CtrlK
BlogDocsLog inGet started
Tessl Logo

iso42001-specialist

ISO/IEC 42001:2023 AI Management System (AIMS) specialist for compliance teams running internal audits. Three decisions: (1) Where are the gaps against Clauses 4-10 and what do we close first? (2) What goes in the AI risk register and which Annex A controls treat each risk? (3) What's the 12-month internal audit plan that satisfies Clause 9.2? Use when preparing for certification, scoping internal audit cycles, or onboarding AI systems into an existing ISMS (27001) / QMS (13485) program. NOT an executive AI strategy skill (see chief-ai-officer-advisor). NOT EU AI Act compliance (see compliance-team-eu-ai-act).

64

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.gemini/skills/iso42001-specialist/SKILL.md

The canonical home for this skill is iso42001-specialist in alirezarezvani/claude-skills

SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Well-structured and actionable content with clear workflows, but it is held back by missing validation/verification feedback loops in batch audit workflows and by references/scripts that are cited but not bundled. Adding validation checkpoints and shipping the referenced files would lift the lower dimensions.

Suggestions

Add explicit validation/verification checkpoints to each workflow (e.g., 'verify each gap is closed before stage 1', 're-confirm control coverage and re-run if any high-risk item lacks a treating control') so batch/audit operations include error-recovery loops.

Bundle the referenced files (references/iso42001_clauses.md, references/aims_controls_annex_a.md, references/aims_implementation_guide.md, references/cross_framework_mapping_ai.md) and the scripts (aims_gap_analyzer.py, ai_risk_register_builder.py, aims_audit_scheduler.py), or remove the references if they are not part of this skill package.

Trim the repeated NOT/disambiguation statements that duplicate the frontmatter description to reduce redundancy and tighten conciseness.

DimensionReasoningScore

Conciseness

Dense and mostly assumes Claude's intelligence with minimal padding, but carries some redundancy between the description's NOT-disambiguation and the body's repeated boundary statements.

4 / 5

Actionability

Concrete executable commands (python scripts/aims_gap_analyzer.py aims_evidence.json) and four numbered workflows with an output-standard template; minor gaps because the referenced scripts are not bundled alongside the skill.

4 / 5

Workflow Clarity

Four clearly sequenced workflows with goals, but these batch/audit operations (remediation plans, risk acceptance) lack explicit validation checkpoints and error-recovery feedback loops, capping workflow clarity per the rubric.

3 / 5

Progressive Disclosure

Good section structure with one-level-deep signaled references, but the referenced files (references/*.md and scripts/*.py) do not actually exist in the bundle, so the navigation links are dead when scored against the actual bundle structure.

3 / 5

Total

14

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that names three concrete decisions, gives explicit use-when triggers, and disambiguates from adjacent skills. Minor room to add a few more natural user phrasings/synonyms for trigger terms.

DimensionReasoningScore

Specificity

Lists multiple concrete actions framed as three numbered decisions (gap analysis against Clauses 4-10, AI risk register with Annex A control mapping, 12-month audit plan satisfying Clause 9.2), giving comprehensive coverage of capabilities.

5 / 5

Completeness

Explicitly answers both what (three named decisions) and when ('Use when preparing for certification, scoping internal audit cycles, or onboarding AI systems into an existing ISMS/QMS program') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural keywords a compliance user would say ('internal audits', 'certification', 'AI risk register', 'Annex A controls', 'ISMS/QMS') with good synonyms (ISO 42001 + AIMS), but a few common natural phrasings are not fully enumerated.

4 / 5

Distinctiveness Conflict Risk

Clear niche (ISO 42001 AIMS internal audit) with explicit boundary disambiguation against two adjacent skills ('NOT chief-ai-officer-advisor', 'NOT compliance-team-eu-ai-act'), minimizing conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 4 missing

Warning

referenced_paths_exist

Referenced path issues: 16 missing

Warning

Total

14

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.