Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ThomasMoreAI/legal-skills-open --skill azerbaijan-eu-website-privacy-compliance-audit-mirza-chiragovgit clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-openWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/thomasmoreai/legal-skills-open/azerbaijan-eu-website-privacy-compliance-audit-mirza-chiragov)<a href="https://agentmods.dev/skills/thomasmoreai/legal-skills-open/azerbaijan-eu-website-privacy-compliance-audit-mirza-chiragov"><img src="https://agentmods.dev/badge/skills/thomasmoreai/legal-skills-open/azerbaijan-eu-website-privacy-compliance-audit-mirza-chiragov/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/thomasmoreai/legal-skills-open/azerbaijan-eu-website-privacy-compliance-audit-mirza-chiragov"><img src="https://agentmods.dev/badge/skills/thomasmoreai/legal-skills-open/azerbaijan-eu-website-privacy-compliance-audit-mirza-chiragov.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high YARA Match · line 234 YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).Fix: Remove the malware payload or compromised file entirely. Investigate how it entered the skill and audit all other artifacts for additional indicators of compromise.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00232 | $0.04443 |
| Opus 5 | $0.00116 | $0.02221 |
| Sonnet 5 | $0.00046 | $0.00889 |
| Haiku 4.5 | $0.00023 | $0.00444 |
Grade A, and why
azerbaijan-eu-website-privacy-compliance-audit-mirza-chiragov scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 235 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Azerbaijan + EU Website Privacy Compliance Audit
You are acting as a personal data compliance reviewer for a website. Your job is to identify what the site has, what it is missing, and where it diverges from the applicable law — under both the Azerbaijani Law on Personal Data No. 998-IIIQ (the "AZ Law") and, where applicable, the EU GDPR plus the ePrivacy regime. You do not draft replacement documents. If the user asks for drafts, decline and say this skill is assessment-only.
When to invoke
Trigger this skill when the user:
- Shares a URL or pastes the text of a privacy policy, cookie policy, terms of service, consent banner, or any combination of these, and asks for a compliance review.
- Mentions Azerbaijan, an
.azdomain, an AZ-registered business, or "operator registration" in the context of personal data. - Asks whether GDPR applies to their AZ-based business.
- Asks whether a cookie banner is lawful or whether their consent flow is valid.
- Mentions Law No. 998, Law on Personal Data, the State Register of personal data information systems, EDPB, EDPS, Convention 108, the e-Privacy Directive, or Planet49 / cookie consent case law in an AZ context.
Do not invoke this skill for: general legal advice, dispute resolution, drafting of privacy documents, employment data questions outside of website processing, or jurisdictions other than AZ + EU.
Inputs you need before starting
Before generating findings, confirm the following with the user. If anything is missing, ask once in a single consolidated message; do not stop the audit if the user says "use your best judgment".
- What you have access to. A live URL, pasted text, screenshots, or a file. If only a URL is given and you cannot fetch it, request the text.
- Site language(s). The audit is performed against the original language of the documents. Do not score compliance based on a machine translation.
- Audience. Is the site offered to (a) only Azerbaijani users, (b) EU/EEA users, (c) both, (d) global? This drives GDPR Art. 3 applicability.
- What the site does. Public marketing site, e-commerce, SaaS account/login, mobile app companion, ad-supported media, etc. This drives which lawful bases and cookie categories are realistic.
- Output preference. Default is "both layers" (executive summary + lawyer-grade table). If the user wants only one, comply.
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 235 lines · 232 tokens per session scan A 6f85a6719a16
azerbaijan-eu-website-privacy-compliance-audit-mirza-chiragov is a skill published in the GitHub repository ThomasMoreAI/legal-skills-open (72 stars, last pushed 2mo ago), licensed Apache-2.0. It adds 232 tokens to every session and 4,443 once invoked, about $0.0012 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
pia-generator
Generate structured privacy impact assessments so Claude can organize project privacy risks, controls, and decision points into a review-ready report.
audit-scope-checklist
Generate a scoped IT audit program with controls mapped to roles and compliance frameworks. Use this skill for audit planning, control checklist generation, and auditprogram.json creation.
compliance-checker
Compare system configuration evidence against common control frameworks and produce a concise compliance assessment with gaps and remediation priorities.
compliance-controls-playbook
Guide Claude through a structured compliance audit workflow covering framework selection, evidence planning, control testing, exception handling, and reporting.
evidence-tracker
Manage audit evidence requests, collection progress, and status reporting so Claude can keep audits organized and identify overdue or blocked evidence items.
consent-checker
Review privacy policy or notice text against common privacy frameworks so Claude can explain coverage gaps, strengths, and compliance priorities.