CtrlK
BlogDocsLog inGet started
Tessl Logo

813-regulations-iso-42001

Use when reviewing, designing, or modifying Java enterprise systems that use GenAI, LLMs, AI-assisted coding, RAG, AI agents, generated code, generated dependencies, prompt workflows, external model providers, or AI-enabled business logic and need ISO/IEC 42001 AI management system-aware engineering guidance. Part of Plinth Toolkit

58

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/813-regulations-iso-42001/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured skill body with a clear sequenced workflow, strong bundle-file navigation, and specific review guidance. Its main weakness is heavy verbatim repetition of the risk enumerations, disclaimers, and owner lists, which pads the token budget without adding information.

Suggestions

State the seven-risk enumeration, the not-legal-advice disclaimer, and the owner-role list once each (in Constraints or the ISO review section) and reference them briefly elsewhere — the repetition across four to five sections is pure token padding.

Add a final validation step to the workflow, e.g., verify the produced report covers scope, evidence gaps, and owner handoffs before presenting it.

Replace the abstract risk-to-control mapping list in step 4 with one or two worked Java examples (or point explicitly to the matching section in the engineering-examples reference) to make it concretely executable.

DimensionReasoningScore

Conciseness

The body is noticeably verbose through verbatim repetition: the seven-risk enumeration ('hallucinated code, insecure generated implementation, generated dependency and supply-chain contamination, IP leakage, confidentiality breach, regulatory non-compliance risk, and biased generated business logic') appears in four sections, the not-legal/certification/audit-advice disclaimer appears about four times in varied forms, and the owner-role list repeats across five sections. It avoids score 1 because it does not explain concepts Claude already knows, but 'several unnecessary... padded sections' clearly matches anchor 2.

2 / 5

Actionability

The workflow names the exact four bundle files with an explicit reading order and per-file usage ('Read references/... , assets/questions/... in that order'), lists concrete artifacts to review (SBOM, RAG source registries, model version records, CI/CD workflows), and specifies required report sections. As an instruction-only skill this is mostly executable guidance; it falls short of 5 because the risk-to-control mapping is an abstract enumeration rather than worked concrete patterns, and above 3 because the steps are specific and directly executable.

4 / 5

Workflow Clarity

Five clearly sequenced steps with an explicit gating checkpoint ('Do not start implementation review until the summary, examples reference, questionnaire rules, and report template are understood') and questionnaire-before-report ordering. It misses 5 because there is no final validation/verification step for the produced report, and exceeds 3 because sequence and checkpoints are explicit rather than implicit.

4 / 5

Progressive Disclosure

The body is an overview pointing to four clearly signaled bundle files (linked both inline near the top and again in the Reference section), all one level deep, and every referenced path exists on disk in references/ and assets/. This matches 'clear overview with well-signaled one-level-deep references; content appropriately split; easy navigation'.

5 / 5

Total

15

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-scoped, highly specific trigger description with excellent natural keyword coverage and a distinct niche. Its main weakness is that the capability ('what this skill does') is only implied within the when-clause, with no explicit action statement.

Suggestions

Add an explicit what-clause before the when-clause, e.g., 'Reviews GenAI-assisted Java delivery and AI-enabled Java systems through an ISO/IEC 42001 AI management system lens, producing evidence-based review reports.'

Include a few more natural trigger variations users might say, such as 'AI governance', 'AI compliance', or 'LLM integration', to broaden keyword matching.

State the concrete outputs (engineering review report, questionnaire classification) so users know what the skill produces, not just when to invoke it.

DimensionReasoningScore

Specificity

The domain is named concretely ('Java enterprise systems that use GenAI, LLMs, AI-assisted coding, RAG, AI agents...'), but the only actions are the generic verbs 'reviewing, designing, or modifying' with no concrete capability statements such as producing review reports or completing a questionnaire. It fits 'names domain and 1-2 concrete actions, but not comprehensive' — above 2 because the scoping is highly concrete, below 4 because no specific action list is given.

3 / 5

Completeness

The 'when' is explicit and specific ('Use when reviewing, designing, or modifying...'), but the 'what' is only implied inside the when-clause ('need ISO/IEC 42001 AI management system-aware engineering guidance') rather than stated as a capability. This matches 'has both what and when; when could be more explicit or specific' in net quality — not 5 because the what is never explicitly stated, not 3 because a discernible what exists alongside an excellent when.

4 / 5

Trigger Term Quality

Strong natural keyword coverage with synonyms users would actually say: 'GenAI, LLMs, AI-assisted coding, RAG, AI agents, generated code, generated dependencies, prompt workflows, external model providers, AI-enabled business logic, ISO/IEC 42001'. A few natural terms are missing (e.g., 'AI governance', 'AI compliance', framework names like Spring Boot), matching 'good keyword coverage; a few natural terms missing' rather than the comprehensive synonym coverage of 5.

4 / 5

Distinctiveness Conflict Risk

'ISO/IEC 42001 AI management system-aware engineering guidance' for 'Java enterprise systems' with GenAI is a clear niche with distinct triggers and minimal conflict risk against other skills. The 'Part of Plinth Toolkit' tag does not blur the trigger.

5 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 2 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 6 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
jabrena/plinth
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.