Mmcp.market

doncheli-data-policy skill

by doncheli·doncheli/don-cheli-sdd·57 stars·Apache-2.0

Audit and document what personal or sensitive data the project collects, processes, and stores. Activate when user mentions "privacy", "data policy", "what data", "GDPR", "personal data", "data retention", "PII".

A100/100content scan

Is the doncheli-data-policy skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the doncheli-data-policy skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/doncheli/don-cheli-sdd.git /tmp/don-cheli-sdd
mkdir -p ~/.claude/skills
cp -r /tmp/don-cheli-sdd/.agent/skills/doncheli-data-policy ~/.claude/skills/doncheli-data-policy
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Don Cheli: Data Policy Auditor

Instructions

  1. Scan the codebase for PII and sensitive data patterns:
  • Database models / schemas for fields like email, phone, name, address, IP, location
  • API request/response payloads
  • Logging statements that may capture sensitive fields
  • Third-party integrations that receive user data
  1. Build a data inventory table: field name, model, purpose, retention, shared with
  2. Check against common compliance requirements:
  • GDPR: lawful basis, right to erasure, data minimization
  • CCPA: disclosure, opt-out
  • SOC2: access controls, encryption at rest/transit
  1. Flag violations as [critical | warning | info]
  2. Generate a draft Privacy Notice section if requested (--generate-notice)
  3. Save the audit to .dc/data-policy-audit-.md
  4. Never make assumptions about compliance status — only report findings and flag gaps

Output Format

## Data Policy Audit — 2026-03-28

### Data Inventory
| Field     | Model      | Purpose       | Retention | Shared With     |
|-----------|-----------|---------------|-----------|----------------|
| email     | User       | Auth, comms   | Indefinite| SendGrid, Auth0|
| ip_address| AuditLog   | Security      | 90 days   | Internal only  |

### Compliance Gaps
🔴 CRITICAL: ip_address logged in plain text in audit_logs — encrypt or hash
🟡 WARNING:  No data retention policy enforced for User.email — GDPR Art. 5(e)
🟢 INFO:     No right-to-erasure endpoint found — required for GDPR compliance

### Recommendations
1. Add @Encrypted() decorator to ip_address field
2. Implement DELETE /users/:id endpoint that purges all PII
3. Document data retention in Privacy Policy

More skills from doncheli/don-cheli-sdd

  • Adoncheli-api-contractDesign complete API contracts covering endpoints, auth, rate limiting, error handling, retries, circuit breaker and idempotency. Activate when user mentions "api contract", "api design", "endpoint", "webhook", "REST", "GraphQL", "OpenAPI", "design the API".
  • Adoncheli-api-contractDesign complete API contracts covering endpoints, auth, rate limiting, error handling, retries, circuit breaker and idempotency. Activate when user mentions "api contract", "api design", "endpoint", "webhook", "REST", "GraphQL", "OpenAPI", "design the API".
  • Adoncheli-audit-trailRecord and query the decision log for a project. Activate when user mentions "audit", "trail", "log decisions", "decision history", "why was this decided", "ADR", "architecture decision".
  • Adoncheli-audit-trailRecord and query the decision log for a project. Activate when user mentions "audit", "trail", "log decisions", "decision history", "why was this decided", "ADR", "architecture decision".
  • Adoncheli-changelogAuto-generate CHANGELOG.md entries from git commit history. Activate when user mentions "changelog", "release notes", "what changed", "generate changelog", "CHANGELOG", "release history".
  • Adoncheli-changelogAuto-generate CHANGELOG.md entries from git commit history. Activate when user mentions "changelog", "release notes", "what changed", "generate changelog", "CHANGELOG", "release history".
  • Adoncheli-context-healthReport the current state of the context window and recommend compression or cleanup actions. Activate when user mentions "context health", "context window", "how much context", "context full", "running out of context", "compress context".
  • Adoncheli-context-healthReport the current state of the context window and recommend compression or cleanup actions. Activate when user mentions "context health", "context window", "how much context", "context full", "running out of context", "compress context".
  • Adoncheli-data-policyAudit and document what personal or sensitive data the project collects, processes, and stores. Activate when user mentions "privacy", "data policy", "what data", "GDPR", "personal data", "data retention", "PII".
  • Adoncheli-debateRun an adversarial multi-role debate to surface trade-offs and reach a reasoned decision. Activate when user mentions "debate", "discuss", "trade-off", "decision", "compare options", "pros and cons", "choose between".
  • Adoncheli-debateRun an adversarial multi-role debate to surface trade-offs and reach a reasoned decision. Activate when user mentions "debate", "discuss", "trade-off", "decision", "compare options", "pros and cons", "choose between".
  • Adoncheli-diagramAuto-generate Mermaid or C4 diagrams from code analysis. Activate when user mentions "diagram", "mermaid", "architecture diagram", "C4", "class diagram", "sequence diagram", "ERD", "flowchart", "visualize code".

All agent skills → · MCP servers