CtrlK
BlogDocsLog inGet started
Tessl Logo

vanta

Vanta integration. Manage data, records, and automate workflows. Use when the user wants to interact with Vanta data.

64

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/vanta/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable, dominated by copy-paste-ready CLI commands and a clear connection state-machine with feedback loops. Its main weaknesses are a dangling 'Step 2' reference, missing verification for destructive proxy calls, and minor redundancy between the two action-listing sections.

Suggestions

Resolve the dangling 'Step 2' reference by explicitly labeling the next phase (e.g. '## Step 2: Discover and run actions') or removing the cross-reference.

Add a verification/check step for destructive proxy requests (e.g. dry-run or confirm before DELETE/PUT) since the proxy permits arbitrary HTTP methods.

Merge the redundant 'Searching for actions' and 'Popular actions' sections into one to remove the duplicated action-list command.

DimensionReasoningScore

Conciseness

The body is dominated by lean, executable commands and a flag table, assuming Claude's competence; only minor marketing-style padding ('so you can focus on the integration logic rather than auth plumbing', 'This will burn less tokens') keeps it just below the 5 anchor.

4 / 5

Actionability

Provides copy-paste-ready, fully executable commands for the common cases (install, login, connection ensure/get, action list/run, request) plus a flag table, matching the 5 anchor for fully executable guidance covering common cases.

5 / 5

Workflow Clarity

The connect→ready→search→run flow is well sequenced with an explicit state-machine (READY/CLIENT_ACTION_REQUIRED/CONFIGURATION_ERROR) and a poll-again feedback loop; it falls short of 5 because 'Step 2' is referenced but never labeled, and destructive proxy operations (POST/PUT/DELETE) carry no verification guidance.

4 / 5

Progressive Disclosure

As a single well-organized file with clear section headers and no nested references, structure is good; the minor redundancy between 'Searching for actions' and 'Popular actions' (both show the same list command) and lack of any split reference keeps it at 4 rather than 5.

4 / 5

Total

17

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly identifies the Vanta niche and includes an explicit 'Use when' trigger, giving it strong distinctiveness and completeness. It is held back from the top tier by generic action verbs and a single-trigger 'when' clause that omits natural compliance-related keywords.

Suggestions

Replace generic verbs with concrete capabilities, e.g. 'Pull findings, controls, and evidence; manage access requests and vendors; automate compliance workflows.'

Broaden the 'when' clause with multiple natural triggers: 'Use when the user wants to query Vanta data, review findings/controls, or automate compliance tasks (SOC 2, ISO 27001, HIPAA).'

Add the product's compliance framing as a trigger term so users referencing SOC 2/HIPAA route to this skill.

DimensionReasoningScore

Specificity

Names the Vanta domain plus a few action terms ('Manage data, records, and automate workflows'), but the actions are generic rather than concrete; it is not comprehensive, fitting the 3 anchor ('Names domain and 1-2 concrete actions') better than 2 (which would name only the domain) or 4 (which requires several specific actions).

3 / 5

Completeness

Has both a clear 'what' ('Manage data, records, and automate workflows') and an explicit 'when' ('Use when the user wants to interact with Vanta data'), matching the 4 anchor; it is not a 5 because the 'when' offers only a single trigger rather than multiple concrete trigger phrases.

4 / 5

Trigger Term Quality

Includes natural terms users would say ('Vanta', 'interact with Vanta data') with decent coverage, but misses common variations a user might actually use such as 'compliance', 'SOC 2', or 'Vanta API'; this places it above the 3 anchor (single generic keyword) but short of 5 (comprehensive synonyms/extensions).

4 / 5

Distinctiveness Conflict Risk

'Vanta integration' targets a distinct, named compliance product with a clear niche and minimal overlap with other skills, matching the 5 anchor ('Clear niche with distinct triggers; minimal conflict risk').

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.