CtrlK
BlogDocsLog inGet started
Tessl Logo

azure-compliance

Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.

66

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is azure-compliance in microsoft/GitHub-Copilot-for-Azure

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, token-efficient overview with concrete tooling, a clear workflow, and verified one-level-deep references. The main gaps are high-level workflow steps without example invocations or validation checkpoints, and three orphaned reference files that are absent from the navigation.

Suggestions

Add one or two example MCP tool invocations (e.g., an azqr call with subscription/parameter shape) to the Assessment Workflow so steps 2-3 are copy-paste executable rather than high-level.

Link auth-best-practices.md, azqr-recommendations.md, and azqr-remediation-patterns.md from a table or section in SKILL.md so all bundle content is discoverable through the top-level navigation.

Trim or merge the Best Practices and Priority Classification sections, whose generic guidance Claude can infer, into the workflow or reference files to tighten token usage.

DimensionReasoningScore

Conciseness

The body is dominated by lean tables (MCP tools, error handling, priorities) with no explanations of concepts Claude already knows. Not a 5 because the "Best Practices" and "Priority Classification" sections contain generic guidance ("Run compliance scans on a regular schedule", "Critical | Immediate remediation required") that could be trimmed or inferred.

4 / 5

Actionability

Concrete MCP tool identifiers and an error table with exact remediation commands ("Run `az login` and retry") give executable guidance, with details pushed to real reference files. Falls short of 5 because workflow steps remain high-level ("Run azqr and capture output artifacts", "Analyze Scan Results") with no example tool invocations or parameters.

4 / 5

Workflow Clarity

The 5-step Assessment Workflow is a clear sequence, and the Error Handling table provides explicit recovery paths for auth, access, and missing-resource failures. Not a 5 because there are no explicit validation checkpoints within the workflow itself (e.g., confirming a non-empty subscription list before scanning); not a 3 because error-recovery guidance is present and the scans are read-only, so the destructive-cap does not apply.

4 / 5

Progressive Disclosure

The body is a well-organized overview with one-level-deep, clearly signaled references (Assessments table and SDK Quick References), and every linked path resolves to a real bundle file. Not a 5 because three bundle files in references/ (auth-best-practices.md, azqr-recommendations.md, azqr-remediation-patterns.md) are never linked or mentioned in SKILL.md, leaving that content undiscoverable via navigation.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it names concrete capabilities with a specific tool, uses third person, and includes an explicit WHEN clause with natural trigger phrases and synonyms. The only weakness is keyword coverage with a few missing natural variations, which keeps trigger quality and specificity at 4 rather than 5.

DimensionReasoningScore

Specificity

"Run Azure compliance and security audits with azqr plus Key Vault expiration checks" and "best-practice assessment, resource review, policy/compliance validation, and security posture checks" list several concrete, tool-anchored actions. Not a 5 because coverage has minor gaps (e.g., no mention of report/output generation); well above a 3's 1-2 concrete actions.

4 / 5

Completeness

Explicitly answers what ("Run Azure compliance and security audits with azqr plus Key Vault expiration checks") and when ("WHEN: compliance scan, security audit, ... Key Vault expiration check, expired certificates, expiring secrets") with concrete trigger phrases, matching the top anchor exactly.

5 / 5

Trigger Term Quality

"compliance scan, security audit, BEFORE running azqr, Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources" are natural user phrases with good synonym coverage (expired certificates / expiring secrets). A few common variations (e.g., "Azure audit", "policy compliance review") are missing, keeping it below 5.

4 / 5

Distinctiveness Conflict Risk

A clear Azure-specific niche anchored by the named azqr tool and Key Vault expiration monitoring; trigger terms are distinct and unlikely to fire for unrelated skills, matching the clear-niche anchor.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 9 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 9 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
microsoft/azure-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.