Agent skill

Ccpa Cpra Compliance

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Complete CCPA/CPRA compliance implementation covering California Civil Code §1798.100-199.

Apache-2.0Auto-check passedLegal & Compliance

Install Ccpa Cpra Compliance

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill ccpa-cpra-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills ccpa-cpra-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/ccpa-cpra-compliance .claude/skills/ccpa-cpra-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ccpa-cpra-compliance
GitHub stars
301
Token cost
~4.1k tokens
SKILL.md length
2,051 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Complete CCPA/CPRA compliance implementation covering California Civil Code §1798.100-199.

  • Works in 10 steps: Right to Know (§1798.100, §1798.110,… → Right to Delete (§1798.105) → Right to Correct (§1798.106) — Added by… → …
  • California privacy
  • SKILL.md covers Overview, Applicability (§1798.140(d)), Key Definitions and Consumer Rights, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Ccpa Cpra Compliance is an agent skill from mukul975/Privacy-Data-Protection-Skills. Complete CCPA/CPRA compliance implementation covering California Civil Code §1798.100-199. Includes consumer rights framework, business obligations, service provider and contractor requirements, enforcement mechanisms, and CPPA rulemaking. Triggers on CCPA, CPRA, California privacy, consumer rights.

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • California privacy
  • Consumer rights

Example prompts

  • “/ccpa-cpra-compliance”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Right to Know (§1798.100, §1798.110, §1798.115)
  2. Right to Delete (§1798.105)
  3. Right to Correct (§1798.106) — Added by CPRA
  4. Right to Opt-Out of Sale/Sharing (§1798.120)
  5. Right to Limit Use of Sensitive PI (§1798.121) — Added by CPRA
  6. Right to Non-Discrimination (§1798.125)
  7. Assessment (Weeks 1-4)
  8. Legal Framework (Weeks 5-8)
  9. Technical Implementation (Weeks 9-16)
  10. Operations (Weeks 17-20)

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ccpa Cpra Compliance loads about 4.1k tokens when it runs, and up to ~7k if it reads all its reference files. Until then it costs about 80 tokens; SKILL.md has 2,051 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,051 words, ~4,057 tokens.

Download SKILL.mdSave it as .claude/skills/ccpa-cpra-compliance/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
ccpa-cpra-compliance
description
Complete CCPA/CPRA compliance implementation covering California Civil Code §1798.100-199. Includes consumer rights framework, business obligations, service provider and contractor requirements, enforcement mechanisms, and CPPA rulemaking. Triggers on CCPA, CPRA, California privacy, consumer rights.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
us-state-privacy-laws
metadata.tags
ccpa, cpra, california-privacy, consumer-rights, business-obligations

CCPA/CPRA Compliance

Overview

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), establishes comprehensive consumer privacy rights under California Civil Code §1798.100-199. The CPRA, approved by voters on November 3, 2020 (Proposition 24), substantially amended the CCPA effective January 1, 2023, with a lookback period to January 1, 2022. The California Privacy Protection Agency (CPPA) was established as the first dedicated state privacy enforcement agency in the United States.

The CPRA replaced the California Attorney General as the primary enforcement body with the CPPA, added the category of sensitive personal information, created new consumer rights (correction and limit use of sensitive PI), expanded the definition of "sharing" for cross-context behavioral advertising, and introduced requirements for data processing agreements.

Applicability (§1798.140(d))

A business is subject to CCPA/CPRA if it:

  1. Has annual gross revenues exceeding $25,000,000 in the preceding calendar year (adjusted by the CPPA for inflation starting January 1, 2024)
  2. Annually buys, sells, or shares the personal information of 100,000 or more consumers or households (CPRA increased from 50,000)
  3. Derives 50% or more of its annual revenues from selling or sharing consumers' personal information

Liberty Commerce Inc. Assessment: Liberty Commerce Inc., with annual revenues of $48 million and processing personal information of approximately 320,000 California consumers through its e-commerce platform, meets threshold (1) and threshold (2). Liberty Commerce Inc. is classified as a "business" under §1798.140(d).

