API Design
WrongStack/WrongStack
A skill your agent uses when designing, implementing, or reviewing an HTTP API — endpoints, request and response shapes, errors, pagination, versioning, and authorization.
Design privacy API patterns including data subject API for DSAR endpoints, consent API for preference management, deletion API with cascading delete orchestration, and audit API for compliance…
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-api-design -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-api-design --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/privacy-api-design .claude/skills/privacy-api-design && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "privacy-api-design" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-api-design into .claude/skills/privacy-api-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-api-design", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-api-designType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-api-design -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-api-design --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/privacy-api-design .agents/skills/privacy-api-design && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "privacy-api-design" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-api-design into .agents/skills/privacy-api-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-api-design", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-api-design -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-api-design --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/privacy-api-design .cursor/skills/privacy-api-design && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "privacy-api-design" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-api-design into .cursor/skills/privacy-api-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-api-design", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/privacy-api-design--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-api-design -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-api-design --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/privacy-api-design .gemini/skills/privacy-api-design && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "privacy-api-design" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-api-design into .gemini/skills/privacy-api-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-api-design", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-api-designInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-api-design -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/privacy-api-design .github/skills/privacy-api-design && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "privacy-api-design" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-api-design into .github/skills/privacy-api-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-api-design", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-api-design -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills privacy-api-design --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/privacy-api-design .opencode/skills/privacy-api-design && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "privacy-api-design" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/privacy-api-design into .opencode/skills/privacy-api-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-api-design", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
privacy-api-designDesign privacy API patterns including data subject API for DSAR endpoints, consent API for preference management, deletion API with cascading delete orchestration, and audit API for compliance…
Privacy API Design is an agent skill from mukul975/Privacy-Data-Protection-Skills. Design privacy API patterns including data subject API for DSAR endpoints, consent API for preference management, deletion API with cascading delete orchestration, and audit API for compliance reporting. Provides OpenAPI specifications, error handling, rate limiting, and authentication patterns.
Its SKILL.md is about 7.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Backend & APIs, covering Privacy and GDPR, API design and OpenAPI specifications. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
auth.cipherengineeringlabs.comapi.cipherengineeringlabs.comsupport.cipherengineeringlabs.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Privacy API Design loads about 7.1k tokens when it runs, and up to ~7.7k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 194 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 194 words, ~7,124 tokens.
.claude/skills/privacy-api-design/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Privacy APIs provide programmatic interfaces for data subject rights exercise, consent management, data deletion, and audit logging. Well-designed privacy APIs enable organizations to automate compliance workflows, integrate with consent management platforms, and provide data subjects with self-service privacy controls. This skill covers API design patterns, OpenAPI specifications, authentication, and error handling for privacy-critical endpoints.
External Consumers Privacy API Gateway Backend Services
+------------------+ +--------------------+ +------------------+
| Data Subject App |----HTTPS/TLS--->| Authentication | | DSAR Service |
+------------------+ | Rate Limiting |----internal---->| Consent Service |
| Request Validation | | Deletion Service |
+------------------+ | Audit Logging | | Audit Service |
| Partner Portal |----HTTPS/TLS--->| Versioning | | Identity Service |
+------------------+ +--------------------+ +------------------+
|
+------------------+ v
| Internal Systems |----mTLS-------->+--------------------+
+------------------+ | Privacy Event Bus |
| (async processing) |
+--------------------+openapi: 3.1.0
info:
title: Cipher Engineering Labs - Data Subject Rights API
version: 1.0.0
description: >
API for data subjects to exercise their privacy rights under GDPR,
CCPA/CPRA, and other applicable privacy regulations.
