pia-generation

pia-generation is a skill for Claude Code from zhou210712/claude-for-legal-ZH. It costs 85 tokens per session (4,555 once invoked), scanned A, original, Apache-2.0.

A privacy impact assessment (PIA) is a structured review of how a new feature, product, or activity uses personal information. It records what data is used, why, for how long, who can access it, and what could go wrong.

In plain words
What is it for?
Use it to assess new personal-information processing activities and produce an internal PIA for legal or privacy review.
Why use it?
It helps product teams identify privacy risks and decide whether a formal assessment is needed before work proceeds. It also records required safeguards, owners, and approvals.

Skill for Claude Code

Written for Claude Code: argument-hint in frontmatter. Also seen: reads .claude/ paths; mentions CLAUDE.md.

Part of the privacy-legal plugin — 3 skills shipped together

Good fit Use it to assess new personal-information processing activities and produce an internal PIA for legal or privacy review.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/zhou210712/claude-for-legal-zh/pia-generation
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add zhou210712/claude-for-legal-ZH --skill pia-generation
Clone the repo
git clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZH

Made for: Claude Code.

Or install privacy-legal, the plugin that ships this one along with the rest of its 3 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for pia-generation

README.md
[![agentmods](https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/pia-generation/github.svg)](https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/pia-generation)
Your own site
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/pia-generation"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/pia-generation/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for pia-generation

Your own site · 80×15
<a href="https://agentmods.dev/skills/zhou210712/claude-for-legal-zh/pia-generation"><img src="https://agentmods.dev/badge/skills/zhou210712/claude-for-legal-zh/pia-generation.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 85 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,555 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00085 $0.04555
Opus 5 $0.00043 $0.02278
Sonnet 5 $0.00017 $0.00911
Haiku 4.5 $0.00009 $0.00456

Measured 9d ago against content hash fb9a5850cef1, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

pia-generation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

privacy-legal/skills/pia-generation/SKILL.md · 281 lines

How it starts

The opening of the file, as written. The whole thing — 281 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/pia-generation

  1. 加载 ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md → PIA 内部规范(触发标准、结构、深度、审批)。
  2. 执行以下工作流。
  3. 检查:是否确实需要 PIA?(内部触发标准 + 检索各适用制度的法定评估触发条件——引用主源,核实时效。)
  4. 录入:向产品团队提问。可抽取已提供的 PRD 信息。
  5. 按内部格式撰写 PIA。包含个人信息处理规则一致性检查。
  6. 输出附条件清单和指定负责人。路由审批。
/privacy-legal:pia-generation "位置共享功能"
/privacy-legal:pia-generation
PRD: [网盘链接]

个人信息保护影响评估生成

事项上下文

事项上下文。 检查实践级 CLAUDE.md 中的 ## 事项工作区。如果 已启用(法务用户的默认值),跳过本段——技能使用实践级上下文,事项机制不可见。如果已启用且无活动事项,询问:"这是哪个事项?运行 /privacy-legal:matter-workspace switch <slug> 或说 实践级。"加载活动事项的 matter.md 获取事项特定上下文和覆盖项。将输出写入事项文件夹 ~/.claude/plugins/config/claude-for-legal/privacy-legal/matters/<matter-slug>/。除非 跨事项上下文开启,否则绝不读取其他事项的文件。


目的地检查

在生成输出前,检查输出目的地。如果用户指定了目的地(渠道、分发列表、对方当事人、"所有人"),询问是否在保密圈内。公共渠道、全公司列表、对方当事人/对方律师、供应商和客户(就工作成果而言)会放弃保护。当目的地疑似在圈外时,标示并提供 (a) 仅供法务的保密版本,(b) 供更广泛渠道的净化版本,或 (c) 两者——不要默默加上保密抬头然后帮助粘贴到该抬头无法保护的地方。参见本插件 CLAUDE.md 中的 ## 共享护栏 → 目的地检查

目的

PIA 是与产品团队的对话,被记录下来。它问:什么数据,为什么,多久,谁看,什么可能出错。本技能结构化这场对话,并以本团队的格式写出输出——与冷启动访谈从种子 PIA 学习到的格式一致。

法域假设

本评估假定你的配置中指定的法域范围。隐私规则、评估触发条件和合法性基础因法域而异(个保法 vs. GDPR vs. 其他法域)。如果处理活动、处理者或受影响个人信息主体属于不同法域,本分析可能不直接适用。

加载关于本功能/活动的先前上下文

在撰写新 PIA 之前,检查输出文件夹中是否有关于同一功能、处理活动或对方当事人的先前工作。读取 ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md## 输出 获取路径。扫描:

  • 先前的 use-case-triage 结果涵盖本活动——分诊的风险评级、强制条件和标注的关注点是 PIA 的入口。
  • 先前的 pia-generation 输出涵盖相同或重叠的活动——新 PIA 应做好衔接(什么变了,什么延续)。一个对着同一活动静默产生不同结论的 PIA 是审核律师无法发现的矛盾。
  • 先前的 dpa-review 输出涵盖范围内的供应商——DPA 审查中的发现为 PIA 对下游处理者/跨境/保留风险的分析提供信息。

如果找到先前的输出,在 PIA 中引用:

"先前的分诊([日期])将本活动评为[风险等级],并要求[条件]。本 PIA 以此发现为基础——[哪些条件已满足,哪些仍待满足,哪些被重新界定]。"

如果先前存在 PIA:

"本 PIA 取代[日期]的 PIA,因为[原因——范围变化、新数据类别、供应商变更、法规变化]。延续的结论:[X]。修订的结论:[Y,因为Z]。"

从上游继承严重程度作为底线,遵循 ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md## 共享护栏 中的跨技能严重程度底线规则。被分诊评为高风险的活动,不能在 PIA 中静默变为低风险,除非说明理由和变化了什么。

如果未找到先前的输出,明确说明——"输出文件夹中无关于本活动的先前分诊或 PIA;此为冷启动"——以便审核律师知道检查已经执行过且未发现需要衔接的内容。

Read the full file on GitHub · 281 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 281 lines · 85 tokens per session scan A fb9a5850cef1

Subscribe to this mod's changes

pia-generation is a skill published in the GitHub repository zhou210712/claude-for-legal-ZH (212 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 85 tokens to every session and 4,555 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

specification-writing

A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.

wanshuiyin/Auto-claude-code-research-in-sleep · 49 tokens

regulatory-research-fallback

Fallback workflow for regulatory research when web extraction tools fail on government PDFs.

HKUDS/OpenSpace · 20 tokens

x-scorecard

OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.

x-cmd/x-cmd · 57 tokens

gesellschaftsrechtliche-satzungen-agb

Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.

Klotzkette/claude-fuer-deutsches-recht · 69 tokens

memstack-business-gdpr

Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…

cwinvestments/memstack · 121 tokens

nda-review

Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…

LegalQuants/lq-ai · 79 tokens