Use when the user wants to interact with SafeBase data.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/safebase/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, mostly actionable guide to driving SafeBase through the Membrane CLI, with clear sequencing and state-handling checkpoints. It would benefit from trimming the entity list and filler lines, and from adding output verification around action runs.

Suggestions

Trim the long entity bullet list to the handful a user most commonly touches, or move the full catalog to a separate reference file.

Remove filler directives like "Use action names and parameters as needed" that add tokens without instruction.

Add a brief verification step after running actions (e.g. inspect the `output` field / check for error states) to support destructive or batch operations.

DimensionReasoningScore

Conciseness

The body is mostly efficient with executable commands, but the ~30-item entity list, the SafeBase intro paragraph, and filler lines like "Use action names and parameters as needed" add unnecessary tokens.

3 / 5

Actionability

It provides concrete, copy-paste-ready CLI commands for install, login, connection, search, action runs, and proxying, with only minor gaps (abstract "QUERY" intent and unresolved CONNECTION_ID placeholders).

4 / 5

Workflow Clarity

The install→auth→connect→search→run sequence is clear with state-based checkpoints and a poll-after-action feedback loop for the connection flow, though action execution lacks explicit verification.

4 / 5

Progressive Disclosure

Content is organized into well-labeled sections with no nested references and a single external docs link, but all detail lives inline in one file with no split-out reference files.

4 / 5

Total

15

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is third-person, names the product and domain, and includes an explicit Use-when trigger, satisfying the core completeness bar. Its main weakness is generic verb choices that limit specificity and add minor overlap risk.

Suggestions

Replace generic verbs ("Manage data, records, automate workflows") with concrete SafeBase actions such as answering security questionnaires, managing Trust Center documents, and tracking vendor risk.

Expand the Use-when clause with natural trigger phrases users would say, e.g. security questionnaires, trust centers, vendor risk, or compliance reviews.

Tighten distinctiveness by referencing SafeBase-specific concepts (Trust Center, questionnaires) rather than generic "data and records".

DimensionReasoningScore

Specificity

The description names the SafeBase domain and a few actions ("Manage data, records, and automate workflows"), but the verbs are generic rather than concrete, so it does not reach comprehensive specific actions.

3 / 5

Completeness

It states both a "what" (manage data, records, automate workflows) and an explicit "when" ("Use when the user wants to interact with SafeBase data"), but the "when" could be more specific.

4 / 5

Trigger Term Quality

"SafeBase" and "interact with SafeBase data" give good keyword coverage around the named product, though natural variations (security questionnaires, trust center) are missing.

4 / 5

Distinctiveness Conflict Risk

The named product "SafeBase" gives a clear niche with minimal conflict risk, but the generic "data, records, workflows" phrasing leaves minor overlap with other data-management skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.