compliance-review-planner

compliance-review-planner is a skill for Claude Code, Codex from serejaris/kimi-skills. It costs 151 tokens per session (3,065 once invoked), scanned A, original, MIT.

A skill that creates a structured legal-compliance checklist for a described business feature or process. It covers rules such as GDPR, China’s personal-information and data-security laws, advertising law, and sector-specific requirements.

In plain words
What is it for?
It is for reviewing user-data processing, profiling, cross-border transfers, advertising, e-commerce, apps, and other features before release.
Why use it?
It helps identify which rules may apply, how serious each risk is, and what changes may reduce the risk before launch.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit It is for reviewing user-data processing, profiling, cross-border transfers, advertising, e-commerce, apps, and other features before release.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/serejaris/kimi-skills/compliance-review-planner
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add serejaris/kimi-skills --skill compliance-review-planner
Clone the repo
git clone --depth 1 https://github.com/serejaris/kimi-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for compliance-review-planner

README.md
[![agentmods](https://agentmods.dev/badge/skills/serejaris/kimi-skills/compliance-review-planner/github.svg)](https://agentmods.dev/skills/serejaris/kimi-skills/compliance-review-planner)
Your own site
<a href="https://agentmods.dev/skills/serejaris/kimi-skills/compliance-review-planner"><img src="https://agentmods.dev/badge/skills/serejaris/kimi-skills/compliance-review-planner/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for compliance-review-planner

Your own site · 80×15
<a href="https://agentmods.dev/skills/serejaris/kimi-skills/compliance-review-planner"><img src="https://agentmods.dev/badge/skills/serejaris/kimi-skills/compliance-review-planner.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 151 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,065 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00151 $0.03065
Opus 5 $0.00076 $0.01533
Sonnet 5 $0.00030 $0.00613
Haiku 4.5 $0.00015 $0.00307

Measured 12d ago against content hash 3adb78b8b4f7, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

compliance-review-planner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/compliance-review-planner/SKILL.md · 228 lines

How it starts

The opening of the file, as written. The whole thing — 228 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Compliance Checklist Builder — 业务场景合规检查清单构建器

根据用户描述的业务场景,识别适用的法律法规,输出结构化的合规检查清单,涵盖 GDPR、个人信息保护法、广告法、网络安全法、数据安全法等主要法规。

Quick Start

用户只需描述业务场景,Agent 会:

  1. 识别适用法规:根据业务场景判断涉及哪些法律法规
  2. 生成检查清单:输出结构化的检查项列表
  3. 标注风险等级:按严重程度排序,标明高/中/低风险
  4. 给出整改建议:针对每项不合规风险提供可落地的整改方向

用户只需说:

"我们要上线一个用户画像功能,帮我做个合规检查清单"

Agent 会引导用户补充必要信息,然后输出完整的合规检查清单。


一、支持的法规体系

核心法规

法规 简称 适用范围 关注重点
个人信息保护法 个保法/PIPL 中国境内处理个人信息 知情同意、最小必要、个人信息出境
通用数据保护条例 GDPR 涉及欧盟用户数据 合法基础、数据主体权利、DPO、DPIA
数据安全法 DSL 中国境内数据处理活动 数据分类分级、安全评估、重要数据出境
网络安全法 CSL 网络运营者 等保、日志留存、安全事件报告
广告法 广告发布与经营 禁用极限词、虚假宣传、医疗广告
电子商务法 电子商务经营者 公示信息、用户评价、搭售
反不正当竞争法 市场经营活动 商业贿赂、虚假宣传、侵犯商业秘密
消费者权益保护法 消保法 消费者权益相关 知情权、公平交易权、个人信息

行业专项法规

行业 相关法规/标准
金融 《个人金融信息保护技术规范》(JR/T 0171)、《银行保险机构数据安全管理办法》
医疗 《人口健康信息管理办法》、《医疗大数据标准》
教育 《未成年人保护法》中网络保护专章、《儿童个人信息网络保护规定》
汽车 《汽车数据安全管理若干规定》
App 《App 违法违规收集使用个人信息行为认定方法》、《常见类型移动互联网应用程序必要个人信息范围规定》

二、合规检查流程(SOP)

第 1 步:收集业务场景信息

向用户确认以下关键信息:

