More screenshots
Works with the AI tools you already use
Legal, Security & Compliance Auditor
Adaptive GDPR, CCPA, security, and AI compliance audit with severity-graded findings and law citations
$10
Legal, Security & Compliance Auditor
Example session with this skill installed
I'm launching a SaaS app (Next.js + Prisma + Clerk + OpenAI) in the EU and California next month. Run a full privacy
and compliance audit and tell me what to fix first.
- Read your context and instructions
- Compiled the legal security
- Generated the document
Scope determined: GDPR + UK GDPR + CCPA/CPRA + Security + LLM. LGPD/PIPL/DPDPA not in scope.
I scanned 142 source files. Writing the full report to COMPLIANCE_AUDIT.md.
Summary: 20 findings — 3 Critical, 6 High, 7 Medium, 4 Low.
Top priority right now: an OpenAI API key was committed in PR #214 and never rotated. The key is reachable via
git log --all -S 'sk-proj-' even though it was removed in a later commit. Rotate it in the OpenAI dashboard now,
then install gitleaks as a pre-commit hook.
Other Critical findings:
- Request middleware logs full POST bodies — passwords leak to Sentry on signup (src/middleware.ts:18).
- No account-deletion endpoint exists (GDPR Art. 17, CCPA §1798.105). The schema has no anonymization helpers either.
Recommended order: fix the 3 Criticals this week. Add the EU cookie consent gate and "Do Not Sell or Share" link
before launch. The full report at COMPLIANCE_AUDIT.md contains file:line for each finding, the article cited, and a
concrete fix.
This audit is an engineering checklist, not legal counsel. Consult a qualified data protection lawyer for binding
decisions.
legal-security-compliance-auditor.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it audits
- GDPR + UK GDPR — 23 checks: lawful basis, consent, all data-subject rights (Art. 15–22), data protection by design, security, breach notification, international transfers
- CCPA / CPRA — 17 checks: notice at collection, sale/share opt-out, Global Privacy Control, minor opt-in, sensitive PI, request response SLA
- Data security — 20 checks: password hashing, encryption at rest and in transit, secrets in code, PII in logs, JWT and session security, SQL injection, security headers, CORS
- LLM disclosure & AI compliance — 16 checks: AI labeling, inaccuracy warnings, data sent to providers, EU AI Act Art. 50, prompt injection, vector store privacy, automated decisions
- LGPD (Brazil), PIPL (China), DPDPA (India) — 24 conditional checks loaded only when the skill detects you target those markets
How it works
- Detects target markets from i18n files, currencies, domains, languages, framework signals. Asks if signals are ambiguous.
- Maps your PII surface — database models, API endpoints, forms, logs, third parties, LLM integrations, cookies, auth flows.
- Runs applicable checklists against the map.
- Writes COMPLIANCE_AUDIT.md with Critical / High / Medium / Low findings. Every finding has the exact file:line, the article cited (e.g. "GDPR Art. 17(1)(a)"), what's wrong, why it matters, and a concrete fix.
Why this skill stands out
- Adaptive scope — auto-detects target jurisdictions, so you get only the checks that apply
- Concrete fixes, not vague advice — "Replace SHA-256 with argon2id (m=19456 KB, t=2, p=1), migrate on next login" beats "use stronger hashing"
- Honest boundaries — produces an engineering audit, not legal advice; report ends with disclaimer recommending qualified counsel
- Agent-agnostic — Claude Code, Cursor, Codex CLI, VS Code Copilot, Gemini CLI, Windsurf
- Stack-aware — recognizes Prisma, Drizzle, TypeORM, SQLAlchemy, Django ORM, Active Record, Mongoose, plus Next.js, FastAPI, Express, NestJS, Rails routing
Who it's for
- Founders preparing for production launch in EU / UK / US
- Engineers preparing for a SOC 2 / ISO 27001 / DPIA review
- Teams adding AI features who need to disclose properly
- Anyone shipping a product that touches user data
Trigger phrases
The skill auto-loads when you naturally ask things like:- "Check my app for GDPR compliance"
- "Do a privacy audit before launch"
- "Find data protection issues"
- "Audit my codebase for personal data handling"
- "Review my app before launching in the EU"
Limitations
Static review only. Does not write fixes (you decide what to change), does not generate Privacy Policy / Terms text, does not certify compliance. Consult a qualified data protection lawyer for binding decisions.How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 4 months ago
- Passed all security checks, Safe to install