Reviews contracts for compliance issues, drafts and audits privacy policies, assesses GDPR/CCPA/HIPAA/SOX/PCI-DSS obligations, identifies regulatory requirements, and flags legal risks across multiple jurisdictions. Use when the user asks about legal compliance, regulatory requirements, GDPR, CCPA, privacy policies, terms of service, contract review, data protection, data handling, legal review, or industry-specific regulations such as HIPAA, SOX, or PCI-DSS.
96
96%
Does it follow best practices?
Impact
Pending
No eval scenarios have been run
Passed
No known issues
Quality
Discovery
100%Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.
This is an excellent skill description that hits all the marks. It provides specific, concrete actions, comprehensive trigger terms covering multiple regulatory frameworks and user intents, an explicit 'Use when...' clause, and a clearly defined niche in legal compliance that is unlikely to conflict with other skills. The description uses proper third-person voice throughout.
| Dimension | Reasoning | Score |
|---|---|---|
Specificity | Lists multiple specific concrete actions: reviews contracts, drafts and audits privacy policies, assesses specific regulatory obligations (GDPR/CCPA/HIPAA/SOX/PCI-DSS), identifies regulatory requirements, and flags legal risks across jurisdictions. | 3 / 3 |
Completeness | Clearly answers both 'what does this do' (reviews contracts, drafts privacy policies, assesses regulatory obligations, flags legal risks) AND 'when should Claude use it' with an explicit 'Use when...' clause listing numerous trigger scenarios. | 3 / 3 |
Trigger Term Quality | Excellent coverage of natural terms users would say: 'legal compliance', 'regulatory requirements', 'GDPR', 'CCPA', 'privacy policies', 'terms of service', 'contract review', 'data protection', 'data handling', 'legal review', 'HIPAA', 'SOX', 'PCI-DSS'. These are all terms users would naturally use when seeking this kind of help. | 3 / 3 |
Distinctiveness Conflict Risk | Occupies a clear niche in legal compliance and regulatory review. The specific regulatory frameworks (GDPR, CCPA, HIPAA, SOX, PCI-DSS) and legal-specific actions (contract review, privacy policy drafting) make it highly distinguishable from other skills. | 3 / 3 |
Total | 12 / 12 Passed |
Implementation
92%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This is a high-quality skill with excellent actionability—concrete checklists, example output tables with specific contract language, precise regulatory citations, and clear risk classification tiers. The workflows are well-sequenced with explicit validation checkpoints. The main weakness is that all content is inline in a single file; splitting detailed checklists (e.g., GDPR checklist, CCPA checklist, contract clause library) into referenced files would improve token efficiency when only a subset of workflows is needed.
Suggestions
Consider splitting the detailed GDPR/CCPA checklists and example tables into separate referenced files (e.g., GDPR_CHECKLIST.md, CONTRACT_CLAUSES.md) to reduce token load when only one workflow is invoked.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The content is dense with actionable checklists, tables, and specific regulatory references. There is no unnecessary explanation of what GDPR or CCPA are—it assumes Claude knows these frameworks and jumps straight to what to check and how to output findings. | 3 / 3 |
Actionability | Every workflow provides concrete, specific steps with example output tables, exact regulatory article references (Art. 6, Art. 28, Art. 30), specific suggested contract language, precise timelines (72-hour notification, 30-day response), and structured checklists. The guidance is immediately executable. | 3 / 3 |
Workflow Clarity | Multi-step processes are clearly sequenced with numbered steps, explicit validation checkpoints (e.g., 'Before finalising review, confirm the report includes...'), gap tables for audit workflows, and clear escalation tiers (High/Medium/Low with specific criteria). Error recovery is addressed through the validation checkpoint pattern. | 3 / 3 |
Progressive Disclosure | The content is well-structured with clear section headers and logical organization across four workflows, but it's a fairly long monolithic file with no references to external files for detailed checklists or templates. The regulatory checklists and example tables could be split into separate reference files for better token efficiency when only one workflow is needed. | 2 / 3 |
Total | 11 / 12 Passed |
Validation
90%Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.
Validation — 10 / 11 Passed
Validation for skill structure
| Criteria | Description | Result |
|---|---|---|
frontmatter_unknown_keys | Unknown frontmatter key(s) found; consider removing or moving to metadata | Warning |
Total | 10 / 11 Passed | |
010799b
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.