CtrlK
BlogDocsLog inGet started
Tessl Logo

healthcare-phi-compliance

Protected Health Information (PHI) and Personally Identifiable Information (PII) compliance patterns for healthcare applications. Covers data classification, access control, audit trails, encryption, and common leak vectors.

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is tdg-personal/healthcare-phi-compliance

SKILL.md
Quality
Evals
Security

Quality

Content

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a tight, actionable reference with executable code, a verification-oriented deployment checklist, and clean section organization that needs no external files.

DimensionReasoningScore

Conciseness

Lean, well-sectioned content that assumes competence with SQL/TypeScript and adds only healthcare-specific domain knowledge; the deployment checklist recaps rules in scannable imperative form rather than padding with basic explanations.

3 / 3

Actionability

Provides fully executable RLS policies, a TypeScript AuditEntry interface, schema COMMENT statements, and copy-paste safe/unsafe error-handling and logging examples.

3 / 3

Workflow Clarity

Organizes protection into three explicit layers and supplies a deployment checklist with verification items ('RLS enabled on all PHI/PII tables', 'Cross-facility data isolation verified') plus a test with an expected outcome.

3 / 3

Progressive Disclosure

Self-contained with no bundle files; content is split into clearly signaled sections (When to Use, How It Works, Examples, Deployment Checklist) with no nested references and easy navigation.

3 / 3

Total

12

/

12

Passed

Description

67%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description names a well-scoped niche and concrete capability areas, but it is missing explicit 'when to use' trigger guidance and the most common regulatory keywords a user would naturally mention.

Suggestions

Add an explicit trigger clause, e.g. 'Use when building features that touch patient records, implementing healthcare access control, or reviewing code for PHI/PII exposure.'

Include the regulatory terms users naturally say (HIPAA, GDPR, DISHA) in the description rather than only in the body, to improve trigger-term coverage.

Lead with verb-based actions ('Classify, control access to, and audit PHI/PII...') to make capabilities read as concrete actions rather than topics.

DimensionReasoningScore

Specificity

Lists multiple concrete capability areas — 'data classification, access control, audit trails, encryption, and common leak vectors' — going beyond naming only the domain.

3 / 3

Completeness

Clearly states what the skill covers but lacks any 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 2 per the rubric.

2 / 3

Trigger Term Quality

Includes natural healthcare terms (PHI, PII, compliance, audit trails, encryption) but omits common regulatory variations users would say, notably HIPAA, GDPR, and 'patient data privacy' that appear only in the body.

2 / 3

Distinctiveness Conflict Risk

Targets a clear niche (healthcare PHI/PII compliance) with distinct triggers unlikely to collide with other skills.

3 / 3

Total

10

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.