Agent skill

Consent Receipt Spec

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Implement the Kantara Initiative consent receipt specification including machine-readable receipt structure, JWT-based verification mechanisms, receipt lifecycle management, and integration patterns…

Apache-2.0Auto-check passedBackend & APIs

Install Consent Receipt Spec

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill consent-receipt-spec -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills consent-receipt-spec --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/consent-receipt-spec .claude/skills/consent-receipt-spec && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
consent-receipt-spec
GitHub stars
301
Token cost
~4.4k tokens
SKILL.md length
489 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implement the Kantara Initiative consent receipt specification including machine-readable receipt structure, JWT-based verification mechanisms, receipt lifecycle management, and integration patterns…

  • Tasks that involve Authentication
  • SKILL.md covers Overview, Consent Receipt Structure, Machine-Readable Receipt Format and JWT-Based Verification Mechanism, plus 3 more sections
  • Runs Python scripts from its folder; reaches cipherengineeringlabs.com
  • Tasks that involve Third-party API integration

What it does

Consent Receipt Spec is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implement the Kantara Initiative consent receipt specification including machine-readable receipt structure, JWT-based verification mechanisms, receipt lifecycle management, and integration patterns for consent management platforms. Supports ISO/IEC 27560 consent record information structure.

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Backend & APIs, covering Authentication, Third-party API integration and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Authentication
  • Tasks that involve Third-party API integration
  • Tasks that involve Privacy and GDPR

Example prompts

  • “/consent-receipt-spec”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cipherengineeringlabs.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Consent Receipt Spec loads about 4.4k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 489 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 489 words, ~4,355 tokens.

Download SKILL.mdSave it as .claude/skills/consent-receipt-spec/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
consent-receipt-spec
description
Implement the Kantara Initiative consent receipt specification including machine-readable receipt structure, JWT-based verification mechanisms, receipt lifecycle management, and integration patterns for consent management platforms. Supports ISO/IEC 27560 consent record information structure.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-engineering
metadata.tags
consent-receipt, kantara-initiative, consent-management, jwt-verification, iso-27560

Overview

A consent receipt is a record of a consent transaction provided to the individual (data subject) as evidence that consent was given. The Kantara Initiative Consent Receipt Specification v1.1 defines a standard, machine-readable format that enables individuals to track and manage their consent across multiple organizations. This skill covers the implementation of consent receipts aligned with the Kantara specification and ISO/IEC 27560:2023.

Core Fields (Kantara v1.1)
FieldTypeRequiredDescription
versionStringYesSpecification version (e.g., "KI-CR-v1.1.0")
jurisdictionStringYesLegal jurisdiction (ISO 3166-1 alpha-2)
consentTimestampDateTimeYesUTC timestamp of consent grant
collectionMethodStringYesHow consent was collected (web form, verbal, paper)
consentReceiptIDUUIDYesUnique identifier for this receipt
publicKeyStringNoPublic key for receipt verification
languageStringYesLanguage of the consent interaction (BCP 47)
piiPrincipalIdStringYesIdentifier for the data subject
piiControllersArrayYesList of data controllers
policyUrlURLYesLink to the privacy policy
servicesArrayYesServices for which consent is given
sensitiveBooleanYesWhether special category data is involved
spiCatArrayNoSpecial categories of data processed
PII Controller Object
FieldTypeRequiredDescription
piiControllerStringYesName of the controller organization
onBehalfBooleanNoWhether acting on behalf of another controller
contactStringYesContact information for the controller
addressObjectYesPhysical address of the controller
emailStringYesContact email address
phoneStringNoContact phone number
piiControllerUrlURLNoURL of the controller's website
Service Object
FieldTypeRequiredDescription
serviceStringYesName of the service
purposesArrayYesList of processing purposes
Show full SKILL.md (220 more words)Show less
Purpose Object
FieldTypeRequiredDescription
purposeStringYesDescription of the processing purpose
purposeCategoryArrayYesCategory codes for the purpose
consentTypeStringYes"explicit" or "implicit"
piiCategoryArrayYesCategories of PII processed
primaryPurposeBooleanYesWhether this is the primary purpose
terminationStringYesHow consent can be withdrawn
thirdPartyDisclosureBooleanYesWhether data is shared with third parties
thirdPartyNameStringNoName of third party (if applicable)

