Action-oriented guidelines for privacy by design, data minimization, third-party audits, and modern browser privacy APIs.

Apache-2.0Auto-check passed

Install Privacy

skills CLI
$ npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install GoogleChrome/modern-web-guidance-src privacy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/GoogleChrome/modern-web-guidance-src.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills-src/privacy .claude/skills/privacy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
privacy
GitHub stars
1.1k
Token cost
~2.1k tokens
SKILL.md length
730 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

Action-oriented guidelines for privacy by design, data minimization, third-party audits, and modern browser privacy APIs.

  • Works in 7 steps: Privacy by Design and Data Minimization → Third-Party Audits and Mitigations → Cookie Deprecation and Partitioned Storage → …
  • Dealing with user data
  • SKILL.md covers 1. Privacy by Design and Data…, 2. Third-Party Audits and…, 3. Cookie Deprecation and… and 4. Privacy-Preserving Identity…, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Privacy is an agent skill from GoogleChrome/modern-web-guidance-src. Action-oriented guidelines for privacy by design, data minimization, third-party audits, and modern browser privacy APIs. Use this skill when dealing with user data, cookies, tracking, third-party scripts, or browser privacy APIs.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with JavaScript. The licence is Apache-2.0.

When your agent uses it

  • Dealing with user data
  • Third-party scripts
  • Browser privacy APIs

Example prompts

  • “/privacy”

Requirements

  • Node.js

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Privacy by Design and Data Minimization
  2. Third-Party Audits and Mitigations
  3. Cookie Deprecation and Partitioned Storage
  4. Privacy-Preserving Identity (FedCM)
  5. Fingerprinting & User-Agent Reduction
  6. Contextual Request Defenses with Fetch Metadata
  7. Fine-Grained Capability Control (Permissions API)

What it can do on your machine

Read from SKILL.md and the folder at commit c312847. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript, http and html).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Privacy loads about 2.1k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 730 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from GoogleChrome/modern-web-guidance-src at commit c312847, republished under its Apache-2.0 licence (© GoogleChrome). 730 words, ~2,136 tokens.

Download SKILL.mdSave it as .claude/skills/privacy/SKILL.md (or your agent's skills folder).
name
privacy
description
Action-oriented guidelines for privacy by design, data minimization, third-party audits, and modern browser privacy APIs. Use this skill when dealing with user data, cookies, tracking, third-party scripts, or browser privacy APIs.

Privacy

Web application architects and developers must treat privacy not as a compliance afterthought, but as a foundational architectural design requirement. Modern web platforms are shifting away from implicit tracking toward explicit, user-consented, browser-mediated identity and permission exchanges.

1. Privacy by Design and Data Minimization

Reducing the digital footprint to limit breach exposure and foster user trust.

DOs:
  • DO collect only adequate, relevant, and strictly necessary data for a stated purpose.
  • DO use lower granularity ("fuzzing") where precise data is not required (e.g., age brackets vs. exact birthdates).
  • DO offer guest checkouts to avoid forced account creation.
  • DO explain why data is collected inline, using aria-describedby to link inputs to their explanations.
  • DO use the Clear-Site-Data HTTP header upon logout to wipe client-side cookie caches and local storage.
DON'Ts:
  • DON'T collect data speculatively "just in case" it becomes useful.
  • DON'T rely on dark patterns or pre-checked opt-ins to force consent.
Code Examples:
Clear-Site-Data (HTTP)

Send this header on the page after logout confirmation.

http
Clear-Site-Data: "cache", "cookies", "storage"
Inline Transparency (HTML)
html
<div>
  <label for="email">Email address*</label>
  <input id="email" type="email" name="email" required aria-describedby="whyemail">
  <a href="#whyemail">Why do we need this?</a>
  
  <aside id="whyemail">
    We need this email to send password resets. We will not use it for marketing unless you opt-in.
  </aside>
</div>

2. Third-Party Audits and Mitigations

Limiting leakage introduced by external scripts, embeds, and tracking pixels.

DOs:
  • DO audit third parties technically using DevTools (Network panel) and HAR logs.
  • DO use the Façade Pattern (Lazy Loading) to load static thumbnails first, only loading heavy widget iframes upon user click.
  • DO replace third-party social buttons with static HTML sharing links (e.g., zero tracking SDKs).
  • DO set strict HTTP Referrer policies (strict-origin-when-cross-origin or no-referrer) to prevent leaking sensitive URL query parameters.
  • DO use rigid Permissions-Policy to lock down powerful APIs (geolocation, camera) globally or for subframes.
  • DO use Content-Security-Policy-Report-Only for continuous automated audits of where third-party scripts are attempting to send data.
DON'Ts:
  • DON'T use default tracking SDKs if a static hyperlink suffices.
Code Examples:
Referrer-Policy and Permissions-Policy (HTTP)
http
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: accelerometer=(), camera=(), fullscreen=*

Architecting for a web without unpartitioned third-party cookies.

