CtrlK
BlogDocsLog inGet started
Tessl Logo

akf-trust-metadata

The AI native file format. EXIF for AI — stamps every file with trust scores, source provenance, and compliance metadata. Embeds into 20+ formats (DOCX, PDF, images, code). EU AI Act, SOX, HIPAA auditing.

53

Quality

60%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

—

The risk profile of this skill

Fix and improve this skill with Tessl

tessl review fix ./skills/akf-trust-metadata/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

87%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a well-crafted, concise skill that provides clear, actionable CLI commands for AI content provenance stamping. Its main weakness is the lack of explicit workflow sequencing and validation steps — particularly important for compliance-related operations where confirming metadata was correctly embedded matters. The content is otherwise efficient and well-structured for its scope.

Suggestions

Add a validation/verification step after stamping, e.g., 'akf read <file>' to confirm metadata was correctly embedded, and describe what to do if it fails.

Consider adding an explicit numbered workflow for the most common use case (e.g., 1. Read existing metadata → 2. Modify file → 3. Stamp → 4. Verify stamp → 5. Audit if compliance-required) to improve workflow clarity.

DimensionReasoningScore

Conciseness

The content is lean and efficient. It doesn't explain what metadata is, what EXIF is in detail, or how compliance frameworks work — it assumes Claude knows these things. Every section is brief and purposeful with minimal filler.

3 / 3

Actionability

Every section provides concrete, copy-paste-ready CLI commands with clear flags and arguments. Evidence examples are specific and practical. The install command is included. All guidance is directly executable.

3 / 3

Workflow Clarity

The skill presents a reasonable implicit workflow (read before modifying, stamp after creating, audit for compliance), but lacks explicit sequencing, validation checkpoints, or error recovery steps. For a tool that stamps compliance metadata, there should be a verify/validate step after stamping to confirm the metadata was correctly embedded.

2 / 3

Progressive Disclosure

For a simple, single-purpose CLI tool skill under 50 lines with no bundle files, the content is well-organized into clear, logically separated sections (when to use, stamp, read, audit, classify, install, links). No external references are needed and the structure supports easy scanning.

3 / 3

Total

11

/

12

Passed

Description

32%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description reads like marketing copy rather than a functional skill description. While it conveys a unique niche around AI provenance and compliance metadata embedding, it relies heavily on buzzwords ('AI native file format', 'EXIF for AI') and lacks the explicit 'Use when...' trigger guidance essential for Claude to correctly select this skill from a large pool. The core capability is somewhat discernible but would benefit from clearer, more actionable language.

Suggestions

Add an explicit 'Use when...' clause, e.g., 'Use when the user needs to embed provenance metadata, trust scores, or compliance audit trails into files, or mentions AI Act, SOX, or HIPAA compliance requirements.'

Replace marketing language ('AI native file format', 'EXIF for AI') with concrete action verbs in third person, e.g., 'Embeds trust scores, source provenance, and compliance metadata into 20+ file formats including DOCX, PDF, images, and code files.'

Add natural trigger terms users might actually say, such as 'audit trail', 'content authenticity', 'metadata stamping', 'regulatory compliance', or 'document provenance tracking'.

DimensionReasoningScore

Specificity

Names several concrete actions like 'stamps every file with trust scores, source provenance, and compliance metadata' and 'Embeds into 20+ formats', but reads more like marketing copy than a clear list of discrete capabilities. The actions are somewhat specific but mixed with buzzword-heavy language ('AI native file format', 'EXIF for AI').

2 / 3

Completeness

Describes what it does (embeds metadata into files) but completely lacks a 'Use when...' clause or any explicit trigger guidance for when Claude should select this skill. Per the rubric, a missing 'Use when...' clause caps completeness at 2, and the 'what' portion is also somewhat unclear due to marketing-style language, bringing this to 1.

1 / 3

Trigger Term Quality

Includes some useful keywords like 'DOCX', 'PDF', 'images', 'code', 'EU AI Act', 'SOX', 'HIPAA', 'provenance', 'compliance metadata', and 'trust scores'. However, it's unclear what natural user requests would trigger this — users are unlikely to say 'AI native file format' or 'EXIF for AI'. Missing common variations like 'audit trail', 'metadata tagging', or 'content authenticity'.

2 / 3

Distinctiveness Conflict Risk

The compliance/provenance metadata niche is fairly distinct, and mentioning specific regulations (EU AI Act, SOX, HIPAA) helps differentiate it. However, the broad mention of '20+ formats' including PDF and DOCX could overlap with other document-processing skills, and the lack of clear trigger conditions increases conflict risk.

2 / 3

Total

7

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.