Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zgbrenner/agentcounsel --skill vendor-privacy-diligencegit clone --depth 1 https://github.com/zgbrenner/agentcounselWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zgbrenner/agentcounsel/vendor-privacy-diligence)<a href="https://agentmods.dev/skills/zgbrenner/agentcounsel/vendor-privacy-diligence"><img src="https://agentmods.dev/badge/skills/zgbrenner/agentcounsel/vendor-privacy-diligence/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zgbrenner/agentcounsel/vendor-privacy-diligence"><img src="https://agentmods.dev/badge/skills/zgbrenner/agentcounsel/vendor-privacy-diligence.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00086 | $0.03776 |
| Opus 5 | $0.00043 | $0.01888 |
| Sonnet 5 | $0.00017 | $0.00755 |
| Haiku 4.5 | $0.00009 | $0.00378 |
Grade A, and why
Vendor Privacy Diligence scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 158 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Vendor Privacy Diligence
Purpose
Produce a structured, attorney-ready privacy diligence read on a vendor, processor, or sub-processor before contract, at renewal, or when the vendor's role changes. The skill inventories what the vendor's own materials claim about its privacy posture, maps the data the vendor would touch against the client's stated requirements, builds a risk and gap table, drafts the follow-up questions the gaps demand, and packages contract-term asks for the attorney negotiating the DPA. It produces draft legal work product for attorney review — not legal advice and not a vendor approval.
This skill evaluates diligence materials, not the vendor's actual practices: every posture statement in the output is an attributed claim from a provided document, never a verified fact. The skill never concludes that a vendor is compliant, safe, or approved — engagement decisions belong to the client, on counsel's advice.
Use When
- Procurement or a business team proposes a new vendor or tool that will process personal data, and counsel wants a privacy read before contracting.
- A vendor's completed security or privacy questionnaire has come back and needs to be organized against the client's requirements.
- A vendor is being re-reviewed at renewal, after an incident, after an acquisition, or because its role or the data scope has expanded.
- A processor proposes a new sub-processor and the client's approval workflow requires a diligence pass.
- Counsel wants a follow-up question list and contract-term asks assembled before DPA negotiation begins.
- Diligence on a transaction surfaced a target's key vendors and the privacy posture of each needs a first-pass organization.
Required Inputs
- The vendor diligence materials — completed questionnaires, certification summaries or attestation reports, privacy notices, sub-processor lists, security summaries, data-flow descriptions, or the vendor's trust-center exports. Work only from what is provided; a vendor described from memory or reputation is not diligence.
- What the vendor will process — the data categories, data subject groups, and processing purposes, as stated by the user or the documents. If the data scope is unstated, flag
[CONFIRM: data scope]and treat scope-dependent findings as provisional. - The client's requirements baseline — internal vendor-privacy standards, a diligence checklist, or requirements stated inline by the user. If no baseline is provided, say so, organize the review around the gaps the materials themselves reveal, and flag every "requirement" framing as
[CONFIRM: client requirement]— do not invent a standard the client never adopted. - The engagement context — what the vendor is hired to do and the client's own role for this processing (controller, processor, or both). The same vendor answer can be fine for one role and a gap for the other.
- Optional: the draft contract or DPA, if one exists — reviewed here only to note where diligence findings should become negotiated terms; the document review itself belongs to
dpa-review. - Optional: the prior diligence file for renewals — so the output can record what changed.
- Optional: the practice group's
practice-profiles/privacy.mdif it has been populated and is loaded alongside this skill. If present, use its Standard Positions and Escalation Thresholds to benchmark vendor answers; if absent, proceed without profile benchmarking.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 158 lines · 86 tokens per session scan A 6c9465ee293d
Vendor Privacy Diligence is a skill published in the GitHub repository zgbrenner/agentcounsel (19 stars, last pushed 1mo ago), licensed MIT. It adds 86 tokens to every session and 3,776 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
gdpr-data-handling-note
Drafts a plain-language data handling notice for a journalistic or media production project that involves collecting, storing, or processing personal data — structured to meet GDPR transparency requirements while remaining understandable to non-lawyers.
gdpr-note-writer
Drafts a GDPR compliance note for a specific piece of journalistic content or data collection activity — documenting the lawful basis for processing personal data, what data is held, how long it is retained, and who has access.
implementing-gdpr-data-protection-controls
The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's comprehensive data protection law governing the collection, processing, storage, and transfer of personal data. This skill cover.
gdpr-privacy
Use when producing the GDPR artifacts a product publishes or hands over: a privacy policy true to what it processes, a cookie/consent banner, a lawful basis per purpose, an Art. 28 DPA, an SCC transfer mechanism, or a DSAR flow. Drafts for counsel review. NOT internal retention rules (that is data-policy), NOT…
gdpr-expert
Expert in GDPR compliance, data protection, privacy by design, consent management, DPO responsibilities, and EU data regulations. Use when the user mentions privacy, data protection, compliance, consent, a DPO, or eu regulation, or when the task involves GDPR Fundamentals, Key Principles, Data Subject Rights, or…
legal-risk-checker
Reviews a story brief, draft article, or broadcast script and flags potential legal risks — including defamation, privacy, contempt of court, and data protection — so you know what to check before publication.