CtrlK
BlogDocsLog inGet started
Tessl Logo

whitehat-security

WhiteHat Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with WhiteHat Security data.

56

Quality

65%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/whitehat-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with executable Membrane CLI commands and a solid connection-state workflow, but it loses points for an unnecessary explanatory intro and the absence of validation guidance around destructive proxy/action operations.

Suggestions

Trim the opening descriptive paragraph about what WhiteHat Security is; assume Claude's domain knowledge.

Add a validation/verification checkpoint before destructive proxy calls (e.g. confirm a DELETE target or dry-run a batch action) to lift the workflow-clarity cap.

Move the entity overview and proxy flag table into a referenced reference file if the skill grows, keeping SKILL.md a lean overview.

DimensionReasoningScore

Conciseness

The body is mostly efficient with concrete commands, but the opening paragraph ("WhiteHat Security is a SaaS platform focused on application security testing...") and the bare "Use action names and parameters as needed" line explain context Claude largely already knows and could be trimmed.

3 / 5

Actionability

It provides copy-paste-ready commands for every common case (install, login, connection ensure, action list/run, request) plus a flag table for proxy options, fully covering the typical workflow.

5 / 5

Workflow Clarity

The connection workflow is well-sequenced with explicit state checks and a poll-after-action feedback loop, but destructive-capable operations (the proxy DELETE example and action runs) lack validation/verification checkpoints, capping the score per the rubric.

3 / 5

Progressive Disclosure

Content is organized into clear, well-labeled sections in a single self-contained file with no bundle files to reference; minor gaps are the inline overview/entity list that adds little navigational value.

4 / 5

Total

15

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is third-person, names a clear niche brand, and includes an explicit "Use when" trigger covering both what and when. Its weakness is generic action language and a broad trigger clause that lacks security-specific keywords.

Suggestions

Replace generic verbs with concrete security actions, e.g. "Scan assets, review findings, and manage vulnerability records".

Sharpen the trigger clause with natural terms users would say, e.g. "Use when the user wants to scan for vulnerabilities or review WhiteHat findings".

Mention file/data types or entities (findings, assets, projects) to improve trigger-term coverage.

DimensionReasoningScore

Specificity

Names the domain (WhiteHat Security) and a couple of actions ("Manage data, records, and automate workflows"), but the actions are generic rather than concrete security-specific operations like scanning or finding remediation.

3 / 5

Completeness

It states both a "what" (manage data, records, automate workflows) and an explicit "Use when..." trigger, but the "when" clause is broad rather than tied to specific trigger phrases.

4 / 5

Trigger Term Quality

The natural keyword "WhiteHat Security" appears, but the trigger clause ("interact with WhiteHat Security data") is generic and misses common variations users might say such as "scan", "vulnerabilities", or "findings".

3 / 5

Distinctiveness Conflict Risk

Anchoring to the named WhiteHat Security brand gives it a clear niche with minimal conflict risk, though the generic action verbs could mildly overlap with other data-management skills.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.