CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-compliance-checker

Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks

55

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/antigravity-aws-compliance-checker/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an exemplary progressive-disclosure overview — lean, well-organized, and pointing to a real, sectioned one-level-deep reference with clear loading guidance. Its weakness is actionability: the SKILL.md itself contains no executable command, quick-start snippet, or concrete step, delegating everything to the guide.

Suggestions

Add a minimal quick-start block in the body — e.g. one representative AWS CLI check command or an invocation example from the guide — so the skill is actionable before loading the full reference.

Briefly sequence the top-level workflow (run checks → generate report → review findings) in the body so the multi-step process is visible without opening the guide.

State where the guide's validation/prerequisites live (e.g. name the section) so "treat its validation requirements as mandatory" points to a concrete location.

DimensionReasoningScore

Conciseness

The ~30-line body contains zero padding and no explanations of concepts Claude already knows — every section (Detailed Guide, When to Use, Example Prompts, Limitations) is minimal and earns its tokens. This matches the "lean and efficient; every token earns its place" anchor.

5 / 5

Actionability

The body offers no executable command, code, or specific steps — all concrete material is delegated via "Read [the detailed guide](references/detailed-guide.md) before executing this skill." The example prompts are illustrative user inputs, not executable guidance, matching the "high-level hints but missing the specific steps to execute" anchor rather than anchor 3, which requires some concrete (even if incomplete) instruction in the content itself.

2 / 5

Workflow Clarity

The single instruction "Read [the detailed guide]... before executing" with guidance to load relevant sections vs. read completely is a coherent single-step workflow, but the body itself contains no sequencing or validation checkpoints — validation is only deferred ("Treat its safety, prerequisites, and validation requirements as mandatory"). This sits at anchor 3: sequence is implied and checkpoints are missing, and batch compliance checks without body-level validation cannot score above 3.

3 / 5

Progressive Disclosure

Verified against the actual bundle: the body is a concise overview with a single clearly-signaled, one-level-deep reference (references/detailed-guide.md), which exists and is well-sectioned (Supported Frameworks, CIS/PCI-DSS/HIPAA/SOC 2 checks, Best Practices) to support focused loading ("For focused work, load the relevant sections; for end-to-end work, read the guide completely"). This matches the anchor for a clear overview with well-signaled one-level-deep references.

5 / 5

Total

15

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly communicates a compliance-checking capability anchored to four well-known frameworks, giving it good trigger terms and distinctiveness. Its main weaknesses are the absence of an explicit "Use when..." trigger clause and a single generic action verb, leaving both completeness and specificity at the midpoint.

Suggestions

Add an explicit trigger clause, e.g. "Use when the user asks for a compliance check, audit preparation, or continuous compliance monitoring against CIS, PCI-DSS, HIPAA, or SOC 2."

List concrete actions beyond "checking" — e.g. "runs CIS benchmark checks, generates PCI-DSS/HIPAA/SOC 2 compliance reports" — to raise specificity.

Mention AWS explicitly in the description so it matches the skill's actual scope and distinguishes it from non-AWS compliance skills.

DimensionReasoningScore

Specificity

The description names the compliance domain and four concrete frameworks ("CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks"), but the only action stated is the generic "Automated compliance checking" — no specific actions like generating reports or auditing specific AWS configurations. It does not reach anchor 4, which requires several specific listed actions.

3 / 5

Completeness

The "what" is clear (automated compliance checking against four named benchmarks), but there is no "Use when..." clause or equivalent trigger guidance, capping completeness at 3 per the judging guidelines. Not anchor 2, since the "what" half is concrete rather than vague.

3 / 5

Trigger Term Quality

Terms like "compliance", "CIS", "PCI-DSS", "HIPAA", and "SOC 2" are exactly what users say when they need this skill. It falls short of anchor 5 because common variations like "audit", "security", and "AWS" are absent.

4 / 5

Distinctiveness Conflict Risk

Naming four specific compliance frameworks carves out a distinct niche with low conflict risk against unrelated skills. It is not anchor 5 because the description omits "AWS" and could still overlap with other general security-audit or compliance skills.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
boisenoise/skills-collections
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.