All skills
lassejlv avatar

/legal-policy-drafter

@f5b9ecd
by Lasselassejlv/skills50 stars
1

Draft, update, or audit legal-policy documents such as TERMS.md, PRIVACY.md, cookie notices, SaaS policies, app-store privacy text, and GDPR-friendly privacy disclosures from repository evidence. Use for legal policy work that requires inspecting product behavior, data flows, billing, auth, analytics, subprocessors, and missing business facts without inventing unsupported claims.

Use this Skill: https://skilld.dev/gh/lassejlv/skills/legal-policy-drafter

This session only. Nothing lands on disk.

referencesprovider-research.md

≈736 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Provider Research

Use this reference when the repository reveals third-party services that affect TERMS.md, PRIVACY.md, cookies, subprocessors, international transfers, or payment/refund wording.

Rule

Verify current official provider pages before naming a provider as a processor/subprocessor or making claims about privacy, DPAs, subprocessors, data location, retention, cookies, or AI training. Prefer official privacy pages, DPA pages, subprocessor pages, product docs, and security pages. Do not rely on package names alone.

Use Context7 for library/framework/API/CLI docs. Use web search for current provider legal/privacy/subprocessor/DPA pages.

Research Notes Format

Keep working notes like this before drafting:

| Provider | Evidence | Role | Data likely involved | Policy impact | Confidence |
| --- | --- | --- | --- | --- | --- |
| Stripe | package.json + official privacy/DPA URL | payment processor | billing/contact/payment metadata | Payments, retention, subprocessors, transfers | High |

Common Provider Categories

  • Payments: Stripe, Paddle, Lemon Squeezy, Chargebee, PayPal. Check checkout, invoices, tax records, subscription renewal, refund/cancellation flow, and payment processor wording.
  • Email: Resend, SendGrid, Mailgun, Postmark, AWS SES, SMTP. Check transactional email, marketing email, unsubscribe, message metadata, and provider role.
  • Authentication: Clerk, Auth0, Supabase Auth, Firebase Auth, Better Auth, OAuth providers. Check account identifiers, sessions, OAuth profile data, cookies, and security logs.
  • Analytics: PostHog, Plausible, Google Analytics, Vercel Analytics, Segment, Amplitude, Mixpanel. Check cookies/local storage, event data, consent, IP handling, and opt-out controls.
  • Error tracking/monitoring: Sentry, Bugsnag, Datadog, Logtail/Better Stack, Axiom. Check logs, stack traces, IP/device data, user IDs, retention, and masking.
  • Hosting/storage/database: Vercel, Cloudflare, AWS, GCP, Azure, Railway, Fly.io, Supabase, Neon, PlanetScale, R2, S3. Check hosting region, backups, logs, storage, transfers, and subprocessors.
  • AI providers: OpenAI, Anthropic, Google AI, Mistral, Groq, Replicate. Check prompts/files/outputs, model training settings, retention, abuse monitoring, and user-facing AI disclosures.
  • Support/customer messaging: Intercom, Crisp, Zendesk, Help Scout, Linear, GitHub Issues. Check support messages, contact details, attachments, and retention.
  • CDN/media: Cloudflare, Imgix, UploadThing, Cloudinary. Check IP logs, uploaded media, transformations, and retention.

Claims To Avoid Without Evidence

  • "We never share data."
  • "We are GDPR compliant."
  • "Data is encrypted at rest and in transit."
  • "We delete all data within X days."
  • "We host exclusively in the EU/US."
  • "We do not use cookies."
  • "AI providers never train on your data."
  • "We offer refunds" or "all sales are final."

Use TODO(confirm): instead.

Source: SKILL.md on GitHub

1 warning13d3 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The legal-policy-drafter skill is designed to generate evidence-based legal documents by analyzing a repository's codebase and external documentation. It includes robust instructions to prevent fabrication of facts and incorporates manual review steps, making it a safe tool for its intended purpose.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: MEDIUM · 1 issue

Signed by skilld at f5b9ecd. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 5 months ago

README badge

README badge for lassejlv/skills/legal-policy-drafter