Install the "cloud-retention-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/cloud-retention-config into .claude/skills/cloud-retention-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-retention-config", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-retention-config -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "cloud-retention-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/cloud-retention-config into .agents/skills/cloud-retention-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-retention-config", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-retention-config -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "cloud-retention-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/cloud-retention-config into .cursor/skills/cloud-retention-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-retention-config", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-retention-config -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "cloud-retention-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/cloud-retention-config into .gemini/skills/cloud-retention-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-retention-config", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-retention-config -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "cloud-retention-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/cloud-retention-config into .github/skills/cloud-retention-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-retention-config", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-retention-config -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "cloud-retention-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/cloud-retention-config into .opencode/skills/cloud-retention-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-retention-config", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
cloud-retention-config
GitHub stars
301
Token cost
~3.7k tokens
SKILL.md length
1,294 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0
At a glance
Configures cloud storage retention policies across AWS S3, Azure Blob Storage, and Google Cloud Storage.
Works in 5 steps: Identical retention periods: Replicated… → Synchronized lifecycle rules: Lifecycle… → Legal hold propagation: Legal holds… → …
Tasks that involve File uploads and storage
SKILL.md covers Overview, Legal Context, AWS S3 Lifecycle and Retention… and Microsoft Azure Blob Storage…, plus 3 more sections
Runs Python scripts from its folder; calls gcloud, aws and az
What it does
Cloud Retention Config is an agent skill from mukul975/Privacy-Data-Protection-Skills. Configures cloud storage retention policies across AWS S3, Azure Blob Storage, and Google Cloud Storage. Covers lifecycle rules, object lock, legal hold, immutability policies, cross-region replication retention alignment, and compliance mode configuration. Activate for cloud retention, S3 lifecycle, Azure retention, GCP retention policy queries.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering File uploads and storage and Privacy and GDPR. It works with Google Cloud, Microsoft Azure, Amazon S3 and Azure Blob Storage. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
When your agent uses it
Tasks that involve File uploads and storage
Tasks that involve Privacy and GDPR
Example prompts
“Use the cloud-retention-config skill to configure cloud storage retention policies across AWS S3, Azure Blob Storage, and Google Cloud Storage”
“/cloud-retention-config”
Requirements
Python 3
Workflow steps
5 steps, taken from the first numbered list in SKILL.md.
1Identical retention periods: Replicated data in the destination region must have the same retention period as the source.
2Synchronized lifecycle rules: Lifecycle transitions and expirations must be configured identically on source and destination…
3Legal hold propagation: Legal holds applied in the source must also be applied in the destination. Configure automated propagation.
4Deletion propagation: When an object expires or is deleted in the source, the replica must also be deleted. Configure replication to…
5Jurisdictional considerations: If the destination region is in a different jurisdiction, confirm that the applicable retention…
What it can do on your machine
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
gcloud
aws
az
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use gcloud, aws and az, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Cloud Retention Config loads about 3.7k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 1,294 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~93
When it runs· the whole SKILL.md, loaded when a task matches
~3.7k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~5.3k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Download SKILL.mdSave it as .claude/skills/cloud-retention-config/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
cloud-retention-config
description
Configures cloud storage retention policies across AWS S3, Azure Blob Storage, and Google Cloud Storage. Covers lifecycle rules, object lock, legal hold, immutability policies, cross-region replication retention alignment, and compliance mode configuration. Activate for cloud retention, S3 lifecycle, Azure retention, GCP retention policy queries.
Cloud storage platforms provide native retention and lifecycle management features that can enforce data retention schedules at the infrastructure level. Proper configuration ensures that personal data stored in cloud environments is automatically transitioned, archived, or deleted according to retention policies, while legal hold and object lock features prevent premature deletion of data subject to regulatory or litigation requirements. This skill covers configuration for the three major cloud platforms: AWS S3, Microsoft Azure Blob Storage, and Google Cloud Storage.
Legal Context
GDPR Article 5(1)(e) — Storage Limitation
Cloud storage retention policies are a technical implementation of the storage limitation principle, ensuring data is not retained beyond the period necessary for processing purposes.
GDPR Article 32 — Security of Processing
Retention configuration must include appropriate security measures, including encryption at rest, access controls, and audit logging for all retention-related operations.
GDPR Article 25 — Data Protection by Design and by Default
Cloud retention policies should be configured as default settings on all storage resources, rather than applied retroactively.
AWS S3 Lifecycle and Retention Configuration
S3 Lifecycle Rules
S3 Lifecycle rules automate transitions between storage classes and object expiration:
Lifecycle Rule Configuration for Orion Data Vault Corp
Rule Name
Prefix/Tag Filter
Transition
Expiration
Purpose
customer-data-lifecycle
prefix: customer-data/
90 days → S3 Glacier Instant Retrieval; 365 days → S3 Glacier Deep Archive
Critical consideration for GDPR erasure: If using Compliance Mode, data subject erasure requests under Art. 17 cannot be fulfilled until the retention period expires. Use Governance Mode for data categories where erasure requests are possible, and reserve Compliance Mode only for data with mandatory statutory retention that overrides the right to erasure under Art. 17(3)(b).
