CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/compliance-coverage-scoring

Scores existing tests and evidence against a named compliance framework's criteria list (GDPR, CCPA/CPRA, SOC 2 Trust Services Criteria, HIPAA Security Rule, PCI DSS, ISO/IEC 27001), marking every criterion met, partial, not met, or not applicable with a stated evidence requirement per state, and recording each scope exclusion with its criterion reference, reason, named approver, and re-review date. Includes an adversarial readiness-review mode with hard refusal rules (never "ready" with an unjustified gap), and the ISO/IEC 27001:2022 Annex A per-control test-pattern catalog in references/iso27001.md. Produces a readiness self-assessment only: not certification, not an audit opinion, not legal advice. Use when a framework version has been named and an evidence set already exists, and someone needs a per-criterion readiness score before an observation period opens, before a qualified assessor arrives, or in response to a regulator inquiry.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable body with a clear multi-step workflow, explicit validation via adversarial refusal rules, and clean reference splitting. The only notable gap is the two-level reference nesting under the ISO branch and some repetition of the self-assessment disclaimer.

DimensionReasoningScore

Conciseness

The body is efficient and largely assumes Claude's competence, with most detail (HIPAA required/addressable, window-bound evidence) being genuinely specialized rather than common knowledge; minor instances of over-explanation remain, such as repeating the 'not certification / not legal advice' framing across the intro, matrix template, and anti-patterns.

4 / 5

Actionability

Fully actionable: a copy-paste-ready coverage-matrix markdown template with real criterion IDs and example cells, an executable exclusion-record YAML shape, four concrete scoring rules, and runnable `grep`/`find` commands for adversarial evidence discovery.

5 / 5

Workflow Clarity

A clearly sequenced five-step workflow (resolve -> score -> record exclusions -> emit matrix -> dry run) with explicit validation checkpoints in the adversarial readiness-review refusal rules and feedback loops in Step 5 (monthly re-score, re-baseline against assessor findings, rebuild on version change).

5 / 5

Progressive Disclosure

Good structure: the SKILL.md spine is a lean overview with well-signaled one-level-deep links to frameworks.md and iso27001.md, each accompanied by when-to-read guidance; the minor gap is that the ISO branch nests a second level (iso27001.md -> annex-a-control-index.md and technical-control-test-patterns.md), which is clearly labeled 'Deep reference' but is not the clean one-level-deep structure a 5 requires.

4 / 5

Total

18

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, highly specific description that explicitly covers both what the skill does and when to use it, in correct third-person voice with minimal conflict risk. Its only weakness is verbosity: it enumerates every framework, state, and exclusion field, which pads the description without adding trigger value.

DimensionReasoningScore

Specificity

Lists several concrete actions ('Scores existing tests and evidence against a named compliance framework's criteria list', 'marking every criterion met, partial, not met, or not applicable', 'recording each scope exclusion with its criterion reference, reason, named approver, and re-review date') with comprehensive coverage, but the action list is padded by enumerating all six frameworks and all four exclusion fields rather than staying lean.

4 / 5

Completeness

Clearly and explicitly answers both 'what' (scores evidence against a versioned criteria list into four states, records exclusions, emits a self-assessment) and 'when' ('Use when a framework version has been named and an evidence set already exists, and someone needs a per-criterion readiness score before an observation period opens, before a qualified assessor arrives, or in response to a regulator inquiry') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Good keyword coverage of natural domain terms users would say ('GDPR', 'CCPA', 'SOC 2', 'HIPAA', 'PCI DSS', 'ISO/IEC 27001', 'readiness score', 'regulator inquiry', 'observation period', 'qualified assessor'), though a few common synonyms and bare file extensions are absent.

4 / 5

Distinctiveness Conflict Risk

Clear niche (per-criterion compliance readiness scoring against named frameworks) with distinct triggers and an explicit non-attestation boundary, giving minimal conflict risk with other skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Reviewed

Table of Contents