Gdpr Compliance Scanner - Auto-activating skill for Security Advanced. Triggers on: gdpr compliance scanner, gdpr compliance scanner Part of the Security Advanced skill category.
36
3%
Does it follow best practices?
Impact
96%
1.01xAverage score across 3 eval scenarios
Passed
No known issues
Optimize this skill with Tessl
npx tessl skill review --optimize ./planned-skills/generated/04-security-advanced/gdpr-compliance-scanner/SKILL.mdQuality
Discovery
7%Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.
This description is extremely weak, consisting essentially of a skill name, a duplicated trigger phrase, and a category label. It provides no information about what the skill actually does (e.g., scanning code for GDPR violations, auditing data handling practices, checking privacy policies) and offers no guidance on when Claude should select it. It reads like auto-generated boilerplate rather than a useful skill description.
Suggestions
Add concrete actions describing what the skill does, e.g., 'Scans codebases and data pipelines for GDPR compliance issues, identifies personal data handling violations, checks consent mechanisms, and audits data retention policies.'
Add an explicit 'Use when...' clause with natural trigger terms, e.g., 'Use when the user asks about GDPR compliance, data privacy audits, personal data protection, consent management, data subject rights, or EU privacy regulations.'
Include diverse natural trigger keywords users would actually say, such as 'GDPR audit', 'privacy compliance', 'data protection check', 'personal data', 'right to erasure', 'data breach', 'privacy policy review'.
| Dimension | Reasoning | Score |
|---|---|---|
Specificity | The description contains no concrete actions whatsoever. It only states the skill name and category ('Security Advanced') without describing what the skill actually does—no mention of scanning, checking, auditing, or any specific GDPR-related capabilities. | 1 / 3 |
Completeness | The description fails to answer both 'what does this do' and 'when should Claude use it.' There is no explanation of capabilities and no explicit 'Use when...' clause—only an auto-trigger statement that repeats the skill name. | 1 / 3 |
Trigger Term Quality | The only trigger terms listed are 'gdpr compliance scanner' repeated twice. There are no natural user keywords like 'GDPR audit', 'data privacy', 'personal data', 'data protection', 'privacy policy', or 'compliance check' that users would naturally say. | 1 / 3 |
Distinctiveness Conflict Risk | The mention of 'GDPR' provides some domain specificity that distinguishes it from generic security skills, but the lack of concrete actions or scope means it could overlap with other compliance or security scanning skills. | 2 / 3 |
Total | 5 / 12 Passed |
Implementation
0%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This skill is an empty template/placeholder with no actual content about GDPR compliance scanning. It contains only generic boilerplate text that repeats the skill name without providing any actionable guidance, code, tools, scanning criteria, or compliance frameworks. It would provide zero value to Claude in performing GDPR compliance scanning tasks.
Suggestions
Add concrete, executable scanning steps—e.g., specific checks for data processing records, consent mechanisms, data subject rights endpoints, and privacy policy validation with actual code or tool commands.
Include a GDPR compliance checklist covering key articles (Art. 6 lawful basis, Art. 13/14 transparency, Art. 15-22 data subject rights, Art. 25 privacy by design, Art. 30 records of processing, Art. 32 security measures, Art. 35 DPIAs).
Provide example scanner output format showing findings, severity levels, and remediation guidance so Claude knows what to produce.
Add specific tools and commands for automated scanning (e.g., cookie consent checkers, privacy policy analyzers, data flow mapping tools) with executable examples.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The content is entirely filler and boilerplate. It explains nothing Claude doesn't already know, repeats 'gdpr compliance scanner' excessively, and provides zero substantive information about GDPR compliance scanning. | 1 / 3 |
Actionability | There is no concrete guidance whatsoever—no code, no commands, no specific steps, no tools, no scanning methodology. Every section is vague and abstract, describing what the skill supposedly does without actually doing it. | 1 / 3 |
Workflow Clarity | No workflow is defined. There are no steps, no sequence, no validation checkpoints. The mention of 'step-by-step guidance' is a claim without any actual steps provided. | 1 / 3 |
Progressive Disclosure | The content is a flat, monolithic block of generic placeholder text with no meaningful structure, no references to detailed materials, and no navigation to deeper content. | 1 / 3 |
Total | 4 / 12 Passed |
Validation
81%Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.
Validation — 9 / 11 Passed
Validation for skill structure
| Criteria | Description | Result |
|---|---|---|
allowed_tools_field | 'allowed-tools' contains unusual tool name(s) | Warning |
frontmatter_unknown_keys | Unknown frontmatter key(s) found; consider removing or moving to metadata | Warning |
Total | 9 / 11 Passed | |
3076d78
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.