contact:
name: Privacy Engineering Team
email: privacy-engineering@cipherengineeringlabs.com
servers:
- url: https://api.cipherengineeringlabs.com/privacy/v1
description: Production
security:
- BearerAuth: []
- OAuth2: [dsar:read, dsar:write]
paths:
/dsar/requests:
post:
operationId: createDSARRequest
summary: Submit a new data subject access request
tags: [DSAR]
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/DSARCreateRequest'
responses:
'202':
description: Request accepted for processing
content:
application/json:
schema:
$ref: '#/components/schemas/DSARResponse'
headers:
X-Request-ID:
schema:
type: string
format: uuid
Location:
schema:
type: string
format: uri
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'429':
$ref: '#/components/responses/RateLimited'
get:
operationId: listDSARRequests
summary: List data subject's own requests
tags: [DSAR]
parameters:
- name: status
in: query
schema:
type: string
enum: [pending, in_progress, completed, rejected]
- name: type
in: query
schema:
type: string
enum: [access, deletion, portability, rectification, restriction, objection]
- name: page
in: query
schema:
type: integer
minimum: 1
default: 1
- name: per_page
in: query
schema:
type: integer
minimum: 1
maximum: 100
default: 20
responses:
'200':
description: List of DSAR requests
content:
application/json:
schema:
$ref: '#/components/schemas/DSARListResponse'
/dsar/requests/{requestId}:
get:
operationId: getDSARRequest
summary: Get status and details of a specific DSAR
tags: [DSAR]
parameters:
- name: requestId
in: path
required: true
schema:
type: string
format: uuid
responses:
'200':
description: DSAR details
content:
application/json:
schema:
$ref: '#/components/schemas/DSARDetailResponse'
'404':
$ref: '#/components/responses/NotFound'
/dsar/requests/{requestId}/download:
get:
operationId: downloadDSARData
summary: Download the data package for a completed access request
tags: [DSAR]
parameters:
- name: requestId
in: path
required: true
schema:
type: string
format: uuid
responses:
'200':
description: Data package download
content:
application/zip:
schema:
type: string
format: binary
headers:
Content-Disposition:
schema:
type: string
'404':
$ref: '#/components/responses/NotFound'
'410':
description: Download link has expired
components:
schemas:
DSARCreateRequest:
type: object
required:
- requestType
- email
- identityVerification
properties:
requestType:
type: string
enum: [access, deletion, portability, rectification, restriction, objection]
description: Type of data subject right being exercised
email:
type: string
format: email
description: Email address associated with the account
identityVerification:
type: object
properties:
method:
type: string
enum: [account_login, email_verification, document_upload]
verificationToken:
type: string
required: [method]
details:
type: string
maxLength: 2000
description: Additional details about the request
dataCategories:
type: array
items:
type: string
enum: [profile, transactions, communications, analytics, marketing, all]
description: Specific data categories (for access/portability)
rectificationData:
type: object
additionalProperties: true
description: Corrected data values (for rectification requests)
preferredFormat:
type: string
enum: [json, csv, pdf]
default: json
description: Preferred data export format (for access/portability)
DSARResponse:
type: object
properties:
requestId:
type: string
format: uuid
status:
type: string
enum: [pending, identity_verification, in_progress, completed, rejected]
requestType:
type: string
submittedAt:
type: string
format: date-time
estimatedCompletionDate:
type: string
format: date-time
regulatoryDeadline:
type: string
format: date-time
description: Maximum date by which response must be provided
DSARDetailResponse:
allOf:
- $ref: '#/components/schemas/DSARResponse'
- type: object
properties:
statusHistory:
type: array
items:
type: object
properties:
status:
type: string
timestamp:
type: string
format: date-time
note:
type: string
downloadAvailable:
type: boolean
downloadExpiresAt:
type: string
format: date-time
DSARListResponse:
type: object
properties:
data:
type: array
items:
$ref: '#/components/schemas/DSARResponse'
pagination:
$ref: '#/components/schemas/Pagination'
Pagination:
type: object
properties:
page:
type: integer
perPage:
type: integer
totalPages:
type: integer
totalItems:
type: integer
responses:
BadRequest:
description: Invalid request parameters
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
Unauthorized:
description: Authentication required
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
NotFound:
description: Resource not found
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