Key Definitions

Personal Information (§1798.140(v))

Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Categories include:

CategoryExamples
IdentifiersReal name, alias, postal address, unique personal identifier, online identifier, IP address, email, account name, SSN, driver's license, passport number
Commercial InformationRecords of personal property, products or services purchased, obtaining, or considered
Biometric InformationPhysiological, biological, or behavioral characteristics used to establish individual identity (fingerprint, face, voice, iris, keystroke patterns)
Internet/Network ActivityBrowsing history, search history, information regarding interaction with website, application, or advertisement
Geolocation DataPhysical location or movements
Sensory DataAudio, electronic, visual, thermal, olfactory, or similar information
Professional/EmploymentCurrent or past job-related information
Education InformationNon-publicly available education records per FERPA (20 U.S.C. §1232g)
InferencesProfiles reflecting preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, aptitudes
Sensitive PI (CPRA)SSN/driver's license/passport, account log-in with password, precise geolocation, racial/ethnic origin, religious/philosophical beliefs, union membership, contents of mail/email/text, genetic data, biometric data for identification, health information, sex life/sexual orientation data
Sale (§1798.140(ad))

Selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer's personal information by the business to a third party for monetary or other valuable consideration.

Sharing (§1798.140(ah)) — Added by CPRA

Sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating a consumer's personal information by the business to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including situations where no money is exchanged.

Service Provider vs. Contractor (§1798.140(ag), §1798.140(j))
AspectService ProviderContractor
DefinitionProcesses PI on behalf of business per written contractProcesses PI made available by business per written contract
Contract RequirementsWritten agreement prohibiting selling/sharing, limiting use to specified purposesWritten agreement with same prohibitions plus certification of understanding, grant of compliance audit rights
SubcontractingMay engage subcontractors with written contractMay engage subcontractors with written contract and business notification
Compliance AuditsNot expressly required in statuteBusiness has right to audit contractor compliance

Consumer Rights

1. Right to Know (§1798.100, §1798.110, §1798.115)

Consumers may request that a business disclose:

  • Categories of PI collected
  • Categories of sources
  • Business or commercial purpose for collecting, selling, or sharing
  • Categories of third parties to whom PI is disclosed
  • Specific pieces of PI collected about the consumer

Lookback period: 12 months preceding the request (business may voluntarily go beyond).

Liberty Commerce Inc. Implementation: Liberty Commerce Inc. provides a "Know My Data" portal at privacy.libertycommerce.com/know where verified consumers can request all five categories of disclosure. The system generates a structured report in machine-readable format (JSON) and human-readable format (PDF) within 10 business days.

2. Right to Delete (§1798.105)

Consumers may request deletion of personal information collected from them. Upon receiving a verified request, the business must delete the PI and direct service providers and contractors to delete the consumer's PI.

Exceptions (§1798.105(d)): Transaction completion, security, error repair, free speech (Cal. Civ. Code §1798.105(d)(4)), internal uses reasonably aligned with consumer expectations, compliance with legal obligation, internal uses compatible with the context of collection.

Liberty Commerce Inc. Implementation: Liberty Commerce Inc. processes deletion requests through a cascading deletion workflow that propagates to all service providers (payment processor, shipping partner, analytics provider) within 45 calendar days. Retained data for legal compliance (tax records per 26 U.S.C. §6001) is documented with the specific legal basis.

3. Right to Correct (§1798.106) — Added by CPRA

Consumers may request correction of inaccurate personal information. The business must use commercially reasonable efforts to correct the information.

Liberty Commerce Inc. Implementation: Liberty Commerce Inc. allows consumers to self-correct profile data (name, address, email, phone) directly in their account. For data in backend systems (purchase history corrections, loyalty points), verified requests are processed through the privacy team with documentation of the correction.

4. Right to Opt-Out of Sale/Sharing (§1798.120)

Consumers have the right to direct a business that sells or shares their personal information to stop selling or sharing that information. The business must respect this direction.

Key requirements:

  • "Do Not Sell or Share My Personal Information" link on homepage
  • Must honor Global Privacy Control (GPC) signals as valid opt-out requests (CPPA Regulations §7025)
  • No re-solicitation for 12 months after opt-out
  • Must not discriminate against consumers who opt out (§1798.125)

Liberty Commerce Inc. Implementation: Liberty Commerce Inc. displays a persistent "Do Not Sell or Share My Personal Information" link in the footer of every page. The system detects GPC signals via the Sec-GPC: 1 HTTP header and navigator.globalPrivacyControl JavaScript API, automatically applying opt-out status to the browsing session and associating it with the consumer's account if authenticated.

