Privacy Compliance Guide

AdvisoryAudited by Static analysis on May 11, 2026.

Overview

No suspicious patterns detected.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Business privacy practices, vendor lists, revenue ranges, and customer counts could be exposed if users paste or share the completed audit carelessly.

Why it was flagged

The template encourages users to provide business-sensitive compliance details. This is purpose-aligned, but such information may be sensitive if stored in chat history, shared outputs, or agent memory outside this skill.

Skill content
| **Annual Revenue** | [Range — determines CCPA applicability] | ... | **Customer Count** | [Approximate — determines CCPA applicability] |
Recommendation

Use aggregated descriptions rather than raw customer records, avoid pasting unnecessary personal data, and store completed compliance outputs securely.

What this means

A user might mistake the generated checklist or policy guidance for definitive legal advice.

Why it was flagged

The guide frames its output as helping avoid fines. That is aligned with the skill purpose, but privacy compliance is legal and jurisdiction-specific, so users should not over-rely on the template as a guarantee.

Skill content
Build a privacy-compliant e-commerce operation that protects customer data, avoids regulatory fines
Recommendation

Treat the skill as an educational planning aid and have a qualified privacy/legal professional review final policies and high-risk decisions.

What this means

Users cannot easily verify the maintainer, content source, or update process for changing privacy laws.

Why it was flagged

The skill has no code or install dependency risk, but the provenance of the compliance content is not documented.

Skill content
Source: unknown; Homepage: none
Recommendation

Cross-check current legal thresholds and requirements against official regulator guidance or counsel before implementation.