Comprehensive methodology for auditing website cookies and tracking technologies.

Apache-2.0Auto-check passedLegal & Compliance

Install Cookie Audit

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill cookie-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills cookie-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/cookie-audit .claude/skills/cookie-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cookie-audit
GitHub stars
297
Token cost
~2k tokens
SKILL.md length
859 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Comprehensive methodology for auditing website cookies and tracking technologies.

  • Works in 5 steps: Preparation → Automated Scanning → Cookie Categorization → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Audit Methodology, Ongoing Monitoring and Key Legal References
  • Runs Python scripts from its folder

What it does

Cookie Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. Comprehensive methodology for auditing website cookies and tracking technologies. Covers automated scanning, cookie categorization, lifecycle documentation, and compliance gap analysis referencing the Planet49 CJEU ruling (C-673/17).

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “/cookie-audit”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Preparation
  2. Automated Scanning
  3. Cookie Categorization
  4. Gap Analysis
  5. Reporting

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cookie Audit loads about 2k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 859 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 859 words, ~2,044 tokens.

Download SKILL.mdSave it as .claude/skills/cookie-audit/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
cookie-audit
description
Comprehensive methodology for auditing website cookies and tracking technologies. Covers automated scanning, cookie categorization, lifecycle documentation, and compliance gap analysis referencing the Planet49 CJEU ruling (C-673/17).
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
cookie-consent-compliance
metadata.tags
cookie-audit, cookie-scanning, tracker-detection, planet49, cookie-categorization

Auditing Website Cookies and Trackers

Overview

A cookie audit is the foundational step in achieving cookie consent compliance. It involves systematically identifying, categorizing, and documenting every cookie and tracking technology deployed on a website. The Court of Justice of the European Union in Planet49 GmbH v. Bundesverband der Verbraucherzentralen (Case C-673/17, 1 October 2019) established that pre-ticked checkboxes do not constitute valid consent under the ePrivacy Directive, and that users must be informed about cookie duration and third-party access before consenting. A thorough audit reveals what consent must be obtained and what disclosures must be made.

Audit Methodology

Phase 1: Preparation

Before scanning, document the audit scope for Pinnacle E-Commerce Ltd:

ParameterValue
Primary domainwww.pinnacle-ecommerce.com
Subdomains in scopeshop.pinnacle-ecommerce.com, account.pinnacle-ecommerce.com, blog.pinnacle-ecommerce.com
Authenticated pagesYes — customer account, checkout flow
Mobile-specific pagesm.pinnacle-ecommerce.com
Third-party integrationsGoogle Analytics 4, Meta Pixel, Hotjar, Stripe, Intercom
Scan frequencyQuarterly (next: Q2 2026)
Phase 2: Automated Scanning

Deploy scanning tools to capture all cookies and tracking technologies:

Browser-Based Scanning

Use a headless Chromium instance to crawl the site and capture:

  • First-party cookies set via Set-Cookie headers
  • First-party cookies set via document.cookie JavaScript API
  • Third-party cookies from embedded resources
  • LocalStorage and SessionStorage entries
  • IndexedDB databases
  • Pixels and beacons (1x1 image requests, navigator.sendBeacon() calls)
  • Browser fingerprinting scripts (canvas, WebGL, AudioContext)

Network-Level Capture

Monitor HTTP/HTTPS traffic to identify:

  • Tracking parameters in URL query strings (utm_*, fbclid, gclid)
  • Redirect chains through tracking domains
  • Cookie syncing between third parties
  • Server-to-server data sharing endpoints

Classify each cookie using the ICC UK Cookie Guide categories, aligned with the ePrivacy Directive Article 5(3):

Category 1: Strictly Necessary Cookies essential for the website to function. No consent required under Article 5(3) exemption.

Examples for Pinnacle E-Commerce Ltd:

Cookie NameDomainDurationPurpose
session_id.pinnacle-ecommerce.comSessionMaintains user session state
csrf_token.pinnacle-ecommerce.comSessionCross-site request forgery protection
cart_itemsshop.pinnacle-ecommerce.com24 hoursShopping cart contents
auth_tokenaccount.pinnacle-ecommerce.com30 minutesAuthentication state
load_balancer.pinnacle-ecommerce.comSessionServer load distribution

Category 2: Performance/Analytics Cookies that collect aggregate usage data. Consent required.

Cookie NameDomainDurationPurpose
_ga.pinnacle-ecommerce.com2 yearsGoogle Analytics client ID
_ga_XXXXXXX.pinnacle-ecommerce.com2 yearsGA4 session persistence
_gid.pinnacle-ecommerce.com24 hoursGA4 session distinction
hjSessionUser*.pinnacle-ecommerce.com1 yearHotjar user identification
hjSession*.pinnacle-ecommerce.com30 minutesHotjar session data

Category 3: Functionality Cookies that remember user preferences. Consent required unless strictly necessary.

