CtrlK
BlogDocsLog inGet started
Tessl Logo

regulatory-audit-generator

Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like "run a compliance check," "GDPR/PIPL compliance," "pre-launch review," "privacy impact assessment (PIA/DPIA)," or asking if a feature is compliant.

66

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/regulatory-audit-generator/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, highly actionable SOP for compliance-check generation, with a concrete output template and explicit decision rules. Its weaknesses are token efficiency (padded intro plus re-teaching regulations Claude already knows) and the total absence of progressive disclosure — everything is inlined in one long file.

Suggestions

Cut the Quick Start section down to a one-line example prompt; the four-step list duplicates the SOP and adds marketing padding.

Move the five scenario check-point tables and the regulation/industry tables into separate reference files (e.g., references/scenarios.md, references/regulations.md) and link to them from SKILL.md.

Trim the Description column of the scenario tables to the legal-basis citation and threshold only, removing explanations of GDPR/PIPL articles that Claude already knows.

Add a final SOP step that re-checks the checklist against the applicable-regulation rules before delivering it, to close the workflow_clarity validation gap.

DimensionReasoningScore

Conciseness

The Quick Start section is padded marketing prose ("Users simply describe their business scenario, and the Agent will...", "Users just need to say:") that duplicates the SOP, and the scenario tables re-explain GDPR/PIPL basics Claude already knows; the legal-basis citations and thresholds are the real added value. Mostly efficient with tightening needed, not the 'minor instances' of the 4 anchor.

3 / 5

Actionability

Concrete, executable guidance throughout: IF/THEN regulation-selection rules, an exact copy-paste checklist output template, a data-gathering table with example values, and P0–P3 priority criteria. It falls short of the 5 anchor only because there is no worked example of a completed checklist covering a common case.

4 / 5

Workflow Clarity

A clearly sequenced 4-step SOP (gather info → identify regulations → generate checklist → output priorities) with an explicit rule to ask follow-ups rather than assume. This is not a destructive/batch operation so the cap at 3 does not apply, but no validation checkpoint exists before emitting the final checklist, keeping it below the 5 anchor.

4 / 5

Progressive Disclosure

A single 228-line monolithic file with no bundle files at all; the five scenario check-point tables and the regulation reference tables are reference material that clearly belongs in separate one-level-deep files, and the inline References section is a static bibliography rather than navigable pointers. Structure exists, but content that should be separate is inline — the 3 anchor.

3 / 5

Total

14

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

Strong description: third-person voice, explicit what-and-when structure, and a rich set of natural trigger phrases with synonyms. The only soft spot is that all named capabilities are facets of one deliverable (the checklist) rather than a broader action inventory.

Suggestions

Broaden the action inventory beyond checklist construction (e.g., identifying applicable regulations, flagging missing consent mechanisms) to move specificity from 4 to 5.

Add a few more natural trigger variants such as "data privacy review" or "advertising law check" to widen trigger coverage.

DimensionReasoningScore

Specificity

"Builds compliance checklists" and "Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations" list several specific outputs, but all describe a single deliverable rather than the comprehensive multi-action coverage of the 5 anchor; it is clearly above the 3 anchor's '1-2 concrete actions but not comprehensive'.

4 / 5

Completeness

The description explicitly answers what ("Builds compliance checklists... Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations") and when ("Triggered by requests like...") with concrete trigger phrases, matching the 5 anchor; it clearly exceeds the 4 anchor where 'when' is only partly explicit.

5 / 5

Trigger Term Quality

Natural trigger phrases include "run a compliance check," "GDPR/PIPL compliance," "pre-launch review," "privacy impact assessment (PIA/DPIA)," and "asking if a feature is compliant" — these are exactly what a user would say, with synonyms (PIA/DPIA, GDPR/PIPL) covered, matching the comprehensive 5 anchor rather than the 4 anchor's 'a few natural terms missing'.

5 / 5

Distinctiveness Conflict Risk

"Business scenarios involving GDPR, PIPL, or advertising/data laws" carves out a clear compliance-audit niche with distinct trigger phrases (GDPR/PIPL compliance, PIA/DPIA), giving minimal conflict risk with other skills — the 5 anchor's 'clear niche with distinct triggers'.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.