CtrlK
BlogDocsLog inGet started
Tessl Logo

validate-trigger

Validate an existing Sim webhook trigger against provider API docs and repository conventions

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./.agents/skills/validate-trigger/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable, well-sequenced validation workflow with concrete file paths, commands, and explicit validation checkpoints. Its main structural weakness is that everything lives in one long inline file with no progressive disclosure, though as a self-contained checklist-style skill it remains easy to navigate.

Suggestions

Split the per-layer detail (Steps 3–6 checklists) into one-level-deep reference files (e.g., references/trigger-checks.md, references/provider-handler-checks.md) and keep SKILL.md as an overview with clearly signaled links.

Trim the Checklist Summary section, which restates the step sections, and drop the 'You are an expert auditor' preamble to reduce token overhead.

Move the report-format severity examples into a small reference file or condense them, since they duplicate rules already embedded in the step checklists.

DimensionReasoningScore

Conciseness

The body is dense checklists with concrete identifiers throughout and no explanations of concepts Claude already knows. Minor padding — the 'You are an expert auditor' preamble, repeated emphases like 'do not skip any', and a Checklist Summary that restates the step sections — keeps it below a 5.

4 / 5

Actionability

Guidance is fully executable: exact file paths ('apps/sim/triggers/{service}/', 'apps/sim/lib/webhooks/providers/registry.ts'), runnable commands ('bun run type-check', 'bun run --cwd apps/sim test lib/webhooks/providers/<handler-basename>'), and precise contract details ('{ providerConfigUpdates: { externalId } }', 'safeCompare', fail-closed secret handling).

5 / 5

Workflow Clarity

Steps 1–8 are clearly sequenced with an explicit validation and feedback loop: report findings by severity, 'fix every critical and warning issue', re-read modified files, run type-check and handler tests, and confirm no guessed payload schemas remain. Not below 5 because every checkpoint is explicit, including error-recovery guidance for unknown payload schemas.

5 / 5

Progressive Disclosure

There are no bundle files (references/, scripts/, assets/ all absent), and all ~230 lines of per-layer checklists are inlined in a single SKILL.md. Sections are well-organized, but the per-file detail (trigger files vs. provider handler vs. registries) is the kind of content that could be split into one-level-deep reference files, matching the 'content that should be separate is inline' anchor. Not a 2 because the document is clearly sectioned and navigable, not a wall of text.

3 / 5

Total

17

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description states a specific, well-scoped 'what' with distinct domain vocabulary, but omits any 'when to use' trigger guidance and lists only a single capability. Adding an explicit use-when clause and a slightly broader action list would make it fully effective for skill triggering.

Suggestions

Append a trigger clause such as 'Use when validating, auditing, or reviewing an existing Sim webhook trigger implementation' to answer the 'when' explicitly.

Enumerate one or two more concrete actions (e.g., 'check signature verification, payload alignment, and subscription lifecycle') so the description reads as multiple capabilities rather than a single verb.

Add natural synonyms users might say ('audit', 'check', 'review a webhook trigger') to strengthen trigger-term coverage.

DimensionReasoningScore

Specificity

Names the domain ('Sim webhook trigger') and a couple of concrete validation targets ('provider API docs', 'repository conventions'), but offers only one action verb ('validate') rather than the several specific actions of the higher anchors. Not a 2 because the domain and both reference baselines are explicit, not generic.

3 / 5

Completeness

The 'what' is clear ('Validate an existing Sim webhook trigger against provider API docs and repository conventions') but there is no 'Use when...' clause or equivalent trigger guidance, which caps completeness at 3 per the judging guidelines. Not a 2 because the 'what' is specific rather than vague.

3 / 5

Trigger Term Quality

Terms like 'webhook trigger', 'validate', 'Sim', and 'API docs' match what a developer would naturally say when asking for this. Missing common synonyms ('audit', 'check', 'verify', specific provider names) keeps it below a 5.

4 / 5

Distinctiveness Conflict Risk

'Sim webhook trigger' is a clear niche with distinct vocabulary and minimal conflict risk against unrelated skills. Minor overlap risk remains with sibling Sim skills (e.g., a create-trigger or validate-selector skill), so it is not a 5.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
simstudioai/sim
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.