Guides preparation of compliance documentation for CockroachDB Cloud deployments, covering SOC 2, PCI DSS, ISO 27001, HIPAA, and GDPR certifications. Use when responding to compliance questionnaires, preparing for audits, locating certification documents, or assessing cluster configuration for compliance readiness.
90
88%
Does it follow best practices?
Impact
Pending
No eval scenarios have been run
Passed
No known issues
Quality
Discovery
100%Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.
This is an excellent skill description that clearly defines its scope, lists specific compliance frameworks, and provides explicit trigger guidance via a well-constructed 'Use when' clause. It uses proper third-person voice throughout and covers both the 'what' and 'when' comprehensively. The description is concise yet thorough, with strong natural trigger terms that users would actually use.
| Dimension | Reasoning | Score |
|---|---|---|
Specificity | Lists multiple specific concrete actions: preparing compliance documentation, responding to compliance questionnaires, preparing for audits, locating certification documents, and assessing cluster configuration for compliance readiness. Also names specific frameworks (SOC 2, PCI DSS, ISO 27001, HIPAA, GDPR). | 3 / 3 |
Completeness | Clearly answers both 'what' (guides preparation of compliance documentation for CockroachDB Cloud covering specific certifications) and 'when' (explicit 'Use when' clause listing four specific trigger scenarios: questionnaires, audits, certification documents, compliance readiness assessment). | 3 / 3 |
Trigger Term Quality | Excellent coverage of natural terms users would say: 'compliance', 'SOC 2', 'PCI DSS', 'ISO 27001', 'HIPAA', 'GDPR', 'audit', 'certification', 'compliance questionnaires', 'CockroachDB Cloud'. These are all terms a user would naturally use when seeking compliance help. | 3 / 3 |
Distinctiveness Conflict Risk | Highly distinctive with a clear niche: CockroachDB Cloud compliance documentation specifically. The combination of the specific product (CockroachDB Cloud) and specific domain (compliance/certifications) makes it very unlikely to conflict with other skills. | 3 / 3 |
Total | 12 / 12 Passed |
Implementation
77%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This is a well-structured compliance documentation skill with strong actionability through concrete SQL queries, CLI commands, and detailed control mappings. The workflow is clear and logically sequenced. The main weakness is moderate verbosity — some content could be tightened or offloaded to reference files, and the inline tables partially duplicate what the referenced compliance-matrix.md should contain.
Suggestions
Move the detailed per-framework control mapping tables (SOC 2, PCI DSS, HIPAA) into the referenced compliance-matrix.md file and keep only a summary in the main SKILL.md to reduce length and avoid duplication.
Remove or condense the Prerequisites and When to Use sections, which largely restate obvious context that Claude can infer from the skill description.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The skill is reasonably well-structured but includes some unnecessary verbosity, such as the 'Prerequisites' section (understanding your compliance requirements is obvious), the 'When to Use This Skill' section which largely restates the description, and some redundancy across the compliance framework tables. The questionnaire response templates in Step 4 explain things Claude likely already knows (e.g., what TLS is, what encryption at rest means). | 2 / 3 |
Actionability | The skill provides concrete, executable SQL queries and CLI commands for assessing cluster compliance configuration, specific table mappings of controls to features, and clear checklists with expected states. The questionnaire response templates give copy-paste-ready answers. The audit preparation steps are specific and actionable. | 3 / 3 |
Workflow Clarity | The five-step workflow is clearly sequenced from identification through assessment to audit preparation. The compliance checklist in Step 3 includes explicit validation checks with expected states. The audit preparation section has a clear before/during sequence. Since this is a read-only documentation preparation skill, destructive operation feedback loops are not needed. | 3 / 3 |
Progressive Disclosure | The skill references a compliance matrix file (references/compliance-matrix.md) and links to many related skills, which is good progressive disclosure structure. However, no bundle files were provided, so the compliance-matrix.md reference cannot be verified. The inline content is quite long with detailed tables that could potentially be offloaded to reference files, and the SOC 2, PCI DSS, and HIPAA control mapping tables add significant length that the compliance-matrix.md reference was presumably meant to handle. | 2 / 3 |
Total | 10 / 12 Passed |
Validation
100%Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.
Validation — 11 / 11 Passed
Validation for skill structure
No warnings or errors.
84bc1e4
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.