CtrlK
BlogDocsLog inGet started
Tessl Logo

hipaa-compliance

HIPAA-specific entrypoint for healthcare privacy and security work. Use when a task is explicitly framed around HIPAA, PHI handling, covered entities, BAAs, breach posture, or US healthcare compliance requirements.

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, lean routing skill: the decision-gate checklist and guardrails are concrete and actionable, the workflow is clearly sequenced with explicit escalation criteria, and content is appropriately kept inline. The only notable weakness is mild trigger redundancy between the opening paragraph, the 'When to Use' section, and the frontmatter description.

DimensionReasoningScore

Conciseness

The body is lean — no explanation of what HIPAA or PHI means, guardrails are tight imperative bullets, and the examples are compact. A minor trim is possible: the opening paragraph ('Use this as the HIPAA-specific entrypoint when a task is clearly about US healthcare compliance') and the 'When to Use' section restate the same trigger conditions already in the frontmatter description, a small redundancy that keeps it below anchor 5.

4 / 5

Actionability

Guidance is concrete for an instruction-only skill: five specific decision-gate questions ('Is this data PHI?', 'Does a vendor or model provider require a BAA before touching the data?'), actionable guardrails ('blocked-by-default until BAA status and data boundaries are clear', 'Prefer opaque internal IDs over names, MRNs, phone numbers'), and worked examples with response patterns. It stops short of anchor 5 because the executable detail is delegated to 'healthcare-phi-compliance' with no fallback pointer, so the file alone doesn't fully cover the common cases.

4 / 5

Workflow Clarity

'How It Works' gives a clear numbered sequence — apply the implementation skill, run the five-question HIPAA decision-gate checklist, then a conditional escalation rule ('Escalate to healthcare-reviewer if the task affects patient safety, clinical workflows, or regulated production architecture'). The decision gates function as an explicit validation checklist, matching anchor 5; this is not a destructive or batch operation so no validation cap applies.

5 / 5

Progressive Disclosure

No bundle files exist and none are needed — the skill is a thin router whose ~70 lines are appropriately inline, with well-organized sections (When to Use, How It Works, Guardrails, Examples, Related Skills) and clearly signaled sibling-skill references. Nothing that belongs in a separate file is inlined, and navigation is easy.

5 / 5

Total

18

/

20

Passed

Description

81%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with excellent, natural trigger terms and a clearly bounded niche. The 'when' clause is fully explicit; the main weakness is a thin 'what' — it identifies the skill's role as an entrypoint without naming the concrete actions or delegation targets, which also slightly limits specificity.

Suggestions

State one or two concrete actions in the 'what' portion (e.g., 'Applies HIPAA decision gates for PHI, BAAs, and minimum-necessary access, and routes to the underlying healthcare privacy and reviewer skills').

Briefly name what the entrypoint delegates to so the 'what' answers what happens after the skill triggers, not just that it is a routing layer.

DimensionReasoningScore

Specificity

The description names the domain ("HIPAA-specific entrypoint for healthcare privacy and security work") and a single functional role, but lists no concrete actions comparable to 'extract text, fill forms, merge documents' — an entrypoint skill delegates rather than performs, yet the delegation itself is not stated. It sits above anchor 2 (domain named, actions generic) because the entrypoint scope is stated precisely, but below anchor 4 (several specific actions).

3 / 5

Completeness

Both parts are present: 'what' is stated ("HIPAA-specific entrypoint for healthcare privacy and security work") and 'when' is fully explicit with concrete trigger phrases. It falls short of anchor 5 because the 'what' is high-level — it says the skill is an entrypoint but not what it actually does (apply HIPAA decision gates, route to implementation/reviewer skills), so the 'what' could be more concrete.

4 / 5

Trigger Term Quality

Trigger coverage is comprehensive and natural: "HIPAA, PHI handling, covered entities, BAAs, breach posture, or US healthcare compliance requirements" — these are exactly the terms a user working in this space would say, including abbreviations (PHI, BAAs) and the 'US healthcare compliance' phrasing. No common synonyms are missing.

5 / 5

Distinctiveness Conflict Risk

A clear niche with distinct triggers: HIPAA, PHI, BAAs, covered entities, and US healthcare compliance are unambiguous signals that separate this from general privacy, security-review, or generic healthcare skills. The 'explicitly framed around HIPAA' qualifier further narrows the trigger.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.