CtrlK
BlogDocsLog inGet started
Tessl Logo

right-to-erasure

Use when auditing account settings pages, privacy dashboards, or API routes to verify that a complete data deletion path exists for users.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/right-to-erasure/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A compact, well-structured audit skill with excellent progressive disclosure into a real reference file. Its weaknesses are a redundant GDPR background paragraph and the absence of explicit validation checkpoints for the destructive deletion flow in the body itself.

Suggestions

Trim or remove the opening GDPR regulatory paragraph (fines, turnover thresholds) — Claude already knows Article 17, and the same text exists in references/rule.md.

Add an explicit validation step to the body (e.g., after deletion, verify localStorage/sessionStorage/IndexedDB are empty and the POST returned 200), or at minimum signal the Verification section in references/rule.md, since the deletion flow is destructive and currently capped by the missing-checkpoint rule.

Reduce duplication between the Quick Reference bullets and the Check section, which restate the same deletion requirements twice in ~10 lines.

DimensionReasoningScore

Conciseness

The Quick Reference and Check/Fix/Explain/Code Review sections are lean, but the opening GDPR paragraph ("fines of up to €20 million or 4% of global annual turnover... builds trust with users") explains legal background Claude already knows and is duplicated verbatim in references/rule.md, fitting 'mostly efficient but includes some unnecessary explanation'.

3 / 5

Actionability

Concrete, specific guidance throughout — "Clear all client-side storage: localStorage, sessionStorage, IndexedDB, and cookies" and "Flag missing client-side storage clearance, absent confirmation UI, or missing server-side deletion calls" — with no code in the body, which is acceptable for an instruction-only skill since the guidance is actionable. It stops short of fully executable, copy-paste-ready commands, so the 5 anchor does not fit.

4 / 5

Workflow Clarity

The Check → Fix → Explain → Code Review sequence is coherent, but this skill governs a destructive operation (data deletion) and the body contains no explicit validation/verification checkpoint — "confirm receipt to the user" is only implicit, and the verification steps live in references/rule.md without being signaled. Per the destructive-operation cap, workflow clarity cannot exceed 3.

3 / 5

Progressive Disclosure

A lean ~30-line overview with a single well-signaled, one-level-deep reference ("see `references/rule.md`"), which exists in the bundle and appropriately holds the implementation details and code. This matches 'clear overview with well-signaled one-level-deep references; content appropriately split'.

5 / 5

Total

15

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-formed trigger-style description with an explicit 'Use when' clause, concrete audit surfaces, and a clear single-purpose action. Its main gaps are limited action coverage (only verification is named) and missing the most common user synonyms like GDPR or 'right to be forgotten'.

DimensionReasoningScore

Specificity

The description names the privacy/data-deletion domain and one composite concrete action ("auditing account settings pages, privacy dashboards, or API routes to verify that a complete data deletion path exists"), but lists only that single verification action rather than several specific actions, matching the '1-2 concrete actions, not comprehensive' anchor.

3 / 5

Completeness

It explicitly answers both what ("verify that a complete data deletion path exists for users") and when ("Use when auditing account settings pages, privacy dashboards, or API routes") with concrete trigger phrases, matching the top anchor; the 'when' clause is already fully explicit, so the 4 anchor's caveat does not apply.

5 / 5

Trigger Term Quality

It includes multiple natural keywords users would say — "account settings pages", "privacy dashboards", "API routes", "data deletion" — but misses common variations like "GDPR", "right to be forgotten", or "delete account", matching the 'good keyword coverage; a few natural terms missing' anchor.

4 / 5

Distinctiveness Conflict Risk

The data-deletion audit niche is mostly distinct with concrete triggers, but "privacy dashboards" and privacy auditing could overlap with sibling privacy-checklist skills (e.g., cookie consent, privacy policy), matching 'mostly distinct; minor overlap risk'.

4 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.