# Cookie policy from your code (/legal--cookie-policy)

/legal--cookie-policy is a Claude Code skill in the Business section. Scans your code to inventory the cookies and trackers it really sets, then drafts a cookie policy based on that inventory.

- Web version: https://skills.sgomez.dev/en/s/legal--cookie-policy
- Section: [Business](https://skills.sgomez.dev/en/business.md)
- Author: Santiago Gómez de la Torre
- License: MIT
- Source: https://github.com/sgomez-dev/claude-skills/blob/main/skills/legal/cookie-policy.md
- Updated 10 Jul 2026

## Use it when

- You need a cookie policy that matches what your site actually sets
- You want to know if cookies fire before consent
- You added analytics, pixels or embeds and the policy needs updating

## Not for

- Replacing the advice of a lawyer
- Finding cookies that only appear at runtime: those need a browser check

## What you get

A legal/COOKIE_POLICY.md file with categorized cookie tables, plus an inventory and a fix list in the chat.

## How to ask for it

- `/legal--cookie-policy generate the cookie policy for my Next.js site`
- `/legal--cookie-policy scan the code and create the cookie notice`
- `/legal--cookie-policy I need a cookie policy based on my actual trackers`

## Install

macOS · Linux:

```
curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash
```

Windows:

```
irm https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.ps1 | iex
```

Claude Code plugin:

```
/plugin marketplace add sgomez-dev/claude-skills
/plugin install legal-skills@claude-skills-collection
```

## Permissions

- Reads: `**/*`
- Writes: `legal/**`, `COOKIE_POLICY*.md`
- Runs: —
- Network: No
- Destructive: No

## Author's description

Generate a cookie policy from the cookies and trackers actually set in code

## Questions about this skill

### Does it catch every cookie?

No. Static scanning can miss cookies injected at runtime by tag managers or embeds. It recommends verifying in the browser (DevTools, Application, Cookies).

### Will this make me GDPR compliant?

It helps draft the policy and flags problems such as non-essential cookies set without consent, but it is a starting draft, not legal advice.

### What if my product is an API with no frontend?

It says so and produces a minimal statement instead of inventing cookies.


- [How we review this](https://skills.sgomez.dev/en/methodology.md)
