评估SDK插件与嵌入式收集

A review workflow for third-party software components embedded in apps, mini-programs, or websites, such as analytics, advertising, payment, or crash-reporting SDKs. It records what they collect, whether consent is linked to startup, and who receives the data.

In plain words
What is it for?
Use it to build an SDK inventory, map collection points and recipients, check consent and automatic startup, and list evidence gaps and potential compliance issues.
Why use it?
It helps identify missing records, consent controls, oversight, and evidence when outside code collects data. It also separates this review from a general app or contract review.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/lawyeah-tech/lawyeah/sdk
Any agent
npx skills add Lawyeah-Tech/lawyeah --skill sdk
Clone the repo
git clone --depth 1 https://github.com/Lawyeah-Tech/lawyeah

Made for: Claude Code, Codex.

Per session 28 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,136 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00028 $0.01136
Opus 5 $0.00014 $0.00568
Sonnet 5 $0.00006 $0.00227
Haiku 4.5 $0.00003 $0.00114

Measured 2d ago against content hash f50259d65ea6, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

评估SDK插件与嵌入式收集 scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

领域/数据隐私与网络安全/skills/评估SDK插件与嵌入式收集/SKILL.md · 88 lines

What it actually says

评估 SDK 插件与嵌入式收集

任务目标

形成 SDK 清单、收集点、同意与监督缺口。C 端 App 审查只分流。

depends-on 为空。接受用户、律师、机关或其他来源的等价事实、处理记录和证据清单。

工作边界

正触发:App、小程序或网站嵌入第三方 SDK、插件或像素。

负触发并输出 触发判定:负触发,未启动本任务

  • C 端 App 审查商品本身;
  • 只要一份委托合同;
  • 只要下架整改报告;
  • 回改大众 App 审查清单;

本任务不给胜诉率或免罚承诺。审查起草本窗搁置。企业合规整案与知识产权只分流。

建立坐标

确认:宿主应用;SDK 名称与版本;收集种类;初始化是否与同意绑定;是否自启动;接收方。

同时掌握处理者与权利人双方秘密或潜在冲突时,先停止策略输出,澄清代表哪一方。

来源和判断状态

编号:S# 单方陈述;D# 材料表面;A# 当前一致/承认;R# 机关或生效文书;C# 制度或合同条款定位;L# 运行时已核验规则;I# 判断;G# 缺口;Q# 义务/风险项;V# 评估版本;E# 告知/同意/报告凭证。

判断只用 现有依据支持现有依据不支持依据不足,无法形成结论。不得输出胜诉率、必然免罚、必然合法或唯一处罚金额。未知人数或金额不写零。

律页能力增强

本技能属于律页法律技能家族,并支持 Lawyeah MCP 按需增强。

  • 运行环境提供 Lawyeah MCP 时,执行 Agent 根据当前任务按需使用法律法规、法律实务、裁判案例或文书范本检索。
  • 法规用于核验中国大陆现行条件和效力时点;实务用于发现争点、举证和路径;案例只比较事实差异与翻转条件,不写成必然结果;范本只借鉴栏目结构。
  • 任何结果都要复核法域、效力、时点、地区和与当前事实的差异。不得把已失效《合同法》及其解释当作现行规则。
  • MCP 未安装、未启用、未暴露、无结果、结果冲突或暂时不可用时,不拒绝执行、不中断主流程。继续使用本技能内置方法和用户材料完成可处理部分;依赖未核验规则的法律结论、期限或机关路径保持停止或待核。
  • 不向用户索取密钥、令牌或完整凭证。MCP 是可选增强,不是用户运行技能的强制依赖。

