CtrlK
BlogDocsLog inGet started
Tessl Logo

access-review

Conduct periodic access reviews and certifications. Implement access governance and recertification workflows. Use when managing access compliance.

55

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./plugins/agentic-awesome-skills-claude/skills/access-review/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers genuinely actionable audit content — complete multi-platform scripts, a well-sequenced review workflow with SLAs, and a real one-level-deep reference file. Its main weaknesses are token bulk from fully inlined scripts, annotation artifacts that break copy-paste executability, and reference navigation that is misleading (three Contents entries to one file, dangling scripts/ paths).

Suggestions

Remove the invalid "<!-- security-allowlist: ... -->" HTML comments from the bash pipelines (they are not valid bash and break verbatim execution), or replace them with proper '#' shell comments.

Fix the Contents section so each label points to the content it names (e.g., anchors within details.md) instead of three links to the same file, and remove or clearly flag the unbundled scripts/*.sh invocations in references/details.md.

Move the three full audit scripts out of SKILL.md into a scripts/ bundle (or a reference file) and keep only usage summaries inline to reduce the entrypoint's token footprint.

DimensionReasoningScore

Conciseness

The body is dense and operational with no concept re-explanation, but it inlines three full multi-page scripts (~240 lines of bash) plus a Python module that duplicate material and could be summarized with pointers. "Mostly efficient but includes some... could be tightened" matches anchor 3; not 2 because there is no padded prose, and not 4 because the inlined scripts and the workflow/checklist redundancy with references/details.md consume budget unnecessarily.

3 / 5

Actionability

The AWS, GitHub, and Okta scripts plus the boto3 module are concrete, real CLI/API invocations with output files — "mostly executable guidance with minor gaps" (anchor 4). Not 5 because the scripts are not copy-paste runnable: three pipeline lines embed invalid HTML comment annotations ("<!-- security-allowlist: ... -->") that bash cannot parse, plus hard-coded placeholders (ORG="your-org", a specific analyzer ARN/account).

4 / 5

Workflow Clarity

The 5-phase workflow (scope, extract, review, remediate, report) is clearly sequenced with explicit SLAs ("Complete within 5 business days"), decision options (approve/modify/revoke), escalation for non-responses, and a confirmation step for revocations — matching anchor 4's 'clear sequence with most checkpoints present'. Not 5 because there are no feedback/verify-retry loops (e.g., re-check after revocation or confirm remediation SLA breach), and the scripts themselves have no error handling.

4 / 5

Progressive Disclosure

References are one level deep and real (references/details.md exists and contains the certification automation, checklist, and best practices), but the Contents section lists three distinct labels that all point to the same file, and references/details.md invokes scripts/*.sh that are not bundled (the skill itself notes "Docs-only import: upstream templates and scripts not bundled"). Combined with large script bodies inlined in SKILL.md, this matches anchor 3 ('some structure... references present but not clearly signaled; content that should be separate is inline'); not 2 because the file split and section headers do provide workable navigation.

3 / 5

Total

14

/

20

Passed

Description

62%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, in third person, and answers both what and when, but stays at a high level of abstraction. It omits the platforms and concrete detection capabilities the skill actually delivers, which limits trigger coverage.

Suggestions

Name the concrete capabilities and platforms, e.g. "Audit AWS IAM, GitHub, and Okta access; detect unused permissions, stale access keys, and inactive accounts".

Enrich the when-clause with natural trigger phrases users would say: "Use when running access audits or recertification campaigns, or when preparing SOC 2 / ISO 27001 access-governance evidence".

DimensionReasoningScore

Specificity

"Conduct periodic access reviews and certifications. Implement access governance and recertification workflows" names the domain and two actions, but they are generic — no platforms (AWS IAM, GitHub, Okta), no concrete operations like unused-permission detection. Matches anchor 3 ('names domain and 1-2 concrete actions, but not comprehensive'); not 4 because it lacks the several specific actions the body actually covers.

3 / 5

Completeness

Both parts are explicit: what ("Conduct periodic access reviews and certifications. Implement access governance and recertification workflows") and when ("Use when managing access compliance"). Matches anchor 4 ('both what and when; when could be more explicit'); not 5 because the when-clause is a single generic condition with no concrete trigger phrases, and not 3 because the when-clause is explicit, not merely implied.

4 / 5

Trigger Term Quality

Relevant phrases include "access reviews", "certifications", "recertification", and "access compliance", but common user phrasings are missing: "access audit", "SOC 2", "stale access keys", "unused permissions", "privileged access review". Some relevant keywords with missing variations matches anchor 3; not 4 because the synonym coverage is thin for a compliance domain with a rich vocabulary.

3 / 5

Distinctiveness Conflict Risk

"Access reviews and certifications" plus "recertification workflows" carve a distinct governance niche unlikely to fire for unrelated skills. Minor overlap risk with general compliance/audit skills keeps it at anchor 4 rather than 5.

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.