CtrlK
BlogDocsLog inGet started
Tessl Logo

804-regulations-eu-nis2

Use when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. Supports essential or important entities, critical-sector services, managed service providers, supply-chain dependencies, and cybersecurity incident escalation obligations without ingesting raw code, logs, runbooks, tickets, provider documents, or other operational free text. Part of Plinth Toolkit

57

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/804-regulations-eu-nis2/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill is well structured for progressive disclosure and has a clear, gated workflow, but the body is heavily padded with repeated constraint prose and its central recommendation step lacks concrete mapping guidance. The evidence-inventory format the whole workflow depends on is never defined, which limits how actionable the guidance is on its own.

Suggestions

State the raw-content prohibition and the legal-advice disclaimer once each (e.g., in Constraints) and reference them from the workflow steps instead of repeating the full enumeration three times; this alone would remove roughly a third of the body.

Define or point to the expected structure of the sanitized evidence inventory (its required fields or a small example entry) so steps 2-4 are executable rather than aspirational.

Replace the 'When to use this skill' section (which duplicates the frontmatter description) with one or two concrete before/after examples of mapping an inventory fact to a recommended control, which would strengthen actionability at no token cost.

DimensionReasoningScore

Conciseness

The raw-content prohibition is repeated nearly verbatim at least three times (intro paragraph, 'NO RAW OPERATIONAL CONTENT' constraint, and workflow step 3), the 'not legal advice' disclaimer appears twice in adjacent paragraphs, and the 'When to use this skill' section duplicates the frontmatter description. This matches anchor 2 ('noticeably verbose; several unnecessary explanations or padded sections') better than 3, since whole passages could be deleted without losing information.

2 / 5

Actionability

Steps 1 and 5 are concrete (exact reference files named with reading order, and a report template with enumerated required sections), but step 4 is only a category list ('asset and service inventory, secure configuration, dependency and vulnerability management...') with no worked example of mapping an inventory fact to a control, and the expected structure of the sanitized evidence inventory is never specified. This fits anchor 3 ('some concrete guidance but incomplete; missing key details').

3 / 5

Workflow Clarity

The five-step workflow is clearly sequenced with an explicit comprehension gate ('Do not start implementation review until... are understood') and a stop condition ('if it is missing or incomplete, stop and request a corrected inventory'). It matches anchor 4 ('clear sequence with most checkpoints present; minor validation gaps') rather than 5, since there is no validate-and-retry loop for the report output.

4 / 5

Progressive Disclosure

The body is an overview that cleanly delegates depth to three one-level-deep, verified bundle files (chapters summary, engineering examples, report template), each clearly signaled in prose and again in a closing Reference section. This matches anchor 5 ('clear overview with well-signaled one-level-deep references; content appropriately split').

5 / 5

Total

14

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, niche-targeted description with an explicit 'Use when' clause, third-person voice, and a good set of natural trigger terms. Its main weaknesses are the generic action verbs and an indirect statement of what the skill actually produces. It avoids over-claims and reads as an honest scope statement.

DimensionReasoningScore

Specificity

The description lists several specific capabilities and domains ('reviewing, designing, or modifying Java enterprise systems', 'essential or important entities, critical-sector services, managed service providers, supply-chain dependencies, and cybersecurity incident escalation obligations'), but the core verbs remain generic and the concrete output (an engineering review report) is never mentioned. This matches anchor 4 ('several specific actions; minor gaps') rather than 3 (more than 1-2 actions are named) or 5 (the actions themselves are not fully concrete).

4 / 5

Completeness

Both parts are present: an explicit 'Use when reviewing, designing, or modifying...' trigger clause and a stated capability set. The 'what' is somewhat indirect ('Supports essential or important entities...') rather than a crisp list of concrete actions, fitting anchor 4 ('both what and when; when could be more explicit or specific') rather than anchor 5.

4 / 5

Trigger Term Quality

Natural user terms like 'NIS2', 'Java enterprise', 'cybersecurity', 'incident escalation', 'supply-chain', and 'managed service providers' are present and would be said by users needing this skill. However common variations such as 'compliance', 'audit', 'security review', or 'EU directive' are missing, matching anchor 4 rather than 5's comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

The combination of 'NIS2' and 'Java enterprise systems' carves out a clear niche with distinct trigger phrases, making accidental triggering by generic security, compliance, or Java skills very unlikely. This clearly matches anchor 5 ('clear niche with distinct triggers; minimal conflict risk').

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 3 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
jabrena/plinth
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.