CtrlK
BlogDocsLog inGet started
Tessl Logo

shiftleft

ShiftLeft integration. Manage data, records, and automate workflows. Use when the user wants to interact with ShiftLeft data.

59

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/shiftleft/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill body is highly actionable with executable CLI commands and a clear connection workflow including polling-based validation. Its weaknesses are mild verbosity in the intro/auth prose and a broken 'Step 2' cross-reference that slightly harms workflow navigation.

Suggestions

Remove filler prose such as 'so you can focus on the integration logic rather than auth plumbing' and tighten the ShiftLeft intro paragraph to one line.

Fix the broken 'Step 2' cross-reference by either labeling a Step 2 section (searching/running actions) or rewording to 'skip to Searching for actions'.

Consider moving the detailed clientAction state reference and the proxy flags table into a references/ file to shorten the main SKILL.md and improve progressive disclosure.

DimensionReasoningScore

Conciseness

The body is mostly efficient commands with brief explanations, but includes unnecessary prose such as 'so you can focus on the integration logic rather than auth plumbing' and a padded intro paragraph about what ShiftLeft is, matching 'mostly efficient but includes some unnecessary explanation'; not 4 because several sentences could be trimmed without losing clarity.

3 / 5

Actionability

It provides copy-paste-ready, fully executable commands across install, auth, connection, action search/run, and proxy, plus a flags table, matching 'fully executable; copy-paste ready code or commands; specific examples cover the common cases'.

5 / 5

Workflow Clarity

The connection flow is sequenced with polling and explicit state checks (READY / CLIENT_ACTION_REQUIRED / CONFIGURATION_ERROR) acting as validation checkpoints and a feedback loop, matching 'clear sequence with most checkpoints present'; not 5 because the prose references 'Step 2' which is never labeled, leaving a minor navigation gap.

4 / 5

Progressive Disclosure

Content is organized into clear, well-labeled sections (Overview, Authentication, Connecting, Searching, Popular actions, Best practices) with no bundle files needed and no nested references, matching 'good structure; most content appropriately placed'; not 5 because at ~145 lines some material (detailed clientAction handling, the proxy flags table) could be split into a reference file.

4 / 5

Total

16

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description covers both what the skill does and when to use it, anchored to a distinct named product. Its main weakness is generic action language and limited trigger-term variety, which keep specificity and trigger quality at mid-range.

Suggestions

Replace generic verbs ('Manage data, records, and automate workflows') with concrete ShiftLeft-specific actions (e.g., 'list findings, scan projects, manage policies and code locations').

Expand the trigger clause with natural variations users would say, e.g., 'Use when the user wants to query ShiftLeft findings, run scans, or manage ShiftLeft projects and policies.'

Add file-format or object terms users actually mention (findings, scans, policies, pull requests) to improve trigger-term coverage.

DimensionReasoningScore

Specificity

Names the domain (ShiftLeft) and a couple of actions ('Manage data, records, and automate workflows'), but the actions are generic rather than concrete, matching the 'names domain and 1-2 concrete actions but not comprehensive' anchor; not a 2 because it does list multiple action verbs, not a 4 because none are specific.

3 / 5

Completeness

Both 'what' ('Manage data, records, and automate workflows') and 'when' ('Use when the user wants to interact with ShiftLeft data') are present, but the trigger is somewhat generic, matching 'has both what and when; when could be more explicit'; not 5 because the trigger phrases are not concrete and varied.

4 / 5

Trigger Term Quality

The phrase 'Use when the user wants to interact with ShiftLeft data' provides the natural product-name trigger but lacks synonyms or variations, fitting 'some relevant keywords but missing common variations'.

3 / 5

Distinctiveness Conflict Risk

Tying the trigger to the specific named product ShiftLeft gives it a clear niche with minor overlap risk, matching 'mostly distinct; minor overlap risk'; not 5 because the action description ('manage data, records') is generic and could overlap with other data-management skills.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.