CtrlK
BlogDocsLog inGet started
Tessl Logo

build-zoom-rest-api-app

Use when calling REST APIs.

44

Quality

45%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/zoom/skills/rest-api/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is admirably lean and correctly structured as an overview-plus-references, but it stops one level short of executable: no code, commands, or endpoint specifics, no validation checkpoints in the workflow, and a reference section whose links are 40% broken while the majority of the bundle goes unlisted. Conciseness is exemplary; the failures are actionability and navigation.

Suggestions

Fix the dangling references: the three dead links (concepts/api-architecture.md, concepts/authentication-flows.md, troubleshooting/token-scope-playbook.md) either need to be created or repointed at the actual files (e.g. references/authentication.md, references/full-guide.md), and consider indexing the other ~30 unlisted bundle files so they are discoverable.

Add at least one executable anchor to the body — e.g. the OAuth token endpoint, a minimal curl/code snippet for an authenticated call with pagination, or the webhook signature-verification recipe — so the workflow's step 4 is demonstrable rather than descriptive.

Insert validation checkpoints into the workflow: verify token audience/scopes before the first write call, and verify webhook signature before processing any event, with a retry/fix loop for failures (the feedback-loop the rubric expects for risky write operations).

DimensionReasoningScore

Conciseness

The body is a lean 28-line overview: one scoping sentence, six tightly written workflow steps, and a link list — no explanation of concepts Claude already knows, no padding, no filler. Every token earns its place, matching anchor 5 ("Lean and efficient; assumes Claude's competence"); it shows none of the over-explanation that would drop it to 4.

5 / 5

Actionability

The workflow gives real, specific direction ("user-level OAuth for user-owned resources", "check token audience, missing scopes... rate-limit headers", "signature verification and replay protection") but contains no executable detail — no endpoint names, base URL, token-flow commands, or code, and the auth guidance defers specifics to reference files that don't resolve. This lands between anchor 2 (high-level hints) and anchor 4 (mostly executable): anchor 3's "some concrete guidance but incomplete; missing key details" is the best fit.

3 / 5

Workflow Clarity

The six steps form a clear, sensibly ordered sequence (define resource → pick endpoint/scopes → confirm auth → implement → webhooks → debug), which exceeds anchor 2's "rough sequence with gaps". But there are no explicit validation checkpoints — nothing like "verify token/scopes before the first call" or "verify webhook signature before processing" — and step 6's debug list is a symptom checklist, not a validate-fix-retry loop, matching anchor 3 ("sequence present but checkpoints missing or implicit").

3 / 5

Progressive Disclosure

The split itself is right: a concise overview with one-level-deep, clearly labeled links per topic, which is anchor-4 behavior. But scored against the actual bundle, 3 of the 8 links (concepts/api-architecture.md, concepts/authentication-flows.md, troubleshooting/token-scope-playbook.md) point to paths that do not exist, and roughly 30 real bundle files (authentication.md, accounts.md, team-chat.md, phone.md, etc.) are never surfaced — navigation is broken and incomplete, which drags it to anchor 3 ("some structure but could be better organized").

3 / 5

Total

14

/

20

Passed

Description

25%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a one-line generic trigger with no mention of Zoom, no statement of what the skill does, and trigger terms so broad they would capture every REST API task. It is the minimum viable "when" clause and nothing else.

Suggestions

State the "what": name the concrete actions, e.g. "Manages Zoom meetings, webinars, recordings, users, and account resources via the Zoom REST API, covering OAuth user- and account-level authentication, pagination, rate limits, and webhook verification."

Add Zoom-specific trigger terms users would actually say — "Zoom", "Zoom API", "create a Zoom meeting", "Zoom OAuth", "Zoom webhooks" — instead of the generic "calling REST APIs".

Rewrite in the pattern of the good examples: capability sentence first, then "Use when working with Zoom meetings, webinars, recordings, or Zoom account/user administration from application code."

DimensionReasoningScore

Specificity

The only text is "Use when calling REST APIs" — it names a domain (REST APIs) with the single generic action of "calling", and lists zero of the skill's actual capabilities (Zoom meetings, webinars, recordings, users, auth, webhooks). This matches anchor 2 ("Names the domain but actions are minimal or generic", e.g. "Processes PDF files") rather than anchor 1, because the domain is at least identified and an action is implied; it is not anchor 3 since no concrete Zoom-specific actions are named.

2 / 5

Completeness

A "when" clause is present ("Use when calling REST APIs") but there is no "what" at all — the skill's purpose is never stated. This is exactly anchor 2 ("only 'when' is present without 'what'", e.g. "Use when working with documents"). It cannot be anchor 3 because there is no clear "what" to score, and cannot be anchor 1 because the "when" clause is explicit rather than entirely vague.

2 / 5

Trigger Term Quality

The sole keyword phrase is "calling REST APIs" — generic and structure-equivalent to the anchor-2 example "Works with files". It is missing every natural term a user with this need would say ("Zoom", "meeting", "webinar", "recording", "chat", "OAuth", "Zoom API"), so it is not anchor 3's "some relevant keywords"; it is above anchor 1 only because "REST APIs" is a phrase users do naturally say, keeping it from being pure jargon.

2 / 5

Distinctiveness Conflict Risk

"Use when calling REST APIs" would fire for any REST-API task — Stripe, GitHub, internal services — creating high overlap risk with virtually any HTTP-client skill, matching anchor 2 ("Very broad; high overlap risk with many similar skills"). It stays above anchor 1 because it is scoped to REST APIs rather than literally anything, but it lacks the clear niche (Zoom) that would justify 3+.

2 / 5

Total

8

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
openai/plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.