Agent skill

Breach Response Playbook

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Builds a comprehensive breach response team playbook defining CSIRT and privacy team structure with named roles (incident commander, legal counsel, communications, IT forensics, DPO), escalation…

Apache-2.0Auto-check passedSecurity

Install Breach Response Playbook

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-response-playbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills breach-response-playbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/breach-response-playbook .claude/skills/breach-response-playbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
breach-response-playbook
GitHub stars
301
Token cost
~3.1k tokens
SKILL.md length
1,321 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Builds a comprehensive breach response team playbook defining CSIRT and privacy team structure with named roles (incident commander, legal counsel, communications, IT forensics, DPO), escalation…

  • Tasks that involve Security operations
  • SKILL.md covers Overview, Team Structure — CSIRT +…, Escalation Matrix and Communication Templates, plus 3 more sections
  • Runs Python scripts from its folder
  • Tasks that involve Incident response

What it does

Breach Response Playbook is an agent skill from mukul975/Privacy-Data-Protection-Skills. Builds a comprehensive breach response team playbook defining CSIRT and privacy team structure with named roles (incident commander, legal counsel, communications, IT forensics, DPO), escalation matrices, communication templates, pre-negotiated vendor contacts, and regulatory authority contacts organized by jurisdiction. Keywords: breach response playbook, CSIRT, incident response team, escalation matrix, communication templates, vendor contacts.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Security, covering Security operations, Incident response and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Security operations
  • Tasks that involve Incident response
  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the breach-response-playbook skill to build a comprehensive breach response team playbook defining CSIRT and privacy team structure with named…”
  • “/breach-response-playbook”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Breach Response Playbook loads about 3.1k tokens when it runs, and up to ~4.3k if it reads all its reference files. Until then it costs about 119 tokens; SKILL.md has 1,321 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,321 words, ~3,092 tokens.

Download SKILL.mdSave it as .claude/skills/breach-response-playbook/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
breach-response-playbook
description
Builds a comprehensive breach response team playbook defining CSIRT and privacy team structure with named roles (incident commander, legal counsel, communications, IT forensics, DPO), escalation matrices, communication templates, pre-negotiated vendor contacts, and regulatory authority contacts organized by jurisdiction. Keywords: breach response playbook, CSIRT, incident response team, escalation matrix, communication templates, vendor contacts.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-breach-response
metadata.tags
breach-playbook, csirt, incident-response-team, escalation-matrix, communication-templates

Building Breach Response Team Playbook

Overview

A breach response team playbook is the operational manual that enables rapid, coordinated response when a personal data breach occurs. It pre-defines roles and responsibilities, escalation paths, communication templates, and external contact information so that the response team can act immediately without spending critical hours on logistics during an actual incident.

Team Structure — CSIRT + Privacy Integration

Core Response Team
RolePrimaryBackupContactResponsibility
Incident Commander (IC)Thomas Brenner (CISO)Marcus Weber (SOC Lead)+49 30 7742 8100 / ic@stellarpayments.euOverall coordination, resource allocation, containment decisions
Data Protection OfficerDr. Elena VasquezAnna Schmidt (Deputy DPO)+49 30 7742 8001 / dpo@stellarpayments.euNotification decisions, risk assessment, regulatory liaison, data subject communication
Legal CounselSarah Chen (General Counsel)External: Dr. Klaus Fischer (Freshfields)+49 30 7742 8200 / legal@stellarpayments.euLegal advice, privilege management, regulatory strategy, law enforcement coordination
IT Forensics LeadPetra Hoffmann (IT Director)External: Sarah Mitchell (Mandiant)+49 30 7742 8300 / it-forensics@stellarpayments.euEvidence preservation, forensic investigation, scope determination, root cause analysis
Communications LeadMartin Keller (Comms Director)Lisa Braun (Senior Comms Manager)+49 30 7742 8400 / comms@stellarpayments.euMedia response, customer communication, internal communication, social media monitoring
Executive SponsorMarcus Lindqvist (CEO)CFO: Dr. Andrea Hoffmann+49 30 7742 8000 / ceo@stellarpayments.euStrategic decisions, board notification, public statements, regulatory engagement
Customer RelationsJames Park (VP Customer Success)Maria Santos (Customer Success Director)+49 30 7742 5000 / customers@stellarpayments.euCustomer inquiry management, B2B client communication, service status updates
HR LeadClaudia Richter (CHRO)Stefan Müller (HR Director)+49 30 7742 7500 / hr-confidential@stellarpayments.euEmployee communication, Works Council coordination, insider threat scenarios
Extended Team (Activated as Needed)
RoleContactActivation Trigger
Board LiaisonBoard Secretary (Dr. Friedrich Weber)Breach affecting 10,000+ data subjects or likely to result in high risk
Cyber InsuranceAllianz Claims: +49 89 3800 0 (ref: SPG-CYB-2025-001)Any breach likely to exceed EUR 50,000 in response costs
External IR FirmMandiant: +1 703 935 1700 (retainer: SPG-IR-2025-007)Any breach requiring forensic investigation beyond SOC capability
External LegalFreshfields: +49 30 20 28 39 000 (ref: SPG-LEG-2025-012)Breach involving regulatory risk, litigation risk, or cross-border notification
External CommunicationsBrunswick Group: +49 69 2400 5510Breach with media exposure or affecting 50,000+ individuals
Credit Monitoring VendorExperian Enterprise: +44 115 941 0888 (retainer: SPG-EXP-2025-003)Breach involving financial data, government IDs, or health data

