CtrlK
BlogDocsLog inGet started
Tessl Logo

soc2-audit-prep

/cs:soc2-audit-prep <scope> — SOC 2 Type II readiness 6-question forcing interrogation. Observation-period focused. Use before Type II observation begins, mid-period checkpoint, or pre-field-test month-10 readiness.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.gemini/skills/soc2-audit-prep/SKILL.md

The canonical home for this skill is soc2-audit-prep in alirezarezvani/claude-skills

SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured, lean, and actionable with concrete commands and a usable output template. Its chief gap is workflow clarity: the multi-step process omits explicit validation checkpoints between steps.

Suggestions

Insert an explicit validation/verification step after each workflow command (e.g., "confirm gap_analyzer produced scope findings before building the control matrix").

Add a short feedback loop for the mock-audit step (run audit_simulator, review flagged exceptions, re-run after fixes) to raise workflow clarity.

Confirm the referenced scripts (gap_analyzer.py, control_matrix_builder.py, evidence_tracker.py, audit_simulator.py) resolve to real files, since none exist in this skill bundle.

DimensionReasoningScore

Conciseness

Mostly lean bullet-driven content with bolded takeaways and no generic concept explanation; a few lines (e.g., "75% control overlap — the canonical pair") could be trimmed but earn their place.

4 / 5

Actionability

Provides concrete executable bash commands in the workflow and a complete output template, with only minor gaps since the referenced scripts live outside this bundle.

4 / 5

Workflow Clarity

A clear 4-step numbered sequence exists but lacks explicit validation checkpoints or feedback loops (e.g., verifying evidence_tracker or gap_analyzer output before proceeding).

3 / 5

Progressive Disclosure

Well-organized into clear sections with signaled links to related skills and a playbook; no bundle files exist, and the inlined question/output content is appropriately placed with only minor organization gaps.

4 / 5

Total

15

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly establishes a specific SOC 2 Type II niche with explicit timing triggers, distinguishing it well from sibling compliance skills. Its main weakness is that the capability phrasing ("forcing interrogation") is jargon-heavy and does not enumerate the concrete actions performed.

Suggestions

Replace the jargon "forcing interrogation" with a plain enumeration of what the skill does (e.g., "runs a 6-question readiness checklist covering scope, control coverage, change management, exceptions, evidence sampling, and cross-framework reuse").

Add a couple of user-natural trigger synonyms (e.g., "SOC 2 audit", "Type II readiness", "observation-period gap analysis") to broaden trigger coverage.

DimensionReasoningScore

Specificity

Names the domain ("SOC 2 Type II readiness") and a concrete action ("6-question forcing interrogation"), but does not enumerate the constituent actions, so coverage is not comprehensive.

3 / 5

Completeness

Both "what" (readiness 6-question interrogation) and an explicit "when" ("Use before Type II observation begins, mid-period checkpoint, or pre-field-test month-10 readiness") are present; the "what" leans on jargon and could be more explicit.

4 / 5

Trigger Term Quality

Natural compliance-audit terms a practitioner would say are present ("SOC 2 Type II", "observation period", "field-test", "readiness"), though a few common synonyms are missing.

4 / 5

Distinctiveness Conflict Risk

A clear niche (SOC 2 Type II observation-period prep) with distinct triggers and only minor adjacency to sibling ISO 27001 / GDPR skills, giving minimal conflict risk.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 suspicious

Warning

Total

15

/

16

Passed

Repository
alirezarezvani/claude-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.