5. Right to Limit Use of Sensitive PI (§1798.121) — Added by CPRA

Consumers may direct a business to limit its use of sensitive personal information to specified purposes (performing services/providing goods, preventing security incidents, resisting malicious/deceptive actions, ensuring safety, short-term transient use, performing services on behalf of the business, verifying/maintaining quality, upgrading/enhancing services).

Liberty Commerce Inc. Implementation: Liberty Commerce Inc. displays a "Limit the Use of My Sensitive Personal Information" link adjacent to the opt-out link. When activated, the system restricts processing of sensitive PI categories (precise geolocation, racial/ethnic origin data from surveys, payment card details beyond transaction processing) to the enumerated permitted purposes.

6. Right to Non-Discrimination (§1798.125)

A business may not discriminate against a consumer for exercising their CCPA rights, including by:

  • Denying goods or services
  • Charging different prices or rates
  • Providing a different level or quality of goods or services
  • Suggesting that the consumer will receive a different price or quality

Financial incentive programs are permitted if the consumer is notified and opts in, the incentive is reasonably related to the value of the consumer's data, and the business can explain the valuation methodology.

Business Obligations

Show full SKILL.md (850 more words)Show less
Privacy Notice (§1798.100(a), §1798.130(a)(5))

The privacy notice must be updated at least once every 12 months and include:

  • Categories of PI collected in the preceding 12 months
  • Categories of sensitive PI collected
  • Purposes for which each category is used and whether it is sold or shared
  • Length of time each category is retained (or criteria for determining retention) — added by CPRA
  • Categories of sources
  • Categories of third parties to which PI is disclosed
  • Instructions for submitting consumer requests
  • Whether the business sells or shares PI, and categories involved
  • Categories of PI disclosed for a business purpose

Liberty Commerce Inc. Implementation: Liberty Commerce Inc. publishes its California Privacy Notice at privacy.libertycommerce.com/california, updated annually in January. The notice uses a layered format with a summary table followed by detailed sections. Retention periods are specified per data category (e.g., transaction records: 7 years per tax requirements; browsing data: 13 months; account data: duration of account plus 30 days).

Data Processing Agreements (§1798.100(d)) — Added by CPRA

Businesses must enter into agreements with service providers, contractors, and third parties that:

  • Specify the business purpose for which PI is made available
  • Require the recipient to comply with CCPA/CPRA obligations
  • Grant the business rights to take reasonable steps to ensure compliance
  • Require notification if the recipient determines it can no longer meet its obligations
  • Grant the business the right to stop and remediate unauthorized use of PI
Data Minimization (§1798.100(c)) — Added by CPRA

A business's collection, use, retention, and sharing of PI must be:

  • Reasonably necessary and proportionate to the purposes for which the PI was collected or processed
  • Not further processed in a manner incompatible with those purposes
Consumer Request Processing (§1798.130)
RequirementDetail
Response deadline45 calendar days from receipt of verifiable request
ExtensionUp to 45 additional days (90 total) with notice to consumer
VerificationReasonable methods to verify identity; match at least two data points for access; three data points for specific pieces
Authorized agentsMust accept requests from authorized agents with signed permission or power of attorney
Free requestsAt least two free requests per 12-month period
FormatDelivered in readily usable, machine-readable format (for portability requests)
Toll-free numberRequired for businesses that operate exclusively online only if they have a direct relationship with the consumer
Record Keeping (CPPA Regulations §7101)

Businesses that buy, receive, or sell the PI of 10,000,000 or more consumers must compile metrics for the prior calendar year and disclose:

  • Number of requests to know, delete, correct, and opt-out received
  • Number of requests complied with in whole or in part
  • Number of requests denied
  • Median number of days to respond

Enforcement

CPPA Enforcement (§1798.199.40-199.100)
  • Administrative enforcement actions by the CPPA
  • Administrative fines up to $2,500 per violation; $7,500 per intentional violation or violations involving minors under 16
  • CPPA has authority to issue regulations, conduct investigations, and bring enforcement actions
  • 30-day cure period was eliminated by CPRA effective January 1, 2023
Private Right of Action (§1798.150)

Limited to data breach claims where nonencrypted and nonredacted PI (as defined in Cal. Civ. Code §1798.81.5(d)(1)(A)) is subject to unauthorized access due to the business's failure to implement reasonable security measures.

