CtrlK
BlogDocsLog inGet started
Tessl Logo

security-journey

Security Journey integration. Manage data, records, and automate workflows. Use when the user wants to interact with Security Journey data.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/security-journey/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a strong, actionable integration guide with executable commands and a well-validated connection state machine. Its main weaknesses are minor conciseness padding and a dangling 'Step 2' cross-reference that slightly muddies the workflow sequence.

Suggestions

Resolve the dangling 'skip to Step 2' reference by either labeling the next section 'Step 2: Search for actions' or rewording to 'skip to Searching for actions'.

Trim marketing filler such as 'so you can focus on the integration logic rather than auth plumbing' to tighten token efficiency.

Add a brief validation note for `action run` and `membrane request` outputs (e.g. check the `output`/response field and HTTP status) to close the workflow-clarity gap for proxy operations.

DimensionReasoningScore

Conciseness

The body is mostly lean, command-driven content that assumes Claude's competence, with only minor padding such as 'so you can focus on the integration logic rather than auth plumbing' and the marketing-flavored best-practice framing.

4 / 5

Actionability

It provides copy-paste-ready, fully executable commands for the common cases (install, login, connection ensure, action list/run, proxy) with concrete examples and a thorough proxy-flag table, matching the 'fully executable; copy-paste ready' anchor.

5 / 5

Workflow Clarity

The connection flow has explicit state-based validation (READY/BUILDING/CLIENT_ACTION_REQUIRED/CONFIGURATION_ERROR) and a re-poll feedback loop, but the dangling 'skip to Step 2' reference and absence of output-validation guidance for run/proxy operations are minor gaps keeping it below 5.

4 / 5

Progressive Disclosure

Content is well-organized into clearly headed sections (Overview, Authentication, Connecting, Searching, Running, Proxy, Best practices) with easy navigation and no nested references; with no bundle files present, structure is good though some inline detail (e.g. the proxy flag table, connection states) could live in a reference.

4 / 5

Total

17

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is functional and includes an explicit trigger tied to a named platform, but its capability language is generic boilerplate ('manage data, records, and automate workflows') rather than concrete actions. Strengthening the action list with specific Security Journey operations would lift specificity and trigger quality.

Suggestions

Replace generic verbs with concrete Security Journey actions, e.g. 'Manage organizations, users, courses, enrollments, modules, and learning paths; run reports and assignments.'

Expand the trigger with natural synonyms users actually say, e.g. 'Use when the user wants to manage Security Journey training, courses, enrollments, or pull security training reports.'

Tie the 'when' clause to the specific entities in the body (Course, Enrollment, Track, Report) so it doubles as a trigger-term and distinctiveness signal.

DimensionReasoningScore

Specificity

The description names the Security Journey domain but the listed actions ('Manage data, records, and automate workflows') are generic verbs with no concrete operations, matching the 'actions are minimal or generic' anchor rather than the concrete-actions anchor above.

2 / 5

Completeness

Both a 'what' ('Manage data, records, and automate workflows') and an explicit 'Use when the user wants to interact with Security Journey data' trigger are present, but the 'when' could be more specific, matching the 'has both what and when; when could be more explicit' anchor.

4 / 5

Trigger Term Quality

It surfaces the dominant natural keyword 'Security Journey' and 'data' in the trigger clause, but lacks common variations or synonyms a user might say, fitting 'some relevant keywords but missing common variations'.

3 / 5

Distinctiveness Conflict Risk

Naming the specific Security Journey platform gives a clear niche with low wrong-skill trigger risk, but the generic 'manage data, records, and automate workflows' framing creates minor overlap with other data-integration skills, so it is not a pristine niche.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.