C15t
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
A skill your agent uses when the user has a vendor's published privacy policy (URL, PDF, or pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted.
$ npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LegalQuants/lq-ai vendor-privacy-policy-first-pass --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LegalQuants/lq-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vendor-privacy-policy-first-pass .claude/skills/vendor-privacy-policy-first-pass && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vendor-privacy-policy-first-pass" agent skill from https://github.com/LegalQuants/lq-ai/tree/main/skills/vendor-privacy-policy-first-pass into .claude/skills/vendor-privacy-policy-first-pass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-policy-first-pass", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LegalQuants/lq-ai/tree/main/skills/vendor-privacy-policy-first-passType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LegalQuants/lq-ai vendor-privacy-policy-first-pass --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegalQuants/lq-ai.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/vendor-privacy-policy-first-pass .agents/skills/vendor-privacy-policy-first-pass && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vendor-privacy-policy-first-pass" agent skill from https://github.com/LegalQuants/lq-ai/tree/main/skills/vendor-privacy-policy-first-pass into .agents/skills/vendor-privacy-policy-first-pass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-policy-first-pass", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LegalQuants/lq-ai vendor-privacy-policy-first-pass --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegalQuants/lq-ai.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/vendor-privacy-policy-first-pass .cursor/skills/vendor-privacy-policy-first-pass && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vendor-privacy-policy-first-pass" agent skill from https://github.com/LegalQuants/lq-ai/tree/main/skills/vendor-privacy-policy-first-pass into .cursor/skills/vendor-privacy-policy-first-pass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-policy-first-pass", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LegalQuants/lq-ai.git --path skills/vendor-privacy-policy-first-pass--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LegalQuants/lq-ai vendor-privacy-policy-first-pass --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegalQuants/lq-ai.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/vendor-privacy-policy-first-pass .gemini/skills/vendor-privacy-policy-first-pass && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vendor-privacy-policy-first-pass" agent skill from https://github.com/LegalQuants/lq-ai/tree/main/skills/vendor-privacy-policy-first-pass into .gemini/skills/vendor-privacy-policy-first-pass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-policy-first-pass", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LegalQuants/lq-ai vendor-privacy-policy-first-passInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LegalQuants/lq-ai.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/vendor-privacy-policy-first-pass .github/skills/vendor-privacy-policy-first-pass && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vendor-privacy-policy-first-pass" agent skill from https://github.com/LegalQuants/lq-ai/tree/main/skills/vendor-privacy-policy-first-pass into .github/skills/vendor-privacy-policy-first-pass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-policy-first-pass", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LegalQuants/lq-ai vendor-privacy-policy-first-pass --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LegalQuants/lq-ai.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/vendor-privacy-policy-first-pass .opencode/skills/vendor-privacy-policy-first-pass && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vendor-privacy-policy-first-pass" agent skill from https://github.com/LegalQuants/lq-ai/tree/main/skills/vendor-privacy-policy-first-pass into .opencode/skills/vendor-privacy-policy-first-pass/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-privacy-policy-first-pass", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vendor-privacy-policy-first-passA skill your agent uses when the user has a vendor's published privacy policy (URL, PDF, or pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted.
Vendor Privacy Policy First Pass is an agent skill from LegalQuants/lq-ai. Use when the user has a vendor's published privacy policy (URL, PDF, or pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted. Produces a short structured report covering what the policy says about key data practices (collection, use, sharing, retention, transfers, rights) plus identification of red flags that warrant escalation to deeper review. Explicitly a first pass, not a full privacy assessment, DPA negotiation, or compliance certification.
Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files (for example `examples/example_clean_policy.md`, `examples/example_red_flags.md` and `reference/policy_topics.md`).
It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: Open-source AI for legal teams. Bring your own keys, run it where you want, own your data. The licence is Apache-2.0.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 7ac94dd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vendor Privacy Policy First Pass loads about 4.3k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 1,578 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LegalQuants/lq-ai at commit 7ac94dd, republished under its Apache-2.0 licence (© LegalQuants). 1,578 words, ~4,264 tokens.
