Top Agent Skills
25837 skills
Nist Pf Control
Implement the NIST Privacy Framework CONTROL function covering CT.DM data management, CT.DP data processing policies and procedures, and CT.PO disassociated processing. Provides technical control architectures, data management workflows, and de-identification implementation guidance.
228 · bundle
Nist Pf Protect
Implement the NIST Privacy Framework PROTECT function covering PR.AC access control, PR.DS data security, and PR.PO protective policies. Provides technical control implementation guidance, encryption standards, access management architectures, and security-privacy integration patterns.
228 · bundle
Pia Health Data
Conducts Privacy Impact Assessment for health data processing under GDPR Article 9, HIPAA, and sector-specific health privacy regulations. Covers special category data safeguards, clinical research data, patient portals, health wearables, genetic data, and cross-border health data transfers. Keywords: health data PIA, DPIA, Article 9, HIPAA, special category data, clinical research, patient privacy, genetic data.
228 · bundle
Coppa Compliance
Implements Children's Online Privacy Protection Act (COPPA) compliance under 16 CFR Part 312. Covers verifiable parental consent methods including signed forms, credit card verification, government ID, knowledge-based authentication, and video call. Includes FTC safe harbor programs and enforcement actions. Keywords: COPPA, FTC, children, parental consent, safe harbor, verifiable consent.
228 · bundle
Data Portability
Executes GDPR Article 20 data portability requests, covering machine-readable format requirements (JSON, CSV, XML), direct controller-to-controller transfer mechanisms, and scope limitations to data provided by the subject on consent or contract basis. Activate for portability, data export, Art. 20, data transfer queries.
228 · bundle
Health Data Dpia
Guides DPIA for health and medical data processing covering Art. 9(2)(h)-(j) exemptions, HIPAA crosswalk for transatlantic operations, clinical trial data protection under EU CTR 536/2014, and genetic data specifics under Art. 9(1). Activate for healthcare systems, clinical research, health apps, or medical device data. Keywords: health data, DPIA, Art. 9, clinical trial, genetic data, HIPAA, medical records, special category.
228 · bundle
Transfer Records
Guides maintenance of cross-border transfer registers, audit trails, and compliance documentation under GDPR Art. 30 and Art. 46, EDPB record-keeping guidance, and supervisory authority expectations. Keywords: transfer register, audit trail, Art. 30, Art. 46, documentation, compliance records.
228 · bundle
Vcdpa Compliance
Virginia Consumer Data Protection Act (VCDPA) compliance implementation. Covers 5 consumer rights, controller obligations, processor requirements, opt-in for sensitive data, data protection impact assessments, AG enforcement, and cure period provisions. Effective January 1, 2023.
228 · bundle
AI Data Retention
Manages AI model retention and machine unlearning requirements. Covers training data deletion verification, model versioning for compliance, machine unlearning techniques (SISA, gradient-based), and retraining triggers. Keywords: AI retention, machine unlearning, model versioning, training data deletion, retraining, storage limitation.
228 · bundle
Breach Simulation
Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities. Covers scenario creation with realistic inject timelines, participant role assignment, communication testing across internal and external channels, decision-point evaluation, and after-action report generation. Keywords: tabletop exercise, breach simulation, incident response testing, scenario design, after-action report.
228 · bundle
Connecticut Ctdpa
Connecticut Data Privacy Act (CTDPA) compliance. Covers consumer rights, controller obligations, dark pattern prohibition, loyalty program exemption, universal opt-out requirement effective January 2025, sensitive data consent, and AG enforcement. Effective July 1, 2023.
228 · bundle
Cpra Sensitive Pi
CPRA §1798.121 sensitive personal information restrictions and compliance. Covers all 9 sensitive PI categories including SSN, precise geolocation, racial/ethnic origin, biometric, genetic, health, and sex life data. Right to limit use/disclosure, permitted purposes, and implementation.
228 · bundle
Gdpr Gap Analysis
Guides systematic assessment of current state versus GDPR requirements across all chapters with prioritised remediation matrix. Activate when starting compliance programmes or conducting periodic reassessment. Keywords: gap analysis, compliance assessment, remediation matrix, GDPR readiness.
228 · bundle
Ropa Dpia Linkage
Links RoPA entries to Data Protection Impact Assessments and lawful basis assessments. Covers cross-reference systems, dependency tracking, and update cascade triggers between RoPA, DPIA register, and lawful basis documentation. Activate for RoPA-DPIA link, cross-reference, dependency tracking, impact assessment linkage, cascade updates.
