CtrlK
BlogDocsLog inGet started
Tessl Logo

compliance

Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

57

Quality

64%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./crates/openfang-skills/bundled/compliance/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, compliance-specific reference with strong named artifacts, but it reads as a topical checklist rather than a sequenced, checkpointed workflow and lacks the templates needed to make guidance directly executable.

Suggestions

Trim the intro's persona language and tighten principle explanations so every token adds actionable value.

Add at least one explicit sequenced workflow with validation checkpoints, e.g. an audit-preparation sequence (scope → gap assessment → implement controls → collect evidence → internal validation → audit).

Provide a concrete template or worked example for a high-value task, such as a sample control-to-requirement mapping table or a DSAR workflow, to lift actionability.

DimensionReasoningScore

Conciseness

The body is mostly dense and compliance-specific rather than explaining basics Claude knows, but the intro paragraph carries persona/credential language ("hands-on experience", "practical for engineering teams") and several principles have explanatory clauses that could be trimmed, matching 'mostly efficient but could be tightened'.

2 / 3

Actionability

Techniques name concrete artifacts and specifics ("Self-Assessment Questionnaire (SAQ)", "Business Associate Agreements (BAAs)", "72 hours for GDPR, 60 days for HIPAA"), but no templates, sample policies, or worked examples are provided to make the guidance directly executable, matching 'some concrete guidance but incomplete'.

2 / 3

Workflow Clarity

Content is organized into thematic sections with one sequenced pattern (the incident-response playbook), but core tasks like audit preparation or program building have no explicit step sequence and there are no validation checkpoints, matching 'steps listed but validation gaps'.

2 / 3

Progressive Disclosure

The body is under 50 lines with no bundle files and no need for external references, and it is well-organized into clearly labeled sections (Key Principles, Techniques, Common Patterns, Pitfalls), satisfying the simple-skill standard for progressive disclosure.

3 / 3

Total

9

/

12

Passed

Description

72%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is clearly niched with strong natural trigger terms, but it describes a role rather than concrete actions and omits an explicit 'Use when...' clause, capping completeness.

Suggestions

Add an explicit 'Use when...' clause, e.g. 'Use when preparing for SOC 2/GDPR/HIPAA/PCI-DSS audits or when the user asks about compliance, data protection, or regulatory controls.'

Replace the role phrasing with concrete actions, e.g. 'Maps regulatory requirements to technical controls, builds evidence-collection pipelines, and prepares audit-ready documentation for SOC 2, GDPR, HIPAA, and PCI-DSS.'

DimensionReasoningScore

Specificity

Names a clear domain and specific frameworks ("SOC 2, GDPR, HIPAA, PCI-DSS"), but lists no concrete actions — it describes a role ("Compliance expert for...") rather than capabilities, matching the 'names domain and some actions, but not comprehensive' anchor without reaching the multi-action level.

2 / 3

Completeness

It states what the skill covers (compliance expertise for named frameworks) but has no explicit "Use when..." trigger clause; per the guideline, a missing explicit trigger caps completeness at 2.

2 / 3

Trigger Term Quality

The named frameworks ("SOC 2, GDPR, HIPAA, PCI-DSS") plus "compliance" and "security frameworks" are exactly the natural terms a user would say when they need this skill, matching the good coverage anchor.

3 / 3

Distinctiveness Conflict Risk

It carves out a clear regulatory/compliance niche anchored by distinct named-framework triggers, making it unlikely to fire for unrelated skills.

3 / 3

Total

10

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
RightNow-AI/openfang
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.