CtrlK
BlogDocsLog inGet started
Tessl Logo

ciso-advisor

Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting. Use when building security programs, justifying security budget, selecting compliance frameworks, managing incidents, assessing vendor risk, or when user mentions CISO, security strategy, compliance roadmap, zero trust, or board security reporting.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is ciso-advisor in alirezarezvani/claude-skills

SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured, mostly concise, and actionable with concrete formulas and examples. Its main weaknesses are missing validation/feedback loops in the workflows and progressive-disclosure gaps: referenced bundle files are absent and substantial reference-grade content is inlined.

Suggestions

Add explicit validation or verification steps to the compliance roadmap and incident-response workflows (e.g., 'validate gap analysis against control list before producing remediation plan') to lift workflow clarity past the batch-operation cap.

Create the referenced files references/security_strategy.md, references/compliance_roadmap.md, and references/incident_response.md (or remove the dangling pointers), since the metadata and body cite scripts/risk_quantifier.py and scripts/compliance_tracker.py that are also missing.

Move the inline Security Metrics, Integration with Other C-Suite Roles, and Output Artifacts tables into a single reference file to slim SKILL.md to a true overview and improve progressive disclosure.

DimensionReasoningScore

Conciseness

Largely lean and assumes Claude's competence—tables, formulas, and terse bullets replace prose—but sections like the keywords list and several 'See references/...' pointers add minor redundancy. A few spots could be tightened.

4 / 5

Actionability

Provides concrete, executable guidance—the ALE formula, a runnable Quick Start with python commands, a budget-justification worked example, and tiered vendor rules. Minor gap: scripts are invoked but their inputs/outputs aren't specified, and some guidance stays at framework level.

4 / 5

Workflow Clarity

Sequencing is present for compliance (SOC 2 Type I → Type II → ISO/HIPAA) and architecture (IAM → segmentation → classification), and proactive triggers give conditional guidance. However workflows lack explicit validation checkpoints or feedback loops; the cap applies for batch/destructive-style operations even though this is advisory.

3 / 5

Progressive Disclosure

References to references/security_strategy.md, compliance_roadmap.md, and incident_response.md are clearly signaled, but those bundle files do not exist on disk, and significant detail (metrics table, integration table, output artifacts) is inlined in SKILL.md rather than split out.

3 / 5

Total

14

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a strong, specific, third-person statement that comprehensively covers CISO capabilities and provides explicit 'Use when...' trigger guidance with natural keywords. It is concise yet complete and clearly distinguishable from other skills.

DimensionReasoningScore

Specificity

Lists multiple concrete actions—'Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting'—with comprehensive coverage of the CISO domain.

5 / 5

Completeness

Explicitly answers both 'what' (security leadership, risk quantification, compliance roadmap, etc.) and 'when' via a clear 'Use when building security programs, justifying security budget... or when user mentions CISO...' clause with concrete triggers.

5 / 5

Trigger Term Quality

Includes natural terms users would say including synonyms and acronyms: 'CISO, security strategy, compliance roadmap, zero trust, board security reporting, security budget, vendor risk'.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear CISO/executive security-leadership niche with distinct triggers (CISO, board security reporting, compliance roadmap, zero trust) and minimal overlap risk with other skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 10 missing

Warning

Total

15

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.