CtrlK
BlogDocsLog inGet started
Tessl Logo

data-minimisation

Use when reviewing form components, API payloads, or client-side storage to identify fields that are collected but not consumed by a stated feature.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/data-minimisation/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, well-organized overview that defers implementation detail to a real, one-level-deep reference file. The main weaknesses are the near-duplicate 'Check'/'Code Review' sections and opening-paragraph rationale that cost tokens without adding guidance Claude lacks.

Suggestions

Merge 'Check' and 'Code Review' (or frame 'Code Review' explicitly as the PR-context variant of 'Check') to remove the duplicated audit instructions.

Trim the GDPR rationale in the opening paragraph to one sentence — Claude already knows Article 5(1)(c) — and keep the persuasive detail in references/rule.md.

Surface one or two verification steps from references/rule.md (e.g., search the codebase for localStorage.setItem, inspect request bodies in the Network tab) so post-fix validation is visible without opening the reference.

DimensionReasoningScore

Conciseness

'Check' and 'Code Review' give nearly identical audit instructions ('Audit the form fields, API request bodies, and client-side storage keys...' vs 'Review form components, fetch/axios calls, and storage utilities... Flag any field or key that is collected but not read'), and the opening GDPR rationale is motivation Claude already knows — mostly efficient but could be tightened, anchor 3 rather than anchor 4's 'minor instances'.

3 / 5

Actionability

Concrete, executable direction for an instruction-only skill: named audit targets, a precise criterion ('collected but not read by an active feature'), and specific remediation ('Replace raw personal identifiers in analytics and logs with pseudonymous IDs and define a retention window for each stored value'). The minor gap — no inline example of a violation before the reference pointer — keeps it below anchor 5.

4 / 5

Workflow Clarity

A clear Check → Fix → Explain sequence with the audit acting as an explicit pre-fix gate; minor validation gaps remain — no post-fix verification step is surfaced in the body (it lives in references/rule.md), and the redundant 'Code Review' section muddies where it fits in the sequence — so anchor 4 rather than 5.

4 / 5

Progressive Disclosure

A ~30-line overview with a clearly signaled, one-level-deep reference ('For full implementation details, code examples, and framework-specific guidance, see references/rule.md'); the file exists and holds exactly those details with no nested references, so content is appropriately split with easy navigation.

5 / 5

Total

16

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A tight, well-structured description with an explicit 'Use when' clause and concrete review targets. Its main gaps are vocabulary breadth (no 'PII', 'personal data', 'privacy', 'GDPR', 'localStorage', or 'cookies' synonyms) and a single-action scope that omits the fix/anonymise guidance found in the body.

Suggestions

Add natural synonyms such as 'PII', 'personal data', 'privacy', 'GDPR', 'data minimisation', 'localStorage', or 'cookies' so the description triggers on the vocabulary users actually say.

Mention the remediation side of the skill (remove, anonymise, or pseudonymise over-collected fields and analytics payloads) to broaden action coverage beyond identification.

DimensionReasoningScore

Specificity

Names the domain and 1-2 concrete actions — 'reviewing form components, API payloads, or client-side storage' and 'identify fields that are collected but not consumed by a stated feature' — but coverage is not comprehensive: the fix/anonymise and analytics-inspection actions from the body are absent, so it matches anchor 3 rather than anchor 4's 'several specific actions'.

3 / 5

Completeness

Explicitly answers both what ('identify fields that are collected but not consumed by a stated feature') and when ('Use when reviewing form components, API payloads, or client-side storage') with a concrete 'Use when' trigger clause, matching the anchor-5 example structure; not score 4 because the 'when' is already explicit and specific rather than improvable.

5 / 5

Trigger Term Quality

Good natural keywords users would say when reviewing frontend code ('form components', 'API payloads', 'client-side storage', 'fields'), but it misses common variations and synonyms — 'PII', 'personal data', 'privacy', 'GDPR', 'data minimisation', 'localStorage', 'cookies' — placing it between anchors 3 and 4, noticeably above the midpoint.

4 / 5

Distinctiveness Conflict Risk

The purpose qualifier ('collected but not consumed by a stated feature') carves out a distinct niche, but the trigger surface ('reviewing form components', 'API payloads') overlaps with generic code-review and API-design skills — mostly distinct with minor overlap risk, anchor 4 rather than anchor 5's minimal-conflict niche.

4 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.