维度 需要确认的内容 示例
业务描述 功能/服务的具体内容 "用户画像功能,基于行为数据推荐商品"
用户群体 服务对象的地域和人群 "中国大陆用户,含未成年人"
数据类型 收集/处理哪些数据 "姓名、手机号、浏览记录、位置信息"
数据流向 数据存储、传输、共享情况 "存储在阿里云华东节点,共享给第三方广告平台"
业务阶段 新上线 / 已运行需整改 / 并购尽调 "新功能,计划下月上线"
已有措施 当前已采取的合规措施 "有隐私政策,但未做 DPIA"

如果用户未提供部分信息,Agent 应主动追问,而非假设或跳过。

第 2 步:识别适用法规

根据收集到的信息,按以下规则判断适用法规:

IF 处理个人信息 → 个保法
IF 涉及欧盟用户 → GDPR
IF 涉及数据存储/传输 → 数据安全法 + 网络安全法
IF 涉及广告/营销内容 → 广告法
IF 涉及电商交易 → 电子商务法
IF 涉及未成年人 → 未成年人保护法 + 儿童个人信息网络保护规定
IF 数据出境(境外存储/传输/访问) → 个保法第三章 + 数据出境安全评估办法
IF 涉及敏感个人信息 → 个保法第二章第二节(单独同意 + PIIA)
IF 涉及自动化决策 → 个保法第 24 条(透明度 + 拒绝权)
IF 涉及金融数据 → JR/T 0171

第 3 步:生成合规检查清单

按以下结构输出检查清单:

清单输出格式
# [业务场景名称] 合规检查清单

**评估日期**:YYYY-MM-DD
**业务描述**:[简要描述]
**适用法规**:[法规列表]

## 检查清单

| 序号 | 检查项 | 法规依据 | 风险等级 | 当前状态 | 整改建议 |
|------|--------|---------|---------|---------|---------|
| 1 | [检查项描述] | [法规名称 + 条款号] | 高/中/低 | 合规/不合规/待确认 | [具体建议] |

## 风险汇总

- 高风险项:X 项
- 中风险项:X 项  
- 低风险项:X 项

## 优先整改建议

1. [最高优先级整改项及理由]
2. [次高优先级整改项及理由]

Read the full file on GitHub · 228 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 228 lines · 151 tokens per session scan A 3adb78b8b4f7

Subscribe to this mod's changes

compliance-review-planner is a skill published in the GitHub repository serejaris/kimi-skills (6 stars, last pushed 1mo ago), licensed MIT. It adds 151 tokens to every session and 3,065 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

fiscaliste

Fiscaliste IA pour la fiscalité personnelle des particuliers français : optimisation et déclaration de l'impôt sur le revenu, IFI, revenus du capital, revenus fonciers, equity salarial, crypto-actifs et PER. Couvre le calcul de l'IR (barème, quotient familial, décote, PAS, CEHR, revenus exceptionnels), la déclaration…

romainsimon/paperasse · 302 tokens

controleur-fiscal

Inspecteur des finances publiques IA. Simule un contrôle fiscal DGFIP complet sur les comptes d'une entreprise française (SASU, EURL, SAS, SARL). Analyse le FEC, la liasse fiscale, les charges déduites, le compte courant d'associé, la TVA, l'IS selon 8 axes de vérification. Identifie les chefs de redressement…

romainsimon/paperasse · 136 tokens

notaire

Notaire IA pour le droit immobilier, les successions, les donations, le droit de la famille et le droit des sociétés en France. Copilote juridique pour la préparation d'actes, le conseil patrimonial, les calculs de frais et la vérification de conformité. Couvre le calcul des frais de notaire (DMTO, émoluments…

romainsimon/paperasse · 221 tokens

commissaire-aux-comptes

Commissaire aux comptes IA pour l'audit des comptes annuels d'entreprises françaises. Applique la démarche NEP en 7 phases : prise de connaissance, contrôle du FEC, vérification du bilan, du compte de résultat, de la balance, de la liasse fiscale, et contrôles transversaux. Émet une opinion motivée sur la fiabilité…

romainsimon/paperasse · 123 tokens

neo-iso-27001

Use this skill when the user needs to establish, review, or improve an ISO/IEC 27001 ISMS, perform information security risk discovery, define scope, create an evidence matrix, conduct a gap analysis, draft a Statement of Applicability, prepare for an internal audit, or create an improvement plan. Use neo-iso-27701…

Benknightdark/neo-skills · 103 tokens

neo-iso-27701

Use this skill when the user needs to establish, review, or improve an ISO/IEC 27701 PIMS, inventory PII processing, analyze controller and processor responsibilities, create a privacy risk or evidence matrix, conduct a gap analysis, prepare for an audit, or create an improvement plan. Use neo-iso-27001 when the main…

Benknightdark/neo-skills · 102 tokens