CtrlK
BlogDocsLog inGet started
Tessl Logo

isms-audit-expert

Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use when the user mentions ISO 27001, ISMS audit, Annex A controls, Statement of Applicability (SOA), gap analysis, nonconformity management, internal audit, surveillance audit, or security certification preparation. Helps review control implementation evidence, document audit findings, classify nonconformities, generate risk-based audit plans, map controls to Annex A requirements, prepare Stage 1 and Stage 2 audit documentation, and support corrective action workflows.

93

1.25x
Quality

87%

Does it follow best practices?

Impact

97%

1.25x

Average score across 6 eval scenarios

SecuritybySnyk

—

The risk profile of this skill

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable audit skill body with validation checkpoints, real script/tooling references, and templates. Minor gaps: redundant opening lines, missing retry feedback loops in some workflows, and an unlinked bundle file.

Suggestions

Remove the redundant first-line restatement of the frontmatter description and the intro sentence to tighten conciseness.

Expand the validation checkpoints into explicit feedback loops (e.g., 'If validation fails: review finding, correct, and re-verify') for the audit-conduct and corrective-action workflows.

Reference references/iso27001_audit_playbook.md in the References table or remove it from the bundle so all reference files are discoverable from the body.

DimensionReasoningScore

Conciseness

Mostly efficient — tables, numbered steps, and validation checkpoints with no padded concept explanations — but the opening sentence repeats the frontmatter description and the intro line adds minor redundancy that could be trimmed.

4 / 5

Actionability

Provides concrete executable script invocations, a copy-pasteable finding template, classification tables, and checklists; the finding template is a fill-in scaffold rather than runnable code, but that is appropriate for an audit-documentation skill.

4 / 5

Workflow Clarity

Multiple well-sequenced workflows each ending in an explicit '**Validation:**' checkpoint, plus checklists for Stage 1/2; however most validation steps state the condition without a full validate→fix→retry feedback loop, leaving a minor gap below the anchor-5 bar.

4 / 5

Progressive Disclosure

Clear overview with well-signaled one-level-deep references in Tools/References tables pointing to real bundle files; the uncited references/iso27001_audit_playbook.md (present on disk but never linked from the body) is a minor organization gap.

4 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: third-person, comprehensive, with explicit 'Use when' trigger guidance and concrete enumerated capabilities. No vague fluff or over-claims.

DimensionReasoningScore

Specificity

Lists multiple concrete actions (review evidence, document findings, classify nonconformities, generate risk-based audit plans, map controls to Annex A, prepare Stage 1/2 documentation, support corrective actions) with comprehensive coverage, matching the anchor-5 example.

5 / 5

Completeness

Explicitly answers both 'what' (enumerated audit/certification capabilities) and 'when' via a concrete 'Use when the user mentions...' clause with specific trigger phrases, matching the anchor-5 example.

5 / 5

Trigger Term Quality

Comprehensive natural trigger phrases a user would actually say — 'ISO 27001, ISMS audit, Annex A controls, Statement of Applicability (SOA), gap analysis, nonconformity management, surveillance audit' — covering synonyms and acronyms.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear ISO 27001 ISMS-audit niche with distinct, domain-specific triggers that minimize overlap with other skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.