CtrlK
BlogDocsLog inGet started
Tessl Logo

gdpr-data-handling

Implement GDPR-compliant data handling with consent management, data subject rights, and privacy by design. Use when building systems that process EU personal data, implementing privacy controls, or conducting GDPR compliance reviews.

77

1.25x
Quality

66%

Does it follow best practices?

Impact

98%

1.25x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./tests/ext_conformance/artifacts/agents-wshobson/hr-legal-compliance/skills/gdpr-data-handling/SKILL.md

The canonical home for this skill is gdpr-data-handling in wshobson/agents

SKILL.md
Quality
Evals
Security

Quality

Content

46%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers genuinely useful, concrete implementation patterns, but it is a monolithic ~630-line file that spends significant tokens re-teaching GDPR fundamentals Claude already knows and gives destructive operations no validation loops. Splitting patterns into reference files and trimming conceptual padding would markedly improve it.

Suggestions

Move the five implementation patterns (consent, DSAR, retention, privacy-by-design, breach) into files under references/ and keep SKILL.md as a concise overview with clearly signaled one-level-deep links, per progressive disclosure.

Cut the "Core Concepts" section (Article 6 bases, Articles 15–21 rights table) — Claude already knows GDPR structure — and keep only the operational specifics like the 30-day deadline and 72-hour notification window.

Add validation/feedback loops to the destructive and batch workflows: a dry-run mode and post-operation verification for erasure and retention enforcement, and an explicit verify step in DSAR processing.

DimensionReasoningScore

Conciseness

The "Core Concepts" section re-explains GDPR Article 6 lawful bases and Articles 15–21 rights that Claude already knows, "When to Use This Skill" duplicates the frontmatter description, and the ~630-line body carries several padded sections. Not a 1 because the code patterns are substantive rather than filler.

2 / 5

Actionability

Concrete, near-executable code for consent management, DSAR handling, retention enforcement, breach notification, and the consent UI. Minor gaps keep it from copy-paste ready: undefined dependencies (self.db, self.eventBus, self.notify_dpo, generate_request_id) and missing imports (timedelta, List in Pattern 5).

4 / 5

Workflow Clarity

Content is organized as parallel reference patterns rather than a sequenced workflow, and the destructive/batch operations (erasure, retention enforcement) lack validation checkpoints or feedback loops — no dry-run, no post-deletion verification — which caps this dimension at 3 per the rubric.

3 / 5

Progressive Disclosure

No bundle files exist (references/, scripts/, assets/ are absent) and the entire ~600-line skill is one monolithic file. Content that clearly belongs in separate files — five full code patterns plus a compliance checklist — is fully inlined with no references at all, though section headers keep it navigable.

2 / 5

Total

11

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capabilities, an explicit "Use when" clause with realistic triggers, and a distinct GDPR/EU-privacy niche. The only improvement space is broader trigger synonyms and tighter verb-based phrasing.

DimensionReasoningScore

Specificity

Lists several concrete capability areas ("consent management, data subject rights, and privacy by design") but leaves gaps — retention, DSAR handling, and breach notification covered by the skill body are absent, and actions are noun-phrases rather than crisp verbs.

4 / 5

Completeness

Explicitly answers both questions: a clear "what" ("Implement GDPR-compliant data handling with consent management, data subject rights, and privacy by design") followed by an explicit "Use when" clause with three concrete trigger scenarios.

5 / 5

Trigger Term Quality

Natural terms users would say are present ("GDPR", "EU personal data", "privacy controls", "compliance reviews", "consent"), but common variations like "DSAR", "right to be forgotten", and "privacy policy" are missing.

4 / 5

Distinctiveness Conflict Risk

"GDPR", "EU personal data", and "data subject rights" carve out a clear niche with domain-locked triggers and minimal risk of firing for the wrong skill.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (631 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
Dicklesworthstone/pi_agent_rust
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.