Privacy GeneratorSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: privacy-generator description: 'Generates comprehensive privacy policies by scanning websites for data collection signals including cookies, forms, payment processors, and third-party scripts. Use when launching a website or app that collects user data and needs GDPR/CCPA compliance. Trigger with "/privacy-generator" or "create a privacy policy for my website". ' allowed-tools: Read, Write, Glob, Grep, WebFetch version: 1.1.0 author: Intent Solutions <[email protected]> license: MIT tags: - legal - privacy-policy - gdpr - ccpa - data-protection - cookies compatibility: Designed for Claude Code --- # Privacy Policy Generator ## Overview Scans a website or application codebase to detect data collection signals — cookies, web forms, payment processors, analytics scripts, social media embeds, and third-party trackers — then generates a tailored privacy policy with 12 sections. Includes specific GDPR rights (7 individual rights), CCPA rights (6 consumer rights), and cookie consent banner text in both minimal and full GDPR formats. The detection phase maps every data touchpoint to its legal basis and disclosure requirement, ensuring the generated policy accurately reflects actual data practices rather than relying on generic boilerplate. > **Legal Disclaimer:** This skill generates template documents for informational and > educational purposes only. Generated privacy policies are not a substitute for legal > advice. Data protection requirements vary by jurisdiction, industry, and data type. > All documents should be reviewed by a licensed attorney and/or data protection officer > before publication. No attorney-client relationship is created by using this tool. ## Prerequisites - A live website URL or local codebase to scan - Knowledge of the business entity name and jurisdiction - Understanding of what data is collected and why (the scan detects signals but cannot capture server-side-only processing) ## Instructions 1. **Scan for data collection signals.** Use WebFetch on the target URL to detect: | Signal Category | What to Look For | |----------------|------------------| | Cookies | `Set-Cookie` headers, cookie consent banners, tracking pixels | | Analytics | Google Analytics, Mixpanel, Amplitude, Hotjar, Segment | | Forms | Contact forms, registration, login, newsletter signup | | Payments | Stripe, PayPal, Square, Braintree, payment form fields | | Social | Facebook Pixel, Twitter tags, LinkedIn Insight, social login | | Advertising | Google Ads, Facebook Ads, retargeting pixels | | CDN/Third-Party | Cloudflare, AWS CloudFront, Google Fonts, embedded iframes | | Chat/Support | Intercom, Zendesk, Drift, live chat widgets | 2. **If scanning a codebase instead**, use Glob and Grep to find: - Cookie-setting code (`document.cookie`, `setCookie`, `cookies` middleware) - Analytics initialization (`gtag`, `analytics.track`, `mixpanel.init`) - Form handlers and data submission endpoints - Payment SDK imports and configurations - User model/schema definitions showing stored fields - Environment variables referencing third-party API keys 3. **Classify data types collected.** Map detected signals to data categories: - Identifiers (name, email, phone, address) - Financial (payment card, bank account, transaction history) - Technical (IP address, device info, browser fingerprint) - Behavioral (browsing history, click patterns, purchase history) - Content (user uploads, messages, reviews) - Sensitive (health, biometric, political — flag these for special handling) 4. **Determine legal bases (GDPR).** For each data category, assign: - **Consent** — marketing emails, non-essential cookies, analytics - **Contract** — account data, payment processing, service delivery - **Legitimate interest** — security logs, fraud prevention, basic analytics - **Legal obligation** — tax records, regulatory reporting 5. **Generate the 12-section privacy policy:** | # | Section | Covers | |---|---------|--------| | 1 | Introduction | Who the company is, what this policy covers | | 2 | Information We Collect | Data types, collection methods, sources | | 3 | How We Use Your Information | Purposes mapped to legal bases | | 4 | Cookies & Tracking | Cookie types, duration, opt-out mechanisms | | 5 | Information Sharing | Third parties, categories, purposes | | 6 | Data Retention | How long each data type is kept | | 7 | Your Rights Under GDPR | 7 specific rights with exercise instructions | | 8 | Your Rights Under CCPA | 6 specific rights with exercise instructions | | 9 | Data Security | Technical and organizational measures | | 10 | International Transfers | Cross-border data flow safeguards | | 11 | Children's Privacy | Age restrictions, COPPA compliance | | 12 | Contact & Updates | DPO contact, policy change notification | 6. **Detail GDPR rights (Section 7).** Include all seven with exercise instructions: 1. Right of Access (Article 15) — request a copy of personal data 2. Right to Rectification (Article 16) — correct inaccurate data 3. Right to Erasure (Article 17) — "right to be forgotten" 4. Right to Restrict Processing (Article 18) — limit data use 5. Right to Data Portability (Article 20) — receive data in machine-readable format 6. Right to Object (Article 21) — object to processing based on legitimate interest 7. Rights Related to Automated Decision-Making (Article 22) — opt out of profiling 7. **Detail CCPA rights (Section 8).** Include all six: 1. Right to Know — what personal information is collected 2. Right to Delete — request deletion of personal information 3. Right to Opt-Out — "Do Not Sell or Share My Personal Information" 4. Right to Non-Discrimination — equal service regardless of rights exercised 5. Right to Correct — correct inaccurate personal information 6. Right to Limit Use of Sensitive Infor
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__privacy-generator.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Privacy Generator skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Privacy Generator safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Privacy Generator access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Privacy Generator work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.