CtrlK
BlogDocsLog inGet started
Tessl Logo

813-regulations-iso-42001

Use when reviewing, designing, or modifying Java enterprise systems that use GenAI, LLMs, AI-assisted coding, RAG, AI agents, generated code, generated dependencies, prompt workflows, external model providers, or AI-enabled business logic and need ISO/IEC 42001 AI management system-aware engineering guidance. Part of Plinth Toolkit

65

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/813-regulations-iso-42001/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and actionable for an instruction-only governance skill, with a clear sequenced workflow, validation gates, and verified one-level-deep references. Its main weakness is verbosity from repeated enumerations of the same risk and owner lists across multiple sections.

Suggestions

De-duplicate the seven-item GenAI risk list and the owner-role list, which recur nearly verbatim in Scope, ISO/IEC 42001 Engineering Review, Constraints, and Workflow; define them once and reference that definition elsewhere.

Trim the Constraints section's ten bullets to the most decision-relevant guardrails, moving detailed control mappings into the engineering-examples reference to lighten the overview.

Drop the framework enumeration (Spring Boot, Quarkus, Micronaut) unless it changes the guidance; the scope is already stated as framework-agnostic.

DimensionReasoningScore

Conciseness

Structure is efficient (headers, lists) and avoids explaining concepts Claude already knows, but the same seven-item GenAI risk list and ~ten-role owner list recur nearly verbatim across Scope, ISO/IEC 42001 Engineering Review, Constraints, and Workflow, which could be tightened.

3 / 5

Actionability

Provides concrete, executable guidance: a 5-step workflow naming specific files in reading order, a questionnaire checklist, a report template, and a risk-to-control mapping, with only minor gaps (no inline worked example of a filled report).

4 / 5

Workflow Clarity

Five clearly sequenced steps with explicit gates ('Do not start implementation review until... understood'), an evidence-gap escalation checkpoint, and a 'check for gaps between claimed controls and reviewable evidence' validation step; not a full validate-fix-retry loop but appropriate for a review skill.

4 / 5

Progressive Disclosure

SKILL.md is an overview pointing to four well-signaled one-level-deep references (all verified to exist), with a dedicated Reference section; the inline Scope and ten-bullet Constraints sections are slightly heavy for an overview, keeping it just below ceiling.

4 / 5

Total

15

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it explicitly states both what the skill provides and when to use it, with a comprehensive set of natural trigger terms and a well-delineated niche. Minor risk of overlap with adjacent governance skills and somewhat generic action verbs keep it just below ceiling on two dimensions.

DimensionReasoningScore

Specificity

Names the domain ('Java enterprise systems that use GenAI, LLMs, RAG...') and lists several concrete actions ('reviewing, designing, or modifying'), with only minor coverage gaps; the actions are generic verbs but the capability enumeration is comprehensive.

4 / 5

Completeness

Explicitly answers both 'what' (ISO/IEC 42001 AI management system-aware engineering guidance) and 'when' via a concrete 'Use when reviewing, designing, or modifying...' trigger clause.

5 / 5

Trigger Term Quality

Comprehensive coverage of natural terms a user would say ('GenAI, LLMs, AI-assisted coding, RAG, AI agents, generated code, generated dependencies, prompt workflows, external model providers') with synonyms included.

5 / 5

Distinctiveness Conflict Risk

Carves a clear niche (Java enterprise + GenAI + ISO/IEC 42001 governance) with distinct triggers, but the broad GenAI umbrella carries minor overlap risk with sibling AI-governance/regulation skills in the toolkit.

4 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 2 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 6 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
jabrena/plinth
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.