CtrlK
BlogDocsLog inGet started
Tessl Logo

information-security-manager-iso27001

ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use when designing an ISMS, running security risk assessments, implementing controls, pursuing ISO 27001 certification, preparing security audits, responding to security incidents, or verifying compliance. Covers ISO 27001, ISO 27002, healthcare security, and medical device cybersecurity.

64

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.gemini/skills/information-security-manager-iso27001/SKILL.md

The canonical home for this skill is information-security-manager-iso27001 in alirezarezvani/claude-skills

SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Well-structured, actionable content with good validation checkpoints, but weakened by command repetition across sections and references to bundle files that are not actually present. Splitting detail into the missing reference files would improve both conciseness and navigation.

Suggestions

Consolidate the repeated risk_assessment.py / compliance_checker.py command examples into the Tools section and reference them from Quick Start, Workflows, and the Worked Example instead of restating them each time.

Either create the referenced bundle files (scripts/risk_assessment.py, scripts/compliance_checker.py, references/iso27001-controls.md, references/risk-assessment-guide.md, references/incident-response.md) or remove the references — currently they point to non-existent files and break navigation.

Move the detailed worked example, validation checkpoint tables, and control-category listings into the reference files so SKILL.md stays a concise overview pointing one level deep.

DimensionReasoningScore

Conciseness

Mostly actionable tables and commands rather than concept padding, but the same risk_assessment.py and compliance_checker.py commands are repeated across Quick Start, Tools, Workflows, and the Worked Example, inflating length without adding information.

3 / 5

Actionability

Concrete, copy-paste-ready commands with full flags and parameter tables, plus a worked example with sample output; the gap is that the referenced scripts are not present in the bundle, so the commands are not actually runnable as shipped.

4 / 5

Workflow Clarity

Three workflows are clearly sequenced with an explicit "Validation:" checkpoint after each step and certification-readiness checklists; falls short of 5 because there are no explicit validate→fix→retry feedback loops.

4 / 5

Progressive Disclosure

Section structure and a TOC are present and references are signaled by path, but the referenced files (scripts/*.py, references/*.md) do not exist in the bundle and substantial content (worked example, validation tables, control listings) is inlined rather than split out.

3 / 5

Total

14

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly communicates both the skill's purpose and its trigger conditions in third person. Minor headroom only in trigger-term synonym coverage.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — "designing an ISMS, running security risk assessments, implementing controls, pursuing ISO 27001 certification, preparing security audits, responding to security incidents, or verifying compliance" — giving comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

Explicitly states what ("ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies") and when ("Use when designing an ISMS, running security risk assessments...") with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural-term coverage ("ISO 27001", "ISMS", "security risk assessment", "incident response", "compliance", "medical device cybersecurity") with synonyms across standards; a few colloquial variations a user might say are absent, so just short of comprehensive.

4 / 5

Distinctiveness Conflict Risk

Clear niche — ISO 27001 ISMS scoped to HealthTech/MedTech with distinct triggers (certification, SoA, medical device cybersecurity) — giving minimal overlap risk with generic security skills.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 20 missing

Warning

Total

15

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.