Agent skill

Compliance Testing

by petrkindlmann in petrkindlmann/qa-skills

Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…

MITAuto-check passedLegal & Compliance

Install Compliance Testing

skills CLI
$ npx skills add petrkindlmann/qa-skills --skill compliance-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install petrkindlmann/qa-skills compliance-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/compliance-testing .claude/skills/compliance-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance-testing
GitHub stars
168
Token cost
~4.6k tokens
SKILL.md length
2,306 words
Files
6 (incl. references)
Skills in repo
45
Repo updated
First seen
Licence
MIT

At a glance

Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…

  • Works in 5 steps: Compliance is binary → Automate the technical checks, schedule… → Test the unhappy consent states → …
  • Privacy banner. Not for: WCAG/axe-core test authoring — use accessibility-testing
  • SKILL.md covers Discovery Questions, Core Principles, GDPR / CMP Testing with… and EU AI Act Compliance, plus 9 more sections
  • Calls npx

What it does

Compliance Testing is an agent skill from petrkindlmann/qa-skills. Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards, and cookie-inventory auditing. Covers automated consent-flow testing, third-party script blocking before consent, and cookie drift detection. Use when: "GDPR test," "compliance," "CMP test," "cookie consent," "consent mode," "CCPA," "GPC," "AI Act," "Better Ads," "privacy banner." Not for: WCAG/axe-core test authoring —…

Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/better-ads-tests.md`, `references/ci-automation.md` and `references/cookie-compliance.md`).

It sits in Legal & Compliance, covering Privacy and GDPR, Accessibility and AI governance. The repository describes itself as: 50 QA and test-automation skills for Claude Code, Codex, Cursor, and any Agent Skills Standard runtime. The licence is MIT.

When your agent uses it

  • Privacy banner. Not for: WCAG/axe-core test authoring — use accessibility-testing
  • Tasks that involve Privacy and GDPR
  • Tasks that involve Accessibility

Example prompts

  • “GDPR test,”
  • “compliance,”
  • “CMP test,”
  • “/compliance-testing”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Compliance is binary
  2. Automate the technical checks, schedule the legal audits
  3. Test the unhappy consent states
  4. Verify behavior, not the CMP
  5. Defense in depth, config-driven

What it can do on your machine

Read from SKILL.md and the folder at commit b3bb61b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance Testing loads about 4.6k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 197 tokens; SKILL.md has 2,306 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~197
When it runs · the whole SKILL.md, loaded when a task matches
~4.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from petrkindlmann/qa-skills at commit b3bb61b, republished under its MIT licence (© petrkindlmann). 2,306 words, ~4,587 tokens.

Download SKILL.mdSave it as .claude/skills/compliance-testing/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
compliance-testing
description
Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards, and cookie-inventory auditing. Covers automated consent-flow testing, third-party script blocking before consent, and cookie drift detection. Use when: "GDPR test," "compliance," "CMP test," "cookie consent," "consent mode," "CCPA," "GPC," "AI Act," "Better Ads," "privacy banner." Not for: WCAG/axe-core test authoring — use accessibility-testing. Not for: OWASP/vuln scanning — use security-testing. Not for: evaluating your LLM feature's quality or safety — use ai-system-testing. Related: accessibility-testing, security-testing, ai-system-testing, ci-cd-integration.
license
MIT
metadata.author
kindlmann
metadata.version
2.0
metadata.category
process
<objective>
Compliance is binary: a single analytics cookie that fires before consent, or a "Reject all" rendered as a tiny grey link, is a violation no matter how polished the rest of the flow looks. Manual quarterly audits miss the regression a developer shipped on a Tuesday. This skill automates the technical checks — consent state, script blocking, cookie attributes, GPC, Consent Mode v2, AI Act disclosure — so configuration drift fails CI instead of a regulator's inbox.
</objective>

Discovery Questions

First, check for .agents/qa-project-context.md in the project root — it carries applicable regulations, CMP details, ad networks, and geographic scope. Skip any question already answered there. If it is missing, suggest creating one with the qa-project-context skill.

