CtrlK
BlogDocsLog inGet started
Tessl Logo

azure-compliance

Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.

64

Quality

76%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.github/plugins/azure-skills/skills/azure-compliance/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, table-driven overview with clear reference navigation and a sensible workflow, but it lacks inline executable examples and the workflow omits validation checkpoints for a batch operation. Three bundle files are also orphaned from the body's navigation.

Suggestions

Add an inline example invocation of a key MCP tool (e.g. a sample azqr scan call and a keyvault_certificate_get call) so the body offers copy-paste-ready executable guidance rather than just a tool catalog.

Insert an explicit validation checkpoint in the Assessment Workflow — e.g. 'Confirm the scan covered all resources in scope before classifying findings' — since the batch scan currently has no verification step.

Link the three orphaned bundle files (auth-best-practices.md, azqr-recommendations.md, azqr-remediation-patterns.md) from the body so all bundle content is discoverable from SKILL.md.

DimensionReasoningScore

Conciseness

The body is efficient and table-driven with no concept explanations Claude already knows, but the Quick Reference table lightly restates the description's capabilities and the Best Practices bullets offer slightly generic advice — minor instances that could be trimmed rather than a fully lean 5.

4 / 5

Actionability

The MCP Tools table gives concrete tool names and purposes, but the body itself contains no executable code, commands, or example tool invocations; the workflow steps are abstract ('Run azqr and capture output artifacts') and the actual execution detail is deferred to reference files.

3 / 5

Workflow Clarity

The Assessment Workflow is a clear 5-step sequence but lacks explicit validation/verification checkpoints, and because a subscription-wide compliance scan is a batch operation the missing-validation cap at 3 applies despite the supporting Error Handling and Priority Classification tables.

3 / 5

Progressive Disclosure

Structure is good with a clear overview pointing to well-signaled, one-level-deep reference files (3 assessment refs + 9 SDK refs) that all exist, but three bundle files (auth-best-practices.md, azqr-recommendations.md, azqr-remediation-patterns.md) are not linked from the body, leaving a navigation gap that keeps it below 5.

4 / 5

Total

14

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-targeted description that states concrete capabilities and pairs them with an explicit WHEN clause of natural trigger phrases. It is comprehensive, distinct, and free of vague fluff.

DimensionReasoningScore

Specificity

Lists multiple concrete actions spanning the domain — 'Run Azure compliance and security audits with azqr', 'Key Vault expiration checks', 'best-practice assessment, resource review, policy/compliance validation, and security posture checks' — giving comprehensive coverage rather than a couple of named actions.

5 / 5

Completeness

It clearly answers both 'what' (run compliance/security audits with azqr plus Key Vault expiration checks, covering several assessment types) and 'when' via an explicit 'WHEN:' clause with concrete trigger phrases, so the missing-trigger cap at 3 does not apply.

5 / 5

Trigger Term Quality

The explicit WHEN clause packs in natural phrases users would actually say — 'compliance scan', 'security audit', 'Azure best practices', 'expired certificates', 'expiring secrets', 'orphaned resources' — plus the positioning trigger 'BEFORE running azqr', with synonyms (compliance scan / compliance assessment) included.

5 / 5

Distinctiveness Conflict Risk

It carves a clear niche (Azure compliance auditing via azqr + Key Vault expiration) with distinct triggers like 'BEFORE running azqr' and 'Key Vault expiration check', making overlap with other skills minimal.

5 / 5

Total

20

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 9 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 9 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
microsoft/azure-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.