Escalation Matrix

Severity Classification
SeverityCriteriaResponse TimeEscalation Level
SEV-1 (Critical)10,000+ data subjects; special category data (Art. 9); ongoing exfiltration; ransomware with encryptionImmediate (within 15 minutes)IC + DPO + CEO + General Counsel
SEV-2 (High)1,000-10,000 data subjects; financial data; credentials; media exposureWithin 30 minutesIC + DPO + General Counsel
SEV-3 (Medium)100-1,000 data subjects; non-sensitive personal data; contained breachWithin 2 hoursIC + DPO
SEV-4 (Low)Under 100 data subjects; low-sensitivity data; contained with no exfiltrationWithin 4 hoursSOC Lead + Privacy Coordinator
Escalation Flow
SOC Analyst detects alert
    ↓
SOC Lead validates (within 15 min)
    ↓
Personal data involved? → No → Standard security incident process
    ↓ Yes
Classify severity (SEV-1 to SEV-4)
    ↓
SEV-1/2: Activate Incident Commander + DPO immediately
SEV-3: Notify IC + DPO within 2 hours
SEV-4: Notify Privacy Coordinator within 4 hours
    ↓
IC convenes Core Response Team
    ↓
72-hour Art. 33 clock determination
    ↓
Investigation → Risk Assessment → Notification Decision

Communication Templates

Template 1: Internal Breach Alert (Email to Core Response Team)

Subject: [SEV-X] PERSONAL DATA BREACH — Immediate Action Required

From: SOC / Incident Commander To: Core Response Team distribution list

A personal data breach has been identified requiring immediate response.

Incident Summary:

  • Discovery time: [UTC timestamp]
  • Affected system(s): [system names]
  • Breach type: [Confidentiality / Integrity / Availability]
  • Estimated data subjects: [count or range]
  • Personal data categories: [list]
  • Containment status: [Contained / Active / Unknown]

Immediate Actions Required:

  • IC: Convene response team call at [time] on [bridge/Teams link]
  • DPO: Begin risk assessment; determine 72-hour deadline
  • IT Forensics: Preserve evidence on affected systems
  • Legal: Review for privilege and law enforcement considerations
  • Communications: Prepare holding statement; monitor media

Response Team Bridge: [Teams meeting link] Incident Channel: Signal group "SPG-IR-Active"

Template 2: Media Holding Statement

Stellar Payments Group is aware of a security incident affecting [some of our systems / our customer database]. We immediately activated our incident response procedures and are working with leading cybersecurity experts to investigate the matter. The protection of our customers' data is our highest priority. We will provide further information as our investigation progresses. For media inquiries, please contact press@stellarpayments.eu.

Template 3: Customer Service Talking Points

For customer-facing staff during an active breach:

If a customer asks about a security incident:

  • "We are aware of a security issue and our team is actively working to resolve it."
  • "The security of your information is our top priority."
  • "We will communicate directly with any affected customers as soon as our investigation allows."
  • "I can take your contact details and ensure you are notified if your account is affected."

