CtrlK
BlogDocsLog inGet started
Tessl Logo

isms-audit-expert

Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use when the user mentions ISO 27001, ISMS audit, Annex A controls, Statement of Applicability (SOA), gap analysis, nonconformity management, internal audit, surveillance audit, or security certification preparation. Helps review control implementation evidence, document audit findings, classify nonconformities, generate risk-based audit plans, map controls to Annex A requirements, prepare Stage 1 and Stage 2 audit documentation, and support corrective action workflows.

93

1.25x
Quality

90%

Does it follow best practices?

Impact

97%

1.25x

Average score across 6 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is isms-audit-expert in alirezarezvani/claude-skills

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized ISMS audit skill body with explicit validation checkpoints, concrete templates, and good progressive-disclosure structure; its main weakness is referencing bundle files that are not present, which slightly lowers actionability and navigation.

Suggestions

Bundle the referenced files (references/iso27001-audit-methodology.md, references/security-control-testing.md, references/cloud-security-audit.md, scripts/isms_audit_scheduler.py) or remove the references to avoid dangling paths.

Trim the Audit Performance Metrics table and Auditor Competency Requirements bullets if they are not essential to driving audit tasks, to tighten token efficiency toward fully lean.

Add a brief inline example output of isms_audit_scheduler.py so the skill remains actionable even when the script bundle is unavailable.

DimensionReasoningScore

Conciseness

Mostly efficient tables/steps/template that assume Claude's domain knowledge, but the trailing Audit Performance Metrics table and generic Auditor Competency bullets are trimmable padding that keeps it just shy of fully lean.

4 / 5

Actionability

Provides copy-paste-ready artifacts (finding template, script invocations, Stage 1/2 checklists) but the referenced script and reference files are not bundled, leaving minor gaps in executable completeness.

4 / 5

Workflow Clarity

Each multi-step workflow (audit planning, pre-audit, audit conduct, corrective action) ends in an explicit bolded **Validation** checkpoint with feedback loops and checklists, matching the clear-sequence-with-validation anchor.

5 / 5

Progressive Disclosure

Body is a well-structured overview with a clearly signaled one-level-deep References table and Tools section, but the referenced references/ and scripts/ paths do not exist on disk, so navigation cannot fully resolve.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that pairs a concrete capability list with an explicit 'Use when...' trigger clause and domain-specific keywords, covering what and when comprehensively with low conflict risk.

DimensionReasoningScore

Specificity

Lists many concrete actions ('review control implementation evidence, document audit findings, classify nonconformities, generate risk-based audit plans, map controls to Annex A requirements, prepare Stage 1 and Stage 2 audit documentation, support corrective action workflows'), giving comprehensive coverage rather than the minor gaps of a 4.

5 / 5

Completeness

Explicitly answers both what (the action list) and when ('Use when the user mentions ISO 27001, ISMS audit, ...') with concrete trigger phrases, matching the anchor exactly.

5 / 5

Trigger Term Quality

Includes natural terms users would say ('ISO 27001, ISMS audit, Annex A controls, Statement of Applicability (SOA), gap analysis, nonconformity management, internal audit, surveillance audit, security certification preparation') with synonyms, matching the comprehensive anchor.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (ISO 27001 ISMS auditing) with domain-specific triggers (Annex A, SoA, surveillance/Stage 1/Stage 2 audits), making conflict with other skills minimal.

5 / 5

Total

20

/

20

Passed

Validation

81%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 13 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 4 missing

Warning

referenced_paths_exist

Referenced path issues: 7 missing

Warning

Total

13

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.