Applicable regulations
  • Which privacy and platform regulations apply? This sets the entire test matrix.
    • EU: GDPR, ePrivacy Directive (cookies), Digital Services Act (DSA, applied 17 Feb 2024), EU AI Act (prohibitions + AI literacy live since 2 Feb 2025; GPAI obligations + penalties since 2 Aug 2025; Article 50 transparency from 2 Aug 2026 — high-risk obligations postponed, see below).
    • US: CCPA/CPRA plus comprehensive state laws now active in ~20 states (Texas TDPSA, Indiana CDPA eff. 1 Jan 2026, Delaware DPDPA, Nebraska NDPA, Minnesota CDPA, Rhode Island DTPPA, …). Most require honoring Global Privacy Control (Sec-GPC: 1).
    • UK: UK GDPR/DPA, PECR (cookies), Online Safety Act 2023, Data Use and Access Act (DUAA).
    • Other: LGPD (Brazil), PIPEDA (Canada), POPIA (South Africa).
  • What is the legal basis for processing? Consent (opt-in), legitimate interest, or contractual necessity — this decides whether explicit consent must precede processing.
  • Is there a DPO or legal team? They define the legal requirements; this skill only validates the technical implementation against them.
  • What CMP is in use? OneTrust, Cookiebot, Didomi, Usercentrics, Iubenda, Sourcepoint, or Axeptio — or custom? The CMP sets the consent storage format, API, and integration. If you serve ads in the EEA or UK, you must use a Google-certified CMP and Consent Mode v2 — uncertified CMPs block Google ad serving. As of 28 Feb 2026, new TC strings must be TCF v2.3 or Google demand treats traffic as unconsented and drops to Limited Ads.
  • What consent categories exist? Typically Strictly Necessary (always on), Analytics/Performance, Functional/Preferences, Marketing/Targeting.
  • How is consent signaled to third-party scripts? IAB TCF v2 (__tcfapi), a custom data layer, or direct CMP API?
Advertising and accessibility
  • What ad networks and formats? Google Ads, Meta, programmatic; display, video, interstitial. The Coalition for Better Ads defines which formats trigger Chrome ad-filtering.
  • Are there accessibility obligations (ADA, EAA, Section 508)? Those are real compliance, but author them in accessibility-testing — this skill only maps the legal landscape, see below.

Core Principles

1. Compliance is binary

There is no "mostly compliant." A cookie that fires before consent is a violation. A banner you cannot dismiss without accepting is a violation. Test for exact compliance, not "good enough."

Automate: cookies before consent, scripts loading without consent, banner functionality, cookie attributes, consent persistence, GPC, Consent Mode signals. A human still audits privacy-policy language and cross-border transfer documentation. Don't pretend a test settles a legal-language question.

The compliance boundary lives in the "no interaction," "rejected," and "withdrawn" states — that is where violations hide. The "all accepted" state is the least interesting one to test.

4. Verify behavior, not the CMP

CMPs have bugs. Don't trust the CMP UI as proof. Assert the actual outcome: were cookies set, did scripts load, was the GPC opt-out registered. The CMP is an implementation detail; compliance is measured by behavior.

5. Defense in depth, config-driven

Verify at multiple layers — CMP config, network requests, cookie state, client signals. Drive tests from a typed inventory and a tracking-domain list so adding a category or threshold is a data edit, not a suite rewrite. Regulations change; the suite must be cheap to update.

GDPR / CMP Testing with Playwright

Consent-flow compliance breaks into distinct, independently failing checks. Full runnable code for each is in references/gdpr-cmp-tests.md.