Machine-Readable Receipt Format

json
{
  "version": "KI-CR-v1.1.0",
  "jurisdiction": "EU",
  "consentTimestamp": "2026-03-14T10:30:00.000Z",
  "collectionMethod": "web_form",
  "consentReceiptID": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
  "language": "en",
  "piiPrincipalId": "user-98765",
  "piiControllers": [
    {
      "piiController": "Cipher Engineering Labs",
      "onBehalf": false,
      "contact": "Data Protection Officer",
      "address": {
        "streetAddress": "100 Technology Drive",
        "locality": "London",
        "region": "Greater London",
        "postalCode": "EC2A 1NT",
        "country": "GB"
      },
      "email": "dpo@cipherengineeringlabs.com",
      "phone": "+44-20-7946-0958",
      "piiControllerUrl": "https://www.cipherengineeringlabs.com"
    }
  ],
  "policyUrl": "https://www.cipherengineeringlabs.com/privacy-policy",
  "services": [
    {
      "service": "Privacy Analytics Platform",
      "purposes": [
        {
          "purpose": "Provide personalized privacy compliance recommendations",
          "purposeCategory": ["core_service"],
          "consentType": "explicit",
          "piiCategory": ["contact_information", "professional_information"],
          "primaryPurpose": true,
          "termination": "Account settings > Privacy > Withdraw consent",
          "thirdPartyDisclosure": false
        },
        {
          "purpose": "Send product updates and feature announcements",
          "purposeCategory": ["marketing"],
          "consentType": "explicit",
          "piiCategory": ["contact_information"],
          "primaryPurpose": false,
          "termination": "Unsubscribe link in email or Account settings",
          "thirdPartyDisclosure": false
        },
        {
          "purpose": "Aggregate usage analytics to improve platform features",
          "purposeCategory": ["analytics"],
          "consentType": "explicit",
          "piiCategory": ["usage_data", "device_information"],
          "primaryPurpose": false,
          "termination": "Account settings > Privacy > Analytics opt-out",
          "thirdPartyDisclosure": true,
          "thirdPartyName": "Cipher Analytics Processing Ltd"
        }
      ]
    }
  ],
  "sensitive": false,
  "spiCat": []
}

JWT-Based Verification Mechanism

python
"""
Consent receipt generation and verification using JWT (JSON Web Tokens).
Implements Kantara Initiative Consent Receipt Specification v1.1
with cryptographic verification.
"""

import json
import uuid
from datetime import datetime, timezone
from typing import Optional
import jwt  # PyJWT
from cryptography.hazmat.primitives import serialization
from cryptography.hazmat.primitives.asymmetric import rsa, padding
from cryptography.hazmat.backends import default_backend


class ConsentReceiptIssuer:
    """
    Issue and sign consent receipts as JWTs.
    Uses RS256 (RSA with SHA-256) for signing.
    """

    def __init__(self, private_key_pem: bytes, issuer_name: str):
        """
        Args:
            private_key_pem: PEM-encoded RSA private key
            issuer_name: Name of the issuing organization
        """
        self.private_key = serialization.load_pem_private_key(
            private_key_pem, password=None, backend=default_backend()
        )
        self.public_key = self.private_key.public_key()
        self.issuer_name = issuer_name

    def issue_receipt(
        self,
        principal_id: str,
        services: list[dict],
        jurisdiction: str,
        collection_method: str,
        policy_url: str,
        sensitive: bool = False,
        language: str = "en",
        controller_info: dict = None
    ) -> tuple[str, str]:
        """
        Generate a signed consent receipt.

