Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add zhou210712/claude-for-legal-ZH --skill pia-generationgit clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZHWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/pia-generation)<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/pia-generation"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/pia-generation/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/pia-generation"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/pia-generation.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00085 | $0.04555 |
| Opus 5 | $0.00043 | $0.02278 |
| Sonnet 5 | $0.00017 | $0.00911 |
| Haiku 4.5 | $0.00009 | $0.00456 |
Grade A, and why
pia-generation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 281 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/pia-generation
- 加载
~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md→ PIA 内部规范(触发标准、结构、深度、审批)。 - 执行以下工作流。
- 检查:是否确实需要 PIA?(内部触发标准 + 检索各适用制度的法定评估触发条件——引用主源,核实时效。)
- 录入:向产品团队提问。可抽取已提供的 PRD 信息。
- 按内部格式撰写 PIA。包含个人信息处理规则一致性检查。
- 输出附条件清单和指定负责人。路由审批。
/privacy-legal:pia-generation "位置共享功能"
/privacy-legal:pia-generation
PRD: [网盘链接]
个人信息保护影响评估生成
事项上下文
事项上下文。 检查实践级 CLAUDE.md 中的 ## 事项工作区。如果 已启用 为 ✗(法务用户的默认值),跳过本段——技能使用实践级上下文,事项机制不可见。如果已启用且无活动事项,询问:"这是哪个事项?运行 /privacy-legal:matter-workspace switch <slug> 或说 实践级。"加载活动事项的 matter.md 获取事项特定上下文和覆盖项。将输出写入事项文件夹 ~/.claude/plugins/config/claude-for-legal/privacy-legal/matters/<matter-slug>/。除非 跨事项上下文 为 开启,否则绝不读取其他事项的文件。
目的地检查
在生成输出前,检查输出目的地。如果用户指定了目的地(渠道、分发列表、对方当事人、"所有人"),询问是否在保密圈内。公共渠道、全公司列表、对方当事人/对方律师、供应商和客户(就工作成果而言)会放弃保护。当目的地疑似在圈外时,标示并提供 (a) 仅供法务的保密版本,(b) 供更广泛渠道的净化版本,或 (c) 两者——不要默默加上保密抬头然后帮助粘贴到该抬头无法保护的地方。参见本插件 CLAUDE.md 中的 ## 共享护栏 → 目的地检查。
目的
PIA 是与产品团队的对话,被记录下来。它问:什么数据,为什么,多久,谁看,什么可能出错。本技能结构化这场对话,并以本团队的格式写出输出——与冷启动访谈从种子 PIA 学习到的格式一致。
法域假设
本评估假定你的配置中指定的法域范围。隐私规则、评估触发条件和合法性基础因法域而异(个保法 vs. GDPR vs. 其他法域)。如果处理活动、处理者或受影响个人信息主体属于不同法域,本分析可能不直接适用。
加载关于本功能/活动的先前上下文
在撰写新 PIA 之前,检查输出文件夹中是否有关于同一功能、处理活动或对方当事人的先前工作。读取 ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → ## 输出 获取路径。扫描:
- 先前的
use-case-triage结果涵盖本活动——分诊的风险评级、强制条件和标注的关注点是 PIA 的入口。 - 先前的
pia-generation输出涵盖相同或重叠的活动——新 PIA 应做好衔接(什么变了,什么延续)。一个对着同一活动静默产生不同结论的 PIA 是审核律师无法发现的矛盾。 - 先前的
dpa-review输出涵盖范围内的供应商——DPA 审查中的发现为 PIA 对下游处理者/跨境/保留风险的分析提供信息。
如果找到先前的输出,在 PIA 中引用:
"先前的分诊([日期])将本活动评为[风险等级],并要求[条件]。本 PIA 以此发现为基础——[哪些条件已满足,哪些仍待满足,哪些被重新界定]。"
如果先前存在 PIA:
"本 PIA 取代[日期]的 PIA,因为[原因——范围变化、新数据类别、供应商变更、法规变化]。延续的结论:[X]。修订的结论:[Y,因为Z]。"
从上游继承严重程度作为底线,遵循 ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → ## 共享护栏 中的跨技能严重程度底线规则。被分诊评为高风险的活动,不能在 PIA 中静默变为低风险,除非说明理由和变化了什么。
如果未找到先前的输出,明确说明——"输出文件夹中无关于本活动的先前分诊或 PIA;此为冷启动"——以便审核律师知道检查已经执行过且未发现需要衔接的内容。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 281 lines · 85 tokens per session scan A fb9a5850cef1
pia-generation is a skill published in the GitHub repository zhou210712/claude-for-legal-ZH (212 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 85 tokens to every session and 4,555 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
specification-writing
A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.
regulatory-research-fallback
Fallback workflow for regulatory research when web extraction tools fail on government PDFs.
x-scorecard
OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
gesellschaftsrechtliche-satzungen-agb
Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.
memstack-business-gdpr
Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…
nda-review
Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…