Agent skill

Cloud Provider Assessment

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Cloud service provider privacy assessment framework. An agent skill from mukul975/Privacy-Data-Protection-Skills.

Apache-2.0Auto-check passedLegal & Compliance

Install Cloud Provider Assessment

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-provider-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills cloud-provider-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/cloud-provider-assessment .claude/skills/cloud-provider-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-provider-assessment
GitHub stars
297
Token cost
~2.6k tokens
SKILL.md length
1,063 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Cloud service provider privacy assessment framework. An agent skill from mukul975/Privacy-Data-Protection-Skills.

  • Tasks that involve SOC 2 and security compliance
  • SKILL.md covers Overview, Cloud Service Models and…, Assessment Framework and Assessment Scoring, plus 1 more section
  • Runs Python scripts from its folder
  • Tasks that involve Privacy and GDPR

What it does

Cloud Provider Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Cloud service provider privacy assessment framework. Covers ISO 27018 cloud privacy controls, CSA STAR certification, SOC 2 Type II evaluation, shared responsibility model mapping, data residency verification, and cloud-specific privacy risk analysis.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve SOC 2 and security compliance
  • Tasks that involve Privacy and GDPR

Example prompts

  • “/cloud-provider-assessment”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud Provider Assessment loads about 2.6k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 69 tokens; SKILL.md has 1,063 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,063 words, ~2,566 tokens.

Download SKILL.mdSave it as .claude/skills/cloud-provider-assessment/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
cloud-provider-assessment
description
Cloud service provider privacy assessment framework. Covers ISO 27018 cloud privacy controls, CSA STAR certification, SOC 2 Type II evaluation, shared responsibility model mapping, data residency verification, and cloud-specific privacy risk analysis.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
vendor-privacy-management
metadata.tags
cloud-assessment, iso-27018, csa-star, shared-responsibility, data-residency

Cloud Service Provider Privacy Assessment

Overview

Cloud service providers present unique privacy assessment challenges due to shared responsibility models, multi-tenancy architectures, global infrastructure, and the abstraction of physical processing locations. GDPR Article 28 obligations apply fully to cloud processing relationships, but the assessment approach must account for cloud-specific characteristics.

ISO/IEC 27018:2019 provides the international standard for protecting personally identifiable information (PII) in public clouds, supplementing ISO 27001 with cloud-specific privacy controls. The Cloud Security Alliance (CSA) STAR program provides a cloud-specific security assurance framework. SOC 2 Type II with the Privacy trust services criterion addresses personal data handling controls.

At Summit Cloud Partners, cloud providers undergo enhanced assessment incorporating these cloud-specific frameworks alongside standard vendor due diligence.

Cloud Service Models and Privacy Implications

IaaS (Infrastructure as a Service)
AspectController ResponsibilityProvider Responsibility
Data encryption at restConfigure and manage keysProvide encryption infrastructure
Access management (app level)Define and manageProvide IAM platform
Network security (app level)Configure security groups, firewall rulesProvide network infrastructure
Physical securityNoneFull responsibility
Patch management (OS)Controller (or managed service)Hypervisor and below
Data backupConfigure and manageProvide backup infrastructure
Incident detection (app)Application-level monitoringInfrastructure-level monitoring
PaaS (Platform as a Service)
AspectController ResponsibilityProvider Responsibility
Application code securityFull responsibilityNone
Data handling in applicationFull responsibilityNone
Runtime and middlewareLimited — configuration onlyManage platform components
OS and infrastructureNoneFull responsibility
Platform security patchingNoneFull responsibility
Identity managementConfigureProvide identity platform
SaaS (Software as a Service)
AspectController ResponsibilityProvider Responsibility
Data entered by usersDetermine what data to processProcess per controller instructions
Application securityNone (except configuration)Full responsibility
Infrastructure securityNoneFull responsibility
Data portabilityDefine export requirementsProvide export functionality
Data deletionRequest deletionImplement deletion per DPA
Access configurationConfigure user rolesProvide RBAC platform

Assessment Framework

Domain 1: Data Residency and Sovereignty

Assessment Questions:

#QuestionExpected Evidence
1.1In which regions/availability zones will personal data be stored at rest?Architecture documentation specifying data storage locations
1.2Can the controller restrict processing to specific geographic regions?Configuration documentation showing region-locking capability
1.3Are there any circumstances where data may be processed outside the selected region?Disclosure of any cross-region processing (DR, support, analytics)
1.4Where is metadata and telemetry data stored?Often stored in provider's home jurisdiction — must be disclosed
1.5Where do support staff access data from?List of countries from which support personnel may access data
1.6What government access or disclosure obligations apply in processing jurisdictions?Legal analysis of government access powers per EDPB Recommendations 01/2020
Domain 2: Multi-Tenancy and Data Isolation
#QuestionExpected Evidence
2.1How is tenant data isolated from other customers' data?Architecture documentation — logical/physical separation details
2.2Are encryption keys unique per tenant?Key management architecture documentation
2.3Can one tenant's operations affect another tenant's data?Side-channel and cross-tenant risk assessment
2.4How are shared infrastructure components secured?Hypervisor security, shared storage controls
2.5What tenant isolation testing has been performed?Penetration test results covering cross-tenant attacks
Domain 3: ISO 27018 Cloud Privacy Controls

ISO/IEC 27018:2019 extends ISO 27001 with cloud-specific PII protection controls:

