CtrlK
BlogDocsLog inGet started
Tessl Logo

regulatory-audit-generator

Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like "run a compliance check," "GDPR/PIPL compliance," "pre-launch review," "privacy impact assessment (PIA/DPIA)," or asking if a feature is compliant.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete IF-rules, output templates, and article-level legal reference tables, but it carries some conversational Quick Start padding, lacks an explicit validation checkpoint on the final checklist, and is a monolithic file that could split detailed scenario/regulation tables into reference files.

Suggestions

Tighten the Quick Start: replace the conversational narration ('Users simply describe...,' 'Users just need to say:') with a direct one-line trigger example and the numbered capability list.

Add an explicit final validation step to the SOP, e.g. 'Before delivering, verify every applicable regulation from Step 2 is represented and each check item cites a specific article.'

Move the detailed scenario check-point tables (Section 3) and/or industry-specific regulation tables into a reference file (e.g. SCENARIOS.md) and link to it from the body, improving progressive disclosure.

DimensionReasoningScore

Conciseness

Dense, domain-specific tables (article-level legal references) earn their place, but the Quick Start narrates conversational padding — 'Users simply describe their business scenario,' 'Users just need to say:,' 'The Agent will guide the user' — that could be tightened. It is mostly efficient but not fully lean.

2 / 3

Actionability

Provides fully concrete, copy-paste-ready guidance: explicit IF-rules for regulation identification, a markdown checklist output template, a P0–P3 priority matrix, and scenario check-item tables with named regulations and article numbers.

3 / 3

Workflow Clarity

The four-step SOP is clearly sequenced with a defined output format and a soft checkpoint ('proactively ask follow-up questions rather than assume or skip'), but there is no explicit validation/verification step confirming the generated checklist is complete and accurate before delivery.

2 / 3

Progressive Disclosure

Content is well-organized into numbered sections, but the 228-line body is monolithic with all regulation tables and scenario checklists inline and no references to separate detail files; the 'References' section lists external laws rather than skill bundle files.

2 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: third-person voice, concrete capabilities, explicit trigger phrases, and a clearly distinctive compliance-audit niche. It satisfies the what/when requirement and avoids vague fluff or over-claims.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Builds compliance checklists,' 'Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations' — matching the top anchor for specific concrete actions.

3 / 3

Completeness

Explicitly answers both what (builds/outputs a structured checklist with named fields) and when (the 'Triggered by requests like...' clause), meeting the top anchor for both what AND when.

3 / 3

Trigger Term Quality

Provides strong natural-language triggers users would actually say: 'run a compliance check,' 'GDPR/PIPL compliance,' 'pre-launch review,' 'privacy impact assessment (PIA/DPIA),' and 'asking if a feature is compliant,' giving good coverage.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear regulatory-compliance niche with distinct triggers (GDPR/PIPL, PIA/DPIA, pre-launch review) unlikely to conflict with other skills.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.