RateLimited:
description: Rate limit exceeded
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
headers:
Retry-After:
schema:
type: integer
X-RateLimit-Limit:
schema:
type: integer
X-RateLimit-Remaining:
schema:
type: integer
securitySchemes:
BearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
OAuth2:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://auth.cipherengineeringlabs.com/oauth2/authorize
tokenUrl: https://auth.cipherengineeringlabs.com/oauth2/token
scopes:
dsar:read: Read DSAR request status
dsar:write: Submit DSAR requests
consent:read: Read consent preferences
consent:write: Update consent preferences
audit:read: Read audit logspaths:
/consent/preferences:
get:
operationId: getConsentPreferences
summary: Get current consent preferences for the authenticated user
tags: [Consent]
responses:
'200':
description: Current consent preferences
content:
application/json:
schema:
type: object
properties:
subjectId:
type: string
preferences:
type: array
items:
$ref: '#/components/schemas/ConsentPreference'
lastUpdated:
type: string
format: date-time
put:
operationId: updateConsentPreferences
summary: Update consent preferences (bulk update)
tags: [Consent]
requestBody:
required: true
content:
application/json:
schema:
type: object
required: [preferences]
properties:
preferences:
type: array
items:
type: object
required: [purposeId, granted]
properties:
purposeId:
type: string
granted:
type: boolean
channels:
type: array
items:
type: string
enum: [email, sms, push, phone, postal]
responses:
'200':
description: Preferences updated
content:
application/json:
schema:
type: object
properties:
updated:
type: array
items:
$ref: '#/components/schemas/ConsentPreference'
consentReceiptId:
type: string
format: uuid
description: ID of the issued consent receipt
/consent/purposes:
get:
operationId: listConsentPurposes
summary: List all available consent purposes
tags: [Consent]
responses:
'200':
description: List of consent purposes
content:
application/json:
schema:
type: object
properties:
purposes:
type: array
items:
type: object
properties:
purposeId:
type: string
name:
type: string
description:
type: string
category:
type: string
enum: [essential, functional, analytics, marketing]
mandatory:
type: boolean
defaultState:
type: boolean
dataCategories:
type: array
items:
type: string
/consent/receipts/{receiptId}:
get:
operationId: getConsentReceipt
summary: Retrieve a specific consent receipt
tags: [Consent]
parameters:
- name: receiptId
in: path
required: true
schema:
type: string
format: uuid
responses:
'200':
description: Consent receipt
content:
application/json:
schema:
$ref: '#/components/schemas/ConsentReceipt'"""
Privacy deletion API with cascading delete orchestration.
Handles deletion requests across multiple backend services
with verification and audit logging.
"""
from dataclasses import dataclass, field
from datetime import datetime, timezone
from enum import Enum
from typing import Optional
import uuid
class DeletionStatus(Enum):
PENDING = "pending"
IN_PROGRESS = "in_progress"
PARTIALLY_COMPLETED = "partially_completed"
COMPLETED = "completed"
FAILED = "failed"
VERIFIED = "verified"
class ServiceDeletionStatus(Enum):
PENDING = "pending"
IN_PROGRESS = "in_progress"
COMPLETED = "completed"
FAILED = "failed"
SKIPPED = "skipped" # For legally exempt data
@dataclass
class DeletionTarget:
service_name: str
data_categories: list[str]
priority: int # Lower number = delete first
legal_hold_check: bool = True
retention_exempt: bool = False # True if data must be retained (e.g., tax records)
@dataclass
class ServiceDeletionResult:
service_name: str
status: ServiceDeletionStatus
records_deleted: int
records_retained: int
retention_reason: Optional[str]
completed_at: Optional[datetime]
error_message: Optional[str]
@dataclass
class DeletionRequest:
request_id: str
subject_id: str
status: DeletionStatus
created_at: datetime
scope: list[str] # Data categories to delete
exclude: list[str] # Data categories exempt from deletion
service_results: list[ServiceDeletionResult] = field(default_factory=list)
verified_at: Optional[datetime] = None
verification_method: Optional[str] = None
class CascadingDeletionOrchestrator:
"""
Orchestrate data deletion across multiple backend services
in the correct order, handling dependencies, legal holds,
and retention requirements.
"""
def __init__(self, service_registry: list[DeletionTarget], audit_logger):
self.targets = sorted(service_registry, key=lambda t: t.priority)
self.audit = audit_logger
def execute_deletion(
self,
subject_id: str,
scope: list[str],
exclude: list[str] = None
) -> DeletionRequest:
"""
Execute cascading deletion across all registered services.
