CtrlK
BlogDocsLog inGet started
Tessl Logo

iso27001-audit-prep

/cs:iso27001-audit-prep <scope> — ISO 27001 ISMS audit readiness 6-question forcing interrogation. Use before annual Clause 9.2 internal audit, surveillance audit prep, or stage 1 certification readiness.

64

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.gemini/skills/iso27001-audit-prep/SKILL.md

The canonical home for this skill is iso27001-audit-prep in alirezarezvani/claude-skills

SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, well-structured audit-prep skill body that assumes competence and packs in concrete control references, SLAs, and an output template. Its main gaps are missing explicit validation feedback loops in the workflow and reliance on non-bundled external scripts for its commands.

Suggestions

Add an explicit validation checkpoint to the Workflow (e.g., 'after the mock audit, verify no high/critical findings remain before declaring READY; re-run on gaps'), turning the implicit verdict into a validate->fix->retry loop to lift workflow_clarity above 3.

Either bundle the referenced scripts (isms_audit_scheduler.py, audit_simulator.py, cross_framework_mapper.py) under ./scripts/ or replace the commands with guidance that does not depend on external repo paths, so the actionable steps are self-contained and verifiable.

Consider moving the full Output Format template and the six detailed questions' control-reference bullets into a ./references/ file referenced one level deep, keeping SKILL.md as a tighter overview to push progressive_disclosure toward 5.

DimensionReasoningScore

Conciseness

Tight bullet structure with no preamble explaining ISO 27001, Annex A, or Clause 9.2; bold taglines and control IDs assume Claude's competence and every section earns its place, matching the 'lean and efficient' anchor.

5 / 5

Actionability

Provides concrete control IDs (A.5.15, A.8.2), SLAs (24-hour, 30-day), and bash commands, but the commands reference external non-bundled scripts (ra-qm-team/..., ../../skills/compliance-os/...) so they are not truly copy-paste ready, fitting the 'mostly executable with minor gaps' anchor.

4 / 5

Workflow Clarity

A 3-step Workflow plus six sequenced questions ending in a verdict is a clear sequence, but there is no explicit validate->fix->retry feedback loop and checkpoints are only implicit, matching the 'steps listed but validation gaps' anchor.

3 / 5

Progressive Disclosure

No bundle files exist; the body is self-contained with well-organized section headers and one-level-deep signaled references to external playbooks (iso27001_audit_playbook.md, multi_framework_audit_playbook.md), fitting the 'good structure, references mostly clear' anchor rather than a fully split level-5 layout.

4 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-constructed description that cleanly pairs a specific 'what' with concrete 'when to use' triggers for the ISO 27001 ISMS audit niche. It is held back only by listing a single primary action and minor naming overlap with sibling audit-prep skills.

DimensionReasoningScore

Specificity

Names the domain (ISO 27001 ISMS audit readiness) and one concrete action ('6-question forcing interrogation'), but does not enumerate several distinct actions, matching the 'names domain and 1-2 concrete actions' anchor rather than the 'several specific actions' level above.

3 / 5

Completeness

Explicitly answers both 'what' ('6-question forcing interrogation' for ISMS audit readiness) and 'when' with concrete trigger phrases ('Use before annual Clause 9.2 internal audit, surveillance audit prep, or stage 1 certification readiness').

5 / 5

Trigger Term Quality

Includes natural compliance-user phrases such as 'Clause 9.2 internal audit', 'surveillance audit prep', and 'stage 1 certification readiness' with audit-type synonyms, giving good keyword coverage just short of the fully comprehensive level 5.

4 / 5

Distinctiveness Conflict Risk

The 'ISO 27001 ISMS' / 'Clause 9.2' qualifiers carve a clear niche, but the shared 'audit-prep' suffix and existence of sibling SOC 2 / GDPR / AIMS audit-prep skills create minor overlap risk, keeping it just below the minimal-conflict level 5.

4 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 suspicious

Warning

Total

15

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.