CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/compliance-coverage-scoring

Scores existing tests and evidence against a named compliance framework's criteria list (GDPR, CCPA/CPRA, SOC 2 Trust Services Criteria, HIPAA Security Rule, PCI DSS, ISO/IEC 27001), marking every criterion met, partial, not met, or not applicable with a stated evidence requirement per state, and recording each scope exclusion with its criterion reference, reason, named approver, and re-review date. Produces a readiness self-assessment only: not certification, not an audit opinion, not legal advice. Use when a framework version has been named and an evidence set already exists, and someone needs a per-criterion readiness score before an observation period opens, before a qualified assessor arrives, or in response to a regulator inquiry.

80

Quality

100%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

Quality

Content

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-engineered compliance skill: a clear five-step workflow, concrete and copy-paste-ready artifacts, explicit re-scoring checkpoints as validation feedback loops, and per-framework detail appropriately offloaded to a single real reference file. It assumes Claude's competence and adds only domain-specific, non-obvious guidance.

DimensionReasoningScore

Conciseness

The body is dense with non-obvious domain rules (evidence bars per state, the four scoring rules, required-vs-addressable handling) rather than concepts Claude already knows, and tables keep it tight; the repeated 'readiness self-assessment only' framing is deliberate emphasis for a legally sensitive skill, not filler. Every section earns its tokens.

3 / 3

Actionability

Provides a copy-paste-ready coverage matrix template, a concrete YAML exclusion record shape, exact criterion-reference formats (e.g. '164.504(e)'), and per-state evidence bars with 'Not sufficient' columns — fully actionable guidance despite being instruction-only.

3 / 3

Workflow Clarity

A clearly sequenced 5-step process with explicit validation checkpoints: Step 5 schedules re-scoring before/during/at-close/after the window and on version change, exclusion rules act as automated validation (missing field → not met, expired → void), and verdict bands plus the anti-patterns table serve as checklists and feedback loops.

3 / 3

Progressive Disclosure

The spine stays a lean workflow overview and pushes per-framework detail to references/frameworks.md, which is a real file referenced at well-signaled points one level deep — matching the score-3 anchor of a clear overview with well-signaled one-level-deep references.

3 / 3

Total

12

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, third-person description that names concrete actions, lists the frameworks and situational triggers a user would naturally say, and stays in a distinct niche. It is slightly long but every clause carries information rather than padding.

DimensionReasoningScore

Specificity

Lists multiple concrete actions: 'Scores existing tests and evidence', 'marking every criterion met, partial, not met, or not applicable', 'recording each scope exclusion with its criterion reference, reason, named approver, and re-review date', and 'Produces a readiness self-assessment' — matching the score-3 anchor of several specific concrete actions.

3 / 3

Completeness

Explicitly answers both 'what' (scores evidence against a criteria list, assigns four states, records exclusions) and 'when' via a clear 'Use when a framework version has been named and an evidence set already exists...' clause, matching the score-3 anchor for explicit what-and-when triggers.

3 / 3

Trigger Term Quality

Names the natural trigger terms a user would say — GDPR, CCPA/CPRA, SOC 2, HIPAA Security Rule, PCI DSS, ISO/IEC 27001 — plus the situational triggers 'before an observation period opens', 'before a qualified assessor arrives', and 'in response to a regulator inquiry', giving good natural-term coverage rather than jargon.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear niche (per-criterion compliance readiness scoring against named frameworks with a stated evidence bar) and its triggers are framework-specific, so it is unlikely to fire for an unrelated skill.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Reviewed

Table of Contents