  • Consent banner and dark patterns — banner appears on first visit; accept and reject have equal prominence (reject is not a tiny link); a privacy-policy link is present.
  • Cookie state before/after consent — the critical test: no non-essential cookies before consent; analytics cookies only after accepting; nothing non-essential after rejecting. Maintain isStrictlyNecessary / isAnalyticsCookie classifiers against your inventory.
  • Consent persistence and withdrawal — consent survives navigation; the user can withdraw via privacy settings, which must then clear the relevant cookies.
  • Third-party script blocking — tracking scripts (google-analytics.com, googletagmanager.com, facebook.net, analytics.tiktok.com, bat.bing.com, …) must not load before consent and should load after acceptance. This is the most critical check — monitor with page.on('request').
  • Global Privacy Control (Sec-GPC: 1) — a required honored signal under CCPA/CPRA and most active US state laws. With the header set, assert navigator.globalPrivacyControl === true (the real browser signal) and that marketing cookies are absent. Do not assert an invented window.__cmp.gpcStatus global — it does not exist; TCF v1's __cmp is legacy and TCF v2 uses __tcfapi.
  • TCF v2 consent state — every TCF-certified CMP exposes window.__tcfapi('getTCData', 2, cb). Read purpose/vendor consent through it directly instead of guessing at CMP-private globals; the same call exposes tcfPolicyVersion, which doubles as a TCF-v2.3 freshness guard.
  • Google Consent Mode v2 — required since March 2024 for Google ads in the EEA/UK. Default state must be denied for ad_storage / analytics_storage / ad_user_data / ad_personalization; an update signal must fire granted after acceptance. The interception assumes the gtag arguments-array shape — note the object-form fallback in the reference.

EU AI Act Compliance

The Act applies in phases, and the timeline shifted in 2026. Note: the Digital Omnibus (Nov 2025 proposal; 7 May 2026 provisional agreement) postponed the high-risk obligations — do not test against the old 2 Aug 2026 high-risk date.

ObligationAppliesWhat to test
Prohibitions + AI literacy2 Feb 2025 (live)No Article 5 prohibited practices (social scoring, real-time public biometric ID, manipulative AI). Document AI features in scope; gate prohibited libraries.
GPAI obligations + penalties2 Aug 2025 (live)Model cards, training-data summaries, copyright-policy and disclosure pages exist.
Article 50 transparency2 Aug 2026AI-generated content marked; deepfake disclosure; user told they are interacting with AI. Test the disclosure label/watermark. Still live on this date.
Machine-readable marking grace2 Dec 2026Systems already on the market before 2 Aug 2026 get until here to add the watermark/marking (Omnibus compressed six months to three).
High-risk (Annex III, use-case)2 Dec 2027Risk management, data governance, human oversight, transparency UI. Postponed from 2 Aug 2026 by the Omnibus.
High-risk (Annex I, product-regulated)2 Aug 2028As above, embedded in regulated products. Postponed from 2 Aug 2027.

Write the Article 50 disclosure test now; defer the high-risk UI tests until the Annex III obligations land. See references/eu-ai-act-tests.md for the Article 50 transparency-disclosure test and the Article 5 prohibited-practice (biometric library) gate. For LLM-specific evaluation (hallucination, jailbreak resistance, prompt-injection), use the ai-system-testing skill.

Better Ads Standards

The Coalition for Better Ads defines ad formats that trigger browser-level ad filtering (Chrome filters ads on non-compliant sites).

FormatDesktopMobileTest approach
Pop-up adsYesYesCheck for modal/overlay within 5s of load without user action
Auto-playing video with soundYesYesRead the live video.autoplay / video.muted properties (not the HTML attributes)
Prestitial countdown adsYesYesCheck for a countdown timer blocking content
Large sticky ads (>30% viewport)YesYesMeasure sticky element dimensions vs viewport
Ad density >30%NoYesCalculate total ad area vs content area
Flashing animated adsNoYesMonitor animation frame rate (>3 flashes/second)

The muted-video check must read the live DOM property (el.muted), not getAttribute('muted') — player scripts set video.muted = true in JS without ever adding the content attribute, so an attribute-only check reports muted ads as having sound and misses muted-then-unmuted ads.

Note: the CBA added two desktop and two mobile ad experiences on 14 Jan 2025; Chrome assessment of those begins no earlier than 14 May 2026. Re-check newer combined formats against the current Better Ads Standards page before that date. See references/better-ads-tests.md for the auto-playing-video and mobile ad-density checks.

