Agent skill

Vendor Privacy Policy First Pass

by LegalQuants in LegalQuants/lq-ai

A skill your agent uses when the user has a vendor's published privacy policy (URL, PDF, or pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted.

Apache-2.0Auto-check passedLegal & Compliance

Install Vendor Privacy Policy First Pass

skills CLI
$ npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LegalQuants/lq-ai vendor-privacy-policy-first-pass --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LegalQuants/lq-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vendor-privacy-policy-first-pass .claude/skills/vendor-privacy-policy-first-pass && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vendor-privacy-policy-first-pass
GitHub stars
150
Token cost
~4.3k tokens
SKILL.md length
1,578 words
Files
6
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user has a vendor's published privacy policy (URL, PDF, or pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted.

  • Works in 3 steps: Document orientation → Structured summary → Red-flag identification
  • The user has a vendors published privacy policy (URL
  • SKILL.md covers When this skill applies, Inputs, Workflow and Output, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vendor Privacy Policy First Pass is an agent skill from LegalQuants/lq-ai. Use when the user has a vendor's published privacy policy (URL, PDF, or pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted. Produces a short structured report covering what the policy says about key data practices (collection, use, sharing, retention, transfers, rights) plus identification of red flags that warrant escalation to deeper review. Explicitly a first pass, not a full privacy assessment, DPA negotiation, or compliance certification.

Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files (for example `examples/example_clean_policy.md`, `examples/example_red_flags.md` and `reference/policy_topics.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Open-source AI for legal teams. Bring your own keys, run it where you want, own your data. The licence is Apache-2.0.

When your agent uses it

  • The user has a vendors published privacy policy (URL
  • Pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted

Example prompts

  • “/vendor-privacy-policy-first-pass”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Document orientation
  2. Structured summary
  3. Red-flag identification

What it can do on your machine

Read from SKILL.md and the folder at commit 7ac94dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vendor Privacy Policy First Pass loads about 4.3k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 1,578 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LegalQuants/lq-ai at commit 7ac94dd, republished under its Apache-2.0 licence (© LegalQuants). 1,578 words, ~4,264 tokens.

Download SKILL.mdSave it as .claude/skills/vendor-privacy-policy-first-pass/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
vendor-privacy-policy-first-pass
description
Use when the user has a vendor's published privacy policy (URL, PDF, or pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted. Produces a short structured report covering what the policy says about key data practices (collection, use, sharing, retention, transfers, rights) plus identification of red flags that warrant escalation to deeper review. Explicitly a first pass, not a full privacy assessment, DPA negotiation, or compliance certification.
lq_ai.title
Vendor Privacy Policy First Pass
lq_ai.version
1.0.0
lq_ai.author
LegalQuants
lq_ai.tags
privacy, vendor, due-diligence, triage, gdpr, ccpa
lq_ai.jurisdiction
regime-aware
lq_ai.trigger_examples
review this privacy policy, first pass on this vendor's privacy policy, are there red flags in this privacy policy, summarize what this privacy policy says…
lq_ai.output_format
markdown
lq_ai.self_improvement
false

Vendor Privacy Policy First Pass

Conduct a fast triage assessment of a vendor's privacy policy to help the user decide whether deeper diligence is warranted before sharing data with the vendor. The output is a structured summary plus red-flag identification, not a full privacy assessment.

This skill is calibrated for the in-house counsel use case: a vendor has been proposed, the user has limited time, and the question is "does this policy contain anything that would change our decision to proceed, or does it look standard enough that we can move to DPA negotiation and security review?"

When this skill applies

Apply when the user provides a vendor's privacy policy (or what is presented as one) and asks for a quick assessment. Common triggers:

  • Vendor proposed during procurement; quick read needed before deeper review.
  • Vendor's published policy used as a baseline for DPA negotiation (the policy describes what the vendor says it does; the DPA captures what the vendor commits to do).
  • Periodic re-review of an existing vendor's updated privacy policy.
  • Pre-meeting prep before a vendor security/privacy review call.

Do not apply when:

  • The user wants a full privacy assessment. This skill is a first pass; full assessments are out of scope. Recommend a comprehensive privacy assessment performed by qualified privacy counsel, especially for high-sensitivity data flows.
  • The user wants DPA review. Use DPA Checklist Review for that. The privacy policy is the vendor's public representation; the DPA is the contractual commitment. They serve different purposes and warrant different reviews.
  • The user wants to evaluate the vendor's actual security practices. Privacy policies describe data practices, not security architecture. Security questionnaires, SOC 2 Type II reports, and penetration test summaries are the appropriate inputs for security review.
  • The document is something other than a privacy policy (cookie policy alone; terms of service; security exhibit; AUP). Privacy policies have a recognizable structure (data collection, use, sharing, retention, rights, contact). If the document doesn't have these elements, it isn't a privacy policy.
  • The user wants assistance drafting a privacy policy. Out of scope; recommend privacy counsel and a policy template appropriate to the user's jurisdiction and data practices.

