CtrlK
BlogDocsLog inGet started
Tessl Logo

ciso-advisor

Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting. Use when building security programs, justifying security budget, selecting compliance frameworks, managing incidents, assessing vendor risk, or when user mentions CISO, security strategy, compliance roadmap, zero trust, or board security reporting.

75

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

The risk profile of this skill

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, highly actionable advisory skill body with real executable scripts, concrete formulas and worked examples, and clean one-level-deep references to verified bundle files. Main weakness is mild token redundancy (a Keywords section echoing the description) rather than any structural defect.

Suggestions

Remove or fold the '## Keywords' section into the frontmatter description, since it duplicates those same trigger terms and adds context-window cost without new information.

Tighten concept glosses Claude already knows — e.g., 'Zero trust is a direction, not a product' and the inline 'Single Loss Expectancy × Annual Rate of Occurrence' expansion — to prescriptive guidance only.

Consider presenting the six Core Responsibilities as a sequenced decision flow (assess risk → sequence compliance → design architecture → prepare IR → justify budget → assess vendors) with a checkpoint between each, rather than as parallel numbered topics.

DimensionReasoningScore

Conciseness

Body is information-dense and prescriptive (metrics table, red flags, integration matrix) rather than padded, but the standalone '## Keywords' section largely duplicates the description's trigger terms and a few lines expand concepts Claude knows (e.g., 'Zero trust is a direction, not a product', ALE acronym gloss). Not a 5 because of this minor redundancy; not a 3 because the bulk earns its tokens.

4 / 5

Actionability

Fully executable guidance: copy-paste Quick Start commands (`python scripts/risk_quantifier.py`, `python scripts/compliance_tracker.py` — both real files), the `ALE = SLE × ARO` formula with board-language template, a worked budget example ($200K / $2M / 40% = $800K), tiered vendor rules, and an Output Artifacts table mapping requests to concrete deliverables.

5 / 5

Workflow Clarity

The Communication section defines an explicit Internal Quality Loop (self-verify → peer-verify → critic pre-screen → tagged output) with real validation checkpoints, and the reasoning technique gives a decision framework. Held at 4 rather than 5 because the six 'Core Responsibilities' are parallel topic areas rather than a strictly sequenced workflow with per-step checkpoints; not 3 because the output-validation feedback loop is genuinely explicit.

4 / 5

Progressive Disclosure

Clear overview structure with well-signaled, one-level-deep references — every `references/*.md` and `scripts/*.py` cited (security_strategy, compliance_roadmap, incident_response, risk_quantifier, compliance_tracker) resolves to a real bundle file, and a 'Detailed References' section gives one-line navigation for each. Body acts as overview, details live in referenced files.

5 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: comprehensive concrete actions, an explicit 'Use when' clause with rich natural trigger terms, correct third-person voice, and a clearly delineated niche that avoids conflict with sibling skills. No changes needed.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting' — with comprehensive coverage of the CISO domain. Third-person voice ('Security leadership') is correct.

5 / 5

Completeness

Explicitly answers both what ('Security leadership for growth-stage companies. Risk quantification in dollars...') and when ('Use when building security programs, justifying security budget... or when user mentions CISO...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive natural-term coverage including synonyms users actually say — 'CISO, security strategy, compliance roadmap, zero trust, or board security reporting' — plus scenario phrases like 'justifying security budget' and 'assessing vendor risk'. File extensions are inapplicable to this advisory skill.

5 / 5

Distinctiveness Conflict Risk

Clear niche (CISO-level security leadership for growth-stage companies) with distinct triggers ('CISO', 'zero trust', 'board security reporting') that minimize overlap with adjacent compliance or engineering skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.