CtrlK
BlogDocsLog inGet started
Tessl Logo

composio

Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet. Use QM’s authenticated backend for app discovery, consent, and execution without exposing project keys.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

100%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, dense, instruction-only skill with executable code, exact API contracts, and explicit validation and error-handling checkpoints for risky operations. All content earns its place and is appropriately self-contained, with the web-chat and Slack flows clearly delineated per context.

DimensionReasoningScore

Conciseness

Every sentence is operational policy — widget directives, endpoints, and guardrails — with zero explanation of concepts Claude already knows (no OAuth primer, no library introductions). Apparent repetition (e.g., 'as its own paragraph') occurs in distinct contexts serving different flows, so nothing reads as padding. Not 4: there is no over-explanation to trim.

5 / 5

Actionability

Fully executable: a copy-paste-ready JS `apps()` helper with auth headers and error handling, exact endpoints ('toolkits', 'connections', 'tools?' + URLSearchParams, 'authorize', 'execute'), exact widget directives ('::connect-apps{}', '::link-slack-account{}', '::add-to-slack{}'), and concrete field names (discovered.slug, accountId, discovered.version). Covers the common web-chat and Slack-conversation cases.

5 / 5

Workflow Clarity

Clear numbered 5-step API sequence plus an explicit first-reply decision flow when an app is missing. Validation checkpoints are explicit: poll 'connections' and only claim success once the account ID is listed, inspect 'successful' and 'error' rather than HTTP status, and never auto-retry uncertain writes; drafts-remain-drafts guards the destructive send/delete operations. This satisfies the feedback-loop requirement for write operations.

5 / 5

Progressive Disclosure

No bundle files exist and none are needed: the ~53-line body is organized under clear section headers (setup widget, missing-app flow, backend API) with all content appropriately inline. Per the rubric's simple-skill note, a short self-contained skill with well-organized sections and no external references earns full marks.

5 / 5

Total

20

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly states both capability and trigger conditions in third person with natural user phrasing. It is specific about the widget-rendering behavior and the security boundary (no project keys exposed), with only minor gaps in trigger synonyms and action coverage.

DimensionReasoningScore

Specificity

Lists several concrete actions ('Show the app connection picker or setup widget', 'app discovery, consent, and execution without exposing project keys'), though the backend capabilities are named as domain nouns rather than distinct actions and coverage has minor gaps (e.g., checking connection status, per-app linking). Not 3 (more than 1-2 actions named) and not 5 (not comprehensive).

4 / 5

Completeness

Explicitly answers both questions: what ('Show the app connection picker or setup widget... Use QM's authenticated backend for app discovery, consent, and execution') and when ('when users ask to connect apps, reopen setup, or need an app that isn't connected yet') with concrete trigger phrases. Uses third-person voice as required.

5 / 5

Trigger Term Quality

Includes natural phrases users would say: 'connect apps', 'reopen setup', 'need an app that isn't connected yet'. A few natural terms are missing, such as 'integrations', 'link account', and specific app names (Slack, Gmail, Notion).

4 / 5

Distinctiveness Conflict Risk

'QM's authenticated backend', 'app connection picker', and 'project keys' establish a clear niche with distinct triggers, with only minor overlap risk against generic OAuth/integration-connection skills.

4 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
yc-software/qm
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.