使用 Lawyeah MCP

宿主可调用时:search_law 核验对外提供、告知同意及 App 监管关于 SDK 的现行要求。不虚构案件系统。

工具不可用时继续主体、场景、系统和问题清单;依赖未核验规则的法律结论、期限或机关路径字段停止。

五个判断节点

执行顺序和停止条件以 SDK 治理方法 为准。这里只列入口,不代替节点。

节点 1 清单

含广告、统计、推送、地图、支付、崩溃。未知 SDK 标缺口。

节点 2 收集点

自启动、后台、剪切板、设备信息分列。

节点 3 同意与告知

SDK 收集须可对应告知和同意。初始化早于同意则红旗。

节点 4 角色与监督

多数 SDK 为对外提供或共同处理。无协议无监督标缺口。

节点 5 C 端分账

不回改 C 端商品。下架走下架原子。

停止与安全

  • 整体停止:指导隐蔽集成未披露 SDK。
  • 字段停止:SDK 实际收集行为事实不足。
  • 目标停止:主目标变为 C 端 App 审查或下架报告。

交付

严格按 输出合同 八节交付。正触发状态只用 已形成部分形成并明确受限字段因停止条件未形成。边界见 路由

Files

What ships with it

4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 88 lines · 28 tokens per session scan A f50259d65ea6

Subscribe to this mod's changes

评估SDK插件与嵌入式收集 is a skill published in the GitHub repository Lawyeah-Tech/lawyeah (5 stars, last pushed 2d ago), licensed Apache-2.0. It adds 28 tokens to every session and 1,136 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

cn-law-hub

用于查询、检索、核验、下载、导出、批量采集中国官方法律法规、规章、条约和具体法条。Use this skill aggressively when the user asks to 查法律、查法规、查条例、查规章、查条约、查法条、查第几条、找法律依据、引用法律依据、核验现行有效、判断是否废止/已修改/尚未生效、下载法规全文、导出法规目录、批量下载法规文件、按关键词检索具体法条、展开法条分析,或在中国法律咨询、案例分析、合规审查、合同审查、劳动争议、行政法分析、公司合规、数据合规、政策研究中需要调用、核验或引用中国现行有效法律法规原文作为依据。Trigger also when phrases such as…

ZongziForu/cn-law-hub · 452 tokens

law-to-markdown

将法条/规范文件(.txt/.docx/.pdf)转为 Markdown。适用于用户要求“法条转 markdown”“pdf/docx 转 markdown”。处理 .pdf/.docx 时先检查是否已安装 mineru-ocr skill;未安装先引导安装,安装后优先用 mineru-ocr;仅在用户明确同意时再用本地回退方案。.

pa1nrui1/legal-skills · 90 tokens

legal-citation-comprehensive

全面法学引注诊断、补全与格式化工具。用于检查混乱脚注、识别缺失要素、说明应去哪里查找缺失信息,并在用户提供来源文件、法条、案例或网页信息时生成符合《法学引注手册(第二版)》的中文/外文法律脚注。适用于法学引注、脚注检查、引注修正、引用格式转换、法律文献引用、法条脚注、案例脚注、论文引注。.

lawyerllsx-dotcom/Legal-Workflow-Chain · 119 tokens

legal-fact-checker

法律产出事实核查技能。当用户需要撰写、编辑、分析任何法律文件(法律文书、案例分析、法条评析、合同审查、法律意见书、法学作业等)时触发此技能。核心原则:一切法律产出必须有事实依据,禁止编纂案例、法规或事实。触发词:法律文件、案例分析、法条分析、合同审查、法律意见、法学作业、法规验证、事实核查、凶宅案、合同纠纷、民法作业、法律写作、legal writing、fact check、法律产出。.

lawyerllsx-dotcom/Legal-Workflow-Chain · 143 tokens

legal-research

当用户需要【查法条/查案例/查赔偿标准/判断合法性】时使用。触发词:查一下、法条、怎么规定、法律依据、赔偿标准、合法吗、有没有责任。输出:法条原文+条文号+相关案例(可溯源)。不做:凭记忆回答(必须经检索源核实)。.

lawyerllsx-dotcom/Legal-Workflow-Chain · 87 tokens

workflow-overview

Skill "workflow-overview" from lawyerllsx-dotcom/Legal-Workflow-Chain, covering 工作流总览(workbuddy 版), 工作流全景, 唯一入口与路由优先级(p1-1), 执行路径(自主规划) and 与 case-pipeline 合并互补(复杂案件必读).

lawyerllsx-dotcom/Legal-Workflow-Chain · 63 tokens