CtrlK
BlogDocsLog inGet started
Tessl Logo

compliance-os

Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across multiple frameworks. Four decisions: (1) Given a company profile, which of the 12 supported frameworks apply (ISO 27001/13485/42001/14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR, NIST CSF 2.0, NIS2, HIPAA)? (2) Across selected frameworks, which controls overlap and how much evidence reuses? (3) For a given framework + scope, what does a realistic mock audit produce — drawing from the 205-scenario library? (4) Across selected frameworks, what's the unified evidence checklist with reuse map? Use when standing up a multi-framework program, planning the annual audit calendar, or preparing for certification stage 1. Does NOT replace per-framework skills (it orchestrates them).

66

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

The risk profile of this skill

Fix and improve this skill with Tessl

tessl review fix ./compliance-os/skills/compliance-os/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Well-structured, actionable body with excellent progressive disclosure and real bundle files. Main weaknesses are a padded keyword block and missing validation/feedback checkpoints in the batch-generation workflows.

Suggestions

Trim or relocate the Keywords block into a reference file; it inflates token cost without adding operational value in the main body.

Add explicit validation/feedback checkpoints to Workflows 1-3 (e.g., verify selector output covers all claimed frameworks before mapping; confirm audit-simulator severity distribution before consolidating evidence).

Show one concrete example output (e.g., a sample framework-selector result or overlap-map snippet) to make the commands' expected results unambiguous.

DimensionReasoningScore

Conciseness

Mostly efficient operational guidance, but the long keyword-stuffing block and repeated 'Run X' lines could be tightened; some padding remains.

3 / 5

Actionability

Copy-paste-ready bash commands in Quick Start and Workflows plus deterministic decision rules give concrete executable guidance, though no example outputs are shown.

4 / 5

Workflow Clarity

Four workflows are clearly sequenced with concrete commands, but batch operations (audit simulation, evidence consolidation) lack explicit validation/feedback checkpoints, capping the score.

3 / 5

Progressive Disclosure

SKILL.md is a concise overview with well-signaled one-level-deep references to 6 reference files, 4 scripts, and 3 assets, all of which exist as real bundle files; content is appropriately split.

5 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that names concrete actions, an explicit Use-when trigger, and a clear boundary against per-framework skills. Slightly lacking in synonym/file-extension keyword breadth, otherwise excellent.

DimensionReasoningScore

Specificity

Lists four concrete actions (CONFIGURE/COMPUTE/SIMULATE/CONSOLIDATE) mapped to four explicit decisions with specific outputs and the named 12-framework set, giving comprehensive coverage.

5 / 5

Completeness

Explicitly answers both what (four decisions, configure/compute/simulate/consolidate) and when via a concrete 'Use when...' clause with three trigger scenarios.

5 / 5

Trigger Term Quality

Natural trigger phrases appear ('standing up a multi-framework program', 'planning the annual audit calendar', 'preparing for certification stage 1'), but synonym/file-extension coverage is thinner than the top anchor.

4 / 5

Distinctiveness Conflict Risk

Clear niche (multi-framework orchestration) with an explicit boundary ('Does NOT replace per-framework skills (it orchestrates them)') minimizing overlap with the per-framework skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.