CtrlK
BlogDocsLog inGet started
Tessl Logo

information-security-manager-iso27001

ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use when designing an ISMS, running security risk assessments, implementing controls, pursuing ISO 27001 certification, preparing security audits, responding to security incidents, or verifying compliance. Covers ISO 27001, ISO 27002, healthcare security, and medical device cybersecurity.

73

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

The risk profile of this skill

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and highly actionable, with sequenced workflows that include explicit validation checkpoints and clearly signaled one-level-deep references to real bundle files. The main weakness is minor verbosity from repeated tool-usage examples across Quick Start, Tools, and the Worked Example.

Suggestions

Consolidate the risk_assessment.py and compliance_checker.py usage examples: show them once in Tools and have Quick Start and the Worked Example reference them rather than repeating near-identical commands.

Tighten the Worked Example to highlight only the healthcare-specific deviation from Workflow 2 instead of re-running the full asset/risk/treatment sequence.

Consider moving the parameter tables into the script docstrings or a reference file and keeping SKILL.md focused on when and why to use each tool, reducing inline repetition.

DimensionReasoningScore

Conciseness

Mostly efficient — uses tables and command snippets without explaining concepts Claude already knows — but Quick Start repeats usage shown again in Tools and the Worked Example re-demonstrates Workflow 2, adding minor redundancy.

4 / 5

Actionability

Concrete executable commands throughout ('python scripts/risk_assessment.py --scope ... --template healthcare'), parameter tables, and a realistic verification output block make the guidance copy-paste ready for common cases.

5 / 5

Workflow Clarity

Three workflows each have numbered sequenced steps with explicit '**Validation:**' checkpoints after every step, satisfying the feedback-loop requirement for batch/compliance operations.

5 / 5

Progressive Disclosure

Clear overview with a Table of Contents and one-level-deep, well-signaled references ('## Reference Guides' with a purpose list for each references/*.md), plus bundled documented scripts; minor overlap between Quick Start and Tools keeps it just below 5.

4 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it states concrete capabilities, gives explicit 'Use when' trigger guidance covering the main scenarios, and carves out a distinct healthcare/medtech ISO 27001 niche. Trigger term coverage is very good but could include a couple more common phrasings.

DimensionReasoningScore

Specificity

Lists multiple specific concrete actions — 'designing an ISMS, running security risk assessments, implementing controls, pursuing ISO 27001 certification, preparing security audits, responding to security incidents, or verifying compliance' — giving comprehensive coverage.

5 / 5

Completeness

Explicitly answers 'what' (ISMS implementation and cybersecurity governance for HealthTech/MedTech) and 'when' with a concrete 'Use when ...' clause enumerating trigger situations.

5 / 5

Trigger Term Quality

Strong natural keywords users would say (ISO 27001, ISMS, security risk assessment, incident response, compliance) with synonyms (27001/27002, healthcare/medical device), though a few common phrasings could be added.

4 / 5

Distinctiveness Conflict Risk

Clear niche — ISO 27001 ISMS for healthcare/medtech — with distinct triggers and minimal overlap risk with other skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.