CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-compliance-checker

Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks

52

Quality

58%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/antigravity-aws-compliance-checker/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

55%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The SKILL.md body is well-structured and concise with good progressive disclosure to a real detailed guide, but it offloads all executable guidance and workflow sequencing to the reference, leaving the body itself low on actionability and workflow clarity. Inlining a minimal quick-start check or two with an explicit validation step would meaningfully improve it.

Suggestions

Inline one or two concrete executable compliance checks (e.g. a CIS CloudTrail or root-MFA check command) so the body is actionable without requiring the full guide.

Add an explicit workflow sequence with a validation checkpoint (run check -> review findings -> remediate -> re-run), since this is a batch/audit skill where feedback loops matter.

State prerequisites and required permissions (AWS read-only IAM, CloudTrail visibility) up front so Claude can confirm readiness before executing.

DimensionReasoningScore

Conciseness

The body is lean and efficient: a brief overview, a single clearly signaled reference, example prompts, and limitations, with no over-explanation of concepts Claude already knows.

5 / 5

Actionability

The body itself contains no executable code or commands, only high-level pointers to the detailed guide ("validate AWS compliance"), matching the anchor for minimal concrete guidance with high-level hints.

2 / 5

Workflow Clarity

For a batch/audit operation the body provides no sequenced steps or validation checkpoints; it defers entirely to the reference, and the referenced guide itself lacks an explicit validate-fix-retry feedback loop.

2 / 5

Progressive Disclosure

The body is a clear overview pointing one level deep to a real, well-signaled reference file (references/detailed-guide.md) with instructions to read it, though it relies on a single reference rather than a cleanly split set.

4 / 5

Total

13

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise and names concrete compliance frameworks, giving it solid trigger-term quality and distinctiveness, but it lacks an explicit "Use when..." trigger clause and only states a single generic action. Adding a usage trigger and another concrete action verb would raise completeness and specificity.

Suggestions

Add an explicit trigger clause, e.g. ". Use when validating AWS environments for CIS, PCI-DSS, HIPAA, or SOC 2 audits, or preparing for a compliance review."

Replace or supplement the single generic verb "checking" with concrete actions like "audits, scores, and reports compliance against".

Explicitly scope the description to AWS accounts to reduce overlap with general audit/compliance skills.

DimensionReasoningScore

Specificity

The description names the compliance domain and concrete frameworks (CIS, PCI-DSS, HIPAA, SOC 2) but only offers one generic action verb ("checking"), matching the anchor for naming a domain with 1-2 concrete actions but lacking comprehensive coverage.

3 / 5

Completeness

It gives a clear "what" (automated compliance checking against named benchmarks) but no "when"/"Use when..." clause; per the rubric, a missing explicit trigger clause caps completeness at 3.

3 / 5

Trigger Term Quality

It includes strong natural keywords users would say (compliance, CIS, PCI-DSS, HIPAA, SOC 2, benchmarks), but misses common synonyms such as audit or report, placing it just above the midpoint anchor for good coverage.

4 / 5

Distinctiveness Conflict Risk

The named-framework niche is mostly distinct from other skills, though the absence of an explicit AWS scoping term leaves minor overlap risk with general audit skills.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
boisenoise/skills-collections
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.