DOs:
  • DO use CHIPS (Cookies Having Independent Partitioned State) by appending the Partitioned attribute for 1:1 embeds that do not share state across top-level sites.
  • DO use the Storage Access API (SAA) when cross-site state sharing is functionally critical (such as SSO portals).
  • DO trigger SAA permission requests (requestStorageAccess()) via direct user interaction (click/keypress).
DON'Ts:
  • DON'T rely on unpartitioned SameSite=None cookies as they are being systematically blocked by modern browser engines.
Code Examples:
http
Set-Cookie: session_id=abc123; SameSite=None; Secure; Path=/; Partitioned; HttpOnly
Storage Access API (JavaScript)
javascript
document.getElementById('login-btn').addEventListener('click', async () => {
  try {
    const hasAccess = await document.hasStorageAccess();
    if (!hasAccess) {
      await document.requestStorageAccess();
    }
    // Access granted: unpartitioned cookies are now attached to fetch()
  } catch (err) {
    console.error('Storage access denied', err);
  }
});
Third-Party State Matrix
MechanismScopeRequires InteractionUse Case
CHIPS1:1 PartitionedNoEmbeds (Maps, Widgets)
Storage Access API (SAA)Cross-siteYesSSO Portals, Analytics
FedCMIdentity FederationYes"Sign In with..."

Heuristic Rule: Use CHIPS for isolated widgets (un-shared state), and SAA for shared identity state requiring explicit user consent.

Show full SKILL.md (293 more words)Show less

4. Privacy-Preserving Identity (FedCM)

Moving from opaque navigational redirects to explicit native UI-mediated federation.

DOs:
  • DO use the Federated Credential Management API (FedCM) to mediate "Sign-In" flows natively, preventing IdP tracking of Relying Parties prior to user consent.
  • DO verify the FedCM-returned un-falsifiable token on your backend.
DON'Ts:
  • DON'T bounce users through opaque redirect URL chains if FedCM can fulfill the use-case natively.
Code Examples:
FedCM Sign-In (JavaScript)
javascript
try {
  const credential = await navigator.credentials.get({
    identity: {
      providers: [{
        configURL: "https://idp.example/fedcm.json",
        clientId: "rp-client-id-123"
      }]
    }
  });
  authenticateWithBackend(credential.token);
} catch (error) {
  console.error("FedCM login failed", error);
}

5. Fingerprinting & User-Agent Reduction

Shifting from passive device broadcasting to explicit feature inspection.

DOs:
  • DO use Feature Detection (e.g., 'createImageBitmap' in window) over User-Agent string parsing.
  • DO use User-Agent Client Hints (UA-CH) if you must differentiate environments.
  • DO explicitly request only the minimum required high-entropy hints using the Accept-CH header.
  • DO use the Vary header (e.g., Vary: Sec-CH-UA-Platform) if your server caches vary based on UA-CH.
DON'Ts:
  • DON'T parse navigator.userAgent for non-critical logic.
  • DON'T request a high volume of high-entropy hints simultaneously (interpretable as malicious fingerprinting).
Code Examples:
Feature Detection vs Sniffing (JavaScript)
javascript
// AVOID: if (navigator.userAgent.includes("Chrome")) ...
if ('createImageBitmap' in window) {
  // Use modern API
}

6. Contextual Request Defenses with Fetch Metadata

Using unforgeable headers to reject unauthorized cross-origin requests server-side.

DOs:
  • DO inspect Sec-Fetch-Site, Sec-Fetch-Mode, and Sec-Fetch-Dest headers before processing state-changing requests.
  • DO implement a Resource Isolation Policy (middleware) to automatically reject cross-site calls not intended as simple navigations.
DON'Ts:
  • DON'T process state-changing requests if the origin relationship (Sec-Fetch-Site) is cross-site and the mode is not navigate.
Code Examples:
Resource Isolation Middleware (Express / Node.js)
javascript
app.use((req, res, next) => {
  const site = req.get('Sec-Fetch-Site');
  const mode = req.get('Sec-Fetch-Mode');

  if (!site) return next(); // Fallback for legacy browsers

  if (site === 'same-origin' || site === 'same-site') return next();

  // Allow standard outside user navigations (GET link clicks)
  if (site === 'cross-site' && mode === 'navigate' && req.method === 'GET') {
    return next();
  }

  res.status(403).json({ error: 'Cross-origin request forbidden' });
});

7. Fine-Grained Capability Control (Permissions API)

Querying capabilities before hitting users with automatic prompts.

DOs:
  • DO query navigator.permissions.query() before requesting access to powerful APIs (geolocation, camera).
  • DO present polite explanations in UI explaining why the prompt exists before triggering the browser's native blocking prompt.
DON'Ts:
  • DON'T trigger browser native prompts automatically on page load without context.
Code Examples:
Query Permission Status (JavaScript)
javascript
navigator.permissions.query({ name: 'geolocation' }).then((result) => {
  if (result.state === 'granted') {
    loadMap();
  } else if (result.state === 'prompt') {
    showPolitePermissionExplanation(); // trigger requestStorageAccess upon button click
  }
});

© GoogleChrome, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills-src/privacy of GoogleChrome/modern-web-guidance-src.