ControlRequirementAssessment Check
A.1PII processor consent — process only per controller instructionsVerify contractual terms and processing boundaries
A.2Purpose limitation — no processing beyond controller purposeReview processing scope documentation
A.3Use for marketing — no use of PII for marketing without consentConfirm no data monetization or marketing use
A.4Notification — notify controller of government access requestsVerify government access notification process
A.5Disclosure — document all disclosures of PIIReview disclosure logging mechanism
A.10Return, transfer, and disposal — secure data handling at terminationVerify deletion procedures and certification
A.11Confidentiality — binding confidentiality obligations on personnelVerify personnel agreements cover cloud-specific risks
A.12Sub-contracting — notification of sub-processor engagementVerify sub-processor management per Art. 28(2)
Show full SKILL.md (428 more words)Show less
Domain 4: CSA STAR Assessment

The Cloud Security Alliance STAR (Security, Trust, Assurance, and Risk) program provides three levels:

LevelDescriptionAssessment Method
Level 1: Self-AssessmentProvider completes CSA Consensus Assessments Initiative Questionnaire (CAIQ)Review self-assessment for completeness and substantiation
Level 2: Third-Party AuditIndependent audit against CSA Cloud Controls Matrix (CCM)Review audit report, scope, and findings
Level 3: Continuous MonitoringReal-time monitoring of control effectivenessReview continuous monitoring dashboard and alerts

Key CCM Control Domains for Privacy:

DomainControlsPrivacy Relevance
DSP (Data Security & Privacy)DSP-01 through DSP-19Data classification, retention, inventory, privacy by design
GRC (Governance, Risk, Compliance)GRC-01 through GRC-08Governance framework, risk assessment, policy management
IAM (Identity & Access Management)IAM-01 through IAM-16Access control, credential management, MFA
SEF (Security Incident Management)SEF-01 through SEF-08Incident response, breach notification
Domain 5: SOC 2 Type II Privacy Criterion

The AICPA Trust Services Criteria Privacy criterion evaluates:

CriterionAreaAssessment Focus
P1NoticeProvider discloses privacy practices to controllers
P2Choice and consentController can configure privacy settings
P3CollectionData collection limited to stated purposes
P4Use, retention, disposalProcessing per instructions; retention per DPA; certified deletion
P5AccessController can access and retrieve their data
P6Disclosure to third partiesSub-processor disclosure and management
P7Security for privacyTechnical controls protecting PII
P8QualityData integrity and accuracy controls
P9Monitoring and enforcementCompliance monitoring and breach response
Domain 6: Shared Responsibility Model Mapping

Document the shared responsibility boundary for every control domain:

Control DomainController ResponsibilityProvider ResponsibilityGap/Risk
Data classificationClassify data before uploadProvide classification tools[Gap?]
Encryption key management[Depends on model][Depends on model][Gap?]
Access control (application)[Depends on model][Depends on model][Gap?]
Vulnerability management[Depends on model][Depends on model][Gap?]
Incident detection[Depends on model][Depends on model][Gap?]
Data backup[Depends on model][Depends on model][Gap?]
Compliance reporting[Depends on model][Depends on model][Gap?]

Assessment Scoring

DomainWeightScore (1-5)Weighted
Data residency and sovereignty20%
Multi-tenancy and isolation20%
ISO 27018 compliance15%
CSA STAR level15%
SOC 2 Privacy criterion15%
Shared responsibility clarity15%
TOTAL100%

Key Regulatory References

  • GDPR Article 28 — Controller-processor relationship applies fully to cloud
  • GDPR Article 32 — Security measures including cloud-specific controls
  • ISO/IEC 27018:2019 — Code of practice for protection of PII in public clouds
  • ISO/IEC 27017:2015 — Code of practice for information security controls for cloud services
  • CSA Cloud Controls Matrix (CCM) v4.0 — Cloud security control framework
  • EDPB Recommendations 01/2020 — Supplementary measures for cloud transfers
  • ENISA Cloud Computing Risk Assessment (2009, updated) — EU cloud risk framework

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/cloud-provider-assessment of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Cloud Provider Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud Provider Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud Provider Assessment this skillmukul975/Privacy-Data-Protection-Skills297—~2.6kAutomated safety check: PassApache-2.0
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~4.2kAutomated safety check: PassMIT
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    943 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    943 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    297 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    297 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    297 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Cloud Provider Assessment

What does Cloud Provider Assessment do?

Cloud service provider privacy assessment framework. An agent skill from mukul975/Privacy-Data-Protection-Skills. Cloud Provider Assessment is an agent skill from mukul975/Privacy-Data-Protection-Skills. Cloud service provider privacy assessment framework.

When should I use Cloud Provider Assessment?

Cloud Provider Assessment fits situations like: tasks that involve SOC 2 and security compliance; tasks that involve Privacy and GDPR.

How do I install Cloud Provider Assessment in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-provider-assessment -a claude-code`. Or copy the skill folder (skills/privacy/cloud-provider-assessment in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/cloud-provider-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Cloud Provider Assessment in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-provider-assessment -a codex`. Or copy the skill folder (skills/privacy/cloud-provider-assessment in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/cloud-provider-assessment in your project. Codex loads it when a task matches its description.

Can I use Cloud Provider Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-provider-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-provider-assessment, .gemini/skills/cloud-provider-assessment, .github/skills/cloud-provider-assessment and .opencode/skills/cloud-provider-assessment in your project.

What does Cloud Provider Assessment need to run?

Going by SKILL.md and its folder, Cloud Provider Assessment needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Cloud Provider Assessment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cloud Provider Assessment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cloud Provider Assessment use?

Cloud Provider Assessment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloud Provider Assessment use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Cloud Provider Assessment?

Skills that share tags, products or a category with Cloud Provider Assessment: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars), Audit Report (harness/harness-skills, 115 stars), Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars) and Security Compliance (sangrokjung/claude-forge, 852 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud Provider Assessment?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.