Automation skill for designing, verifying, and improving auth, cost, logging, and security compliance based on the internal AI tool mandatory implementation guide (P0/P1). Supports the full lifecycle of RBAC design, Gateway principles, Firestore policy, behavior logs, cost transparency, and the criteria verification system.
65
47%
Does it follow best practices?
Impact
100%
2.27xAverage score across 3 eval scenarios
Risky
Do not use without reviewing
Optimize this skill with Tessl
npx tessl skill review --optimize ./.agent-skills/ai-tool-compliance/SKILL.mdCompliance project initialization structure
compliance-config.yaml exists
0%
100%
rbac-matrix.yaml exists
0%
100%
log-schema.yaml exists
0%
100%
cost-tracking.yaml exists
20%
100%
p0-rules.yaml exists
0%
100%
All 5 RBAC roles defined
0%
100%
Guest has no permissions
0%
100%
Domain weights sum to 100
20%
100%
Correct default domain weights
0%
100%
Gate thresholds correct
0%
100%
P0 fail override enabled
0%
100%
Log schema required fields
30%
100%
Log schema storage tiers
16%
100%
Cost tracking AI model fields
33%
100%
AI Gateway and cost logging implementation
No direct external AI API calls
100%
100%
AI calls via server function
100%
100%
Cache check before AI call
100%
100%
AI call only on cache miss
100%
100%
Model name logged
100%
100%
Input tokens logged
50%
100%
Output tokens logged
50%
100%
Estimated cost logged
71%
100%
Reference ID returned to client
0%
100%
No raw content in logs/responses
37%
100%
Auth check present
100%
100%
Guest role blocked
0%
100%
Error handler logs failures
50%
100%
Compliance verification report generation
Section 1: Summary present
100%
100%
Section 2: Rule Results table
75%
100%
Evidence with file references
100%
100%
Section 3: Score Breakdown
0%
100%
Section 4: Failures Detail
62%
100%
Section 5: Gate Decision
57%
100%
Section 6: Recommendations
100%
100%
SEC-P0-004 identified as FAIL
58%
100%
AUTH-P0-001 identified as PASS
0%
100%
Grade is Red
25%
100%
Remediation for FAIL
25%
100%
verification-results.json produced
100%
100%
c033769
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.