CtrlK
BlogDocsLog inGet started
Tessl Logo

compliance-os

Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across multiple frameworks. Four decisions: (1) Given a company profile, which of the 12 supported frameworks apply (ISO 27001/13485/42001/14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR, NIST CSF 2.0, NIS2, HIPAA)? (2) Across selected frameworks, which controls overlap and how much evidence reuses? (3) For a given framework + scope, what does a realistic mock audit produce — drawing from the 205-scenario library? (4) Across selected frameworks, what's the unified evidence checklist with reuse map? Use when standing up a multi-framework program, planning the annual audit calendar, or preparing for certification stage 1. Does NOT replace per-framework skills (it orchestrates them).

64

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.gemini/skills/compliance-os-bundle/SKILL.md

The canonical home for this skill is compliance-os in alirezarezvani/claude-skills

SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is information-rich and supplies executable Quick Start commands for all four decisions, but it is undermined by missing bundle files (references, scripts, assets are all absent), no explicit validation feedback loops in the workflows, and some repetition plus a redundant keyword dump. It reads as a strong overview attached to a broken file structure.

Suggestions

Ship the referenced bundle files — references/compliance_os_pattern.md, cross_framework_overlap.md, audit_simulation_methodology.md, evidence_management.md, multi_framework_audit_playbook.md, evidence_artifact_reuse_index.md, the four scripts/*.py, and assets/mock_audit_library.json — the body points to all of them but none exist in the package, breaking progressive disclosure.

Add explicit validation/feedback checkpoints to each workflow (e.g., after audit_simulator.py, verify finding count is 8–15 and ≥40% observations before proceeding; after evidence_pool_generator.py, check for orphan controls) instead of only listing expected outputs.

Trim the Keywords section (line 30) and de-duplicate the four-decision restatement between the intro and Core Responsibilities to reduce token weight without losing guidance.

DimensionReasoningScore

Conciseness

Content is dense and mostly actionable, but the four decisions are restated across the intro, Core Responsibilities, and Workflows, and the long Keywords dump (line 30) duplicates the description's trigger function — material that could be tightened.

3 / 5

Actionability

Quick Start gives copy-paste-ready bash commands for all four decisions with embedded sample data and names concrete scripts, but several workflow steps are comment-only guidance referencing other skills' unbundled tools, leaving minor gaps.

4 / 5

Workflow Clarity

Four workflows are clearly numbered with stated goals and expected outputs, but there are no explicit validation checkpoints or fix-and-retry feedback loops — only implicit 'Output:' descriptions — so checkpoints are missing rather than present.

3 / 5

Progressive Disclosure

Structure is well signaled with a References section pointing one level deep to six .md files plus scripts and an asset, but none of those bundle files actually exist in the package, so the navigation leads to dead ends rather than real detail.

3 / 5

Total

13

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that states concrete capabilities, gives four explicit decisions, includes natural trigger phrases for both what and when, and explicitly disambiguates itself from adjacent per-framework skills. Voice is correctly third person, so no specificity penalty applies.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence' — expanded into four numbered decisions with specific outputs, giving comprehensive coverage rather than vague language.

5 / 5

Completeness

Explicitly answers both what (configure/compute/simulate/consolidate across the four decisions) and when ('Use when standing up a multi-framework program, planning the annual audit calendar, or preparing for certification stage 1') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural phrases a compliance lead would actually say are present — 'standing up a multi-framework program', 'planning the annual audit calendar', 'preparing for certification stage 1' — alongside concrete framework names and file/standard references.

5 / 5

Distinctiveness Conflict Risk

The closing 'Does NOT replace per-framework skills (it orchestrates them)' carves out a clear meta-orchestrator niche with distinct triggers and minimal overlap risk against the per-framework deep-dive skills it names.

5 / 5

Total

20

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 6 missing

Warning

referenced_paths_exist

Referenced path issues: 24 missing

Warning

Total

14

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.