Reviewing Security Architecture
bitwarden/ai-plugins
This skill should be used when the user asks to "review the security architecture", "check authentication patterns", "evaluate trust boundaries", "review encryption implementation", "assess…
Configures privacy settings for enterprise HR systems including SAP SuccessFactors, Workday, and BambooHR.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hr-system-privacy-config -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hr-system-privacy-config --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/hr-system-privacy-config .claude/skills/hr-system-privacy-config && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hr-system-privacy-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hr-system-privacy-config into .claude/skills/hr-system-privacy-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hr-system-privacy-config", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hr-system-privacy-configType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hr-system-privacy-config -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hr-system-privacy-config --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/hr-system-privacy-config .agents/skills/hr-system-privacy-config && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hr-system-privacy-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hr-system-privacy-config into .agents/skills/hr-system-privacy-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hr-system-privacy-config", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hr-system-privacy-config -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hr-system-privacy-config --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/hr-system-privacy-config .cursor/skills/hr-system-privacy-config && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hr-system-privacy-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hr-system-privacy-config into .cursor/skills/hr-system-privacy-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hr-system-privacy-config", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/hr-system-privacy-config--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hr-system-privacy-config -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hr-system-privacy-config --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/hr-system-privacy-config .gemini/skills/hr-system-privacy-config && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hr-system-privacy-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hr-system-privacy-config into .gemini/skills/hr-system-privacy-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hr-system-privacy-config", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hr-system-privacy-configInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hr-system-privacy-config -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/hr-system-privacy-config .github/skills/hr-system-privacy-config && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hr-system-privacy-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hr-system-privacy-config into .github/skills/hr-system-privacy-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hr-system-privacy-config", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hr-system-privacy-config -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hr-system-privacy-config --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/hr-system-privacy-config .opencode/skills/hr-system-privacy-config && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hr-system-privacy-config" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hr-system-privacy-config into .opencode/skills/hr-system-privacy-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hr-system-privacy-config", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hr-system-privacy-configConfigures privacy settings for enterprise HR systems including SAP SuccessFactors, Workday, and BambooHR.
Hr System Privacy Config is an agent skill from mukul975/Privacy-Data-Protection-Skills. Configures privacy settings for enterprise HR systems including SAP SuccessFactors, Workday, and BambooHR. Covers role-based access controls, automated data retention enforcement, cross-border transfer configurations, audit logging, data subject rights facilitation, and field-level security. Keywords: HR system, SAP SuccessFactors, Workday, BambooHR, RBAC, retention automation, cross-border transfer, privacy configuration.
Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Backend & APIs, covering Authorization and RBAC, Privacy and GDPR and Recruiting and HR. It works with Workday. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hr System Privacy Config loads about 4.7k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 2,218 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,218 words, ~4,653 tokens.
.claude/skills/hr-system-privacy-config/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Enterprise HR systems are the central repository for employee personal data, processing everything from recruitment to retirement. Systems like SAP SuccessFactors, Workday, and BambooHR contain names, addresses, national identifiers, salary data, performance evaluations, absence records, health-related fitness conclusions, disciplinary records, and benefits information. The default configuration of these systems is designed for operational efficiency, not GDPR compliance. Privacy professionals must actively configure role-based access controls, data retention automation, cross-border transfer settings, audit logging, and field-level security to ensure that the HR system enforces — rather than merely documents — privacy requirements.
This skill provides configuration guidance for the three most widely deployed HR platforms, focusing on the privacy-critical settings that determine who can see what data, how long data is retained, and how data subject rights are facilitated.
Principle: No employee should have access to more HR data than is necessary for their specific role. Line managers need access to their direct reports' data; HR business partners need access to their client group; payroll needs salary and tax data; IT administrators need system access but not data content.
Standard RBAC Matrix:
| Role | Personal Details | Salary/Compensation | Performance Reviews | Absence Records | Health Data | Disciplinary Records | Recruitment Data |
|---|---|---|---|---|---|---|---|
| Employee (self) | Full | Own salary only | Own reviews | Own absence | Own OH reports | Own records | Own application |
| Line Manager | Direct reports: name, contact, role, start date | No (unless approval workflow) | Direct reports only | Direct reports: dates only (no diagnosis) | No | No (unless involved in process) | Hiring manager: interview candidates |
| HR Business Partner | Client group: full | Client group: full | Client group: full | Client group: dates + fit note status | Fit/unfit conclusion only | Client group: full | Client group: all candidates |
| Payroll | Minimal: name, employee ID, bank details, tax code | Full: all employees | No | Statutory sick pay relevant data only | No | No | No |
| Benefits Administrator | Name, employee ID, enrolment selections | Salary bands (for benefits calculation) | No | No | No | No | No |
| IT Administrator | System access management: name, employee ID, department, email | No | No | No | No | No | No |
| DPO | Audit access to all processing records; no routine access to individual data | Audit only | Audit only | Audit only | Audit only | Audit only | Audit only |
| Senior Leadership | Aggregate reports only | Aggregate/anonymised | Aggregate/anonymised | Aggregate/anonymised | No | No | No |
Principle: Data should be automatically deleted or anonymised when the retention period expires. Manual deletion is unreliable and non-compliant.
