CtrlK
BlogDocsLog inGet started
Tessl Logo

third-party-cookies

Use when reviewing a website for privacy compliance, third-party resource loading, or cookie consent implementation.

48

Quality

53%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/third-party-cookies/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured with excellent progressive disclosure — a concise overview pointing to a real, one-level-deep reference holding the details. Its weaknesses are duplicated conceptual content between body and reference, and body-level guidance that stays high-level because the concrete commands and verification steps all live in the reference file.

Suggestions

Remove the intro/Why-It-Matters paragraph duplicated verbatim in references/rule.md and fold the Quick Reference bullets into Check/Fix to eliminate repetition.

Surface one or two executable checks directly in the body (e.g. the curl Set-Cookie audit command or the DevTools 'Third-party requests' filter) so the Check section is actionable without opening the reference.

Make the verification checkpoint explicit in the Code Review section (e.g. 'Confirm in the production-like response that no non-essential Set-Cookie headers fire before consent') rather than a single vague 'verify' mention.

DimensionReasoningScore

Conciseness

The opening paragraph ('Third-party cookies enable advertising networks to build detailed behavioral profiles... 4% of global annual turnover') explains background Claude already knows and is repeated verbatim in references/rule.md ('Why It Matters'), and the Quick Reference bullets duplicate content from the Check/Fix sections and the reference. Mostly efficient but should be tightened — anchor 3, not 4, because of the duplicated conceptual padding.

3 / 5

Actionability

'Open the browser DevTools Network panel and Application panel (Cookies section)' is concrete, but the Fix section is high-level direction ('Audit and remove unnecessary third-party scripts. Replace cross-site tracking with privacy-preserving first-party analytics') with no commands in the body — the executable specifics (curl audit, DevTools third-party filter, SameSite examples) are all deferred to the reference. Fits anchor 3 ('Some concrete guidance but incomplete; missing key details').

3 / 5

Workflow Clarity

The Check → Fix → Explain → Code Review sequence is coherent and this is not a destructive/batch operation, but validation is only one vague mention ('verify them against the effective production-like response') with the real verification steps (production-like testing, manual response inspection) deferred to the reference. Anchor 3 ('sequence present but checkpoints missing or implicit') fits better than 4.

3 / 5

Progressive Disclosure

The body is a ~35-line, cleanly sectioned overview with a single clearly-signaled one-level-deep reference (references/rule.md, verified to exist, no nested references), and the bulk detail — tables, code examples, verification steps — is appropriately split into that reference. This matches anchor 5 ('Clear overview with well-signaled one-level-deep references; content appropriately split').

5 / 5

Total

14

/

20

Passed

Description

48%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a pure trigger clause: it says when to use the skill but never states what the skill actually does, and it omits the most natural trigger phrase ('third-party cookies'). The domain scoping is specific and conflict risk is low, but completeness and action coverage are weak.

Suggestions

Add a 'what' statement before the trigger, e.g. 'Identifies third-party cookies and tracking scripts on a website, flags consent violations, and recommends privacy-preserving alternatives. Use when reviewing a website for privacy compliance, third-party cookies, tracking, or cookie consent implementation.'

Include the natural terms users would actually say — 'third-party cookies', 'tracking pixels', 'GDPR/CCPA consent' — alongside the current phrasing.

State the concrete outputs of the skill (flagged cookies/scripts, consent-gating recommendations) so the 'what' is explicit rather than implied by the 'Use when' clause.

DimensionReasoningScore

Specificity

The description names the domain clearly ('privacy compliance, third-party resource loading, cookie consent implementation') but contains no concrete actions the skill performs — the only verb is 'reviewing', matching the anchor 'Names the domain but actions are minimal or generic'. It does not reach 4 because no specific capabilities (identify, audit, flag, remediate) are listed.

2 / 5

Completeness

The 'when' is explicit ('Use when reviewing a website for...'), but the 'what' is only weakly implied by the merged clause — there is no separate statement of what the skill does. Per boundary guidance this falls between anchor 2 (only 'when' present without 'what') and anchor 4 (both present, 'when' could be more specific), so 3.

3 / 5

Trigger Term Quality

'privacy compliance' and 'cookie consent' are natural user phrases, but the description misses common variations such as 'third-party cookies', 'tracking', or 'GDPR/CCPA', and 'third-party resource loading' is semi-technical phrasing. This fits anchor 3 ('Some relevant keywords but missing common variations or synonyms') rather than 4's 'good keyword coverage; a few natural terms missing'.

3 / 5

Distinctiveness Conflict Risk

'privacy compliance, third-party resource loading, or cookie consent implementation' carves out a mostly distinct niche with specific triggers, with only minor overlap risk against closely related privacy/consent skills. It is above anchor 3's 'could still overlap with similar skills' but below anchor 5's fully distinct trigger set.

4 / 5

Total

12

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
thedaviddias/Front-End-Checklist
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.