CtrlK
BlogDocsLog inGet started
Tessl Logo

data-handling-template

Data handling plan generator — evidence retention, encryption, chain-of-custody, compliance frameworks (GDPR / HIPAA / PCI-DSS / SOC2).

65

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/soundwave/data-handling-template/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The skill body is lean, well-structured, and highly actionable with a clear sequenced workflow and explicit validation checkpoints appropriate to destructive/batch data-handling operations. The only minor gap is the absence of a concrete code or CLI example for validating against the schema.

Suggestions

Add a one-line executable example for validating output, e.g. a snippet invoking the DataHandlingPlan schema validator on plan/data-handling.json.

Consider moving the engagement-type class table into a references file if additional rows are anticipated, to keep the overview lean.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — it jumps straight into schema defaults, per-class overrides, and a validation checklist with no padding or explanation of concepts Claude already knows, and every token earns its place.

5 / 5

Actionability

Concrete, executable guidance is present throughout — default storage path, per-class retention/classification values, and a validation checklist with explicit predicates — but there is no code or command example, and the schema name to validate against is referenced rather than shown.

4 / 5

Workflow Clarity

A clear five-step sequence with an explicit validation checklist and feedback loops (the anti-patterns and purge-hard-cap rules act as checkpoints, and the orchestrator-refuses-objectives behavior provides error recovery), satisfying the validation requirement for batch/destructive data-handling operations.

5 / 5

Progressive Disclosure

Well-organized into clear sections (When to Use, Workflow steps, Validation Checklist, Anti-patterns, Output) with no nested references; it is a single self-contained file with no bundle files, so the simple-skill exception applies, though the engagement-type table could arguably be split out for a perfect 5.

4 / 5

Total

18

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific and distinct, naming concrete capability areas and real compliance frameworks, but it omits an explicit 'Use when...' trigger clause, which caps its completeness. Adding a sentence stating when to invoke it would lift the completeness dimension.

Suggestions

Append an explicit trigger clause, e.g. 'Use when creating a data handling plan, defining evidence retention, or mapping compliance frameworks.'

Add a natural verb such as 'Generates' or 'Builds' to make the concrete action explicit alongside the capability categories.

Include 'PII handling' or 'data retention policy' as trigger synonyms for broader natural-language coverage.

DimensionReasoningScore

Specificity

Names the domain (data handling plans) and several concrete capabilities — 'evidence retention', 'encryption', 'chain-of-custody', 'compliance frameworks' — with specific framework tokens, though it describes categories rather than discrete actions like 'generate' or 'set retention'.

4 / 5

Completeness

It clearly states the 'what' (a data handling plan generator covering retention/encryption/custody/compliance) but provides no 'Use when...' clause or equivalent explicit trigger guidance in the description itself; the rubric caps completeness at 3 when such a clause is missing.

3 / 5

Trigger Term Quality

Includes natural trigger terms users would say — 'evidence retention', 'chain-of-custody', 'GDPR', 'HIPAA', 'PCI-DSS', 'compliance' — with good coverage of common variations, though it omits a few natural phrasings like 'PII handling' or 'data retention policy'.

4 / 5

Distinctiveness Conflict Risk

The compliance/chain-of-custody/evidence-retention framing is a clear niche with minimal overlap risk, and the named frameworks (GDPR/HIPAA/PCI-DSS/SOC2) give it distinct triggers unlikely to fire for unrelated skills.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.