228 · bundle
Breach Remediation
Conducts structured post-breach remediation using a lessons learned framework covering root cause remediation, control gap closure, policy updates, training modifications, monitoring enhancements, and regulatory follow-up. Provides a systematic approach to preventing breach recurrence and demonstrating accountability to supervisory authorities. Keywords: post-breach, remediation, lessons learned, root cause, control gap, policy update, training.
228 · bundle
Cnil Cookie Banner
Designing and implementing CNIL-compliant cookie consent banners for French and EU audiences. References the EUR 100M Google LLC fine and EUR 150M Meta Platforms fine for non-compliant cookie practices. Covers equal prominence, reject-all buttons, cookie walls prohibition, and 6-month reconsent cycles.
228 · bundle
Consent Withdrawal
Implementation guide for GDPR Article 7(3) consent withdrawal mechanisms. Covers the equal ease requirement ensuring withdrawal is as easy as giving consent, one-click withdrawal implementation, cascading effects on downstream processing, third-party notification workflows, and technical architecture for real-time consent revocation.
228 · bundle
Eu Code Of Conduct
Guides EU Code of Conduct adherence under GDPR Articles 40-41 including EDPB approval requirements, monitoring body accreditation, code drafting, adherence declaration, compliance verification, and complaint handling. Covers sector-specific codes, transnational codes, and Art. 40(3) approval by supervisory authorities. Keywords: code of conduct, Article 40, Article 41, EDPB, monitoring body, adherence.
228 · bundle
Hitech Act Privacy
Implements HITECH Act privacy and security requirements including breach notification expansion, four-tier penalty structure, state attorney general enforcement authority, EHR meaningful use privacy conditions, and business associate direct liability. Keywords: HITECH Act, breach notification, penalty tiers, state AG enforcement, meaningful use, EHR privacy.
228 · bundle
Personal Data Test
Classifies personal vs non-personal data per GDPR Art. 4(1) definition test with decision tree for borderline cases. References Breyer v Germany CJEU C-582/14 dynamic IP ruling and WP29 Opinion 4/2007. Keywords: personal data, GDPR Art 4, data classification, Breyer ruling, identifiability test, PII.
228 · bundle
Pia Review Cadence
Guides the periodic DPIA review lifecycle including trigger identification for regulatory changes, new data categories, technology changes, and breach incidents. Covers version control, stakeholder sign-off procedures, and DPIA register management per Art. 35(11). Keywords: DPIA review, PIA update, review cadence, version control, Art. 35(11), periodic review, trigger events, stakeholder sign-off.
228 · bundle
Ropa 250 Exemption
Assesses the GDPR Article 30(5) exemption for organisations under 250 employees. Covers the three exception conditions that negate the exemption: non-occasional processing, risk to data subject rights, and special category data processing. Activate for Art. 30(5), 250 employee exemption, small business RoPA, SME exemption, occasional processing.
228 · bundle
Scc Implementation
Guides implementation of EU Standard Contractual Clauses under Commission Decision 2021/914 across all four modules (C2C, C2P, P2P, P2C). Covers clause-by-clause completion, Annex I-III drafting, and SCC module selection. Keywords: SCCs, standard contractual clauses, module selection, data transfers, Annex completion.
228 · bundle
Soc2 Privacy Audit
Guides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent, collection, use/retention/disposal, access, disclosure, security, and quality. Includes evidence collection, control testing, and report review. Keywords: SOC 2, privacy criteria, TSP, AICPA, Type II, trust services.
228 · bundle
Us Privacy Federal
Maps the US federal privacy landscape including sectoral laws (HIPAA, GLBA, FERPA, COPPA, FCRA, ECPA, VPPA), FTC Section 5 enforcement, proposed federal comprehensive legislation, and the interaction between federal and state privacy regimes. Keywords: federal privacy, HIPAA, GLBA, FERPA, COPPA, FCRA, FTC, sectoral, preemption.
228 · bundle
Whistleblower Data
Implements data protection compliance for whistleblowing systems under EU Directive 2019/1937 and GDPR. Covers anonymous reporting channels, identity protection for whistleblowers and accused persons, retention limits, access restrictions, and retaliation prevention. Addresses national transpositions and DPA guidance. Keywords: whistleblower, Directive 2019/1937, anonymous reporting, identity protection, retaliation, retention, reporting channel.
228 · bundle
Adequacy Assessment
Guides assessment of third-country adequacy decisions under GDPR Article 45 for international data transfers. Covers the current EC adequacy decisions list, adequacy assessment criteria, partial adequacy handling, and monitoring of adequacy decision reviews. Keywords: adequacy decision, Article 45, third country, adequate protection, EC adequacy list.
