CtrlK
BlogDocsLog inGet started
Tessl Logo

veracode

Veracode integration. Manage data, records, and automate workflows. Use when the user wants to interact with Veracode data.

60

Quality

70%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/veracode/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with executable commands and a clear connection workflow including validation checkpoints, suffering only from minor over-explanation of what Veracode is and a small labeling gap in the step sequence.

DimensionReasoningScore

Conciseness

The body is mostly efficient with copy-paste commands, but the opening paragraph ('Veracode is a cloud-based application security testing platform...') explains what Veracode is, which Claude already knows and could be trimmed.

4 / 5

Actionability

It provides fully executable, copy-paste-ready commands for install, auth, connection setup, action search/run, and proxying, plus a flags table covering the common cases.

5 / 5

Workflow Clarity

The connection flow is clearly sequenced with state checkpoints (READY/BUILDING/CLIENT_ACTION_REQUIRED) and a poll-after-action feedback loop, but the referenced 'Step 2' is never labeled as a section.

4 / 5

Progressive Disclosure

No bundle files exist and the skill is self-contained with well-organized sections; structure is good though all content is inline with nothing split out.

4 / 5

Total

17

/

20

Passed

Description

57%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description has an explicit what-and-when structure and a clear niche, but its capability verbs are generic and its trigger terms lack the natural synonyms (scans, flaws, vulnerabilities) users would actually say.

Suggestions

Replace generic verbs with concrete Veracode actions, e.g. 'Manage applications, sandboxes, builds, scans, flaws, and policies.'

Expand the trigger to include natural terms users say, e.g. 'Use when the user wants to scan applications, review flaws, or manage Veracode findings.'

Tie the 'when' clause to specific Veracode workflows (policy compliance, vulnerability remediation) to sharpen distinctiveness.

DimensionReasoningScore

Specificity

Phrases like 'Manage data, records, and automate workflows' name the Veracode domain but the actions are generic verbs rather than concrete Veracode operations (e.g. scans, flaws, applications).

2 / 5

Completeness

It states what it does ('Manage data, records, and automate workflows') and gives an explicit 'Use when the user wants to interact with Veracode data' trigger, though the 'when' could be more specific.

4 / 5

Trigger Term Quality

'interact with Veracode data' provides the core keyword 'Veracode' but misses natural synonyms and variations users would say, such as scans, vulnerabilities, flaws, or application security.

3 / 5

Distinctiveness Conflict Risk

'Veracode' is a distinct product niche, so conflict risk is low; the generic 'interact with Veracode data' trigger keeps it just short of fully distinct.

4 / 5

Total

13

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.