Open the folder on GitHubat commit c312847

Compare with similar skills

Privacy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Privacy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Privacy this skillGoogleChrome/modern-web-guidance-src1.1k—~2.1kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Tailwindcss Developmentanonaddy/anonaddy4.9k10 repos~865Automated safety check: PassMIT
Figma use_figma Plugin API Ruleswarpdotdev/warp65k4 repos~4.4kAutomated safety check: PassAGPL-3.0
GSAP Core Animationgreensock/gsap-skills16k4 repos~3.7kAutomated safety check: PassMIT
JavaScript Concept Fact Checkerleonardomso/33-js-concepts67k1 repos~5kAutomated safety check: PassMIT

Similar skills

  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Tailwindcss Development

    anonaddy/anonaddy

    Always invoke when the user's message includes 'tailwind' in any form.

    4.9k GitHub starsUsed in 10 repos~865 tokens
    Frontend & DesignAuto-check passed
  • Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.

    65k GitHub starsUsed in 4 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • GSAP Core Animation

    greensock/gsap-skills

    Covers the GSAP core API for tweens, easing, staggers, defaults and matchMedia, and when to choose GSAP over CSS animations or other JavaScript animation libraries.

    16k GitHub starsUsed in 4 repos~3.7k tokens
    Frontend & DesignAuto-check passed
  • JavaScript Concept Fact Checker

    leonardomso/33-js-concepts

    Verifies the technical accuracy of JavaScript concept pages by checking code examples, MDN and ECMAScript claims and external links through a five-phase method.

    67k GitHub starsUsed in 1 repo~5k tokens
    Writing & ContentAuto-check passed
  • Scroll World Landing Page

    oso95/scroll-world

    Builds a scroll-driven landing page where a pre-rendered camera flies through connected AI-generated scenes, using Higgsfield for stills and video clips.

    9.7k GitHub starsUsed in 1 repo~12k tokens
    Frontend & DesignAuto-check: notes

More from GoogleChrome/modern-web-guidance-src

All 14 skills in this repo
  • Nightly Eval Investigation

    GoogleChrome/modern-web-guidance-src

    Downloads and analyzes the latest three distinct nightly evaluation runs (Claude Code, Codex CLI, and Jetski CLI) from the GCS remote dashboard to identify and flag unhealthy or low-performing tasks…

    1.1k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Chrome Extensions

    GoogleChrome/modern-web-guidance-src

    Build and publish Chrome Extensions using Manifest V3 best practices.

    1.1k GitHub stars~6.6k tokensUpdated today
    Auto-check: notes
  • Coherence Auditor

    GoogleChrome/modern-web-guidance-src

    Run a document coherence, link integrity, and git repository status audit across repository markdown files using a dedicated subagent.

    1.1k GitHub stars~901 tokensUpdated today
    Auto-check passed
  • Project Coding Standards

    GoogleChrome/modern-web-guidance-src

    Coding style, architectural conventions, and PR review standards for the modern-web-guidance-src (guidance) repository.

    1.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Project Discipline Guides

    GoogleChrome/modern-web-guidance-src

    Workflow for refactoring discipline-level guides (e.g., JavaScript, CSS) to remove "Common Knowledge" by generating and comparing against model-specific "Knowledge Mirrors".

    1.1k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Project Evals

    GoogleChrome/modern-web-guidance-src

    Best practices for creating expectations and grader files to evaluate guidance quality.

    1.1k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Works with

Questions about Privacy

What does Privacy do?

Action-oriented guidelines for privacy by design, data minimization, third-party audits, and modern browser privacy APIs. Privacy is an agent skill from GoogleChrome/modern-web-guidance-src. Action-oriented guidelines for privacy by design, data minimization, third-party audits, and modern browser privacy APIs.

When should I use Privacy?

Privacy fits situations like: dealing with user data; third-party scripts; browser privacy APIs.

How do I install Privacy in Claude Code?

Run `npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a claude-code`. Or copy the skill folder (skills-src/privacy in GoogleChrome/modern-web-guidance-src) into .claude/skills/privacy in your project. Claude Code loads it when a task matches its description.

How do I install Privacy in Codex?

Run `npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a codex`. Or copy the skill folder (skills-src/privacy in GoogleChrome/modern-web-guidance-src) into .agents/skills/privacy in your project. Codex loads it when a task matches its description.

Can I use Privacy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add GoogleChrome/modern-web-guidance-src --skill privacy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy, .gemini/skills/privacy, .github/skills/privacy and .opencode/skills/privacy in your project.

What does Privacy need to run?

SKILL.md names no scripts, command-line tools or credentials: Privacy is instructions for the agent only. Our summary lists: Node.js.

Does Privacy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Privacy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Privacy use?

Privacy is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Privacy use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Privacy?

Skills that share tags, products or a category with Privacy: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars), Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars) and GSAP Core Animation (greensock/gsap-skills, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Privacy?

GoogleChrome (a GitHub organization) maintains it in GoogleChrome/modern-web-guidance-src, which has 1,134 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 7, 2026.

Source: GoogleChrome/modern-web-guidance-src on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.