228 · bundle
Byod Privacy Policy
Implements BYOD privacy compliance frameworks for personal device use in the workplace. Covers personal vs corporate data separation, MDM capabilities and limitations, employee consent requirements, data wiping boundaries, and monitoring restrictions on personal devices. Keywords: BYOD, mobile device management, MDM, personal device, data separation, containerisation, remote wipe, employee privacy.
228 · bundle
Consent Pref Center
Technical architecture guide for building a multi-purpose consent preference center. Covers per-purpose granularity, easy withdrawal under Article 7(3), version history, audit trails, and IAB Transparency and Consent Framework v2.2 integration. Includes database schema, API design, and UI component specifications.
228 · bundle
Double Opt In Email
Implementation guide for ePrivacy Directive compliant double opt-in email consent. Covers confirmation email workflow design, token expiration handling, record-keeping requirements, suppression list management, and integration with CAN-SPAM Act and CASL requirements for multi-jurisdiction compliance.
228 · bundle
Hipaa Breach Notify
Implements HIPAA breach notification requirements under 45 CFR §164.400-414. Covers individual notification within 60 days, HHS reporting thresholds (500+ immediate, under 500 annual), state attorney general notification, media notification for 500+ in a state, and breach risk assessment. Keywords: HIPAA breach notification, HHS reporting, OCR breach portal, individual notice, state attorney general.
228 · bundle
Hipaa Mobile Health
Addresses HIPAA compliance for mobile health (mHealth) applications, wearable devices, and remote patient monitoring. Covers OCR guidance on mobile device PHI, FDA-regulated mobile medical applications, FTC Health Breach Notification Rule for non-HIPAA apps, BYOD policies, and encryption requirements for ePHI on mobile platforms. Keywords: mHealth, mobile health, HIPAA mobile, wearable, remote monitoring, BYOD, mobile device management, app privacy.
228 · bundle
Hipaa Security Rule
Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. Covers access controls with unique user identification, emergency access procedures, automatic logoff, encryption, audit controls, integrity controls, and transmission security. Keywords: HIPAA Security Rule, ePHI, access controls, encryption, audit controls, technical safeguards.
228 · bundle
Marketing Objection
Manages the absolute right to object to direct marketing under GDPR Article 21(2)-(3), covering immediate cessation of all direct marketing processing, suppression list management, cross-channel enforcement, and profiling for marketing purposes. Activate for marketing opt-out, unsubscribe, Art. 21(2), direct marketing objection queries.
228 · bundle
Nist Pf Communicate
Implement the NIST Privacy Framework COMMUNICATE function covering CM.AW awareness raising and CM.PO communication policies. Provides transparency mechanisms, stakeholder engagement frameworks, privacy notice templates, and communication workflow guidance.
228 · bundle
Vendor Risk Scoring
Vendor privacy risk tiering methodology for processor management. Covers scoring factors including data volume, sensitivity, transfer locations, certifications, breach history, and control maturity with weighted risk calculation and tier assignment.
228 · bundle
AI Privacy Inference
Managing privacy risks from AI-driven inferences about individuals including derived data classification, profiling under GDPR Art. 22, inference accuracy obligations, and controlling automated personality/behaviour predictions. Keywords: AI inference, derived data, profiling, automated predictions, GDPR.
228 · bundle
AI Transparency Reqs
Implements AI transparency requirements under EU AI Act Arts. 13-14 and GDPR Arts. 13-14. Covers user notification of AI interaction, system capability disclosure, limitation documentation, and meaningful information about automated logic. Keywords: AI transparency, EU AI Act, GDPR notification, explainability, automated decision.
228 · bundle
Breach Subject Comms
Manages direct communication to affected data subjects following a personal data breach under GDPR Article 34 when the breach is likely to result in a high risk to their rights and freedoms. Covers the high risk threshold, required notification content per Art. 34(2), exemptions under Art. 34(3), and breach notification letter templates for five scenarios. Keywords: data subject notification, Article 34, high risk, breach communication, GDPR.
228 · bundle
Mui
Material-UI v7 component library patterns including sx prop styling, theme integration, responsive design, and MUI-specific hooks. Use when working with MUI components, styling with sx prop, theme customization, or MUI utilities.
16 · bundle
Jira
Use when the user mentions Jira issues (e.g., "PROJ-123"), asks about tickets, wants to create/view/update issues, check sprint status, or manage their Jira workflow. Triggers on keywords like "jira", "issue", "ticket", "sprint", "backlog", or issue key patterns.
16 · bundle
Gemini
Use when the user asks to run Gemini CLI for code review, plan review, or big context (>200k) processing. Ideal for comprehensive analysis requiring large context windows. Uses Gemini 3 Pro by default for state-of-the-art reasoning and coding.
