CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/test-data-governance-reference

Pure-reference catalog of test-data lifecycle governance: retention schedules for test datasets, cross-environment data-sharing agreements, deletion of test data containing real PII, refresh cadence, access controls, and the legal basis for each policy under GDPR Art. 5 storage limitation and NIST SP 800-122. Use when defining a data-steward role for test environments, authoring a retention policy for a test database, scoping a data-sharing agreement before promoting a dataset from production to staging, or determining the deletion timeline for any test fixture that contains live personal data.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

Quality

Content

85%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is a well-organized, actionable governance reference with clear workflows and excellent progressive disclosure into three real reference files. Its main weakness is conciseness: regulatory article text is restated and the same reference links and DSA/deletion details recur across multiple sections.

Suggestions

Consolidate the inline reference links — state each of the three reference files once in its dedicated section and rely on the closing References list, rather than relinking them in 'How to use' and the worked example.

Trim verbatim restatement of GDPR/NIST article text (e.g., the full Art. 5(1)(e) quote) to the specific clause reference plus the governance implication, since Claude already knows these regulations.

De-duplicate the DSA clause enumeration, which appears both in the 'Cross-environment data-sharing agreements' section and implicitly in the worked example's promotion step.

DimensionReasoningScore

Conciseness

The body is mostly efficient but repeats content — the three reference links recur across 'How to use', the sharing/deletion/access sections, and the references list, and it restates GDPR/NIST article text Claude largely already knows. Not a 3 because of repetition and regulatory restatement; not a 1 because it is not a wall of generic concept explanation.

2 / 3

Actionability

As an instruction-only reference it gives concrete, specific guidance — a tier table with exact retention limits, a metadata-record field list, a refresh cadence table, and anti-patterns with fixes — meeting the highest anchor for an actionable reference skill where executable code is not expected.

3 / 3

Workflow Clarity

The numbered 7-step 'How to use' sequence (intake → promotion → access → refresh → deletion → steward) plus the lifecycle diagram and end-to-end worked example give a clear order, with explicit verification checkpoints (DSA-before-transfer, deletion certificate after deletion) for the destructive/governance context.

3 / 3

Progressive Disclosure

The overview body is well-structured and offloads detail into three clearly signaled, one-level-deep reference files (data-sharing-agreements.md, deletion-standard.md, access-controls.md) — all real bundle files linked inline and listed at the end — matching the anchor for clean overview with well-signaled references.

3 / 3

Total

11

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, well-triggered, complete, and distinctive, using third-person voice throughout with no over-claims. It clearly conveys both the catalog's purpose and the concrete situations that should activate it.

DimensionReasoningScore

Specificity

Lists multiple specific concrete actions — 'retention schedules', 'data-sharing agreements', 'deletion of test data containing real PII', 'refresh cadence', 'access controls' — matching the anchor for listing several concrete capabilities rather than just naming a domain.

3 / 3

Completeness

Explicitly answers both what ('Pure-reference catalog of test-data lifecycle governance...') and when ('Use when defining... authoring... scoping... or determining...'), with explicit trigger guidance, satisfying the highest anchor.

3 / 3

Trigger Term Quality

The 'Use when' clause gives natural phrasings a user would say — 'defining a data-steward role', 'authoring a retention policy', 'scoping a data-sharing agreement', 'determining the deletion timeline' — with good coverage of realistic triggers.

3 / 3

Distinctiveness Conflict Risk

The niche is sharply defined — test-data governance and PII retention — and it explicitly distinguishes itself from sibling skills (synthetic-data, pii-masking-pipeline-builder), making wrong-skill triggering unlikely.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Reviewed

Table of Contents