Inputs

The skill requires the document. Optional inputs (vendor_context, applicable_regimes, data_to_share) refine the analysis:

  • vendor_context changes severity calibration. A privacy policy that allows broad data sharing is a red flag for a marketing automation vendor handling customer PII; the same policy may be standard for an analytics tool handling only aggregated metrics. Without vendor_context, the skill uses general calibration and notes the assumption.
  • applicable_regimes prioritizes regime-specific elements in the report. With applicable_regimes: gdpr, the skill checks for GDPR-required disclosures (Article 13/14 elements, transfer mechanisms, lawful basis); with ccpa, the skill checks for CCPA/CPRA-required disclosures (categories, sale/sharing, sensitive PI, rights). Without specification, the skill assesses against general commercial standards and notes regime-specific considerations as flags rather than findings.
  • data_to_share affects red-flag severity. ML training rights on aggregated metrics is different from ML training rights on user PII. SSN handling considerations matter only if SSNs are in scope.

When optional inputs are not provided, the skill uses default assumptions and notes them in the report.

Workflow

The workflow has three steps. Total elapsed time should be short — this is triage.

Step 1: Document orientation

Before substantive review:

  • Confirm the document is a privacy policy. The recognizable structure: a "what we collect" section, a "how we use it" section, a "who we share with" section, a "your rights" or "choices" section, a contact section. If these elements are absent, the document is something else.
  • Note the policy's effective date. Stale policies (over 18 months old without update) warrant a flag — privacy law has been evolving rapidly.
  • Note the vendor's stated jurisdiction(s) of operation, if disclosed.
  • Note any references to external documents (separate cookie policy, separate AI/ML policy, separate California addendum, separate California "Notice at Collection," GDPR addendum, regional supplement). The skill flags external references but does not fetch them.
  • Estimate the policy's length and density. Short policies (under 1,500 words) often have material omissions; very long policies (over 8,000 words) may bury important provisions.
Step 2: Structured summary

Produce a structured summary covering the standard topics. Use reference/policy_topics.md to ensure coverage. For each topic, note: what the policy says, in plain language; specific clause/section references where applicable; whether the policy's treatment is clear, ambiguous, or absent.

The topics are:

  1. What data is collected — categories, sources (direct from user, automatic via cookies/SDKs, third parties), and whether sensitive categories are included.
  2. Why data is used — stated purposes; legal basis (for GDPR-applicable contexts); whether secondary uses are disclosed.
  3. Who data is shared with — categories of recipients (service providers, affiliates, advertisers, partners, government, anyone via "sale" under CCPA), whether the vendor sells/shares per CCPA, sub-processor arrangements.
  4. Cross-border transfers — whether transfers occur, mechanisms (SCCs, adequacy, BCRs), and recipient countries if disclosed.
  5. Retention — stated retention periods or methodology.
  6. User rights and how to exercise them — access, deletion, correction, opt-out (sale/sharing under CCPA; processing under GDPR), portability, objection, automated-decision-making.
  7. Security — stated commitments (typically high-level; the policy is not a security statement).
  8. Children's data — whether the service is directed at children; COPPA/GDPR-K compliance disclosures.
  9. Contact and complaints — privacy contact information; complaint mechanisms; supervisory-authority disclosure for GDPR.
  10. AI / ML use of data — whether vendor uses customer data for AI/ML training, how, and whether opt-outs exist (the dominant 2025-2026 issue).
Show full SKILL.md (686 more words)Show less
Step 3: Red-flag identification

Walk through the red-flag list in reference/red_flags.md. For each red flag found, note:

  • What the policy says (with citation).
  • Why it's a red flag.
  • Severity (Critical / Material / Minor — using the same rubric tier-down as MSA Review for consistency, but calibrated to triage stakes).
  • What the user should do (e.g., "negotiate in DPA", "request specific contractual carve-out", "request clarification from vendor", "escalate to privacy counsel").

The red-flag categories include:

  • Data collection breadth — collecting categories of data unrelated to the service.
  • Use breadth — broad use rights including secondary uses.
  • Sharing practices — broad sharing with affiliates, advertisers, partners; vendor categorized as "selling" or "sharing" under CCPA when not expected.
  • AI / ML training rights — vendor uses customer data for ML training without opt-out.
  • Data retention — indefinite retention, unclear retention, retention beyond service necessity.
  • Cross-border transfers without mechanism disclosure.
  • Rights mechanism gaps — rights enumerated but no clear exercise mechanism, charges for rights requests, or rights subordinated to vendor's discretion.
  • Vague or boilerplate disclosures — privacy policy is generic and doesn't reflect the actual service.
  • Stale policy — last updated long ago.
  • Inconsistencies with vendor's marketing materials or DPA — privacy policy says one thing; vendor's other materials say another.

