CtrlK
BlogDocsLog inGet started
Tessl Logo

twilio-security-compliance-hipaa

Configure Twilio accounts for HIPAA compliance. Covers BAA requirements, HIPAA Project designation (self-service and support), eligible services list, per-product requirements (Voice, SMS, ConversationRelay, Conversation Intelligence, Flex, Verify), message redaction, and what is NOT eligible. Use this skill when developers are building healthcare workflows on Twilio.

68

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is concise, well-sequenced, and rich in concrete configuration constraints, but it is a monolithic document with no progressive-disclosure split into reference files, and actionability leans on descriptive steps rather than executable artifacts.

Suggestions

Move the large eligible-services tables and per-product requirements into reference files (e.g. ELIGIBLE-SERVICES.md, PER-PRODUCT.md) and link them from a concise overview to improve progressive disclosure.

Add concrete executable snippets where possible (e.g. example API calls or Console deep-links) rather than relying solely on descriptive navigation paths.

The June 6, 2024 date is time-sensitive; consider isolating date/version-dependent branching into a clearly marked section so the core guidance ages gracefully.

DimensionReasoningScore

Conciseness

Lean, scannable, mostly bullet/table content with no filler explaining concepts Claude already knows; every line carries a configuration fact or constraint.

3 / 3

Actionability

Concrete Console navigation paths and ordered prerequisites are given, but most guidance is descriptive configuration steps rather than executable code or copy-paste commands, and some actions rely on 'Contact Support' rather than scriptable steps.

2 / 3

Workflow Clarity

An explicit ordered sequence ('Execute BAA -> Designate HIPAA Project -> Use eligible services -> Per-product requirements') with numbered self-service steps and verification checkpoints ('Verify each subaccount's HIPAA flag'), plus a consolidated CANNOT guardrail list.

3 / 3

Progressive Disclosure

No bundle reference files exist; the SKILL.md is a single well-organized document but the dense eligible-services tables and per-product details could be split into reference files for better navigation.

2 / 3

Total

10

/

12

Passed

Description

85%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that states both the capability and an explicit use-when trigger, with a clearly bounded niche. Trigger-term naturalness could be marginally broader but is solid overall.

DimensionReasoningScore

Specificity

Lists multiple concrete actions and per-product requirements: 'Execute BAA', 'HIPAA Project designation (self-service and support)', 'message redaction', covering Voice, SMS, ConversationRelay, Conversation Intelligence, Flex, Verify.

3 / 3

Completeness

Explicitly answers what ('Configure Twilio accounts for HIPAA compliance') and when ('Use this skill when developers are building healthcare workflows on Twilio'), satisfying the 'Use when...' trigger clause.

3 / 3

Trigger Term Quality

Natural trigger terms like 'healthcare workflows' and 'HIPAA compliance' appear, but coverage of common user phrasings (e.g. 'PHI', 'BAA', 'Twilio healthcare') is partial and somewhat jargon-heavy.

2 / 3

Distinctiveness Conflict Risk

A clear narrow niche (Twilio HIPAA configuration) with distinctive trigger language unlikely to fire for general security or other compliance skills.

3 / 3

Total

11

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
openai/plugins
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.