Install the "data-breach-response" agent skill from https://github.com/borghei/Claude-Skills/tree/main/legal/data-breach-response into .claude/skills/data-breach-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-breach-response", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add borghei/Claude-Skills --skill data-breach-response -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "data-breach-response" agent skill from https://github.com/borghei/Claude-Skills/tree/main/legal/data-breach-response into .agents/skills/data-breach-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-breach-response", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add borghei/Claude-Skills --skill data-breach-response -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "data-breach-response" agent skill from https://github.com/borghei/Claude-Skills/tree/main/legal/data-breach-response into .cursor/skills/data-breach-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-breach-response", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add borghei/Claude-Skills --skill data-breach-response -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "data-breach-response" agent skill from https://github.com/borghei/Claude-Skills/tree/main/legal/data-breach-response into .gemini/skills/data-breach-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-breach-response", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add borghei/Claude-Skills --skill data-breach-response -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "data-breach-response" agent skill from https://github.com/borghei/Claude-Skills/tree/main/legal/data-breach-response into .github/skills/data-breach-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-breach-response", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add borghei/Claude-Skills --skill data-breach-response -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "data-breach-response" agent skill from https://github.com/borghei/Claude-Skills/tree/main/legal/data-breach-response into .opencode/skills/data-breach-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-breach-response", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
data-breach-response
GitHub stars
881
Token cost
~4k tokens
SKILL.md length
1,402 words
Files
5 (incl. scripts, references)
Skills in repo
349
Repo updated
First seen
Licence
MIT
At a glance
Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking.
Breach assessment and response
SKILL.md covers Table of Contents, Clarify First, Tools and Reference Guides, plus 8 more sections
Runs Python scripts from its folder; calls python
Tasks that involve Security operations
What it does
Data Breach Response is an agent skill from borghei/Claude-Skills. Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking. Use for breach assessment and response.
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/enisa_methodology.md`, `references/notification_obligations.md` and `scripts/breach_severity_calculator.py`).
It sits in Legal & Compliance, covering Security operations and Incident response. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.
When your agent uses it
Breach assessment and response
Tasks that involve Security operations
Tasks that involve Incident response
Example prompts
“/data-breach-response”
Requirements
Python 3
What it can do on your machine
Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Ships 2 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Data Breach Response loads about 4k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 42 tokens; SKILL.md has 1,402 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~42
When it runs· the whole SKILL.md, loaded when a task matches
~4k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~12k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Download SKILL.mdSave it as .claude/skills/data-breach-response/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
data-breach-response
description
Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking. Use for breach assessment and response.
⚠️ EXPERIMENTAL — This skill is provided for educational and informational purposes only. It does NOT constitute legal advice. All responsibility for usage rests with the user. Consult qualified legal professionals before acting on any output.
Data Breach Response
Incident response and legal compliance for personal data breaches under GDPR Art. 33/34, CCPA, HIPAA, NIS2, PCI DSS, and other regulations. Calculates breach severity, tracks notification deadlines, and manages response timelines.
Before assessing the breach, confirm these inputs. If any is unknown or vague, ASK — do not assume:
T0 — the moment of awareness — starts the 72h clock; every deadline and "time remaining" in the timeline is calculated from it
Your role: controller or processor — determines whether you notify the SA/data subjects (Art. 33/34) or only the controller (Art. 33(2))
Data categories, scale, and ease of identification — these are the DPC/EI inputs that drive the ENISA severity score and verdict (LOW/MEDIUM/HIGH/VERY HIGH)
Which regulations apply — GDPR, CCPA, HIPAA, PCI DSS, NIS2, AI Act — sets which notification deadlines and authorities the matrix produces
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the assessment.
Tools
Breach Severity Calculator
Calculates ENISA breach severity score from breach parameters. Determines notification obligations based on severity verdict.
NIS2 24-hour early warning and 72-hour notification
Completed vs. pending response actions
Time elapsed and time remaining per deadline
Reference Guides
ENISA Methodology
references/enisa_methodology.md
Complete ENISA breach severity methodology:
DPC (Data Processing Context) scoring 1-4
EI (Ease of Identification) scoring 0.25-1.00
CB (Circumstances of Breach) additive scoring
Formula: SE = (DPC x EI) + CB
Adjustments for encryption, pseudonymization, volume
EDPB case matching (18 reference cases)
Notification Obligations
references/notification_obligations.md
Multi-regulation notification requirements:
GDPR Art. 33 (SA within 72h) and Art. 34 (data subjects)
CCPA, HIPAA, PCI DSS, NIS2, state breach notification
Controller vs. Processor obligation matrix
Cross-border notification rules
AI Act Art. 62 serious incident reporting
Workflows
Workflow 1: Standard Breach Response
Step 1: Emergency check — is there <12h remaining on any deadline?