Show full SKILL.md (978 more words)Show less

Maintain a typed cookie inventory as the source of truth, then assert that actual cookies match it on three axes:

  • Inventory — a CookieDefinition[] capturing name, category, purpose, max expiry, and the Secure / HttpOnly / SameSite attributes each cookie must carry.
  • Attribute validation — every observed cookie must match its definition's flags and not exceed its declared max expiry. Normalize an unset SameSite to None before comparing — Playwright omits or varies it when the server doesn't set it, so an un-normalized check fails spuriously or passes silently.
  • Drift detection — fail the suite (throw, don't warn) when a cookie appears that is not in the inventory, forcing the inventory to stay current as scripts are added.

See references/cookie-compliance.md for the typed inventory and both implementations.

Accessibility is a legal requirement in many jurisdictions, but author the actual tests in accessibility-testing (axe-core, keyboard, screen reader). This table is only the legal landscape so you know what the obligation is.

RegionLawStandardEnforcement
EUEuropean Accessibility Act (EAA)EN 301 549 / WCAG 2.1 AAApplied 28 June 2025; member-state penalties active. WCAG 2.2 alignment expected in the next EN 301 549 revision.
USAADAWCAG 2.1 AA (court precedent)Private lawsuits
USA (federal)Section 508WCAG 2.0 AAFederal procurement requirement
Canada (Ontario)AODAWCAG 2.0 AAFines up to $100K/day
UKEquality Act 2010WCAG 2.1 AA (guidance)Lawsuits

Scheduled Compliance Audits

Run compliance tests weekly (not just on PR) to catch configuration drift, and retain results as long-lived CI artifacts for the audit trail. See references/ci-automation.md for the scheduled GitHub Actions workflow with 90-day artifact retention.

Anti-Patterns

Running compliance tests only in the "all accepted" state. The compliance boundary is the "no interaction" and "rejected" states — that is where violations hide. Test every state: no interaction, accepted, rejected, partially accepted, withdrawn.

Asserting an invented CMP global

Checking window.__cmp.gpcStatus or similar fabricated globals to "prove" a GPC opt-out. That global does not exist. Assert navigator.globalPrivacyControl === true and verify marketing cookies are absent; read real consent state via __tcfapi.

Attribute-only video checks

Treating getAttribute('muted') === null as "has sound." The content attribute is frequently absent on programmatically-muted videos. Read el.muted / el.autoplay live properties instead.

A cookie inventory nobody updates. Use the drift-detection test that throws on any unknown cookie — reality and inventory stay in sync automatically.

CMP-only testing

Trusting the CMP and only exercising its UI. CMPs have bugs. Test the outcome: cookies set, scripts loaded, data transmitted.

Manual-only quarterly audits

Auditing by hand once a quarter. Between audits a developer adds an analytics script that fires before consent and nobody notices for three months. Automated tests catch it on the next CI run.

Ignoring regional differences

One global consent model. GDPR requires opt-in; CCPA allows opt-out via GPC. Serving both regions means testing both experiences.

Treating compliance as one-time

Building the suite once and freezing it. Regulations evolve (ePrivacy Regulation, TCF version bumps, AI Act phases, updated CBA standards). Review quarterly.

Verification

Smallest check first — confirm the compliance suite runs and gates before trusting it:

bash
npx playwright test --project=chromium --grep @compliance

A correct run shows the unhappy-path tests as the gate: "no non-essential cookies before consent" and "no tracking scripts load before consent" must pass on a fresh context (storageState: undefined). To prove the suite actually catches violations, temporarily point it at a page that loads GA before consent — the script-blocking test must go red. A suite that stays green against a known-bad page is asserting nothing. Then confirm the GPC test sees navigator.globalPrivacyControl === true with the Sec-GPC: 1 header set, and that the Consent Mode default-state test reports denied for all four signals.