        Args:
            principal_id: Data subject identifier
            services: List of service/purpose objects
            jurisdiction: Legal jurisdiction code
            collection_method: How consent was collected
            policy_url: URL of the privacy policy
            sensitive: Whether special categories are involved
            language: Language of consent interaction
            controller_info: PII controller details

        Returns:
            Tuple of (receipt_id, signed_jwt_string)
        """
        receipt_id = str(uuid.uuid4())

        if controller_info is None:
            controller_info = {
                "piiController": self.issuer_name,
                "onBehalf": False,
                "contact": "Data Protection Officer",
                "email": f"dpo@{self.issuer_name.lower().replace(' ', '')}.com"
            }

        receipt_payload = {
            "version": "KI-CR-v1.1.0",
            "jurisdiction": jurisdiction,
            "consentTimestamp": datetime.now(timezone.utc).isoformat(),
            "collectionMethod": collection_method,
            "consentReceiptID": receipt_id,
            "language": language,
            "piiPrincipalId": principal_id,
            "piiControllers": [controller_info],
            "policyUrl": policy_url,
            "services": services,
            "sensitive": sensitive,
            "spiCat": [],
            # JWT standard claims
            "iss": self.issuer_name,
            "sub": principal_id,
            "iat": int(datetime.now(timezone.utc).timestamp()),
            "jti": receipt_id,
        }

        # Sign the receipt as a JWT
        signed_token = jwt.encode(
            receipt_payload,
            self.private_key,
            algorithm="RS256",
            headers={"kid": f"{self.issuer_name}-consent-key-1"}
        )

        return receipt_id, signed_token

    def get_public_key_pem(self) -> str:
        """Export the public key for verification by data subjects."""
        return self.public_key.public_bytes(
            encoding=serialization.Encoding.PEM,
            format=serialization.PublicFormat.SubjectPublicKeyInfo
        ).decode("utf-8")


class ConsentReceiptVerifier:
    """
    Verify signed consent receipts.
    Used by data subjects or auditors to confirm receipt authenticity.
    """

    def __init__(self):
        self.trusted_keys: dict[str, bytes] = {}

    def register_issuer_key(self, issuer_name: str, public_key_pem: str):
        """Register a trusted issuer's public key."""
        self.trusted_keys[issuer_name] = public_key_pem.encode("utf-8")

    def verify_receipt(self, token: str) -> tuple[bool, Optional[dict], Optional[str]]:
        """
        Verify a signed consent receipt JWT.

        Returns:
            Tuple of (is_valid, decoded_payload_or_None, error_message_or_None)
        """
        try:
            # Decode without verification first to get the issuer
            unverified = jwt.decode(token, options={"verify_signature": False})
            issuer = unverified.get("iss")

            if issuer not in self.trusted_keys:
                return (False, None, f"Unknown issuer: {issuer}")

            public_key = serialization.load_pem_public_key(
                self.trusted_keys[issuer],
                backend=default_backend()
            )

            # Verify the signature
            decoded = jwt.decode(
                token,
                public_key,
                algorithms=["RS256"],
                issuer=issuer
            )

            # Validate required Kantara fields
            required_fields = [
                "version", "jurisdiction", "consentTimestamp",
                "collectionMethod", "consentReceiptID", "piiPrincipalId",
                "piiControllers", "policyUrl", "services", "sensitive"
            ]

            missing = [f for f in required_fields if f not in decoded]
            if missing:
                return (False, decoded, f"Missing required fields: {missing}")

            return (True, decoded, None)

        except jwt.ExpiredSignatureError:
            return (False, None, "Receipt JWT has expired")
        except jwt.InvalidSignatureError:
            return (False, None, "Invalid signature — receipt may have been tampered with")
        except jwt.DecodeError as e:
            return (False, None, f"Failed to decode JWT: {str(e)}")

Receipt Lifecycle Management

Lifecycle States
ISSUED --> ACTIVE --> WITHDRAWN
  |          |           |
  |          v           v
  |       UPDATED    ARCHIVED
  |          |
  v          v
EXPIRED   ACTIVE (new version)
Lifecycle Manager
python
"""
Manage the lifecycle of consent receipts including
updates, withdrawals, and expiration tracking.
"""

from dataclasses import dataclass
from datetime import datetime, timezone
from enum import Enum


class ReceiptStatus(Enum):
    ISSUED = "issued"
    ACTIVE = "active"
    UPDATED = "updated"
    WITHDRAWN = "withdrawn"
    EXPIRED = "expired"
    ARCHIVED = "archived"


