Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zhou210712/claude-for-legal-ZH --skill dpa-reviewgit clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZHWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/dpa-review)<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/dpa-review"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/dpa-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/dpa-review"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/dpa-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00087 | $0.05126 |
| Opus 5 | $0.00044 | $0.02563 |
| Sonnet 5 | $0.00017 | $0.01025 |
| Haiku 4.5 | $0.00009 | $0.00513 |
Grade A, and why
dpa-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 240 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/dpa-review
- 加载
~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md→ DPA 操作手册。如为占位符,停止并提示设置。 - 获取 DPA。确定方向:我们是受托处理者(客户发来DPA)还是处理者(审供应商的DPA)?不明确时询问。
- 执行以下工作流——逐条对照相应的操作手册行。
- 执行个人信息处理规则一致性检查。
- 输出:带修订标记的审查备忘录。按内部格式保存。
/privacy-legal:dpa-review 客户dpa.pdf
DPA 审查(数据处理协议审查)
事项上下文
事项上下文。 检查实践级 CLAUDE.md 中的 ## 事项工作区。如果 已启用 为 ✗(法务用户的默认值),跳过本段——技能使用实践级上下文,事项机制不可见。如果已启用且无活动事项,询问:"这是哪个事项?运行 /privacy-legal:matter-workspace switch <slug> 或说 实践级。"加载活动事项的 matter.md 获取事项特定上下文和覆盖项。将输出写入事项文件夹 ~/.claude/plugins/config/claude-for-legal/privacy-legal/matters/<matter-slug>/。除非 跨事项上下文 为 开启,否则绝不读取其他事项的文件。
目的
DPA 有两种形态,审查方向几乎完全相反。当客户发来他们的 DPA,我们在捍卫我们的运营灵活性。当我们给供应商发 DPA,我们在保护我们(及我们客户的)数据。两次审查都读同一份 ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md 操作手册,但从相反的行读取。
首先:哪个方向?
做任何事之前,先确定:
- 我们是受托处理者 → 客户向我们发送他们的 DPA → 读取
~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md→ "当我们是受托处理者时" 表(对应个保法第21条委托处理[法条原文]) - 我们是处理者 → 我们正向供应商发送 DPA(或审查他们的)→ 读取 "当我们是处理者时" 表
如果不清楚,询问。方向搞错将颠倒每项建议。
法域假设
本审查假定你的配置中指定的法域范围。隐私规则、响应期限和合法性基础因法域而异(个保法 vs. GDPR vs. 其他法域)。如果处理者、受托处理者或个人信息主体位于不同于配置的法域,本审查可能不直接适用。
加载关于本对方当事人/活动的先前上下文
审查前,检查输出文件夹中关于本对方当事人或处理活动的先前工作。读取 ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → ## 输出 获取输出文件夹路径。扫描:
- 先前的
use-case-triage结果 涵盖同一对方当事人/处理活动——分诊产生风险评级和条件,本 DPA 审查应遵守或明确偏离。 - 先前的
pia-generation输出 涵盖本对方当事人/处理活动——PIA 可能已标注需要 DPA 实施的风险缓解措施。 - 先前的
dpa-review输出 涵盖同一对方当事人——先前的 DPA 审查设定了关于什么可接受、什么被标注、什么已解决的预期。一份静默地与先前审查相矛盾的新审稿侵蚀对工作产品的信任。
如果找到先前的输出,在审查中引用:
"先前的分诊([日期])将本活动评为[风险等级],并以[X]为批准条件。本 DPA 审查与该发现一致。"——或—— "先前的分诊([日期])将本活动评为[风险等级]。本 DPA 审查偏离该发现因为[理由——新事实、不同范围、改变了图景的合同条款]。"
从上游继承严重程度作为底线,遵循 ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → ## 共享护栏 中的跨技能严重程度底线规则。被分诊评为🔴的处理活动不能在 DPA 审查中静默降级为🟢;任何降级均应说明和解释。
如果未找到先前的输出(新对方当事人/新活动),在审查中明确说明——"输出文件夹中无关于本对方当事人的先前分诊或PIA"——以便审核律师知道检查已执行。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 240 lines · 87 tokens per session scan A dd5882bbdbc6
dpa-review is a skill published in the GitHub repository zhou210712/claude-for-legal-ZH (212 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 87 tokens to every session and 5,126 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…