Done When

  • Applicable regulations identified for the product and geographic audience (GDPR, ePrivacy, DSA, EU AI Act, the relevant US state-law subset, UK OSA/DUAA) and documented in .agents/qa-project-context.md.
  • Consent flow tested for every entry point: first visit, accept, reject, withdrawal, and cross-navigation persistence — each as a distinct passing test.
  • Global Privacy Control honored: with Sec-GPC: 1, navigator.globalPrivacyControl === true and marketing cookies absent.
  • Google Consent Mode v2 verified: default denied for ad_storage / analytics_storage / ad_user_data / ad_personalization; update fires granted after accept (only required for sites serving Google ads in EEA/UK).
  • EU AI Act applicability assessed: prohibited-practice gate, GPAI documentation review (if applicable), and Article 50 transparency disclosure tested for any AI-generated content.
  • Cookie audit complete: all cookies categorized in the typed inventory; drift-detection test passes with zero unknown cookies.
  • No undeclared tracking domains or cookies fire that the privacy policy does not disclose (the automatable half — legal-language review is a separate manual/legal sign-off, not a test).
  • Compliance suite runs green in the weekly CI job with results stored as artifacts at 90-day retention.
  • accessibility-testing — Author the actual WCAG/axe-core/keyboard/screen-reader tests there. This skill only maps the accessibility legal landscape; it does not write a11y assertions.
  • security-testing — Security compliance (OWASP Top 10:2025, dependency and supply-chain scanning) complements privacy compliance; different threat model, different tools.
  • ai-system-testing — Defines the eval layer (hallucination, jailbreak, prompt-injection) for AI features. This skill only tests the Article 50 disclosure; that skill tests whether the AI itself behaves.
  • ci-cd-integration — Pipeline configuration for the scheduled weekly audit and compliance quality gates.
  • release-readiness — A failing compliance gate (consent firing before opt-in, missing AI Act disclosure) is a release blocker; wire this suite into the go/no-go checklist there.

Reference Files (in references/)

  • gdpr-cmp-tests.md — Playwright code for banners/dark patterns, cookie state before/after consent, persistence and withdrawal, third-party script blocking, Global Privacy Control (navigator.globalPrivacyControl), TCF v2 __tcfapi consent read + v2.3 version guard, and Google Consent Mode v2.
  • eu-ai-act-tests.md — Article 50 transparency-disclosure test and the Article 5 prohibited-practice (biometric library) gate, with the Omnibus timeline note.
  • better-ads-tests.md — Coalition for Better Ads checks: live-property auto-playing-unmuted-video detection and mobile ad-density measurement.
  • cookie-compliance.md — Typed cookie inventory, attribute validation (with SameSite normalization), and inventory drift detection.
  • ci-automation.md — Scheduled weekly compliance-audit GitHub Actions workflow with 90-day artifact retention.

© petrkindlmann, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/compliance-testing of petrkindlmann/qa-skills.

  • SKILL.md
  • references/better-ads-tests.md
  • references/ci-automation.md
  • references/cookie-compliance.md
  • references/eu-ai-act-tests.md
  • references/gdpr-cmp-tests.md

Open the folder on GitHubat commit b3bb61b

Compare with similar skills

Compliance Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compliance Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compliance Testing this skillpetrkindlmann/qa-skills168—~4.6kAutomated safety check: PassMIT
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Ra Qm Skillsalirezarezvani/claude-skills28k—~833Automated safety check: PassMIT
AI Data Subject Rightsmukul975/Privacy-Data-Protection-Skills297—~2.2kAutomated safety check: PassApache-2.0
Region Configindranilbanerjee/digital-marketing-pro8591 repos~3.5kAutomated safety check: PassMIT
AI Privacy Assessmentmukul975/Privacy-Data-Protection-Skills297—~4.3kAutomated safety check: PassApache-2.0

Similar skills

  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Ra Qm Skills

    alirezarezvani/claude-skills

    Router/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document control, ISO…

    28k GitHub stars~833 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • AI Data Subject Rights

    mukul975/Privacy-Data-Protection-Skills

    Implements data subject rights mechanisms for AI systems including right to explanation of AI decisions, contestation procedures, human review, model output correction, and training data access.

    297 GitHub stars~2.2k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Region Config

    indranilbanerjee/digital-marketing-pro

    Configure a brand's regional settings — timezone, languages, currency, compliance regulations (GDPR, CCPA, APPI, LGPD, EU AI Act Article 50, and more), local platforms, business hours, holiday…

    859 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • AI Privacy Assessment

    mukul975/Privacy-Data-Protection-Skills

    Guides the combined DPIA and AI Act conformity assessment for AI systems processing personal data.