Cookie NameDomainDurationPurpose
locale.pinnacle-ecommerce.com1 yearLanguage preference
currencyshop.pinnacle-ecommerce.com1 yearCurrency selection
recently_viewedshop.pinnacle-ecommerce.com30 daysRecently viewed products

Category 4: Targeting/Advertising Cookies used for ad targeting and cross-site tracking. Consent always required.

Cookie NameDomainDurationPurpose
_fbp.pinnacle-ecommerce.com90 daysMeta Pixel browser ID
_fbc.pinnacle-ecommerce.com90 daysMeta click identifier
_gcl_au.pinnacle-ecommerce.com90 daysGoogle Ads conversion linker
IDE.doubleclick.net13 monthsGoogle ad serving
fr.facebook.com90 daysMeta ad delivery and measurement
Show full SKILL.md (387 more words)Show less
Phase 4: Gap Analysis

For each cookie identified, verify against Planet49 requirements:

Planet49 Compliance Checklist:

  1. Active consent mechanism: Is consent collected via affirmative action (click, toggle), not pre-ticked boxes? (Planet49, para. 62)
  2. Pre-consent information: Before consent is given, is the user informed of:
    • Cookie duration? (Planet49, para. 81)
    • Whether third parties have access? (Planet49, para. 81)
    • The specific purpose of each cookie category?
  3. Granularity: Can users consent to cookie categories individually, not just accept all?
  4. No cookie walls: Is site access available without consenting to non-essential cookies?
  5. Withdrawal mechanism: Can users withdraw consent as easily as they gave it?

Gap Analysis Template:

CookieCategoryConsent CollectedDuration DisclosedThird-Party DisclosedGap
_gaAnalyticsYesNo — listed as "persistent" not "2 years"No — Google not namedDuration + third-party disclosure
_fbpTargetingYesYesYesNone
localeFunctionalityNoNoN/AAssess if strictly necessary
Phase 5: Reporting

The audit report for Pinnacle E-Commerce Ltd must include:

  1. Executive summary: Total cookies found, breakdown by category, critical gaps
  2. Complete cookie inventory: Full table with name, domain, duration, purpose, category, legal basis
  3. Third-party tracker inventory: All third-party domains receiving data, with data types shared
  4. Compliance gap register: Each gap, severity (high/medium/low), remediation recommendation
  5. Cookie policy update recommendations: Specific text changes needed
  6. Consent mechanism assessment: Whether current banner meets Planet49 requirements
  7. Recommended scan schedule: Quarterly for production, on-demand for new feature deployments

Ongoing Monitoring

Schedule automated scans to detect new cookies introduced by:

  • Developer deployments (new analytics or marketing tags)
  • Third-party script updates (vendor SDK updates adding new cookies)
  • A/B testing platforms adding experiment cookies
  • CDN or infrastructure changes

Integrate cookie scanning into the CI/CD pipeline: any new cookie detected in staging must be categorized and documented before deployment to production.

  • CJEU Case C-673/17 (Planet49) — Active consent required; pre-ticked boxes invalid; cookie duration and third-party access must be disclosed before consent
  • ePrivacy Directive 2002/58/EC, Article 5(3) — Consent required for storing/accessing information on user devices, with strictly necessary exemption
  • GDPR Article 4(11) — Definition of consent: freely given, specific, informed, unambiguous indication
  • EDPB Guidelines 05/2020 on Consent — Detailed guidance on valid consent mechanisms
  • ICC UK Cookie Guide (2012) — Cookie categorization framework (strictly necessary, performance, functionality, targeting)
  • CNIL Deliberation No. 2020-091 (17 September 2020) — Guidelines on cookies and other trackers

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/cookie-audit of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Cookie Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cookie Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cookie Audit this skillmukul975/Privacy-Data-Protection-Skills297—~2kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    297 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    297 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    297 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Cookie Audit

What does Cookie Audit do?

Comprehensive methodology for auditing website cookies and tracking technologies. Cookie Audit is an agent skill from mukul975/Privacy-Data-Protection-Skills. Comprehensive methodology for auditing website cookies and tracking technologies.

When should I use Cookie Audit?

Cookie Audit fits situations like: tasks that involve Privacy and GDPR.

How do I install Cookie Audit in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill cookie-audit -a claude-code`. Or copy the skill folder (skills/privacy/cookie-audit in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/cookie-audit in your project. Claude Code loads it when a task matches its description.

How do I install Cookie Audit in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill cookie-audit -a codex`. Or copy the skill folder (skills/privacy/cookie-audit in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/cookie-audit in your project. Codex loads it when a task matches its description.

Can I use Cookie Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill cookie-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cookie-audit, .gemini/skills/cookie-audit, .github/skills/cookie-audit and .opencode/skills/cookie-audit in your project.

What does Cookie Audit need to run?

Going by SKILL.md and its folder, Cookie Audit needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Cookie Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cookie Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cookie Audit use?

Cookie Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cookie Audit use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Cookie Audit?

Skills that share tags, products or a category with Cookie Audit: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cookie Audit?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.