@dataclass
class ReceiptRecord:
    receipt_id: str
    principal_id: str
    status: ReceiptStatus
    issued_at: datetime
    last_updated: datetime
    withdrawn_at: datetime | None
    jwt_token: str
    version: int
    superseded_by: str | None
    purposes: list[str]


class ConsentReceiptLifecycle:
    """
    Manage consent receipt state transitions and history.
    """

    def __init__(self, receipt_store, issuer: ConsentReceiptIssuer):
        self.store = receipt_store
        self.issuer = issuer

    def activate_receipt(self, receipt_id: str) -> bool:
        """Transition a receipt from ISSUED to ACTIVE."""
        record = self.store.get(receipt_id)
        if record and record.status == ReceiptStatus.ISSUED:
            record.status = ReceiptStatus.ACTIVE
            record.last_updated = datetime.now(timezone.utc)
            self.store.update(record)
            return True
        return False

    def update_receipt(
        self,
        receipt_id: str,
        updated_services: list[dict],
        jurisdiction: str,
        policy_url: str
    ) -> str | None:
        """
        Update an existing receipt by issuing a new version.
        The old receipt is marked as UPDATED and linked to the new one.

        Returns the new receipt ID or None if update failed.
        """
        old_record = self.store.get(receipt_id)
        if not old_record or old_record.status not in [
            ReceiptStatus.ACTIVE, ReceiptStatus.ISSUED
        ]:
            return None

        # Issue new receipt
        new_receipt_id, new_jwt = self.issuer.issue_receipt(
            principal_id=old_record.principal_id,
            services=updated_services,
            jurisdiction=jurisdiction,
            collection_method="consent_update",
            policy_url=policy_url
        )

        # Create new record
        new_record = ReceiptRecord(
            receipt_id=new_receipt_id,
            principal_id=old_record.principal_id,
            status=ReceiptStatus.ACTIVE,
            issued_at=datetime.now(timezone.utc),
            last_updated=datetime.now(timezone.utc),
            withdrawn_at=None,
            jwt_token=new_jwt,
            version=old_record.version + 1,
            superseded_by=None,
            purposes=[p["purpose"] for s in updated_services for p in s.get("purposes", [])]
        )
        self.store.save(new_record)

        # Mark old receipt as updated
        old_record.status = ReceiptStatus.UPDATED
        old_record.superseded_by = new_receipt_id
        old_record.last_updated = datetime.now(timezone.utc)
        self.store.update(old_record)

        return new_receipt_id

    def withdraw_consent(self, receipt_id: str, reason: str = "") -> bool:
        """
        Withdraw consent and mark the receipt accordingly.

        Returns True if withdrawal was successful.
        """
        record = self.store.get(receipt_id)
        if not record or record.status not in [
            ReceiptStatus.ACTIVE, ReceiptStatus.ISSUED
        ]:
            return False

        record.status = ReceiptStatus.WITHDRAWN
        record.withdrawn_at = datetime.now(timezone.utc)
        record.last_updated = datetime.now(timezone.utc)
        self.store.update(record)

        return True

    def get_active_receipts(self, principal_id: str) -> list[ReceiptRecord]:
        """Get all active consent receipts for a data subject."""
        return self.store.find_by_principal(
            principal_id, status=ReceiptStatus.ACTIVE
        )

    def get_receipt_history(self, principal_id: str) -> list[ReceiptRecord]:
        """Get the complete consent receipt history for a data subject."""
        return self.store.find_by_principal(principal_id)

ISO/IEC 27560:2023 Alignment

Kantara CR FieldISO 27560 EquivalentNotes
consentReceiptIDConsent Record IdentifierUnique identifier for the record
consentTimestampDate and time of consentWhen consent was collected
piiPrincipalIdPII Principal IdentifierData subject identifier
piiControllersPII ControllerOrganization processing data
services.purposesPurpose(s)Processing purposes
services.purposes.piiCategoryPII CategoriesTypes of personal data
sensitiveSensitive PII indicatorSpecial category flag
jurisdictionJurisdictionApplicable legal framework
collectionMethodMechanism of consentHow consent was obtained
policyUrlPrivacy notice referenceLink to privacy notice

References

  • Kantara Initiative Consent Receipt Specification v1.1.0 (2018)
  • ISO/IEC 27560:2023 — Privacy Technologies — Consent Record Information Structure
  • ISO/IEC 29184:2020 — Guidelines for Online Privacy Notices and Consent
  • RFC 7519 — JSON Web Token (JWT)
  • W3C Data Privacy Vocabularies and Controls Community Group
  • IEEE P7012 — Standard for Machine Readable Personal Privacy Terms

