CtrlK
BlogDocsLog inGet started
Tessl Logo

meta-compliance-audit-bundle

Auditable compliance bundle: deep-research with citations → signable .docx report → read-only PDF archive → memory note of audit findings.

55

Quality

62%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./src/opensquilla/skills/exp/meta-compliance-audit-bundle/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

66%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is lean and well-structured for a meta-skill, surfacing the pipeline and a manual fallback without padding. It is weaker on actionability and workflow clarity, where concrete commands and validation checkpoints are missing.

Suggestions

Add concrete invocation examples or command snippets for each step (research → docx → html-to-pdf → memory_save) so the body is actionable rather than descriptive.

Insert explicit validation checkpoints between steps (e.g., verify the research output has citations before building the report; confirm the PDF rendered before archiving) to lift workflow clarity above the batch-operation cap.

Briefly note expected inputs/outputs per step so a fallback manual run can be executed without inferring from the frontmatter.

DimensionReasoningScore

Conciseness

The body is brief and largely avoids explaining concepts Claude already knows, mapping each step to its output role in a few lines; only slight restatement of the frontmatter's pipeline keeps it from a 5.

4 / 5

Actionability

The body describes the pipeline at a high level and gives a manual fallback sequence, but provides no concrete commands, argument examples, or copy-paste-ready instructions for actually invoking the steps.

3 / 5

Workflow Clarity

Steps are sequenced via depends_on in the frontmatter and summarized in prose, but the body itself lacks explicit validation checkpoints and the bundle involves batch/archive operations where the rubric caps workflow clarity at 3 without feedback loops.

3 / 5

Progressive Disclosure

This is a short skill with no external references, and the content is well-organized into a concise overview plus a Fallback section; per the rubric's simple-skill guidance, this earns a 5 without needing separate files.

5 / 5

Total

15

/

20

Passed

Description

58%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description concretely names the bundle's pipeline outputs (research, .docx, PDF, memory note) and targets a distinct compliance-audit niche. Its main weakness is the absence of an explicit 'Use when...' clause and slightly thin trigger-term coverage.

Suggestions

Add an explicit 'Use when...' clause naming concrete trigger phrases (e.g., 'Use when the user asks for a GDPR or SOC2 self-assessment, compliance audit, or audit bundle').

Broaden trigger terms to include common synonyms like 'SOC2', 'self-assessment', and 'evidence bundle' to improve natural-keyword coverage.

DimensionReasoningScore

Specificity

The description lists several concrete actions across the pipeline — 'deep-research with citations', 'signable .docx report', 'read-only PDF archive', 'memory note of audit findings' — giving clear specific outputs, though each is named at a high level rather than exhaustively enumerated.

4 / 5

Completeness

The 'what' is clearly stated (the bundle's steps and outputs), but the description lacks an explicit 'Use when...' clause; the trigger list lives in frontmatter rather than being surfaced as natural 'when' guidance in the description itself, capping completeness at 3 per the rubric.

3 / 5

Trigger Term Quality

Trigger terms like 'compliance audit', 'audit bundle', and 'GDPR 自评' are present and natural, but coverage is thin — missing common synonyms (SOC2, self-assessment) and a mix of one-word and phrase triggers without file-extension style cues.

3 / 5

Distinctiveness Conflict Risk

The compliance-audit niche is fairly distinct with its own trigger terms and a specific output bundle, though it could overlap marginally with generic research or document-generation skills.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
TokenRhythm/opensquilla
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.