.claude/skills/vendor-privacy-policy-first-pass/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Conduct a fast triage assessment of a vendor's privacy policy to help the user decide whether deeper diligence is warranted before sharing data with the vendor. The output is a structured summary plus red-flag identification, not a full privacy assessment.
This skill is calibrated for the in-house counsel use case: a vendor has been proposed, the user has limited time, and the question is "does this policy contain anything that would change our decision to proceed, or does it look standard enough that we can move to DPA negotiation and security review?"
Apply when the user provides a vendor's privacy policy (or what is presented as one) and asks for a quick assessment. Common triggers:
Do not apply when:
The skill requires the document. Optional inputs (vendor_context, applicable_regimes, data_to_share) refine the analysis:
vendor_context changes severity calibration. A privacy policy that allows broad data sharing is a red flag for a marketing automation vendor handling customer PII; the same policy may be standard for an analytics tool handling only aggregated metrics. Without vendor_context, the skill uses general calibration and notes the assumption.applicable_regimes prioritizes regime-specific elements in the report. With applicable_regimes: gdpr, the skill checks for GDPR-required disclosures (Article 13/14 elements, transfer mechanisms, lawful basis); with ccpa, the skill checks for CCPA/CPRA-required disclosures (categories, sale/sharing, sensitive PI, rights). Without specification, the skill assesses against general commercial standards and notes regime-specific considerations as flags rather than findings.data_to_share affects red-flag severity. ML training rights on aggregated metrics is different from ML training rights on user PII. SSN handling considerations matter only if SSNs are in scope.When optional inputs are not provided, the skill uses default assumptions and notes them in the report.
The workflow has three steps. Total elapsed time should be short — this is triage.
Before substantive review:
Produce a structured summary covering the standard topics. Use reference/policy_topics.md to ensure coverage. For each topic, note: what the policy says, in plain language; specific clause/section references where applicable; whether the policy's treatment is clear, ambiguous, or absent.
The topics are:
Walk through the red-flag list in reference/red_flags.md. For each red flag found, note:
The red-flag categories include:
Produce the report in markdown with this structure (deliberately short — triage):
# Vendor Privacy Policy First Pass: [Vendor / Document name]
**Vendor context:** [user-provided, or "not specified"]
**Applicable regimes considered:** [list, or "general commercial"]
**Data the user expects to share:** [user-provided, or "not specified"]
**Policy effective date:** [date from policy, or "not stated"]
## Bottom line
[Two to three sentences. Headline assessment: clean / standard / has notable concerns / has serious red flags. Recommendation: proceed to DPA / proceed with specific concerns flagged / escalate for deeper review / decline pending substantial vendor changes.]
## Structured summary
[For each of the 10 topics in the workflow's Step 2, a brief subsection. Each subsection: 2-4 sentences plus a citation. Topics where the policy is silent are noted explicitly ("Not addressed.") rather than omitted.]
### Data collected
[Brief description; categories; sources.]
### Use of data
[Brief description; stated purposes; secondary uses if any.]
### Sharing
[Categories of recipients; sale/sharing under CCPA; sub-processors.]
### Cross-border transfers
[Whether transfers occur; mechanisms; recipient countries.]
### Retention
[Periods or methodology.]
### User rights and exercise mechanisms
[Rights enumerated; how to exercise.]
### Security
[Stated commitments.]
### Children's data
[Disclosures, or note the policy doesn't address.]
### Contact and complaints
[Privacy contact; complaint mechanisms.]
### AI / ML use of data
[Whether vendor uses data for ML training; opt-outs.]
## Red flags
[Items requiring user attention. Each with: what the policy says, why it's a flag, severity (Critical / Material / Minor), recommended user action. If no red flags, this section is one sentence: "No red flags identified at the first-pass level."]
## Items the policy doesn't address (gaps)
[Things a comprehensive privacy policy would typically address but this policy doesn't. Distinct from red flags — these are absences rather than problematic provisions. May overlap with regime-specific requirements when `applicable_regimes` is provided.]
