CtrlK
BlogDocsLog inGet started
Tessl Logo

gdpr-data-handling

Practical implementation guide for GDPR-compliant data processing, consent management, and privacy controls.

52

Quality

57%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/AI-Agents-Safe-Coding-Skills-claude/skills/gdpr-data-handling/SKILL.md

The canonical home for this skill is gdpr-data-handling in rmyndharis/antigravity-skills

SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and concise with a clear use/don't-use framing, but it offers only abstract instructional guidance with no concrete GDPR steps, lacks real validation feedback loops for destructive DSR operations, and references a playbook file that is not present in the bundle.

Suggestions

Provide at least one concrete, executable example in the body (e.g. a DSR erasure workflow with specific validation commands) or ensure `resources/implementation-playbook.md` exists and contains it.

Replace the generic Instructions bullets with a concrete sequenced GDPR workflow that includes an explicit validate -> fix -> retry feedback loop for destructive operations like right-to-erasure.

Either create the referenced `resources/implementation-playbook.md` or remove the broken reference so navigation is not a dead-end.

DimensionReasoningScore

Conciseness

The body is lean with no explanation of concepts Claude already knows and clear section structure; minor generic filler remains ("Apply relevant best practices and validate outcomes", "Provide actionable steps and verification") and the intro line repeats the description, so it is efficient with a few instances that could be trimmed rather than fully lean (5).

4 / 5

Actionability

The Instructions are high-level abstract direction ("Clarify goals, constraints, and required inputs", "Apply relevant best practices") with no concrete commands, code, or specific GDPR steps, and the only concrete pointer ("open `resources/implementation-playbook.md`") targets a file that does not exist; this matches minimal concrete guidance with missing execution steps rather than entirely vague (1) or some concrete guidance (3).

2 / 5

Workflow Clarity

A rough sequence is listed (clarify goals -> apply practices -> validate -> provide steps) but validation is only mentioned generically with no real checkpoints or feedback loops; because DSR handling includes destructive erasure operations, the rubric caps workflow clarity at 3 when validation/feedback loops are absent, which this anchor matches.

3 / 5

Progressive Disclosure

The skill is short and well-organized with clear sections and a single clearly-signaled one-level reference to a playbook, which is good structure; it is not a 5 because the referenced `resources/implementation-playbook.md` does not exist in the bundle, so the reference is a dangling navigation dead-end rather than fully working navigation.

4 / 5

Total

13

/

20

Passed

Description

61%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise and names a clear GDPR niche with several relevant sub-areas, but it lacks any explicit "Use when..." trigger guidance and relies on a generic "implementation guide for" verb, which limits both completeness and specificity.

Suggestions

Add an explicit 'Use when...' clause naming concrete trigger phrases, e.g. 'Use when building systems that process EU personal data, managing consent, or handling data subject requests (DSRs).'

Replace the generic 'implementation guide for' with concrete action verbs (e.g. 'Implement consent capture, execute data subject requests, audit processing records').

Include common synonyms users say such as 'data subject requests (DSRs)', 'right to erasure', or 'privacy by design' to broaden trigger coverage.

DimensionReasoningScore

Specificity

The description names the GDPR domain plus several concrete sub-areas ("data processing, consent management, and privacy controls"), but the only verb is the generic "implementation guide for", so actions are minimal rather than multiple concrete verbs like extract/fill/merge; this sits at the 3 anchor (domain + concrete areas, not comprehensive) rather than 4 (no specific action verbs) or 2 (it lists more than one named area).

3 / 5

Completeness

It gives a clear "what" (an implementation guide for GDPR data processing, consent, privacy) but contains no "Use when..." clause or equivalent trigger guidance; per the rubric a missing trigger clause caps completeness at 3, which is the exact anchor match (clear what, when missing).

3 / 5

Trigger Term Quality

It includes several natural terms a user would say ("GDPR", "consent management", "privacy controls", "data processing") giving good keyword coverage; it misses common variations/synonyms such as "data subject requests", "DSR", or "right to be forgotten", so it is above 3 but not at the comprehensive 5 level.

4 / 5

Distinctiveness Conflict Risk

GDPR compliance is a clear, fairly distinct niche with domain-specific triggers, so overlap risk is low; it is not a 5 because the phrase "data processing" is broad and could mildly overlap with general privacy/security or data-pipeline skills, placing it at "mostly distinct; minor overlap risk".

4 / 5

Total

14

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
administrakt0r/AI-Agents-Safe-Coding-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.