CtrlK
BlogDocsLog inGet started
Tessl Logo

whitesource

WhiteSource integration. Manage data, records, and automate workflows. Use when the user wants to interact with WhiteSource data.

49

Quality

54%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/whitesource/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, mostly executable guide to driving WhiteSource via the Membrane CLI, with a clear connection workflow and validation checkpoints. It loses points for an unnecessary introductory explainer about what WhiteSource is and an under-populated entity list that adds little actionable value.

Suggestions

Remove or condense the opening paragraph defining WhiteSource/Mend; Claude already knows this and it competes with context budget.

Trim the bare entity tree (Alert/Project/Product/...) unless each node is tied to a concrete action or command, as it currently reads as padding.

Fix the dangling 'Step 2' reference by labeling the workflow steps consistently so the sequence is unambiguous.

DimensionReasoningScore

Conciseness

The body is mostly efficient with executable CLI commands, but the opening paragraph explaining what WhiteSource/Mend is and who uses it is unnecessary context Claude already knows, and the entity tree is bare padding.

3 / 5

Actionability

It provides concrete, executable `membrane` commands for install, login, connection, action search/run, and proxy requests, with minor gaps such as placeholder CONNECTION_ID values left for the agent to fill.

4 / 5

Workflow Clarity

The connection flow is clearly sequenced (ensure -> wait/poll -> READY/CLIENT_ACTION_REQUIRED/ERROR branches) with explicit polling validation, though step labels are slightly inconsistent (references to 'Step 2' with no labeled Step 2).

4 / 5

Progressive Disclosure

Content is well-organized into headed sections (Authentication, Connecting, Searching, Running actions, Proxy, Best practices) with no bundle files to offload to; structure is clear and navigable for a single-file skill.

4 / 5

Total

15

/

20

Passed

Description

43%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is short, third-person, and product-scoped, but its capabilities are stated generically ('manage data, records, automate workflows') without naming concrete WhiteSource operations. It includes an explicit 'Use when' trigger, though the trigger phrasing is broad.

Suggestions

Replace generic verbs with concrete WhiteSource actions, e.g. 'query vulnerabilities, manage projects and products, pull inventory and license reports'.

Broaden trigger terms to include natural synonyms a user would say, such as 'Mend', 'open source vulnerabilities', or 'SCA'.

Tighten the 'Use when' clause with concrete scenarios like 'when the user asks about vulnerable dependencies or open source license compliance'.

DimensionReasoningScore

Specificity

It names the domain ('WhiteSource integration') but actions are minimal and generic ('Manage data, records, and automate workflows') with no concrete WhiteSource-specific operations listed.

2 / 5

Completeness

A clear 'what' is present ('Manage data, records, and automate workflows') with an explicit 'when' clause ('Use when the user wants to interact with WhiteSource data'), but the 'when' trigger is generic rather than concrete.

3 / 5

Trigger Term Quality

'WhiteSource data' is the only natural keyword; it covers the primary term but misses common variations like 'Mend', 'vulnerabilities', 'open source security', or file extensions users might say.

3 / 5

Distinctiveness Conflict Risk

'WhiteSource' names a specific product niche distinct from most skills, with only minor overlap risk against general data-management skills; the trigger is product-scoped.

4 / 5

Total

12

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
membranedev/application-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.