## Recommended next steps
[Short bulleted list. Common options: proceed to DPA negotiation; request clarification from vendor on specific items; escalate specific issues to privacy counsel; obtain SOC 2 / security questionnaire; decline pending vendor changes.]
## Out of scope for this first pass
[A short paragraph reminding the user what this skill did NOT do: full privacy assessment, DPA review, security architecture review, jurisdictional enforceability analysis, etc. Direct the user to the appropriate next step for each.]The report should be short. A typical first-pass report runs 1-3 pages. If the report is running long (over 4 pages), the document warrants a more comprehensive review than triage; the report should say so and recommend escalation rather than continuing to expand.
vendor_context — this is the dominant 2025-2026 issue and warrants explicit treatment.reference/policy_topics.md — the 10 standard topics covered in the structured summary, with what to look for in each.reference/red_flags.md — categorized red-flag list with severity calibration guidance.examples/example_clean_policy.md — worked example: vendor's privacy policy that's clean enough to proceed to DPA.examples/example_red_flags.md — worked example: vendor's privacy policy with multiple red flags warranting escalation.© LegalQuants, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files in skills/vendor-privacy-policy-first-pass of LegalQuants/lq-ai.
Open the folder on GitHubat commit 7ac94dd
Vendor Privacy Policy First Pass next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vendor Privacy Policy First Pass this skillLegalQuants/lq-ai | 150 | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | |
| C15tc15t/c15t | 1.9k | 1 repos | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Korean Privacy Termskimlawtech/korean-privacy-terms | 587 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
c15t/c15t
Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
kimlawtech/korean-privacy-terms
처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
LegalQuants/lq-ai
A skill your agent uses when the user provides a client alert, regulatory bulletin, law firm memo, or similar legal update and wants the time-sensitive action items, deadlines, and obligations…
LegalQuants/lq-ai
A skill your agent uses when the user asks to find, read, or cite U.S.
LegalQuants/lq-ai
A skill your agent uses when the user has a piece of legal-jargon-heavy text and wants it rewritten in plain language for a specified non-legal audience.
LegalQuants/lq-ai
A skill your agent uses when the user has a contract loaded and asks a specific question about it — what a clause means, where something is addressed, whether a term is unusual, how a provision…
LegalQuants/lq-ai
A skill your agent uses when the user wants to compare the same handful of terms across N contracts side-by-side in a grid — what is the term, survival period, carveouts, and governing law in each…
LegalQuants/lq-ai
A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…
Categories
A skill your agent uses when the user has a vendor's published privacy policy (URL, PDF, or pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted. Vendor Privacy Policy First Pass is an agent skill from LegalQuants/lq-ai. Use when the user has a vendor's published privacy policy (URL, PDF, or pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted.
Vendor Privacy Policy First Pass fits situations like: the user has a vendors published privacy policy (URL; pasted text) and wants a fast triage assessment to decide whether deeper diligence is warranted.
Run `npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a claude-code`. Or copy the skill folder (skills/vendor-privacy-policy-first-pass in LegalQuants/lq-ai) into .claude/skills/vendor-privacy-policy-first-pass in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a codex`. Or copy the skill folder (skills/vendor-privacy-policy-first-pass in LegalQuants/lq-ai) into .agents/skills/vendor-privacy-policy-first-pass in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LegalQuants/lq-ai --skill vendor-privacy-policy-first-pass -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-privacy-policy-first-pass, .gemini/skills/vendor-privacy-policy-first-pass, .github/skills/vendor-privacy-policy-first-pass and .opencode/skills/vendor-privacy-policy-first-pass in your project.
SKILL.md names no scripts, command-line tools or credentials: Vendor Privacy Policy First Pass is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vendor Privacy Policy First Pass is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Vendor Privacy Policy First Pass: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LegalQuants (a GitHub organization) maintains it in LegalQuants/lq-ai, which has 150 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 10, 2026.
Source: LegalQuants/lq-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.