    297 GitHub stars~4.3k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Analyzes how multiple regulations interact for a specific product, service, or business model.

    842 GitHub stars~3.1k tokensUpdated 7 days ago
    Legal & ComplianceAuto-check passed

More from petrkindlmann/qa-skills

All 45 skills in this repo
  • Accessibility Testing

    petrkindlmann/qa-skills

    Test for WCAG 2.2 AA compliance with axe-core + Playwright, keyboard navigation audits, screen reader testing, ARIA pattern validation, and legal compliance mapping (ADA, EAA, Section 508).

    168 GitHub stars~4.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Agentic Browser Testing

    petrkindlmann/qa-skills

    Goal-driven E2E testing where a browser agent (Playwright MCP / computer-use) reads a natural-language goal and explores the app via the accessibility tree to assert outcomes — no pre-written script.

    168 GitHub stars~4.5k tokensUpdated 4 mo ago
    Auto-check passed
  • AI Test Generation

    petrkindlmann/qa-skills

    Use AI to write NEW test code from specs, PRDs, user stories, code diffs, bug reports, or OpenAPI specs.

    168 GitHub stars~4.8k tokensUpdated 4 mo ago
    Auto-check passed
  • API Testing

    petrkindlmann/qa-skills

    Test REST and GraphQL APIs with Playwright APIRequestContext, Supertest, or standalone HTTP clients.

    168 GitHub stars~2.7k tokensUpdated 4 mo ago
    Auto-check passed
  • CI CD Integration

    petrkindlmann/qa-skills

    Design CI/CD pipelines that run test suites. An agent skill from petrkindlmann/qa-skills.

    168 GitHub stars~4.8k tokensUpdated 4 mo ago
    Auto-check passed
  • Contract Testing

    petrkindlmann/qa-skills

    Implement consumer-driven contract testing with Pact-JS (v16).

    168 GitHub stars~4.1k tokensUpdated 4 mo ago
    Auto-check passed

Questions about Compliance Testing

What does Compliance Testing do?

Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…. Compliance Testing is an agent skill from petrkindlmann/qa-skills. Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards, and cookie-inventory auditing.

When should I use Compliance Testing?

Compliance Testing fits situations like: privacy banner. Not for: WCAG/axe-core test authoring — use accessibility-testing; tasks that involve Privacy and GDPR; tasks that involve Accessibility.

How do I install Compliance Testing in Claude Code?

Run `npx skills add petrkindlmann/qa-skills --skill compliance-testing -a claude-code`. Or copy the skill folder (skills/compliance-testing in petrkindlmann/qa-skills) into .claude/skills/compliance-testing in your project. Claude Code loads it when a task matches its description.

How do I install Compliance Testing in Codex?

Run `npx skills add petrkindlmann/qa-skills --skill compliance-testing -a codex`. Or copy the skill folder (skills/compliance-testing in petrkindlmann/qa-skills) into .agents/skills/compliance-testing in your project. Codex loads it when a task matches its description.

Can I use Compliance Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add petrkindlmann/qa-skills --skill compliance-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-testing, .gemini/skills/compliance-testing, .github/skills/compliance-testing and .opencode/skills/compliance-testing in your project.

What does Compliance Testing need to run?

Going by SKILL.md and its folder, Compliance Testing needs the command-line tools its instructions call (npx).

Does Compliance Testing access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Compliance Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Compliance Testing use?

Compliance Testing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compliance Testing use?

About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.

What are the alternatives to Compliance Testing?

Skills that share tags, products or a category with Compliance Testing: Compliance Os (alirezarezvani/claude-skills, 28k stars), Ra Qm Skills (alirezarezvani/claude-skills, 28k stars), AI Data Subject Rights (mukul975/Privacy-Data-Protection-Skills, 297 stars) and Region Config (indranilbanerjee/digital-marketing-pro, 859 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compliance Testing?

petrkindlmann (a GitHub user) maintains it in petrkindlmann/qa-skills, which has 168 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on June 10, 2026.

Source: petrkindlmann/qa-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.