Do NOT:

  • Confirm or deny specific details of the breach
  • Speculate on the number of affected customers
  • Provide information not in the approved talking points
  • Discuss the incident on social media
Show full SKILL.md (558 more words)Show less
Template 4: Board Notification (Email to Board Chair)

Subject: Data Breach Notification to the Board — [Breach Reference]

Dear [Board Chair],

I am writing to inform you of a personal data breach that occurred on [date]. This notification is provided in accordance with our Board-approved Incident Escalation Policy.

Summary: [2-3 sentence description] Scale: [approximate data subjects and data categories] Status: [contained/under investigation] Regulatory notification: [filed/pending/not required] Financial exposure: [estimated response costs and potential regulatory penalties]

A full briefing will be provided at [scheduled time]. In the interim, [CEO name] is overseeing the organizational response.

Template 5: Employee Communication (All-Staff)

Subject: Important Update from [CEO] Regarding a Security Incident

Dear Colleagues,

I want to share an important update. On [date], we identified a security incident affecting [description]. Our security and privacy teams are working around the clock to investigate and resolve the situation.

What we know: [brief, factual description] What we are doing: [containment and investigation actions] What this means for you: [if employee data was involved, say so directly; if not, clarify] What we ask of you: Report any unusual system activity to security@stellarpayments.eu. Do not discuss this matter externally or on social media.

We will provide updates as we learn more. Thank you for your professionalism and support during this time.

[CEO Name]

Regulatory Authority Contact Directory

European Union
CountryAuthorityBreach Portal / ContactPhone
Germany (Berlin)Berliner BfDIdatenschutz-berlin.de+49 30 13889 0
Germany (Federal)BfDIbfdi.bund.de+49 228 997799 0
FranceCNILnotifications.cnil.fr/notifications+33 1 53 73 22 22
IrelandDPCforms.dataprotection.ie+353 57 868 4800
NetherlandsAPautoriteitpersoonsgegevens.nl+31 70 888 8500
SpainAEPDsedeagpd.gob.es+34 91 266 35 17
ItalyGaranteprotocollo@pec.gpdp.it+39 06 696 77 1
BelgiumAPD/GBAgegevensbeschermingsautoriteit.be+32 2 274 48 00
AustriaDSBdsb.gv.at+43 1 52 152 0
PolandUODOuodo.gov.pl+48 22 531 03 00
United Kingdom
AuthorityPortalPhone
ICOico.org.uk/for-organisations/report-a-breach+44 303 123 1113
United States
AuthorityPortalPhone
HHS/OCR (HIPAA)ocrportal.hhs.gov+1 800 368 1019
California AGoag.ca.gov/privacy/databreach/reporting+1 916 210 6276
New York AGag.ny.gov/internet/filing-a-complaint+1 800 771 7755
FTCftc.gov/enforcement+1 877 382 4357
Other International
JurisdictionAuthorityContact
CanadaOPCpriv.gc.ca
AustraliaOAICoaic.gov.au/privacy/notifiable-data-breaches
BrazilANPDgov.br/anpd
SingaporePDPCpdpc.gov.sg

Pre-Negotiated Vendor Contacts

ServiceVendorContract ReferenceActivation ContactSLA
Incident ResponseMandiantSPG-IR-2025-007+1 703 935 1700 / ir@mandiant.comOn-site within 24 hours, remote within 4 hours
External Legal (EU)Freshfields Bruckhaus DeringerSPG-LEG-2025-012+49 30 20 28 39 000Partner-level response within 2 hours
External Legal (US)Covington & BurlingSPG-LEG-2025-013+1 202 662 6000Partner-level response within 2 hours
Credit MonitoringExperian IdentityWorksSPG-EXP-2025-003+44 115 941 0888Portal activation within 48 hours
Crisis CommunicationsBrunswick GroupSPG-COM-2025-001+49 69 2400 5510Team mobilized within 4 hours
Cyber InsuranceAllianz Cyber EnterpriseSPG-CYB-2025-001+49 89 3800 0Claims acknowledgment within 24 hours
eDiscovery / Legal HoldRelativity / ExterroSPG-LIT-2025-004+1 312 263 1333Legal hold activation within 4 hours

