CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/soc2-evidence-collector

Build-an-X for SOC 2 Type II evidence collection and auditor-facing packaging - per-Trust-Services-Criterion test artifacts (Common Criteria CC1.1 - CC9.2; plus Availability A1, Confidentiality C1, Processing Integrity PI1, Privacy P1 - P9 if in scope); auto-collection from CI logs + audit trails + access logs + change-management records; alignment with Vanta / Drata / Secureframe evidence shapes; observation-period sampling. Cross-framework evidence packaging (control-evidence matrix, timestamped bundles, chain-of-custody notes per NIST SP 800-72 - also for ISO 27001 / HIPAA / PCI DSS / GDPR / FedRAMP) lives in references/evidence-packaging.md. Use when the team is preparing for SOC 2 Type II audit and needs continuous evidence collection, or when any audit engagement requires auditor-ready evidence packages built from automated test output.

71

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An actionable, well-structured build-an-X workflow with executable examples and clean progressive disclosure into real reference files. The main improvement is making per-step validation checkpoints more explicit for the batch/destructive evidence-storage operations.

Suggestions

Add explicit validate->fix->retry feedback loops around the immutable/append-only evidence-storage step (Step 6) since continuity gaps there are themselves audit findings.

Tighten the Step 1 scope-decision and Step 4 platform-comparison tables, moving any non-essential rows into references/evidence-source-map.md to reduce inline tokens.

Make the per-step verification in the Step 8 end-to-end recipe concrete commands (e.g., how to 'run a mock auditor query') rather than checklist items alone.

DimensionReasoningScore

Conciseness

Mostly lean - it omits tutorial padding about what SOC 2 is and gets to executable patterns, but the scope-decision tables and platform-comparison sections include some detail that could be trimmed or deferred to references.

4 / 5

Actionability

Provides copy-paste-ready, executable Python collector and test examples that cover common cases (CC6.1 evidence export, CC6.3 deprovisioning test), with concrete collector-run metadata and storage patterns.

5 / 5

Workflow Clarity

A clear 8-step sequence with a checklist-style end-to-end recipe and a mock-audit validation step, but validation checkpoints within individual steps are mostly implicit rather than explicit validate->fix->retry loops.

4 / 5

Progressive Disclosure

Well-structured overview pointing to three clearly-signaled one-level-deep references (evidence-source-map.md, evidence-packaging.md, grc-delivery-and-ci-automation.md), all of which exist as real files, with bulk detail appropriately split out.

5 / 5

Total

18

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, comprehensive third-person description that names concrete capabilities and provides explicit 'Use when...' trigger guidance. Minor room to broaden trigger-term synonyms beyond framework-specific jargon.

DimensionReasoningScore

Specificity

Lists multiple concrete actions - per-criterion test artifacts, auto-collection from CI logs/audit trails/access logs/change-management records, GRC-platform evidence-shape alignment, and observation-period sampling - giving comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

Explicitly answers both 'what' (build-an-X for SOC 2 Type II evidence collection and auditor-facing packaging) and 'when' ('Use when the team is preparing for SOC 2 Type II audit and needs continuous evidence collection, or when any audit engagement requires auditor-ready evidence packages') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Good coverage of natural terms users would say ('SOC 2 Type II audit', 'evidence collection', 'auditor-ready evidence packages', 'Vanta / Drata / Secureframe'), though it leans on framework-specific jargon and omits a few common synonyms like 'compliance' or 'audit prep'.

4 / 5

Distinctiveness Conflict Risk

Clearly niched to SOC 2 evidence collection with distinct triggers (Vanta/Drata/Secureframe, Type II audit), with only minor overlap risk against general compliance or sibling test-pattern catalogs.

4 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Reviewed

Table of Contents