Args:
subject_id: The data subject whose data should be deleted
scope: Data categories to delete (or ["all"])
exclude: Data categories to exclude from deletion
Returns:
DeletionRequest with results from each service
"""
exclude = exclude or []
request = DeletionRequest(
request_id=str(uuid.uuid4()),
subject_id=subject_id,
status=DeletionStatus.IN_PROGRESS,
created_at=datetime.now(timezone.utc),
scope=scope,
exclude=exclude
)
self.audit.log_deletion_start(request)
for target in self.targets:
# Skip if data category not in scope
if "all" not in scope:
relevant_categories = set(target.data_categories) & set(scope)
if not relevant_categories:
continue
# Skip if explicitly excluded
if set(target.data_categories) & set(exclude):
result = ServiceDeletionResult(
service_name=target.service_name,
status=ServiceDeletionStatus.SKIPPED,
records_deleted=0,
records_retained=0,
retention_reason="Excluded by request",
completed_at=datetime.now(timezone.utc),
error_message=None
)
request.service_results.append(result)
continue
# Check retention exemptions
if target.retention_exempt:
result = ServiceDeletionResult(
service_name=target.service_name,
status=ServiceDeletionStatus.SKIPPED,
records_deleted=0,
records_retained=0,
retention_reason="Legal retention requirement",
completed_at=datetime.now(timezone.utc),
error_message=None
)
request.service_results.append(result)
continue
# Check legal holds
if target.legal_hold_check:
hold = self._check_legal_hold(subject_id, target.service_name)
if hold:
result = ServiceDeletionResult(
service_name=target.service_name,
status=ServiceDeletionStatus.SKIPPED,
records_deleted=0,
records_retained=0,
retention_reason=f"Legal hold: {hold}",
completed_at=datetime.now(timezone.utc),
error_message=None
)
request.service_results.append(result)
continue
# Execute deletion for this service
result = self._delete_from_service(subject_id, target)
request.service_results.append(result)
# Determine overall status
statuses = [r.status for r in request.service_results]
if all(s in (ServiceDeletionStatus.COMPLETED, ServiceDeletionStatus.SKIPPED) for s in statuses):
request.status = DeletionStatus.COMPLETED
elif any(s == ServiceDeletionStatus.FAILED for s in statuses):
request.status = DeletionStatus.PARTIALLY_COMPLETED
else:
request.status = DeletionStatus.COMPLETED
self.audit.log_deletion_complete(request)
return request
def verify_deletion(self, request: DeletionRequest) -> DeletionRequest:
"""
Verify that data was actually deleted from all services.
Run after deletion to confirm no data remnants exist.
"""
for result in request.service_results:
if result.status == ServiceDeletionStatus.COMPLETED:
# Attempt to query for the subject's data
remaining = self._check_data_exists(
request.subject_id, result.service_name
)
if remaining > 0:
result.status = ServiceDeletionStatus.FAILED
result.error_message = f"Verification failed: {remaining} records still exist"
request.verified_at = datetime.now(timezone.utc)
request.verification_method = "post_deletion_query"
all_verified = all(
r.status in (ServiceDeletionStatus.COMPLETED, ServiceDeletionStatus.SKIPPED)
for r in request.service_results
)
request.status = DeletionStatus.VERIFIED if all_verified else DeletionStatus.PARTIALLY_COMPLETED
self.audit.log_deletion_verification(request)
return request
def _check_legal_hold(self, subject_id: str, service: str) -> Optional[str]:
"""Check if any legal hold applies to this subject's data."""
# Integration point with legal hold management system
return None # Override in production with actual legal hold check
def _delete_from_service(
self, subject_id: str, target: DeletionTarget
) -> ServiceDeletionResult:
"""Execute deletion against a specific backend service."""
# Integration point with actual backend service deletion API
return ServiceDeletionResult(
service_name=target.service_name,
status=ServiceDeletionStatus.COMPLETED,
records_deleted=0,
records_retained=0,
retention_reason=None,
completed_at=datetime.now(timezone.utc),
error_message=None
)
def _check_data_exists(self, subject_id: str, service: str) -> int:
"""Check if data still exists for a subject in a service."""