Playbook Maintenance

ActivityFrequencyOwner
Review and update contact informationQuarterlyDPO Office
Verify vendor retainer agreements are currentAnnuallyProcurement + DPO
Update regulatory authority contact detailsSemi-annuallyDPO Office
Tabletop exercise using playbookSemi-annuallyDPO + CISO
Full playbook revisionAnnually or after any SEV-1/SEV-2 incidentDPO
Distribute updated playbook to Core Response TeamAfter every revisionDPO Office

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/breach-response-playbook of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Breach Response Playbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Breach Response Playbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Breach Response Playbook this skillmukul975/Privacy-Data-Protection-Skills301—~3.1kAutomated safety check: PassApache-2.0
Forensics OsqueryAgentSecOps/SecOpsAgentKit2201 repos~4.9kAutomated safety check: NotesCustom licence
Ir VelociraptorAgentSecOps/SecOpsAgentKit2201 repos~3.1kAutomated safety check: PassCustom licence
Incident Reporting Navigatordavila7/claude-code-templates33k1 repos~4.7kAutomated safety check: PassCC-BY-4.0
Hunting For Webshell Activitymukul975/Anthropic-Cybersecurity-Skills34k—~904Automated safety check: PassApache-2.0
Detecting Network Anomalies With Zeekmukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: NotesApache-2.0

Similar skills

  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    220 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Ir Velociraptor

    AgentSecOps/SecOpsAgentKit

    Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.

    220 GitHub starsUsed in 1 repo~3.1k tokens
    SecurityAuto-check passed
  • Incident Reporting Navigator

    davila7/claude-code-templates

    A skill your agent uses when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU…

    33k GitHub starsUsed in 1 repo~4.7k tokens
    Legal & ComplianceAuto-check passed
  • Hunting For Webshell Activity

    mukul975/Anthropic-Cybersecurity-Skills

    Runs a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server…

    34k GitHub stars~904 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Network Anomalies With Zeek

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy and configure Zeek (formerly Bro) to passively analyze network traffic, generate structured connection/DNS/HTTP/SSL/file logs, detect anomalous behavior, and write custom scripts for…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Implementing Soar Automation With Phantom

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Breach Response Playbook

What does Breach Response Playbook do?

Builds a comprehensive breach response team playbook defining CSIRT and privacy team structure with named roles (incident commander, legal counsel, communications, IT forensics, DPO), escalation…. Breach Response Playbook is an agent skill from mukul975/Privacy-Data-Protection-Skills. Builds a comprehensive breach response team playbook defining CSIRT and privacy team structure with named roles (incident commander, legal counsel, communications, IT forensics, DPO), escalation matrices, communication templates, pre-negotiated vendor contacts, and regulatory authority contacts organized by jurisdiction.

When should I use Breach Response Playbook?

Breach Response Playbook fits situations like: tasks that involve Security operations; tasks that involve Incident response; tasks that involve Privacy and GDPR.

How do I install Breach Response Playbook in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-response-playbook -a claude-code`. Or copy the skill folder (skills/privacy/breach-response-playbook in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/breach-response-playbook in your project. Claude Code loads it when a task matches its description.

How do I install Breach Response Playbook in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-response-playbook -a codex`. Or copy the skill folder (skills/privacy/breach-response-playbook in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/breach-response-playbook in your project. Codex loads it when a task matches its description.

Can I use Breach Response Playbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-response-playbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/breach-response-playbook, .gemini/skills/breach-response-playbook, .github/skills/breach-response-playbook and .opencode/skills/breach-response-playbook in your project.

What does Breach Response Playbook need to run?

Going by SKILL.md and its folder, Breach Response Playbook needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Breach Response Playbook access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Breach Response Playbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Breach Response Playbook use?

Breach Response Playbook is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Breach Response Playbook use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Breach Response Playbook?

Skills that share tags, products or a category with Breach Response Playbook: Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars), Ir Velociraptor (AgentSecOps/SecOpsAgentKit, 220 stars), Incident Reporting Navigator (davila7/claude-code-templates, 33k stars) and Hunting For Webshell Activity (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Breach Response Playbook?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.