Mmcp.market

regulatory-audit-generator skill

by zebbern·zebbern/claude-code-guide·4.6k stars·MIT

Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like \"run a compliance check,\" \"GDPR/PIPL compliance,\" \"pre-launch review,\" \"privacy impact assessment (PIA/DPIA),\" or asking if a feature is compliant.

A100/100content scan

Is the regulatory-audit-generator skill safe?

Clean: nothing in its files matched our rules. We read 2 files in the folder on 2026-09-28.

No findings.

Install the regulatory-audit-generator skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/zebbern/claude-code-guide.git /tmp/claude-code-guide
mkdir -p ~/.claude/skills
cp -r /tmp/claude-code-guide/skills/regulatory-audit-generator ~/.claude/skills/regulatory-audit-generator
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Regulatory Audit Generator — Business Scenario Compliance Checklist Builder

Identifies applicable laws and regulations based on the user's business scenario description, and outputs a structured compliance checklist covering major regulations such as GDPR, PIPL (Personal Information Protection Law), Advertising Law, Cybersecurity Law, and Data Security Law.

Quick Start

Users simply describe their business scenario, and the Agent will:

  1. Identify applicable regulations: Determine which laws and regulations apply based on the business scenario
  2. Generate a checklist: Output a structured list of check items
  3. Label risk levels: Prioritize by severity, marking high/medium/low risk
  4. Provide remediation recommendations: Offer actionable remediation guidance for each compliance risk

Users just need to say:

"We're launching a user profiling feature — help me create a compliance checklist."

The Agent will guide the user to provide necessary information, then output a complete compliance checklist.

1. Supported Regulatory Frameworks

Core Regulations

Industry-Specific Regulations

2. Compliance Check Procedure (SOP)

Step 1: Gather Business Scenario Information

Confirm the following key information with the user:

If the user has not provided certain information, the Agent should proactively ask follow-up questions rather than assume or skip.

Step 2: Identify Applicable Regulations

Based on collected information, determine applicable regulations using the following rules:

IF processing personal information → PIPL
IF involving EU users → GDPR
IF involving data storage/transmission → Data Security Law + Cybersecurity Law
IF involving advertising/marketing content → Advertising Law
IF involving e-commerce transactions → E-Commerce Law
IF involving minors → Minors Protection Law + Provisions on Protection of Children's Personal Information Online
IF cross-border data transfer (overseas storage/transmission/access) → PIPL Chapter 3 + Measures for Security Assessment of Data Export
IF involving sensitive personal information → PIPL Chapter 2 Section 2 (separate consent + PIIA)
IF involving automated decision-making → PIPL Article 24 (transparency + right to refuse)
IF involving financial data → JR/T 0171

Step 3: Generate the Compliance Checklist

Output the checklist in the following structure:

Checklist Output Format

# [Business Scenario Name] Compliance Checklist

**Assessment Date**: YYYY-MM-DD
**Business Description**: [Brief description]
**Applicable Regulations**: [List of regulations]

## Checklist

| No. | Check Item | Legal Basis | Risk Level | Current Status | Remediation Advice |
|-----|-----------|-------------|------------|----------------|-------------------|
| 1 | [Check item description] | [Regulation name + article number] | High/Medium/Low | Compliant/Non-compliant/To be confirmed | [Specific advice] |

## Risk Summary

- High-risk items: X items
- Medium-risk items: X items
- Low-risk items: X items

## Priority Remediation Recommendations

1. [Highest priority remediation item and rationale]
2. [Second highest priority item and rationale]

Step 4: Output Remediation Priorities

Prioritize remediation actions according to the following rules:

3. Common Business Scenario Check Points

Scenario 1: User Registration and Login

Scenario 2: Marketing and Advertising

Scenario 3: Cross-Border Data Transfer

Scenario 4: User Profiling and Personalized Recommendations

Scenario 5: GDPR Compliance (for EU Users)

4. Risk Level Criteria

5. Deliverables

The Agent should ultimately deliver the following to the user:

  1. Compliance Checklist Table: All check items with legal basis, risk levels, current status, and remediation advice
  2. Risk Summary: Count of high/medium/low risk items
  3. Priority Remediation Roadmap: Remediation action list ordered by P0–P3
  4. Supplementary Notes: Plain-language explanations of key compliance requirements to help non-legal staff understand

6. Disclaimers

  1. Regulatory Currency: Laws and regulations are continuously updated. Regulation references in the checklist should be verified against the latest versions. The Agent should remind users to check for the most recent regulatory developments.
  2. Not Legal Advice: This checklist is for reference only and does not constitute legal advice. For significant compliance decisions, consultation with a qualified attorney is recommended.
  3. Industry Variations: Different industries have specific regulatory requirements. The checklist should be adapted to account for industry-specific considerations.
  4. Ongoing Compliance: Compliance is not a one-time effort. Regular reassessment (at least every six months) is recommended.

References

  • Personal Information Protection Law of the People's Republic of China (PIPL, 2021)
  • Data Security Law of the People's Republic of China (DSL, 2021)
  • Cybersecurity Law of the People's Republic of China (CSL, 2017)
  • Advertising Law of the People's Republic of China (2018 Amendment)
  • EU General Data Protection Regulation (GDPR, 2018)
  • Measures for Standard Contracts for Personal Information Export (2023)
  • Measures for Security Assessment of Data Export (2022)
  • GB/T 35273-2020 Information Security Technology — Personal Information Security Specification

More skills from zebbern/claude-code-guide

  • Aacademic-paper-reviewerSimulates academic peer review, evaluating papers across Originality, Methodology, Results, and Writing to provide Major/Minor Revision recommendations with actionable feedback. Triggers when a user asks to \"review my paper,\" \"simulate peer review,\" or \"give my paper a peer review.
  • Aactive-directory-attacksThis skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", "Silver Ticket", "AS-REP roasting", "NTLM relay", or needs guidance on Windows domain penetration testing.
  • Capi-fuzzing-bug-bountyThis skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
  • Aapi-shape-explorerGenerate multiple radically different interface designs for a module using parallel sub-agents. Use when user wants to design an API, explore interface options, compare module shapes, or mentions "design it twice".
  • Aaudit-flowInteractive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on audit, trace flow, document flow, security review, debug flow, brainstorm, architecture review, post-mortem, incident review.
  • Aauthentication-patternsAuthentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.
  • Aaws-penetration-testingThis skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.
  • Abroken-authenticationThis skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password policies", "test for session fixation", or "identify authentication bypass flaws". It provides comprehensive techniques for identifying authentication and session management weaknesses in web applications.
  • Cburp-suite-testingThis skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using Burp Suite's core features for web application security testing.
  • AcachingCaching strategies — invalidation, TTL guidelines, cache keys, cache layers, and when not to cache. Use when implementing or reviewing caching logic.
  • Achart-imageGenerate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts. Triggers when the user asks to visualize data, create a graph, plot a time series, or generate a chart for a report, alert, or dashboard. Runs as a lightweight, headless Node.js process without a browser.
  • Dcloud-penetration-testingThis skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud resources", "exploit cloud misconfigurations", "test O365 security", "extract secrets from cloud environments", or "audit cloud infrastructure". It provides comprehensive techniques for security assessment across major cloud platforms.

All agent skills → · MCP servers