Output

Produce the report in markdown with this structure (deliberately short — triage):

markdown
# Vendor Privacy Policy First Pass: [Vendor / Document name]

**Vendor context:** [user-provided, or "not specified"]
**Applicable regimes considered:** [list, or "general commercial"]
**Data the user expects to share:** [user-provided, or "not specified"]
**Policy effective date:** [date from policy, or "not stated"]

## Bottom line

[Two to three sentences. Headline assessment: clean / standard / has notable concerns / has serious red flags. Recommendation: proceed to DPA / proceed with specific concerns flagged / escalate for deeper review / decline pending substantial vendor changes.]

## Structured summary

[For each of the 10 topics in the workflow's Step 2, a brief subsection. Each subsection: 2-4 sentences plus a citation. Topics where the policy is silent are noted explicitly ("Not addressed.") rather than omitted.]

### Data collected
[Brief description; categories; sources.]

### Use of data
[Brief description; stated purposes; secondary uses if any.]

### Sharing
[Categories of recipients; sale/sharing under CCPA; sub-processors.]

### Cross-border transfers
[Whether transfers occur; mechanisms; recipient countries.]

### Retention
[Periods or methodology.]

### User rights and exercise mechanisms
[Rights enumerated; how to exercise.]

### Security
[Stated commitments.]

### Children's data
[Disclosures, or note the policy doesn't address.]

### Contact and complaints
[Privacy contact; complaint mechanisms.]

### AI / ML use of data
[Whether vendor uses data for ML training; opt-outs.]

## Red flags

[Items requiring user attention. Each with: what the policy says, why it's a flag, severity (Critical / Material / Minor), recommended user action. If no red flags, this section is one sentence: "No red flags identified at the first-pass level."]

## Items the policy doesn't address (gaps)

[Things a comprehensive privacy policy would typically address but this policy doesn't. Distinct from red flags — these are absences rather than problematic provisions. May overlap with regime-specific requirements when `applicable_regimes` is provided.]

## Recommended next steps

[Short bulleted list. Common options: proceed to DPA negotiation; request clarification from vendor on specific items; escalate specific issues to privacy counsel; obtain SOC 2 / security questionnaire; decline pending vendor changes.]

## Out of scope for this first pass

[A short paragraph reminding the user what this skill did NOT do: full privacy assessment, DPA review, security architecture review, jurisdictional enforceability analysis, etc. Direct the user to the appropriate next step for each.]

The report should be short. A typical first-pass report runs 1-3 pages. If the report is running long (over 4 pages), the document warrants a more comprehensive review than triage; the report should say so and recommend escalation rather than continuing to expand.

Edge cases and refusals

  • Document is not a privacy policy. Stop and tell the user. Common confusion: terms of service (different focus); cookie policy alone (subset of privacy policy); security exhibit (not a privacy policy); AUP (different document); DPA (use DPA Checklist Review).
  • Document is a privacy policy stub — extremely short, missing core sections. Note the inadequacy as a critical finding ("policy does not contain core sections required to be a meaningful privacy notice"); recommend escalation.
  • Document is a privacy policy in a language the user did not flag. Note the language and ask the user to confirm before proceeding.
  • Document is dated and the user has indicated the policy may be outdated. Note the date prominently and flag potential staleness as a finding.
  • Document references many external sub-policies. The skill cannot fetch external content. Note the references explicitly and recommend the user gather the referenced documents and consider running this skill on each.
  • Document is a vendor's privacy policy for one service when the user is evaluating a different service from the same vendor. Vendors often have product-specific privacy policies. Verify the policy applies to the service in scope.
  • Vendor uses customer data for AI/ML training based on what the policy says. Flag explicitly as critical regardless of vendor_context — this is the dominant 2025-2026 issue and warrants explicit treatment.

What this skill does not do

  • Full privacy assessment. This is triage. A full assessment requires: review of the DPA, security exhibit, sub-processor list, transfer impact assessment, audit reports, and operational practices. None of those are in scope here.
  • Compliance certification. The skill does not certify that a policy is GDPR-compliant or CCPA-compliant. Compliance certification requires affirmative legal opinion based on full facts; this is not that.
  • DPA negotiation. The privacy policy is the vendor's public representation; the DPA is the contractual commitment. The DPA review is a separate skill (DPA Checklist Review).
  • Security review. The privacy policy describes data practices, not security architecture. Security review requires SOC 2 reports, penetration tests, security questionnaires.
  • Comparative analysis with other vendors' policies. The skill assesses one policy at a time. Multi-vendor comparison is out of scope (deferred enhancement candidate).
  • Detailed jurisdictional analysis. The skill flags regime-relevance ("this policy may not satisfy GDPR Article 13 disclosure requirements") but does not give jurisdictional opinions ("this policy violates GDPR").

