CtrlK
BlogDocsLog inGet started
Tessl Logo

unbroker

Autonomously remove your info from data-broker sites.

52

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./optional-skills/security/unbroker/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

73%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a strong, highly actionable skill body: an explicit autonomous loop, a validated state machine, per-broker playbooks, and real verification steps for destructive operations, with bundle references that are genuine and one level deep. Its weaknesses are redundancy — several policy rules (PeopleConnect exception, CAPTCHA policy, no-questions rule) are stated two to four times — and one broken verification instruction referencing a test runner and test file that do not exist in the bundle.

Suggestions

Fix the Verification section: scripts/run_tests.sh and tests/skills/test_unbroker_skill.py do not exist in the bundle — either include them or point to a command that actually runs.

State the PeopleConnect delete-wipes-suppression rule once in a single authoritative place (e.g. its site playbook or methods.md) and reference it from the other sections; the same consolidation applies to the CAPTCHA policy, which is currently spread across four sections.

Move the full blind-opt-out doctrine and per-method opt-out detail from the Batch/Procedure sections into references/methods.md, keeping only the decision rule and a pointer inline.

DimensionReasoningScore

Conciseness

The body is dense with genuinely skill-specific operational knowledge (autonomy contract, tier system, cluster-parent ordering, CAPTCHA policy) and wastes little on concepts Claude already knows, but the same rules are restated multiple times: the PeopleConnect delete-wipes-suppression exception appears three times (Batch operation, Procedure step 5, plus its own bolded bullet), the CAPTCHA policy is covered in Prerequisites, Batch operation, Procedure step 5, and Pitfalls, and the "don't ask questions" rule is repeated in the Autonomy contract and Pitfalls. This matches the anchor "mostly efficient but includes some unnecessary explanation or could be tightened"; it is clearly not the lean score-5 anchor, nor padded enough to fall to 2.

3 / 5

Actionability

The body provides exact commands with flags, a ready-to-run loop pseudocode that maps to real CLI commands, concrete env vars, a copy-paste dry-run verification snippet, and per-broker playbook references — overwhelmingly executable guidance. The gap: the Verification section cites "scripts/run_tests.sh tests/skills/test_unbroker_skill.py", but neither scripts/run_tests.sh nor any tests/ directory exists in the bundle, so the primary test instruction cannot be executed as written. This fits "mostly executable guidance; concrete code or commands with minor gaps" rather than the fully copy-paste-ready score-5 anchor.

4 / 5

Workflow Clarity

The Procedure is an explicit 8-step sequence with a concrete while-loop over `$PDD next`, and the destructive/batch operations all carry validation checkpoints and feedback loops: `confirmed_removed` only after a verifying re-scan, subagent `found` claims re-verified by the parent, re-scan of cluster children after each parent confirms, `blocked` sites requeued rather than dropped, lock-timeout recovery guidance, and error paths for broker flows breaking. This matches the score-5 anchor (clear sequence, explicit validation, feedback loops for error recovery) — the destructive-operation cap of 3 does not apply because validation is thoroughly present.

5 / 5

Progressive Disclosure

SKILL.md functions as an operational overview with clearly signaled, one-level-deep references that all exist (references/methods.md, references/site-playbooks.md, references/brokers/*.json including intelius.json, references/legal/drop.md), plus real scripts. It is not the score-5 anchor because the body still inlines substantial policy detail that belongs in methods.md (e.g. the full blind-opt-out doctrine, the PeopleConnect exception stated three times, and the 23-row quick-reference table), which could be split out. It is well above the score-3 anchor, whose hallmark is buried or unsignaled references.

4 / 5

Total

16

/

20

Passed

Description

48%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise and names a distinct niche, but it is a single short sentence: it names only one action, lacks any 'use when' trigger guidance, and is written in second person ("your info") rather than third person. It sits at or below the midpoint on most dimensions despite being highly distinctive as a domain.

Suggestions

Rewrite in third person and enumerate the concrete actions, e.g. "Finds where a person's name, addresses, phone, and email are exposed on data-broker and people-search sites (Spokeo, Whitepages, Intelius...), submits opt-out/deletion requests automatically, verifies removals, and manages recurring re-scans."

Add an explicit trigger clause such as "Use when the user asks to opt out of, be removed from, or delete their data on data-broker or people-search sites, or to clean up after a doxxing."

Include the natural synonyms users say — "people-search", "opt out", "remove me from" — so the skill triggers on phrasings other than the literal "data broker".

DimensionReasoningScore

Specificity

The description "Autonomously remove your info from data-broker sites" names the domain and a single concrete action (remove info), matching the anchor for minimal action coverage ("Names the domain but actions are minimal or generic"). It also uses second person ("your info") rather than the required third person voice, which reduces the score by 1 from the 3 it would otherwise earn for naming the domain plus one concrete action.

2 / 5

Completeness

The "what" is clear (autonomous removal of personal info from data-broker sites), but there is no "Use when..." clause or equivalent trigger guidance anywhere in the description. Per the judging guidelines, a missing 'Use when...' clause caps completeness at 3; the score-4/5 anchors require an explicit 'when' component.

3 / 5

Trigger Term Quality

"data-broker sites" is a relevant keyword, but the description omits the natural variations users actually say: "people-search", "opt out", "Spokeo/Whitepages", "delete me from", or "doxxing" — all of which the skill body itself lists as triggers. Some relevant keywords exist but common synonyms are missing, matching the score-3 anchor.

3 / 5

Distinctiveness Conflict Risk

Data-broker removal is a clear niche with distinct triggers, and "data-broker sites" is a specific, recognizable domain unlikely to fire for unrelated skills. Minor overlap risk exists with general privacy/OSINT-related skills (the body lists osint-investigation as related), matching the "mostly distinct; minor overlap risk" anchor rather than the fully distinct score-5 anchor.

4 / 5

Total

12

/

20

Passed

Validation

75%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 12 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

referenced_paths_exist

Referenced path issues: 1 missing, 2 deeper-than-1-level

Warning

Total

12

/

16

Passed

Repository
NousResearch/hermes-agent
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.