CtrlK
BlogDocsLog inGet started
Tessl Logo

security-compliance-compliance-check

You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform compliance audits and provide implementation guidance.

47

Quality

48%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/security-compliance-compliance-check/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

35%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and concise, but it offers only vague, non-executable instructions and points to a reference file that is missing from the bundle, limiting both actionability and progressive disclosure.

Suggestions

Replace the generic Instructions with concrete, executable steps (e.g., specific checklist templates, commands, or control-mapping examples) to raise actionability.

Add explicit validation checkpoints to the workflow (e.g., verify evidence coverage against each control before marking a regulation compliant).

Either create the referenced 'resources/implementation-playbook.md' or remove the broken reference so progressive disclosure resolves to real content.

DimensionReasoningScore

Conciseness

The body is short and free of concept padding, but the opening paragraph duplicates the frontmatter description and the Instructions are generic boilerplate ('Clarify goals...', 'Apply relevant best practices...') that could be tightened, so it is mostly rather than fully efficient.

2 / 3

Actionability

The Instructions ('Clarify goals, constraints, and required inputs', 'Apply relevant best practices and validate outcomes') are abstract directives with no concrete code, commands, or specific examples, matching the 'describes rather than instructs' anchor.

1 / 3

Workflow Clarity

The Output Format provides a numbered sequence of deliverables, but the actual process Instructions are not a sequenced workflow and contain no validation checkpoints for the audit process.

2 / 3

Progressive Disclosure

Sections are well organized and detail is deferred to a clearly signaled reference, but the referenced 'resources/implementation-playbook.md' does not exist in the bundle, so the navigation cannot reliably lead to deeper material.

2 / 3

Total

7

/

12

Passed

Description

62%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies a clear, distinctive compliance niche with strong natural trigger terms, but its completeness is capped by the absence of an explicit 'Use when' clause and its specificity is penalized for second-person voice.

Suggestions

Rewrite in third person (e.g., 'Performs compliance audits...') to avoid the voice penalty and restore the specificity score.

Add an explicit trigger clause such as 'Use when assessing compliance readiness for GDPR, HIPAA, SOC2, or PCI-DSS' to lift completeness to 3.

Expand the action list beyond 'audits' and 'implementation guidance' to concrete activities (e.g., build control checklists, generate audit evidence) for stronger specificity.

DimensionReasoningScore

Specificity

It names the domain and specific regulations (GDPR, HIPAA, SOC2, PCI-DSS) plus two actions ('Perform compliance audits and provide implementation guidance'), which would rate a 2, but the second-person phrasing 'You are a compliance expert' triggers the rubric's -1 voice penalty, dropping it to 1.

1 / 3

Completeness

It clearly states what the skill does but lacks any explicit 'Use when...' trigger guidance, so per the rubric a missing trigger clause caps completeness at 2 rather than 3.

2 / 3

Trigger Term Quality

The regulation acronyms GDPR, HIPAA, SOC2, and PCI-DSS alongside 'compliance audits' are exactly the natural terms a user would say when requesting this skill, giving good coverage rather than just a few relevant keywords.

3 / 3

Distinctiveness Conflict Risk

The specific regulatory-framework niche with named standards creates a clear, distinctive scope that is unlikely to trigger for unrelated skills.

3 / 3

Total

9

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
rmyndharis/antigravity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.