Content
14%Scale 1-3Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This skill is a massive monolithic dump of compliance-checking scripts with no clear workflow, no progressive disclosure, and significant verbosity. While some bash scripts contain real, executable AWS CLI commands, the Python scripts have incomplete implementations (stub functions, placeholder comments), and there's no guidance on sequencing, error handling, or remediation. The skill would benefit enormously from being restructured into a concise overview with separate bundle files for each framework's checks.
Suggestions
Extract each framework's scripts (CIS, PCI-DSS, HIPAA) into separate bundle files and reference them from a concise SKILL.md overview with clear navigation links.
Add a clear end-to-end workflow: prerequisites (IAM permissions, credential report generation), execution sequence, validation of results, and remediation steps when issues are found.
Remove the 'Supported Frameworks' section listing well-known framework categories and the generic 'Best Practices' section — Claude already knows these.
Complete the stub implementations (run_cis_checks, run_pci_checks, run_hipaa_checks returning empty lists) or remove the compliance-report.py if it's not functional.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Extremely verbose at ~400+ lines. Lists every compliance framework's categories (which Claude already knows), includes massive bash scripts inline, has placeholder functions (run_cis_checks returning empty lists), and explains concepts like what PCI-DSS and HIPAA cover. The 'Supported Frameworks' section is pure padding listing well-known framework categories. | 1 / 3 |
Actionability | The CIS bash scripts are mostly executable and contain real AWS CLI commands, but the PCI-DSS Python checker has incomplete requirements (comments like '# Check for default passwords, etc.'), and the compliance-report.py has stub functions returning empty lists. SOC 2 checks are mentioned but never implemented. | 2 / 3 |
Workflow Clarity | There is no clear workflow for how to actually run a compliance check end-to-end. Scripts are presented as standalone files with no sequencing, no validation checkpoints, no error handling guidance, and no instructions on what to do when issues are found. For a skill involving security auditing, the lack of verification steps and remediation workflows is a significant gap. | 1 / 3 |
Progressive Disclosure | All content is dumped into a single monolithic file with hundreds of lines of inline scripts. The CIS checks alone span multiple large bash scripts that should be in separate bundle files. No bundle files are provided despite the content clearly warranting them. External links are provided but only as generic resources, not as structured references to supporting skill files. | 1 / 3 |
Total | 5 / 12 Passed |