CtrlK
BlogDocsLog inGet started
Tessl Logo

tos-clause-scanner

Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues. Trigger when a user asks to review, audit, or analyze a ToS, privacy policy, or user agreement, or mentions specific concerns like auto-renewal or data authorization.

65

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/tos-clause-scanner/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, actionable instruction-only skill: specific detection patterns, per-category checklists, defined evaluation dimensions, and a complete output template. Its main weaknesses are duplicated workflow sections and abstract severity-calibration guidance.

Suggestions

Merge sections 2.1 (Input Processing) and 6.2 (Workflow) into a single workflow, and drop the Quick Start's restatement of the description, to tighten the document and remove the conciseness penalty.

Add concrete calibration criteria for the Severity / Concealment / Actionability ratings (e.g., what distinguishes a High from a Medium severity finding) so the 'assess the risk' instruction is fully executable.

Move section 4 (Regulatory Reference Framework) and section 5 (Common Industry-Specific Risks) into a separate reference file, keeping SKILL.md as a lean overview with clearly signaled one-level-deep links.

DimensionReasoningScore

Conciseness

Mostly efficient structured tables and checklists, but the workflow is stated twice — 'Identify document type / Extract key clauses / Analyze each clause / Cross-check' in section 2.1 repeats 'read it in full... Scan systematically... Perform an in-depth analysis... produce the structured report' in section 6.2 — and the Quick Start restates the frontmatter description.

3 / 5

Actionability

Concrete, executable guidance: exact phrases to search for ('irrevocable,' 'perpetual,' 'we reserve the right,' 'as long as necessary'), per-category checklists, explicit evaluation dimensions, and a full copy-paste report template. Not fully a 5 because some instructions remain abstract, e.g., 'Assess the risk of every extracted clause' gives no calibration criteria for the High/Medium/Low ratings.

4 / 5

Workflow Clarity

A clear sequence exists (identify document type → extract → analyze → cross-check → sort → report) with a cross-check step as a checkpoint, and this analysis-only skill involves no destructive or batch operation that would cap the score. Below 5 because checkpoints are thin and error-handling (e.g., how to handle incomplete text) is deferred to a boundary note rather than integrated into the workflow.

4 / 5

Progressive Disclosure

Well-organized single-file skill with a clear section hierarchy and no bundle files to reference. Section 4 (regulatory framework) and section 5 (industry-specific risks) are natural candidates for separate reference files, keeping it below the top anchor, but structure and navigation are good.

4 / 5

Total

15

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person voice, concrete capabilities, and an explicit trigger clause with natural user phrasing. Only minor improvements possible by adding a few synonymous trigger terms and broadening the flagged risk types.

DimensionReasoningScore

Specificity

Lists several concrete actions — 'audit... for consumer risks', 'producing a structured report', 'flags unfair clauses, data traps, and liability issues' — but coverage has minor gaps (e.g., IP overreach and dispute-resolution restrictions are not mentioned).

4 / 5

Completeness

Explicitly answers both 'what' (audits agreements and produces a structured report flagging risks) and 'when' ('Trigger when a user asks to review, audit, or analyze a ToS, privacy policy, or user agreement, or mentions specific concerns'), matching the top anchor with concrete trigger phrases.

5 / 5

Trigger Term Quality

Good natural keyword coverage: 'review, audit, or analyze a ToS, privacy policy, or user agreement' plus specific concerns like 'auto-renewal or data authorization'. A few common variations are missing, such as 'terms and conditions', 'fine print', or subscription-cancellation phrasing.

4 / 5

Distinctiveness Conflict Risk

Clear niche — consumer-perspective auditing of ToS/privacy policies — with distinct, unlikely-to-collide triggers; no meaningful overlap risk with generic document or legal skills.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.