Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ZekaiSuni/claude-for-legal-turkish --skill dpa-reviewgit clone --depth 1 https://github.com/ZekaiSuni/claude-for-legal-turkishWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zekaisuni/claude-for-legal-turkish/dpa-review)<a href="https://agentmods.dev/skills/zekaisuni/claude-for-legal-turkish/dpa-review"><img src="https://agentmods.dev/badge/skills/zekaisuni/claude-for-legal-turkish/dpa-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zekaisuni/claude-for-legal-turkish/dpa-review"><img src="https://agentmods.dev/badge/skills/zekaisuni/claude-for-legal-turkish/dpa-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00157 | $0.02120 |
| Opus 5 | $0.00078 | $0.01060 |
| Sonnet 5 | $0.00031 | $0.00424 |
| Haiku 4.5 | $0.00016 | $0.00212 |
Grade A, and why
dpa-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 160 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/dpa-review
Başlamadan
~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.mddosyasını oku.## Veri İşleyen / DPA Playbook,## Yurt Dışına Aktarım,## Aydınlatma / Politika Taahhütlerive## Çıktı Kurallarıbölümlerini yükle.- Profil placeholder ağırlıklıysa önce
/privacy-legal:cold-start-interviewöner. references/currency-watch.mddosyasını güncellik kontrol listesi olarak oku.## Matter Workspacesaçıksa aktif matter'ı yükle; kapalıysa practice-level çalış.
Amaç
Bu skill, DPA'yı yabancı şablon olarak değil, Türkiye'de veri sorumlusu ve veri işleyen ilişkisini düzenleyen sözleşmesel kontrol dokümanı olarak inceler. DPA kısaltması kullanılabilir; çıktı dili "veri işleme sözleşmesi / veri işleyen eki" olmalıdır.
Rolü Belirle
İlk karar şudur:
| Durum | İnceleme açısı |
|---|---|
| Biz veri sorumlusuyuz, tedarikçi verimizi işliyor | Koruyucu inceleme: talimat, güvenlik, alt işleyen, ihlal, silme-iade, denetim, aktarım |
| Biz veri işleyeniz, müşteri DPA gönderdi | Operasyonel savunma: uygulanabilir talimat, makul denetim, gerçekçi ihlal süresi, sorumluluk sınırı |
| Rol belirsiz veya karma | Önce faaliyet bazında veri sorumlusu/veri işleyen/ortak rol analizi yap; belirsizse hukuk incelemesine gönder |
Yanlış rol seçimi bütün önerileri tersine çevirir; belirsizlik varsa tek netleştirme sorusu sor.
Önceki Çıktılar
Aynı tedarikçi, müşteri veya faaliyet için önceki çıktıları kontrol et:
use-case-triagesonucu,pia-generation/ VKED,- önceki
dpa-review, - politika monitor bulgusu,
- ihlal veya Kurul/şikayet notu.
Önceki çıktının risk seviyesi tabandır. Kırmızı riskli bir faaliyet DPA incelemesinde açıklamasız yeşile düşürülemez.
KVKK İnceleme Kapıları
Her sözleşmede şu kapıları kontrol et:
| Kapı | Kontrol |
|---|---|
| Rol ve taraflar | Veri sorumlusu, veri işleyen, alt işleyen ve alıcı rolleri fiili akışla uyumlu mu? |
| İşleme amacı ve talimat | İşleme yalnızca belgelenmiş amaç/talimatla sınırlı mı? |
| Veri kategorileri | Kişisel veri, özel nitelikli veri, çocuk/çalışan/sağlık/biyometri/konum verisi ayrımı var mı? |
| KVKK m.5/m.6 dayanağı | Veri sorumlusu tarafında işleme şartı ve açık rıza ihtiyacı belirlenmiş mi? |
| Aydınlatma | Aydınlatma metni ile DPA kapsamı ve VERBIS/envanter uyumlu mu? |
| Güvenlik | KVKK m.12 teknik/idari tedbirler, erişim, şifreleme, log, yetki, denetim ve olay müdahalesi yeterli mi? |
| Alt işleyen | Alt işleyen listesi, değişiklik bildirimi, itiraz mekanizması ve akış-aşağı yükümlülükleri var mı? |
| İhlal bildirimi | Veri işleyen, veri sorumlusuna gecikmeksizin ve Kurul 72 saat pratiğini destekleyecek hızda bildirim yapıyor mu? |
| Silme/iade/imha | Sözleşme bitiminde iade, silme, imha, yedek dönüş süresi ve tevsik düzenli mi? |
| Denetim | Bağımsız rapor, sertifika, audit hakkı, gizlilik ve maliyet dengesi makul mü? |
| Yurt dışına aktarım | KVKK m.9 mekanizması, standart sözleşme/taahhüt/yeterlilik/istisna, imza ve Kurum bildirimi süreci var mı? |
| Sorumluluk | Veri ihlali, idari para cezası, üçüncü kişi talepleri ve tazminat riskleri kabul edilebilir mi? |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 160 lines · 157 tokens per session scan A 005841aca6ac
dpa-review is a skill published in the GitHub repository ZekaiSuni/claude-for-legal-turkish (103 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 157 tokens to every session and 2,120 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…