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/consent-receipt-spec of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Consent Receipt Spec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Consent Receipt Spec compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Consent Receipt Spec this skillmukul975/Privacy-Data-Protection-Skills301—~4.4kAutomated safety check: PassApache-2.0
Passport Developmenttrypostit/trypost691—~1.9kAutomated safety check: PassMIT
Soundcloud API Integrationsoundcloud/api259—~787Automated safety check: PassNone
MCP API Key AuthenticationYourdaylight/stock_datasource189—~1.2kAutomated safety check: PassMIT
OmniRoute API Keysdiegosouzapw/OmniRoute75k—~1.4kAutomated safety check: PassMIT
Venice API Keysveniceai/skills144—~3.8kAutomated safety check: PassMIT

Similar skills

  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    691 GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Integrates applications with the SoundCloud HTTP API using OAuth 2.1, OpenAPI, and developer docs.

    259 GitHub stars~787 tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • MCP API Key Authentication

    Yourdaylight/stock_datasource

    Sets up and troubleshoots MCP API key authentication for a stock data service, covering key creation, client configuration and per-tool usage statistics.

    189 GitHub stars~1.2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • OmniRoute API Keys

    diegosouzapw/OmniRoute

    Documents the OmniRoute REST endpoints for creating, listing, updating, regenerating and deleting API keys, with per-key scopes, spending limits, expiry and device lists.

    75k GitHub stars~1.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Venice API Keys

    veniceai/skills

    Manages Venice API keys through the /api_keys endpoints: create, list, update and revoke keys, set spending limits, and read rate limits.

    144 GitHub stars~3.8k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Venice API Overview

    veniceai/skills

    High-level map of the Venice.ai API: base URL, auth modes per endpoint, endpoint categories, response headers, pricing model, error shape and versioning.

    144 GitHub stars~3.5k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Consent Receipt Spec

What does Consent Receipt Spec do?

Implement the Kantara Initiative consent receipt specification including machine-readable receipt structure, JWT-based verification mechanisms, receipt lifecycle management, and integration patterns…. Consent Receipt Spec is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implement the Kantara Initiative consent receipt specification including machine-readable receipt structure, JWT-based verification mechanisms, receipt lifecycle management, and integration patterns for consent management platforms.

When should I use Consent Receipt Spec?

Consent Receipt Spec fits situations like: tasks that involve Authentication; tasks that involve Third-party API integration; tasks that involve Privacy and GDPR.

How do I install Consent Receipt Spec in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill consent-receipt-spec -a claude-code`. Or copy the skill folder (skills/privacy/consent-receipt-spec in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/consent-receipt-spec in your project. Claude Code loads it when a task matches its description.

How do I install Consent Receipt Spec in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill consent-receipt-spec -a codex`. Or copy the skill folder (skills/privacy/consent-receipt-spec in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/consent-receipt-spec in your project. Codex loads it when a task matches its description.

Can I use Consent Receipt Spec in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill consent-receipt-spec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/consent-receipt-spec, .gemini/skills/consent-receipt-spec, .github/skills/consent-receipt-spec and .opencode/skills/consent-receipt-spec in your project.

What does Consent Receipt Spec need to run?

Going by SKILL.md and its folder, Consent Receipt Spec needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Consent Receipt Spec access the network?

SKILL.md names 1 domain. In commands or code: cipherengineeringlabs.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Consent Receipt Spec safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Consent Receipt Spec use?

Consent Receipt Spec is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Consent Receipt Spec use?

About 4.4k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 497 tokens, read only when the agent opens those files.

What are the alternatives to Consent Receipt Spec?

Skills that share tags, products or a category with Consent Receipt Spec: Passport Development (trypostit/trypost, 691 stars), Soundcloud API Integration (soundcloud/api, 259 stars), MCP API Key Authentication (Yourdaylight/stock_datasource, 189 stars) and OmniRoute API Keys (diegosouzapw/OmniRoute, 75k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Consent Receipt Spec?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.