CtrlK
BlogDocsLog inGet started
Tessl Logo

azure-compliance

Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.

63

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/azure-skills/skills/azure-compliance/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, token-efficient overview with concrete tool names and clean reference navigation. The main gaps are the absence of validation checkpoints in the scan workflow and three orphaned reference files that SKILL.md never surfaces directly.

Suggestions

Add explicit validation checkpoints to the Assessment Workflow (e.g., after step 2, verify the azqr output artifacts exist and the scan completed for the full requested scope before analyzing findings), and wire the Error Handling table's remediations into the relevant steps as retry loops.

Link the three orphaned reference files (auth-best-practices.md, azqr-recommendations.md, azqr-remediation-patterns.md) from SKILL.md — e.g., in the Assessments or a new Related References section — so they are discoverable in one hop instead of only via cross-links inside other references.

Drop the Quick Reference table (it restates the description and MCP tools listed below it) and add one example azqr tool invocation with its scope arguments to make the workflow copy-paste actionable.

DimensionReasoningScore

Conciseness

The body is a lean, table-driven overview with no concept explanations Claude already knows (no "what is Azure" padding), and the priority/error tables are dense and useful. Not 5 because the Quick Reference table ("Best for | Compliance scans, security audits, Key Vault expiration checks") duplicates the frontmatter description and could be trimmed.

4 / 5

Actionability

Concrete guidance throughout: exact MCP tool identifiers ("mcp_azure_mcp_extension_azqr", "keyvault_certificate_get"), a 5-step workflow, and an error-message-to-remediation table. Not 5 because no example tool invocations or parameters are shown for the common cases (e.g., what arguments the azqr scan takes for a subscription vs. resource group scope).

4 / 5

Workflow Clarity

The 5-step Assessment Workflow is sequenced, but validation checkpoints are missing or implicit — nothing verifies scan artifacts exist before analysis (step 3) or confirms the scan covered the requested scope. The Error Handling table supplies recovery actions but is not integrated into the workflow steps; for a batch scan across many resources the rubric caps workflow clarity at 3 without validation.

3 / 5

Progressive Disclosure

Good structure: SKILL.md is an overview with clearly signaled one-level-deep links (3 assessment references plus 9 SDK guides, all real files). Not 5 because three bundle files (auth-best-practices.md, azqr-recommendations.md, azqr-remediation-patterns.md) are never linked from SKILL.md and are only reachable via a second hop through other references, making them buried.

4 / 5

Total

15

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit WHEN clause and mostly concrete, natural triggers anchored by the distinctive azqr and Key Vault markers. The main weakness is the generic "Covers..." coverage tail, which pads without adding concrete actions or new trigger terms.

DimensionReasoningScore

Specificity

"Run Azure compliance and security audits with azqr plus Key Vault expiration checks" names the tool and several concrete actions, and the WHEN clause names specific checks ("Key Vault expiration check, expired certificates, expiring secrets"). Falls short of 5 because "Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks" is topical coverage language rather than concrete actions.

4 / 5

Completeness

Explicitly answers both: what ("Run Azure compliance and security audits with azqr plus Key Vault expiration checks") and when ("WHEN: compliance scan, security audit, BEFORE running azqr...") with concrete trigger phrases. This matches the top anchor's what+when shape; a 4 would require the when-clause to be less explicit than it is.

5 / 5

Trigger Term Quality

Good natural trigger terms users would actually say: "compliance scan", "security audit", "Azure best practices", "expired certificates", "expiring secrets", "orphaned resources". Not 5 because common variations like "certificate expiry" or "run an azqr scan" are missing and "compliance assessment" redundantly repeats "compliance scan".

4 / 5

Distinctiveness Conflict Risk

"azqr" and "Key Vault expiration" are distinctive niche markers unlikely to collide with other skills. Not 5 because broad terms like "security audit", "best practices", and "orphaned resources" could fire on generic security or housekeeping requests outside this skill's azqr scope.

4 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 9 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 9 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
microsoft/GitHub-Copilot-for-Azure
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.