→ If yes, skip to Step 4 (emergency notification)
Step 2: Initialize breach timeline
→ python scripts/breach_timeline_tracker.py init --breach-id "BR-2026-001" \
--t0 "2026-04-10T08:00:00" --description "Description"
Step 3: Calculate severity
→ python scripts/breach_severity_calculator.py --dpc N --ei N \
--confidentiality N --integrity N --availability N [--malicious]
Step 4: Based on severity verdict, determine notifications
→ LOW (<2): Internal log only, no external notification
→ MEDIUM (2 to <3): Notify supervisory authority within 72h
→ HIGH (3 to <4): Notify SA + individual data subjects
→ VERY HIGH (>=4): Notify SA + data subjects + consider public notice
Step 5: Execute containment and record events
→ python scripts/breach_timeline_tracker.py event --timeline breach.json \
--action "Action taken" --category containment
Step 6: Monitor deadlines continuously
→ python scripts/breach_timeline_tracker.py deadlines --timeline breach.json
Step 7: Complete notification obligations and document
Workflow 2: Emergency Mode (<12h Remaining)
Step 1: Calculate severity immediately
→ python scripts/breach_severity_calculator.py --dpc N --ei N \
--confidentiality N --t0 "original-t0" --json
Step 2: If MEDIUM or higher, prepare phased notification
→ Art. 33(4) allows phased notification when full information unavailable
→ Initial notification: what is known + promise of update
→ Supplementary notification: full details when available
Step 3: File initial SA notification before deadline expires
Step 4: Initialize timeline for ongoing tracking
→ Continue gathering information for supplementary notification
Step 5: Document emergency timeline and decisions
Workflow 3: Processor Breach Notification
Step 1: Processor becomes aware of breach
→ T0 for processor = moment of awareness
Step 2: Processor must notify controller "without undue delay"
→ Check DPA for specific contractual deadline (24h/48h common)
Step 3: Controller's T0 starts when controller becomes aware
→ Controller's 72h clock starts at this point
Step 4: Controller assesses severity independently
→ python scripts/breach_severity_calculator.py (controller's assessment)
Step 5: Controller makes notification decisions
→ Processor provides information; controller decides on SA/subject notification
ENISA Severity Formula
SE = (DPC x EI) + CB
Component
Range
Description
DPC
1-4
Data Processing Context — nature and sensitivity of data
EI
0.25-1.0
Ease of Identification — how easily individuals can be identified
CB
-0.5 to +1.0
Circumstances of Breach — additive factors (malicious intent, volume, loss type)
Severity Verdicts
Score Range
Verdict
Notification Obligations
<2
LOW
Internal log only. No SA or subject notification required
2 to <3
MEDIUM
Notify supervisory authority within 72h (Art. 33)
3 to <4
HIGH
Notify SA within 72h + notify individual data subjects (Art. 34)
>=4
VERY HIGH
Notify SA + data subjects + consider public notice; crisis management
Notification Decision Matrix
Quick reference for notification obligations per regulation and severity.
Regulation
Authority Notification
Individual Notification
Trigger
GDPR Art. 33
SA within 72h
N/A
Unless unlikely to result in risk to rights/freedoms
GDPR Art. 34
N/A
Without undue delay
When likely to result in high risk
CCPA
State AG
Affected consumers
Unencrypted personal information compromised
HIPAA
HHS within 60 days
Affected individuals
Unsecured PHI; >500: notify media
PCI DSS
Card brands within 24h
Cardholders (via issuer)
Cardholder data compromised
NIS2 Art. 23
CSIRT within 24h (early warning), 72h (notification)
N/A
Significant incident
AI Act Art. 62
Market surveillance within 15 days
N/A
Serious incident involving AI system
Controller vs. Processor Obligations
Obligation
Controller
Processor
Notify supervisory authority
Yes (Art. 33)
No (notify controller only)
Notify data subjects
Yes (Art. 34)
No
Document all breaches
Yes (Art. 33(5))
Yes (assist controller)
Notify controller
N/A
Yes, without undue delay (Art. 33(2))
Conduct severity assessment
Yes
Assist (provide information)
Timeline starts (T0)
When controller becomes aware
When processor becomes aware
Troubleshooting
Problem
Possible Cause
Resolution
Severity score is borderline between MEDIUM and HIGH
Parameters are at threshold boundaries
Score conservatively — if near 3.0, treat as HIGH and notify data subjects; document the borderline analysis
72-hour deadline approaching with incomplete information
Complex breach requiring ongoing investigation
Use Art. 33(4) phased notification — notify SA with available information and supplement later
Processor discovered breach but delayed notifying controller
DPA contractual deadline may have been missed
Document the delay; assess whether processor's delay affected controller's ability to comply; review DPA terms
Cross-border breach — unclear which SA to notify
Multi-jurisdictional processing with unclear lead SA
Notify the SA of your main establishment (one-stop-shop); if unclear, notify the SA where most affected subjects reside
Breach involves encrypted data — unclear if notification needed
Encryption may lower severity or eliminate notification
If encryption was effective (strong algorithm, key not compromised), this may make notification unnecessary per Art. 34(3)(a); document the analysis
AI system involved in breach — unclear additional obligations
AI Act Art. 62 may apply alongside GDPR
Assess whether AI system is high-risk under AI Act; if serious incident, notify market surveillance authority within 15 days in addition to GDPR obligations
Show full SKILL.md (519 more words)Show less