16 · bundle
Shadcn
Complete shadcn/ui component management for adding, searching, fixing, styling, and composing UI in any React project. Use this skill whenever the user mentions shadcn, shadcn/ui, adding UI components, building forms or dashboards with Radix, working with component registries (@shadcn, @magicui, @tailark), or any task involving npx shadcn CLI commands. Also trigger when the user asks to fix styling issues, build a settings page, dashboard, or modal flow in a project that uses shadcn/ui — even if they don't say "shadcn" explicitly. This skill manages the full component lifecycle: search, add, view, diff, smart-merge upstream updates, and enforce critical rules for forms, composition, styling, and icons.
16 · bundle
Draw Io
draw.io diagram creation, editing, and review. Use for .drawio XML editing, PNG conversion, layout adjustment, and AWS icon usage.
16 · bundle
Gepetto
Creates detailed, sectionized implementation plans through research, stakeholder interviews, and multi-LLM review. Use when planning features that need thorough pre-implementation analysis.
16 · bundle
Paperjsx
Develop interactive PaperJS applications for visual drawing, animation, and vector graphics. Create canvas-based experiences with JavaScript and PaperJS framework.
16 · bundle
Gh Fix CI
Inspect failing GitHub Actions checks on PRs, fetch detailed logs, summarize failures, create a fix plan, and implement fixes after user approval. For external CI systems, report details only.
16 · bundle
Tweetclaw
Use TweetClaw through OpenClaw for X/Twitter automation workflows, including tweet search, reply search, follower export, media handling, monitors, webhooks, giveaway draws, and approval-gated posting.
16
Excalidraw
Use when working with *.excalidraw or *.excalidraw.json files, user mentions diagrams/flowcharts, or requests architecture visualization - delegates all Excalidraw operations to subagents to prevent context exhaustion from verbose JSON (single files: 4k-22k tokens, can exceed read limits)
16 · bundle
Marp Slide
Create professional Marp presentation slides with 7 beautiful themes (default, minimal, colorful, dark, gradient, tech, business). Use when users request slide creation, presentations, or Marp documents. Supports custom themes, image layouts, and "make it look good" requests with automatic quality improvements.
16 · bundle
Angular Ssr
Implement server-side rendering and hydration in Angular v20+ using @angular/ssr. Use for SSR setup, hydration strategies, prerendering static pages, and handling browser-only APIs. Triggers on SSR configuration, fixing hydration mismatches, prerendering routes, or making code SSR-compatible.
16 · bundle
Datadog CLI
Datadog CLI for searching logs, querying metrics, tracing requests, and managing dashboards. Use this when debugging production issues or working with Datadog observability.
16 · bundle
Idea Refine
Refines ideas iteratively. Refine ideas through structured divergent and convergent thinking. Use "idea-refine" or "ideate" to trigger.
16 · bundle
Angular HTTP
Implement HTTP data fetching in Angular v20+ using resource(), httpResource(), and HttpClient. Use for API calls, data loading with signals, request/response handling, and interceptors. Triggers on data fetching, API integration, loading states, error handling, or converting Observable-based HTTP to signal-based patterns.
16 · bundle
Domain Model
Grilling session that challenges your plan against the existing domain model, sharpens terminology, and updates documentation (CONTEXT.md, ADRs) inline as decisions crystallise. Use when user wants to stress-test a plan against their project's language and documented decisions.
16 · bundle
Plugin Forge
Create and manage Claude Code plugins with proper structure, manifests, and marketplace integration. Use when creating plugins for a marketplace, adding plugin components (commands, agents, hooks), bumping plugin versions, or working with plugin.json/marketplace.json manifests.
16 · bundle
Azure Storage
Design and operate Azure Storage services for durability, performance, and secure access. Use this skill when users ask about Blob, Files, Queues, Tables, or Data Lake storage patterns. Covers redundancy, tiering, access models, lifecycle policies, and compliance.
16
Canvas Design
Create museum-quality visual art through design philosophy. Generate original visual designs, posters, and artwork as PDFs or PNGs using sophisticated aesthetic movements and expert-level craftsmanship.
16 · bundle
Skill Creator
Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends Codex's capabilities with specialized knowledge, workflows, or tool integrations.
16 · bundle
Theme Factory
Toolkit for styling artifacts with a theme. These artifacts can be slides, docs, reportings, HTML landing pages, etc. There are 10 pre-set themes with colors/fonts that you can apply to any artifact that has been creating, or can generate a new theme on-the-fly.
16 · bundle