CtrlK
BlogDocsLog inGet started
Tessl Logo

sonatype

Sonatype integration. Manage data, records, and automate workflows. Use when the user wants to interact with Sonatype data.

58

Quality

68%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/sonatype/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable CLI integration guide with copy-paste commands and a clear connection-state workflow, weakened mainly by an unnecessary introductory paragraph explaining what Sonatype is. Fixing the inconsistent step numbering and trimming conceptual padding would push it higher.

Suggestions

Delete or condense the opening 'Sonatype provides software composition analysis...' paragraph; Claude already knows what Sonatype is.

Reconcile the workflow numbering (label '1a' or remove the '1b'/'Step 2' references) so the connect→ready sequence is unambiguous.

Drop filler lines like 'Use action names and parameters as needed.' that add no executable guidance.

DimensionReasoningScore

Conciseness

The opening paragraph ('Sonatype provides software composition analysis, helping developers and security teams manage open source risk...') explains a concept Claude already knows, and filler like 'Use action names and parameters as needed.' adds little, so it is mostly efficient but includes unnecessary explanation per the 3 anchor.

3 / 5

Actionability

It provides fully executable, copy-paste-ready commands for every common case (install, login, connection ensure, action list, action run, request) plus a flags table, matching the 'fully executable; copy-paste ready' anchor.

5 / 5

Workflow Clarity

There is a clear install→authenticate→connect→poll-until-ready→search→run sequence with state-based checkpoints (READY/BUILDING/CLIENT_ACTION_REQUIRED) and a poll-again feedback loop, but the step numbering is inconsistent (a '1b' with no '1a', references to an unlabeled 'Step 2'), leaving minor gaps short of a 5.

4 / 5

Progressive Disclosure

The single-file CLI guide is well-organized into clearly signaled sections (Install, Authentication, Connecting, Searching, Running, Proxy, Best practices) with no need for external references, matching the 'good structure; most content appropriately placed' anchor; it does not reach 5 only because some reference-style detail (e.g., the full flags table, clientAction schema) could optionally live in a separate file.

4 / 5

Total

16

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly signals its distinct Sonatype niche and provides an explicit 'Use when' trigger, but its capability list is generic ('manage data, records, automate workflows') rather than concrete. Tightening the action verbs to specific Sonatype capabilities would lift specificity and trigger-term coverage.

Suggestions

Replace generic verbs with concrete Sonatype capabilities (e.g., 'scan dependencies for vulnerabilities, review license compliance, search component repositories').

Add natural trigger synonyms beyond 'Sonatype data', such as 'open source risk', 'dependency vulnerabilities', or 'software composition analysis'.

Keep the explicit 'Use when...' clause but tie it to specific user intents like auditing dependencies or checking component licenses.

DimensionReasoningScore

Specificity

The description names the Sonatype domain but its actions are generic ('Manage data, records, and automate workflows') rather than concrete Sonatype-specific capabilities, matching the 'names the domain but actions are minimal or generic' anchor and falling below the 1-2 concrete actions needed for a 3.

2 / 5

Completeness

It states both a 'what' ('Sonatype integration. Manage data, records, and automate workflows.') and an explicit 'when' ('Use when the user wants to interact with Sonatype data.'), but the 'what' is generic, so it does not reach the concrete-trigger-phrases bar of a 5.

4 / 5

Trigger Term Quality

'Sonatype' and 'Sonatype data' are relevant natural keywords, but the description offers no common variations or synonyms, matching the 'some relevant keywords but missing common variations' anchor rather than the fuller coverage of a 4.

3 / 5

Distinctiveness Conflict Risk

'Sonatype integration' names a specific product with a clear niche and distinct trigger, giving minimal conflict risk with other skills, matching the 'clear niche with distinct triggers' anchor.

5 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.