Success Criteria
Breach severity calculated within 2 hours of awareness -- ENISA methodology applied with documented parameters and scoring rationale
SA notification filed within 72 hours of T0 -- for MEDIUM or higher severity breaches, phased notification used when full information unavailable
Data subject notification completed without undue delay -- for HIGH or higher severity breaches, clear communication of impact and protective measures
All response actions tracked with timestamps -- breach timeline maintained from T0 through closure with all events recorded
Cross-regulation obligations identified and met -- GDPR, CCPA, HIPAA, PCI DSS, NIS2, and AI Act obligations assessed and fulfilled per applicable law
Post-breach documentation complete -- internal breach log maintained per Art. 33(5) regardless of notification decision
Scope & Limitations
In Scope:
ENISA breach severity calculation with full parameter support
Filing notifications with supervisory authorities (document preparation only)
Insurance claim processing or coverage analysis
Law enforcement coordination
Public relations or crisis communications strategy
Forensic investigation methodology
Anti-Patterns
Delaying T0 determination to buy more time -- T0 is the moment the controller becomes "aware" of the breach, not when full details are known; deliberately delaying awareness to extend the 72-hour window is a compliance violation and will be treated as such by regulators
Defaulting to no notification without documented analysis -- every breach must be documented and assessed, even if the conclusion is that notification is not required; "we decided not to notify" without documented severity analysis is indefensible
Treating processor notification as controller notification -- processor notifying its own SA does not satisfy the controller's Art. 33 obligation; the controller must make its own independent notification decision and filing
Using encryption as an automatic notification exemption -- Art. 34(3)(a) exemption requires that the encrypted data was rendered unintelligible AND the encryption key was not compromised; weak encryption or compromised keys do not qualify
Ignoring AI Act obligations for AI-involved breaches -- if the breach involves a high-risk AI system, Art. 62 serious incident reporting (15 days to market surveillance authority) applies in addition to GDPR; these are separate obligations with different timelines
Tool Reference
breach_severity_calculator.py
Calculates ENISA breach severity score and determines notification obligations.
Data Breach Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Data Breach Response compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Data Breach Response this skillborghei/Claude-Skills
Runs a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server…
Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise…
Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response…
Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking. Data Breach Response is an agent skill from borghei/Claude-Skills. Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking.
When should I use Data Breach Response?
Data Breach Response fits situations like: breach assessment and response; tasks that involve Security operations; tasks that involve Incident response.
How do I install Data Breach Response in Claude Code?
Run `npx skills add borghei/Claude-Skills --skill data-breach-response -a claude-code`. Or copy the skill folder (legal/data-breach-response in borghei/Claude-Skills) into .claude/skills/data-breach-response in your project. Claude Code loads it when a task matches its description.
How do I install Data Breach Response in Codex?
Run `npx skills add borghei/Claude-Skills --skill data-breach-response -a codex`. Or copy the skill folder (legal/data-breach-response in borghei/Claude-Skills) into .agents/skills/data-breach-response in your project. Codex loads it when a task matches its description.
Can I use Data Breach Response in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill data-breach-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/data-breach-response, .gemini/skills/data-breach-response, .github/skills/data-breach-response and .opencode/skills/data-breach-response in your project.
What does Data Breach Response need to run?
Going by SKILL.md and its folder, Data Breach Response needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.
Does Data Breach Response access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Data Breach Response safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
What licence does Data Breach Response use?
Data Breach Response is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Data Breach Response use?
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.4k tokens, read only when the agent opens those files.
What are the alternatives to Data Breach Response?
Skills that share tags, products or a category with Data Breach Response: Hunting For Persistence Mechanisms In Windows (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Hunting For Webshell Activity (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Soar Playbook With Palo Alto Xsoar (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Conducting Cloud Incident Response (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Data Breach Response?
borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 881 GitHub stars. The repository holds 349 skills in this directory. The repository was last updated on October 7, 2026.
Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.