CtrlK
BlogDocsLog inGet started
Tessl Logo

azure-compliance

Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.

64

Quality

Does it follow best practices?

Impact

No eval scenarios have been run

SecuritybySnyk

Passed

No known issues

SKILL.md
Quality
Evals
Security

Quality

Content

57%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-organized with good progressive disclosure and useful reference/linking, but is held back by redundant trigger sections, a lack of executable command examples, and missing validation checkpoints in the audit workflow.

Suggestions

Consolidate 'When to Use This Skill' and 'Skill Activation Triggers' to remove redundancy and free token budget.

Add concrete, copy-paste-ready MCP tool invocation examples (e.g. example azqr call arguments and expected output) to improve actionability.

Insert explicit validation/verification checkpoints in the Assessment Workflow (e.g. verify scan artifacts were captured before classifying findings).

DimensionReasoningScore

Conciseness

Mostly efficient tables, but the 'Skill Activation Triggers' section largely restates 'When to Use This Skill', and the Quick Reference table repeats the description; some tightening is possible.

2 / 3

Actionability

MCP tool names are listed and the workflow steps are concrete in intent, but there are no copy-paste-ready invocation examples or command snippets — steps like 'Run azqr and capture output artifacts' describe rather than instruct.

2 / 3

Workflow Clarity

A clear 5-step sequence exists with priority and error-handling tables, but batch audit operations lack explicit validation/verification checkpoints, capping clarity at 2.

2 / 3

Progressive Disclosure

Clear overview with well-signaled, one-level-deep references to real files (azure-quick-review.md, azure-keyvault-expiration-audit.md, azure-resource-graph.md, and SDK guides); content is appropriately split out.

3 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong across all dimensions: specific third-person actions, natural trigger terms, explicit when-guidance, and a distinct Azure compliance niche. It is a model example for this rubric.

DimensionReasoningScore

Specificity

Lists multiple specific concrete actions in third person voice — 'Run Azure compliance and security audits with azqr', 'Key Vault expiration checks', 'best-practice assessment, resource review, policy/compliance validation, and security posture checks'.

3 / 3

Completeness

Clearly answers both what the skill does and when to use it via an explicit 'WHEN:' clause listing concrete triggers.

3 / 3

Trigger Term Quality

Good coverage of natural terms a user would say, e.g. 'compliance scan, security audit', 'expired certificates, expiring secrets, orphaned resources'.

3 / 3

Distinctiveness Conflict Risk

The Azure/azqr/Key Vault niche is specific and unlikely to collide with other skills' triggers.

3 / 3

Total

12

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 9 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 9 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
microsoft/azure-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.