S3 Legal Hold
Legal hold is an independent, on/off flag that prevents object deletion regardless of retention settings:
Warning: Locking a retention policy is IRREVERSIBLE. Once locked, the retention period cannot be reduced or removed. The bucket cannot be deleted until every object in it has met its retention period. Only lock policies for data categories with absolute statutory retention requirements that override Art. 17 rights.
When data is replicated across regions for availability or disaster recovery, retention policies must be aligned:
Alignment Requirements
Identical retention periods: Replicated data in the destination region must have the same retention period as the source.
Synchronized lifecycle rules: Lifecycle transitions and expirations must be configured identically on source and destination buckets/containers.
Legal hold propagation: Legal holds applied in the source must also be applied in the destination. Configure automated propagation.
Deletion propagation: When an object expires or is deleted in the source, the replica must also be deleted. Configure replication to handle delete markers.
Jurisdictional considerations: If the destination region is in a different jurisdiction, confirm that the applicable retention requirements in that jurisdiction do not conflict with the source retention period.
Cross-Region Configuration Checklist
Check
AWS
Azure
GCP
Lifecycle rules match source
Apply identical S3 lifecycle rules to destination bucket
Apply identical lifecycle management policy to destination container
Apply identical lifecycle rules to destination bucket
Retention/lock settings match
Configure identical Object Lock settings on destination
Apply identical immutability policy to destination
Apply identical retention policy to destination
Delete marker replication
Enable DeleteMarkerReplication in replication config
Enable blob change feed and handle deletes
Configure bucket notifications for deletion events
Legal hold synchronization
Use Lambda triggered by CloudTrail to propagate legal holds
Use Event Grid + Azure Function to propagate legal holds
Use Cloud Functions triggered by audit logs to propagate holds
Monitoring
CloudWatch metrics on replication lag
Azure Monitor replication metrics
Cloud Monitoring replication metrics
Compliance Monitoring
Monthly Cloud Retention Audit
Policy drift detection: Compare active lifecycle rules and retention policies against the approved retention schedule. Flag any discrepancies.
Coverage verification: Confirm that all storage buckets/containers holding personal data have applicable retention policies.
Legal hold inventory: List all active legal holds across all cloud platforms. Cross-reference with the litigation hold register to identify holds that should have been released.
Expiration verification: Sample recently expired objects to confirm they were actually deleted (not just transitioned or soft-deleted).
Cross-region consistency: Verify that replicated buckets/containers maintain identical retention configuration.
Alert Configuration
Alert
Condition
Action
Policy removed
Retention policy or lifecycle rule deleted from a regulated bucket
Immediate alert to Cloud Security + DPO
Object lock bypass
s3:BypassGovernanceRetention used
Alert to DPO; verify authorized deletion
Legal hold change
Legal hold applied or removed
Log to litigation hold register; alert Legal
Retention policy unlock attempt
Attempt to modify locked retention policy
Alert to Cloud Security (should fail — investigate)
Replication lag > 24h
Cross-region replication behind by more than 24 hours
Alert IT Operations — potential retention gap in DR region
Cloud Retention Config next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Cloud Retention Config compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Cloud Retention Config this skillmukul975/Privacy-Data-Protection-Skills
Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…
Implement cloud DLP using Amazon Macie, Google Cloud DLP API, Microsoft Purview, Azure Information Protection, and Nightfall AI to discover, classify, label, de-identify, and protect sensitive data…
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
Configures cloud storage retention policies across AWS S3, Azure Blob Storage, and Google Cloud Storage. Cloud Retention Config is an agent skill from mukul975/Privacy-Data-Protection-Skills. Configures cloud storage retention policies across AWS S3, Azure Blob Storage, and Google Cloud Storage.
When should I use Cloud Retention Config?
Cloud Retention Config fits situations like: tasks that involve File uploads and storage; tasks that involve Privacy and GDPR.
How do I install Cloud Retention Config in Claude Code?
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-retention-config -a claude-code`. Or copy the skill folder (skills/privacy/cloud-retention-config in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/cloud-retention-config in your project. Claude Code loads it when a task matches its description.
How do I install Cloud Retention Config in Codex?
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-retention-config -a codex`. Or copy the skill folder (skills/privacy/cloud-retention-config in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/cloud-retention-config in your project. Codex loads it when a task matches its description.
Can I use Cloud Retention Config in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill cloud-retention-config -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-retention-config, .gemini/skills/cloud-retention-config, .github/skills/cloud-retention-config and .opencode/skills/cloud-retention-config in your project.
What does Cloud Retention Config need to run?
Going by SKILL.md and its folder, Cloud Retention Config needs Python for the scripts in its folder and the command-line tools its instructions call (gcloud, aws and az). Our summary lists: Python 3.
Does Cloud Retention Config access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Cloud Retention Config safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
What licence does Cloud Retention Config use?
Cloud Retention Config is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Cloud Retention Config use?
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.
What are the alternatives to Cloud Retention Config?
Skills that share tags, products or a category with Cloud Retention Config: Deploying Cloud Deception With Decoy Resources (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Cloud Dlp For Data Protection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Azure Storage (microsoft/GitHub-Copilot-for-Azure, 255 stars) and Neon Object Storage (neondatabase/agent-skills, 100 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Cloud Retention Config?
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.