CtrlK
BlogDocsLog inGet started
Tessl Logo

dt-obs-compliance-assistant

Monitor and investigate EU DORA compliance posture using Dynatrace Compliance Assistant. Covers compliance score, CIF health, incident lifecycle, and ICT risk inputs (vulnerabilities, security detection findings, misconfigurations). Trigger: "DORA compliance", "Digital Operational Resilience Act", "compliance score", "compliance snapshot", "score tier", "Critical or Important Functions", "CIF", "CIF health", "unclassified problems", "potential major incident", "classified major incident", "incident classification under DORA", "compliance.incident bizevent", "DQL for classified incidents", "set up Compliance Assistant", "DORA onboarding". Do NOT use for other compliance frameworks (SOC2, PCI-DSS, HIPAA, ISO 27001), generic Davis problems without DORA or CIF context, generic security findings not scoped to DORA, or score queries without compliance context.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with executable DQL templates and clear, sequenced workflows supported by useful reference tables. Its weaknesses are minor: some repetitive legal-disclaimer language and a monolithic single-file structure where some reference-heavy content could be externalized.

Suggestions

Consolidate the "operational indicator, not a legal determination" caveat into the Critical Disclaimer section once and reference it from workflows rather than restating it multiple times.

Move the full DQL key-fields schema table and the longer query templates into a references/ file (e.g. DQL_REFERENCE.md) and keep only a concise quick-start query inline in SKILL.md to improve progressive disclosure.

Add an explicit validate→fix→retry feedback loop to the Investigate an Incident workflow (e.g., re-run the unclassified-problems query after confirming CIF IDs to verify the anti-join returned expected rows).

DimensionReasoningScore

Conciseness

Most content is domain-specific reference material Claude would not already know (DORA score tiers, permission tables, DQL field schemas) that earns its place, but the "operational indicator, not a legal determination" caveat is repeated across the disclaimer, workflows, and score sections, which is minor over-explanation that could be trimmed.

4 / 5

Actionability

It provides complete, copy-paste-ready DQL query templates (both parameterized and plain variants), a full key-fields schema table with types and descriptions, and concrete permissions/data-source tables, covering the common cases the skill targets.

5 / 5

Workflow Clarity

Three numbered workflows (Check Compliance Score, Investigate an Incident, Review CIF Health) include explicit checkpoints such as confirming DORA, not classifying on behalf of the user, and checking monitoring frequency when data is stale, but they stop short of full validate→fix→retry checklists for complex processes.

4 / 5

Progressive Disclosure

The body is well organized with clear section headers, internal anchor links, and clearly signaled external Dynatrace documentation links for deeper material; the main gap is that no bundle files exist and heavy reference content (full query templates, a 15-row field-schema table) is inlined rather than split into separate reference files.

4 / 5

Total

17

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it clearly states what the skill does, when to use it with a rich set of natural trigger phrases, and where it does not apply. The only minor weakness is a somewhat limited set of action verbs compared to the breadth of coverage areas listed.

DimensionReasoningScore

Specificity

Names the domain and lists several concrete coverage areas ("compliance score, CIF health, incident lifecycle, and ICT risk inputs (vulnerabilities, security detection findings, misconfigurations)"), but the action verbs are limited to "Monitor and investigate", leaving minor coverage gaps relative to a fully comprehensive action list.

4 / 5

Completeness

It explicitly answers both what ("Monitor and investigate EU DORA compliance posture using Dynatrace Compliance Assistant") and when (a concrete "Trigger:" list plus a "Do NOT use for" exclusion list), matching the anchor for clearly and explicitly answering both with concrete trigger phrases.

5 / 5

Trigger Term Quality

The "Trigger:" clause provides comprehensive natural phrases a user would actually say, including synonyms and shorthand ("DORA compliance", "compliance snapshot", "score tier", "CIF", "potential major incident", "DORA onboarding"), matching the comprehensive-coverage anchor.

5 / 5

Distinctiveness Conflict Risk

It carves a clear niche (EU DORA via Dynatrace Compliance Assistant) and an explicit exclusion list (SOC2, PCI-DSS, HIPAA, ISO 27001, generic Davis problems, generic security findings, score queries without compliance context), giving it distinct triggers with minimal conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
Dynatrace/dynatrace-for-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.