Atlas / Skills / jeremylongshore / Privacy Generator

Privacy GeneratorSAFE

skills/jeremylongshore/privacy-generator

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.1.0
Hosts
1 documented
License
MIT
Stars
2,822
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: privacy-generator
description: 'Generates comprehensive privacy policies by scanning websites for data
  collection

  signals including cookies, forms, payment processors, and third-party scripts.

  Use when launching a website or app that collects user data and needs GDPR/CCPA
  compliance.

  Trigger with "/privacy-generator" or "create a privacy policy for my website".

  '
allowed-tools: Read, Write, Glob, Grep, WebFetch
version: 1.1.0
author: Intent Solutions <[email protected]>
license: MIT
tags:
- legal
- privacy-policy
- gdpr
- ccpa
- data-protection
- cookies
compatibility: Designed for Claude Code
---
# Privacy Policy Generator

## Overview

Scans a website or application codebase to detect data collection signals — cookies,
web forms, payment processors, analytics scripts, social media embeds, and third-party
trackers — then generates a tailored privacy policy with 12 sections. Includes specific
GDPR rights (7 individual rights), CCPA rights (6 consumer rights), and cookie consent
banner text in both minimal and full GDPR formats.

The detection phase maps every data touchpoint to its legal basis and disclosure
requirement, ensuring the generated policy accurately reflects actual data practices
rather than relying on generic boilerplate.

> **Legal Disclaimer:** This skill generates template documents for informational and
> educational purposes only. Generated privacy policies are not a substitute for legal
> advice. Data protection requirements vary by jurisdiction, industry, and data type.
> All documents should be reviewed by a licensed attorney and/or data protection officer
> before publication. No attorney-client relationship is created by using this tool.

## Prerequisites

- A live website URL or local codebase to scan
- Knowledge of the business entity name and jurisdiction
- Understanding of what data is collected and why (the scan detects signals but cannot
  capture server-side-only processing)

## Instructions

1. **Scan for data collection signals.** Use WebFetch on the target URL to detect:

   | Signal Category | What to Look For |
   |----------------|------------------|
   | Cookies | `Set-Cookie` headers, cookie consent banners, tracking pixels |
   | Analytics | Google Analytics, Mixpanel, Amplitude, Hotjar, Segment |
   | Forms | Contact forms, registration, login, newsletter signup |
   | Payments | Stripe, PayPal, Square, Braintree, payment form fields |
   | Social | Facebook Pixel, Twitter tags, LinkedIn Insight, social login |
   | Advertising | Google Ads, Facebook Ads, retargeting pixels |
   | CDN/Third-Party | Cloudflare, AWS CloudFront, Google Fonts, embedded iframes |
   | Chat/Support | Intercom, Zendesk, Drift, live chat widgets |

2. **If scanning a codebase instead**, use Glob and Grep to find:
   - Cookie-setting code (`document.cookie`, `setCookie`, `cookies` middleware)
   - Analytics initialization (`gtag`, `analytics.track`, `mixpanel.init`)
   - Form handlers and data submission endpoints
   - Payment SDK imports and configurations
   - User model/schema definitions showing stored fields
   - Environment variables referencing third-party API keys

3. **Classify data types collected.** Map detected signals to data categories:
   - Identifiers (name, email, phone, address)
   - Financial (payment card, bank account, transaction history)
   - Technical (IP address, device info, browser fingerprint)
   - Behavioral (browsing history, click patterns, purchase history)
   - Content (user uploads, messages, reviews)
   - Sensitive (health, biometric, political — flag these for special handling)

4. **Determine legal bases (GDPR).** For each data category, assign:
   - **Consent** — marketing emails, non-essential cookies, analytics
   - **Contract** — account data, payment processing, service delivery
   - **Legitimate interest** — security logs, fraud prevention, basic analytics
   - **Legal obligation** — tax records, regulatory reporting

5. **Generate the 12-section privacy policy:**

   | # | Section | Covers |
   |---|---------|--------|
   | 1 | Introduction | Who the company is, what this policy covers |
   | 2 | Information We Collect | Data types, collection methods, sources |
   | 3 | How We Use Your Information | Purposes mapped to legal bases |
   | 4 | Cookies & Tracking | Cookie types, duration, opt-out mechanisms |
   | 5 | Information Sharing | Third parties, categories, purposes |
   | 6 | Data Retention | How long each data type is kept |
   | 7 | Your Rights Under GDPR | 7 specific rights with exercise instructions |
   | 8 | Your Rights Under CCPA | 6 specific rights with exercise instructions |
   | 9 | Data Security | Technical and organizational measures |
   | 10 | International Transfers | Cross-border data flow safeguards |
   | 11 | Children's Privacy | Age restrictions, COPPA compliance |
   | 12 | Contact & Updates | DPO contact, policy change notification |

6. **Detail GDPR rights (Section 7).** Include all seven with exercise instructions:
   1. Right of Access (Article 15) — request a copy of personal data
   2. Right to Rectification (Article 16) — correct inaccurate data
   3. Right to Erasure (Article 17) — "right to be forgotten"
   4. Right to Restrict Processing (Article 18) — limit data use
   5. Right to Data Portability (Article 20) — receive data in machine-readable format
   6. Right to Object (Article 21) — object to processing based on legitimate interest
   7. Rights Related to Automated Decision-Making (Article 22) — opt out of profiling

7. **Detail CCPA rights (Section 8).** Include all six:
   1. Right to Know — what personal information is collected
   2. Right to Delete — request deletion of personal information
   3. Right to Opt-Out — "Do Not Sell or Share My Personal Information"
   4. Right to Non-Discrimination — equal service regardless of rights exercised
   5. Right to Correct — correct inaccurate personal information
   6. Right to Limit Use of Sensitive Infor
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__privacy-generator.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aSAFEB89first audit
06

Questions

What does the Privacy Generator skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Privacy Generator safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Privacy Generator access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Privacy Generator work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement