Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Use when reviewing a website for GDPR/CCPA compliance, specifically whether cookie consent is obtained before non-essential cookies are set.
.claude/skills/thedaviddias-cookie-consent/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 13% | 0% |
| case-12 | ✗→✓ | ▲ Improved | -14% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 13% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 1% | 0% |
| case-05 | ✓→✓ | = Same ✓ | 7% | 0% |
GDPR violations can result in fines up to €20 million or 4% of global annual turnover. Regulators across the EU have actively fined organizations for deploying tracking cookies without valid consent.
Check whether the site displays a cookie consent notice before setting non-essential cookies. Verify that analytics, advertising, and tracking scripts do not load until the user has actively accepted. Check whether users can reject non-essential cookies without losing access to content.
Implement a cookie consent management platform (CMP) that blocks non-essential scripts until consent is granted. Configure analytics and tracking tags to initialize only after explicit consent. Provide a mechanism for users to change their consent preferences at any time.
Explain what GDPR requires for cookie consent, the difference between essential and non-essential cookies, why pre-ticked boxes are invalid consent, and what a technically compliant consent implementation looks like.
Review server config, headers, forms, and integration points related to Show a cookie consent notice. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response. Check that tracker initialization is gated on consent and that a persistent "change cookie settings" path exists after the banner is gone.
For full implementation details, code examples, and framework-specific guidance, see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/privacy/cookie-consent
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 13,826 | 12,096 | -13% | 1 | 1 | 0% | 2,784 | 3,159 | +13% | 0 | 0 | — |
case-02 | pass→pass | 12,517 | 9,171 | -27% | 1 | 1 | 0% | 2,299 | 2,589 | +13% | 0 | 0 | — |
case-03 | pass→pass | 11,180 | 8,224 | -26% | 1 | 1 | 0% | 2,156 | 2,185 | +1% | 0 | 0 | — |
case-04 | fail→fail | 14,069 | 11,265 | -20% | 1 | 1 | 0% | 2,311 | 2,798 | +21% | 0 | 0 | — |
case-05 | pass→pass | 9,892 | 9,479 | -4% | 1 | 1 | 0% | 2,048 | 2,188 | +7% | 0 | 0 | — |
case-06 | pass→pass | 14,045 | 11,304 | -20% | 1 | 1 | 0% | 2,824 | 2,647 | -6% | 0 | 0 | — |
case-07 | pass→pass | 10,831 | 9,733 | -10% | 1 | 1 | 0% | 1,705 | 2,339 | +37% | 0 | 0 | — |
case-08 | pass→pass | 13,099 | 10,820 | -17% | 1 | 1 | 0% | 2,421 | 2,349 | -3% | 0 | 0 | — |
case-09 | pass→pass | 8,499 | 8,565 | +1% | 1 | 1 | 0% | 1,486 | 2,043 | +37% | 0 | 0 | — |
case-10 | pass→pass | 14,252 | 9,225 | -35% | 1 | 1 | 0% | 2,557 | 2,026 | -21% | 0 | 0 | — |
case-11 | pass→pass | 7,927 | 7,957 | +0% | 1 | 1 | 0% | 1,512 | 2,022 | +34% | 0 | 0 | — |
case-12 | fail→pass | 13,807 | 10,599 | -23% | 1 | 1 | 0% | 2,512 | 2,150 | -14% | 0 | 0 | — |
case-13 | pass→pass | 12,044 | 10,173 | -16% | 1 | 1 | 0% | 2,138 | 2,305 | +8% | 0 | 0 | — |
case-14 | pass→pass | 12,840 | 11,898 | -7% | 1 | 1 | 0% | 2,224 | 3,170 | +43% | 0 | 0 | — |
case-15 | pass→pass | 11,503 | 11,054 | -4% | 1 | 1 | 0% | 2,091 | 2,462 | +18% | 0 | 0 | — |
case-16 | pass→pass | 12,416 | 8,052 | -35% | 1 | 1 | 0% | 2,219 | 1,816 | -18% | 0 | 0 | — |
case-17 | pass→pass | 11,740 | 9,426 | -20% | 1 | 1 | 0% | 2,200 | 2,115 | -4% | 0 | 0 | — |
case-18 | pass→pass | 7,931 | 6,433 | -19% | 1 | 1 | 0% | 1,643 | 1,528 | -7% | 0 | 0 | — |
case-19 | pass→pass | 14,499 | 13,043 | -10% | 1 | 1 | 0% | 2,565 | 2,811 | +10% | 0 | 0 | — |
case-20 | pass→pass | 11,205 | 7,170 | -36% | 1 | 1 | 0% | 2,050 | 1,731 | -16% | 0 | 0 | — |
case-21 | pass→pass | 12,089 | 10,118 | -16% | 1 | 1 | 0% | 1,821 | 2,251 | +24% | 0 | 0 | — |
case-22 | pass→pass | 11,297 | 11,585 | +3% | 1 | 1 | 0% | 2,413 | 2,672 | +11% | 0 | 0 | — |
case-23 | pass→pass | 18,909 | 19,964 | +6% | 1 | 1 | 0% | 4,145 | 3,902 | -6% | 0 | 0 | — |
case-24 | pass→pass | 16,562 | 14,778 | -11% | 1 | 1 | 0% | 3,172 | 3,494 | +10% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 24 cases were attempted. The headline lift of +8 percentage points is the difference between those two pass rates over the 24 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.