Reference materials

  • reference/policy_topics.md — the 10 standard topics covered in the structured summary, with what to look for in each.
  • reference/red_flags.md — categorized red-flag list with severity calibration guidance.
  • examples/example_clean_policy.md — worked example: vendor's privacy policy that's clean enough to proceed to DPA.
  • examples/example_red_flags.md — worked example: vendor's privacy policy with multiple red flags warranting escalation.

© LegalQuants, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files in skills/vendor-privacy-policy-first-pass of LegalQuants/lq-ai.

  • SKILL.md
  • examples/example_clean_policy.md
  • examples/example_red_flags.md
  • reference/policy_topics.md
  • reference/red_flags.md
  • test-plan.md

Open the folder on GitHubat commit 7ac94dd

Compare with similar skills

Vendor Privacy Policy First Pass next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vendor Privacy Policy First Pass compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vendor Privacy Policy First Pass this skillLegalQuants/lq-ai150—~4.3kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from LegalQuants/lq-ai

All 16 skills in this repo
  • A skill your agent uses when the user provides a client alert, regulatory bulletin, law firm memo, or similar legal update and wants the time-sensitive action items, deadlines, and obligations…

    150 GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Case Law Research

    LegalQuants/lq-ai

    A skill your agent uses when the user asks to find, read, or cite U.S.

    150 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Comms Improver

    LegalQuants/lq-ai

    A skill your agent uses when the user has a piece of legal-jargon-heavy text and wants it rewritten in plain language for a specified non-legal audience.

    150 GitHub stars~3.8k tokensUpdated today
    Auto-check passed
  • Contract QA

    LegalQuants/lq-ai

    A skill your agent uses when the user has a contract loaded and asks a specific question about it — what a clause means, where something is addressed, whether a term is unusual, how a provision…

    150 GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Contract Snapshot

    LegalQuants/lq-ai

    A skill your agent uses when the user wants to compare the same handful of terms across N contracts side-by-side in a grid — what is the term, survival period, carveouts, and governing law in each…

    150 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Dpa Checklist Review

    LegalQuants/lq-ai

    A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…

    150 GitHub stars~3.7k tokensUpdated today
    Auto-check passed

Questions about Vendor Privacy Policy First Pass

What does Vendor Privacy Policy First Pass do?

A skill your agent uses when the user has a vendor's published privacy policy (URL, PDF, or pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted. Vendor Privacy Policy First Pass is an agent skill from LegalQuants/lq-ai. Use when the user has a vendor's published privacy policy (URL, PDF, or pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted.

When should I use Vendor Privacy Policy First Pass?

Vendor Privacy Policy First Pass fits situations like: the user has a vendors published privacy policy (URL; pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted.

How do I install Vendor Privacy Policy First Pass in Claude Code?

Run `npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a claude-code`. Or copy the skill folder (skills/vendor-privacy-policy-first-pass in LegalQuants/lq-ai) into .claude/skills/vendor-privacy-policy-first-pass in your project. Claude Code loads it when a task matches its description.

How do I install Vendor Privacy Policy First Pass in Codex?

Run `npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a codex`. Or copy the skill folder (skills/vendor-privacy-policy-first-pass in LegalQuants/lq-ai) into .agents/skills/vendor-privacy-policy-first-pass in your project. Codex loads it when a task matches its description.

Can I use Vendor Privacy Policy First Pass in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-privacy-policy-first-pass, .gemini/skills/vendor-privacy-policy-first-pass, .github/skills/vendor-privacy-policy-first-pass and .opencode/skills/vendor-privacy-policy-first-pass in your project.

What does Vendor Privacy Policy First Pass need to run?

SKILL.md names no scripts, command-line tools or credentials: Vendor Privacy Policy First Pass is instructions for the agent only.

Does Vendor Privacy Policy First Pass access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vendor Privacy Policy First Pass safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vendor Privacy Policy First Pass use?

Vendor Privacy Policy First Pass is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vendor Privacy Policy First Pass use?

About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vendor Privacy Policy First Pass?

Skills that share tags, products or a category with Vendor Privacy Policy First Pass: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vendor Privacy Policy First Pass?

LegalQuants (a GitHub organization) maintains it in LegalQuants/lq-ai, which has 150 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 10, 2026.

Source: LegalQuants/lq-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.