  • Statutory damages: $100-$750 per consumer per incident, or actual damages (whichever is greater)
  • Injunctive or declaratory relief
  • Any other relief the court deems proper
  • 30-day notice and cure period before filing suit

Implementation Roadmap for Liberty Commerce Inc.

Phase 1: Assessment (Weeks 1-4)
  1. Data inventory and mapping of all PI and sensitive PI categories
  2. Identify all data flows: collection, use, sale, sharing, disclosure
  3. Map service providers, contractors, and third parties
  4. Assess current privacy notice against CPRA requirements
  5. Evaluate consumer request processing workflows
  1. Update privacy notice with retention periods, sensitive PI categories, sale/sharing disclosures
  2. Draft/update data processing agreements for all service providers and contractors
  3. Develop consumer request verification procedures
  4. Establish authorized agent acceptance procedures
  5. Create financial incentive program valuation methodology (if applicable)
Phase 3: Technical Implementation (Weeks 9-16)
  1. Deploy "Do Not Sell or Share My Personal Information" link
  2. Deploy "Limit the Use of My Sensitive Personal Information" link
  3. Implement GPC signal detection and honoring
  4. Build consumer request intake portal with identity verification
  5. Implement cascading deletion workflow
  6. Build right-to-know report generation (JSON and PDF)
  7. Implement data minimization controls and retention enforcement
Phase 4: Operations (Weeks 17-20)
  1. Train customer service team on CCPA/CPRA consumer rights
  2. Establish 45-day SLA monitoring for consumer requests
  3. Implement metrics tracking per CPPA Regulations §7101
  4. Schedule annual privacy notice review
  5. Conduct tabletop exercise for consumer request processing

Key Regulatory References

  • California Civil Code §1798.100-199 (CCPA as amended by CPRA)
  • California Privacy Rights Act (Proposition 24, approved November 3, 2020)
  • CPPA Final Regulations (effective March 29, 2023; updated regulations effective March 29, 2024)
  • CPPA Regulations §7001-7102 (Title 11, Division 6, California Code of Regulations)
  • Cal. Civ. Code §1798.81.5 — Data breach notification
  • AG Enforcement Actions: Sephora Inc. ($1.2 million settlement, August 2022) — first public CCPA enforcement action for failure to honor GPC opt-out signals
  • CPPA Enforcement Advisory No. 2024-01 — Dark patterns in consent interfaces

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/ccpa-cpra-compliance of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Ccpa Cpra Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ccpa Cpra Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ccpa Cpra Compliance this skillmukul975/Privacy-Data-Protection-Skills301—~4.1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Ccpa Cpra Compliance

What does Ccpa Cpra Compliance do?

Complete CCPA/CPRA compliance implementation covering California Civil Code §1798.100-199. Ccpa Cpra Compliance is an agent skill from mukul975/Privacy-Data-Protection-Skills.100-199.

When should I use Ccpa Cpra Compliance?

Ccpa Cpra Compliance fits situations like: california privacy; consumer rights.

How do I install Ccpa Cpra Compliance in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ccpa-cpra-compliance -a claude-code`. Or copy the skill folder (skills/privacy/ccpa-cpra-compliance in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/ccpa-cpra-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Ccpa Cpra Compliance in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ccpa-cpra-compliance -a codex`. Or copy the skill folder (skills/privacy/ccpa-cpra-compliance in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/ccpa-cpra-compliance in your project. Codex loads it when a task matches its description.

Can I use Ccpa Cpra Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill ccpa-cpra-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ccpa-cpra-compliance, .gemini/skills/ccpa-cpra-compliance, .github/skills/ccpa-cpra-compliance and .opencode/skills/ccpa-cpra-compliance in your project.

What does Ccpa Cpra Compliance need to run?

Going by SKILL.md and its folder, Ccpa Cpra Compliance needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Ccpa Cpra Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ccpa Cpra Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ccpa Cpra Compliance use?

Ccpa Cpra Compliance is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ccpa Cpra Compliance use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.

What are the alternatives to Ccpa Cpra Compliance?

Skills that share tags, products or a category with Ccpa Cpra Compliance: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ccpa Cpra Compliance?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.