Standard Retention Schedule for HR Data:
| Data Category | Retention Trigger | Retention Period | Post-Retention Action |
|---|---|---|---|
| Recruitment — unsuccessful candidates | Application decision date | 6 months (12 months where discrimination claim risk) | Delete application, CV, interview notes, assessment scores |
| Employment contract | Termination date | 6 years post-termination (contractual claim limitation) | Delete or archive to restricted storage |
| Payroll and tax records | End of tax year | 6-7 years (varies by jurisdiction) | Delete |
| Performance reviews | Termination date | 2 years post-termination (unless ongoing dispute) | Delete |
| Absence records | End of absence year | 2 years current + 1 year archive | Delete detail; retain aggregate statistics |
| Disciplinary records | Outcome date | Per policy: warnings expire after 6-12 months; dismissal records 6 years | Delete expired warnings; retain dismissal records for limitation period |
| Health/occupational health records | Termination date or end of health surveillance | Varies: standard employment 6 years; occupational health surveillance 40 years (asbestos, radiation) | Transfer to occupational health archive |
| Training records | Termination date | 3 years post-termination | Delete |
| DSAR response records | Response date | 2 years | Delete copies; retain log entry |
For multinational organisations, HR systems transfer employee data across borders. Each transfer must comply with Chapter V GDPR.
Transfer scenarios requiring configuration:
| Scenario | Transfer Mechanism | System Configuration |
|---|---|---|
| EU headquarters → EU subsidiary | No restriction (intra-EEA) | Ensure data residency within EEA data centres |
| EU headquarters → UK subsidiary | UK adequacy decision (valid until June 2025, extended) | Configure UK entity as adequate recipient |
| EU headquarters → US subsidiary | EU-US Data Privacy Framework (where US entity is certified) or SCCs | Verify DPF certification; configure SCC-based transfer if not certified |
| EU entity → cloud HR provider (US-hosted) | DPF + SCCs + supplementary measures | Verify provider DPF status; enable encryption; configure data residency if available |
| EU entity → India/Philippines shared services | SCCs + TIA | Implement SCCs; conduct Transfer Impact Assessment; enable supplementary measures |
Mandatory audit events:
| Event | Log Content | Retention |
|---|---|---|
| Data access | Who accessed which employee's record, when, from where | 2 years |
| Data modification | Who changed what field, old value, new value, when | 2 years |
| Data export | Who exported data, scope, format, destination | 2 years |
| Report generation | Who ran what report, parameters, number of records | 2 years |
| Access permission changes | Who granted/revoked access, to whom, scope | 3 years |
| Data deletion | What was deleted, by whom, automated or manual | Permanent (audit trail survives data deletion) |
| Failed access attempts | Who attempted to access data they were not authorised to see | 1 year |
SuccessFactors uses a Role-Based Permissions (RBP) framework:
SuccessFactors provides a Data Retention Management module:
Workday uses a Security Group model:
Workday business processes (hire, promote, terminate, compensation change) have their own security:
Workday provides Data Purge functionality:
BambooHR uses a simpler access model suitable for small to medium enterprises:
BambooHR provides:
Atlas Manufacturing Group uses SAP SuccessFactors for 2,400 employees across Germany, France, UK, and the Netherlands. The DPO conducted a privacy configuration audit and identified the following issues:
| Authority | Case | Fine/Outcome | Key Issue |
|---|---|---|---|
| LfDI Hamburg (Germany) | H&M, 2020 | EUR 35,258,707.95 | HR system used to record excessive employee health and personal data; insufficient access controls |
| CNIL (France) | Dedalus Biologie, 2022 | EUR 1,500,000 | Insufficient access controls on health data in information systems |
| ICO (UK) | British Airways, 2020 | GBP 20,000,000 | Insufficient technical and organisational measures — includes system access controls |
| AEPD (Spain) | CaixaBank, 2021 | EUR 6,000,000 | Insufficient granularity in access controls for personal data systems |
| Autoriteit Persoonsgegevens (NL) | 2022 Audit | Corrective measures | HR system retained terminated employee data beyond retention period |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/hr-system-privacy-config of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Hr System Privacy Config next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hr System Privacy Config this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | |
| Reviewing Security Architecturebitwarden/ai-plugins | 155 | — | ~2.2k | Automated safety check: Pass | Custom licence | |
| Fondo Security Basicsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Healthcare Phi Complianceaffaan-m/ECC | 277k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| K8s Security PoliciesCybereason-Public/owLSM | 280 | 12 repos | ~2k | Automated safety check: Pass | GPL-2.0 |
bitwarden/ai-plugins
This skill should be used when the user asks to "review the security architecture", "check authentication patterns", "evaluate trust boundaries", "review encryption implementation", "assess…
jeremylongshore/tons-of-skills-marketplace
Apply security best practices for Fondo including OAuth token management, financial data protection, SOC 2 compliance, and access control.
affaan-m/ECC
Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Cybereason-Public/owLSM
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
payloadcms/payload
A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Works with
Categories
Configures privacy settings for enterprise HR systems including SAP SuccessFactors, Workday, and BambooHR. Hr System Privacy Config is an agent skill from mukul975/Privacy-Data-Protection-Skills. Configures privacy settings for enterprise HR systems including SAP SuccessFactors, Workday, and BambooHR.
Hr System Privacy Config fits situations like: tasks that involve Authorization and RBAC; tasks that involve Privacy and GDPR; tasks that involve Recruiting and HR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hr-system-privacy-config -a claude-code`. Or copy the skill folder (skills/privacy/hr-system-privacy-config in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/hr-system-privacy-config in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hr-system-privacy-config -a codex`. Or copy the skill folder (skills/privacy/hr-system-privacy-config in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/hr-system-privacy-config in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hr-system-privacy-config -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hr-system-privacy-config, .gemini/skills/hr-system-privacy-config, .github/skills/hr-system-privacy-config and .opencode/skills/hr-system-privacy-config in your project.
Going by SKILL.md and its folder, Hr System Privacy Config needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Hr System Privacy Config is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Hr System Privacy Config: Reviewing Security Architecture (bitwarden/ai-plugins, 155 stars), Fondo Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Healthcare Phi Compliance (affaan-m/ECC, 277k stars) and Configuring Horizon (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.