Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.
83
78%
Does it follow best practices?
Impact
Pending
No eval scenarios have been run
Passed
No known issues
Optimize this skill with Tessl
npx tessl skill review --optimize ./plugin/skills/azure-compliance/SKILL.mdQuality
Discovery
100%Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.
This is a strong skill description that clearly communicates specific capabilities (Azure compliance audits via azqr, Key Vault expiration checks), provides comprehensive trigger terms in an explicit WHEN clause, and occupies a distinct niche. The description is concise yet thorough, using third-person voice and covering both the 'what' and 'when' effectively.
| Dimension | Reasoning | Score |
|---|---|---|
Specificity | Lists multiple specific concrete actions: 'Run Azure compliance and security audits with azqr', 'Key Vault expiration checks', 'best-practice assessment', 'resource review', 'policy/compliance validation', 'security posture checks'. These are concrete, identifiable tasks. | 3 / 3 |
Completeness | Clearly answers both 'what' (run Azure compliance/security audits with azqr, Key Vault expiration checks, best-practice assessment, resource review, policy/compliance validation, security posture checks) and 'when' with an explicit 'WHEN:' clause listing trigger scenarios like 'compliance scan', 'security audit', 'BEFORE running azqr', etc. | 3 / 3 |
Trigger Term Quality | Excellent coverage of natural terms users would say: 'compliance scan', 'security audit', 'Azure best practices', 'Key Vault expiration check', 'expired certificates', 'expiring secrets', 'orphaned resources', 'compliance assessment', and the tool name 'azqr'. These are terms users would naturally use when requesting these tasks. | 3 / 3 |
Distinctiveness Conflict Risk | Highly distinctive with a clear niche: Azure-specific compliance and security auditing using the azqr tool, plus Key Vault expiration checks. The combination of Azure, azqr, Key Vault, and compliance/security terms creates a very specific domain unlikely to conflict with other skills. | 3 / 3 |
Total | 12 / 12 Passed |
Implementation
57%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This skill is well-structured as an overview document with strong progressive disclosure to reference materials. However, it lacks concrete, executable examples (no actual MCP tool invocations with parameters) and the workflow could benefit from explicit validation checkpoints. Some content is redundant between the 'When to Use' and 'Skill Activation Triggers' sections.
Suggestions
Add a concrete example of an MCP tool invocation with actual parameters, e.g., showing how to call `mcp_azure_mcp_extension_azqr` with a specific subscription ID and what the output looks like.
Add validation checkpoints to the workflow, e.g., 'Verify azqr output contains expected resource types before proceeding to analysis' and 'Confirm Key Vault access before running expiration checks'.
Merge 'When to Use This Skill' and 'Skill Activation Triggers' into a single concise section to eliminate redundancy.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The skill includes some unnecessary sections like 'Skill Activation Triggers' which extensively lists things Claude can infer, and the 'When to Use This Skill' section largely duplicates the triggers. The tables are reasonably efficient but there's redundancy between sections. | 2 / 3 |
Actionability | The skill lists MCP tools and provides a workflow, but lacks concrete executable examples—no actual command invocations, no sample tool calls with parameters, no example outputs. The workflow steps are described at a high level without specific commands or code. | 2 / 3 |
Workflow Clarity | The 5-step assessment workflow provides a reasonable sequence but lacks validation checkpoints and feedback loops. For a compliance/security audit involving potentially destructive remediation steps, there's no explicit validate-before-proceeding pattern or error recovery within the workflow itself. | 2 / 3 |
Progressive Disclosure | Excellent use of progressive disclosure with a clear overview page that references detailed materials via well-organized tables. References are one level deep, clearly signaled, and cover multiple assessment types and SDK guides across languages. | 3 / 3 |
Total | 9 / 12 Passed |
Validation
100%Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.
Validation — 11 / 11 Passed
Validation for skill structure
No warnings or errors.
a46a937
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.