# Integration point with service data existence check
return 0paths:
/audit/events:
get:
operationId: queryAuditEvents
summary: Query privacy audit events
tags: [Audit]
security:
- OAuth2: [audit:read]
parameters:
- name: subjectId
in: query
schema:
type: string
- name: eventType
in: query
schema:
type: string
enum: [data_access, consent_change, deletion, dsar_submitted, dsar_completed, breach_detected]
- name: startDate
in: query
required: true
schema:
type: string
format: date-time
- name: endDate
in: query
required: true
schema:
type: string
format: date-time
- name: actorId
in: query
schema:
type: string
- name: page
in: query
schema:
type: integer
default: 1
- name: perPage
in: query
schema:
type: integer
default: 50
maximum: 200
responses:
'200':
description: Audit events
content:
application/json:
schema:
type: object
properties:
events:
type: array
items:
type: object
properties:
eventId:
type: string
format: uuid
eventType:
type: string
timestamp:
type: string
format: date-time
actorId:
type: string
actorType:
type: string
enum: [user, system, admin, api_client]
subjectId:
type: string
resource:
type: string
action:
type: string
purpose:
type: string
outcome:
type: string
enum: [success, failure, denied]
details:
type: object
pagination:
$ref: '#/components/schemas/Pagination'
/audit/reports/compliance:
get:
operationId: getComplianceReport
summary: Generate compliance audit report for a date range
tags: [Audit]
parameters:
- name: startDate
in: query
required: true
schema:
type: string
format: date
- name: endDate
in: query
required: true
schema:
type: string
format: date
- name: format
in: query
schema:
type: string
enum: [json, pdf, csv]
default: json
responses:
'200':
description: Compliance report
content:
application/json:
schema:
type: object
properties:
reportId:
type: string
generatedAt:
type: string
format: date-time
period:
type: object
properties:
start:
type: string
end:
type: string
summary:
type: object
properties:
totalDataAccesses:
type: integer
totalConsentChanges:
type: integer
totalDeletions:
type: integer
totalDSARs:
type: integer
accessDenials:
type: integer
policyViolations:
type: integer| Endpoint Category | Auth Method | Scopes Required | Rate Limit |
|---|---|---|---|
| DSAR (data subject) | OAuth2 PKCE / JWT | dsar:read, dsar:write | 10 req/min |
| DSAR (admin) | OAuth2 Client Credentials | dsar:admin | 100 req/min |
| Consent (data subject) | OAuth2 PKCE / JWT | consent:read, consent:write | 30 req/min |
| Deletion (internal) | mTLS + API key | deletion:execute | 5 req/min |
| Audit (compliance) | OAuth2 Client Credentials | audit:read | 50 req/min |
{
"error": {
"code": "PRIVACY_001",
"type": "identity_verification_required",
"message": "Identity verification is required before processing this request",
"details": {
"verificationMethods": ["email_verification", "document_upload"],
"supportUrl": "https://support.cipherengineeringlabs.com/privacy"
},
"requestId": "req_a1b2c3d4",
"timestamp": "2026-03-14T10:30:00.000Z"
}
}© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/privacy-api-design of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Privacy API Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Privacy API Design this skillmukul975/Privacy-Data-Protection-Skills | 295 | — | ~7.1k | Automated safety check: Pass | Apache-2.0 | |
| API DesignWrongStack/WrongStack | 370 | — | ~1.3k | Automated safety check: Pass | MIT | |
| API Architectcuriositech/some_claude_skills | 243 | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| API Patternssoftspark/ai-toolkit | 179 | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | |
| API ForgeEliasOulkadi/shokunin | 114 | — | ~2.9k | Automated safety check: Pass | MIT | |
| API Designmajiayu000/claude-skill-registry | 666 | 1 repos | ~542 | Automated safety check: Pass | MIT |
WrongStack/WrongStack
A skill your agent uses when designing, implementing, or reviewing an HTTP API — endpoints, request and response shapes, errors, pagination, versioning, and authorization.
curiositech/some_claude_skills
Expert API designer for REST, GraphQL, gRPC architectures. An agent skill from curiositech/some_claude_skills.
softspark/ai-toolkit
API design: naming, versioning, pagination, idempotency, OpenAPI, error contracts and safe retries.
EliasOulkadi/shokunin
Design REST/GraphQL APIs with OpenAPI 3.1, error handling, pagination, rate limiting, webhooks, and idempotency.
majiayu000/claude-skill-registry
Expert at designing clean, consistent, and developer-friendly APIs.
Jeffallan/claude-skills
Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
mukul975/Privacy-Data-Protection-Skills
Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.
Categories
Design privacy API patterns including data subject API for DSAR endpoints, consent API for preference management, deletion API with cascading delete orchestration, and audit API for compliance…. Privacy API Design is an agent skill from mukul975/Privacy-Data-Protection-Skills. Design privacy API patterns including data subject API for DSAR endpoints, consent API for preference management, deletion API with cascading delete orchestration, and audit API for compliance reporting.
Privacy API Design fits situations like: tasks that involve Privacy and GDPR; tasks that involve API design; tasks that involve OpenAPI specifications.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-api-design -a claude-code`. Or copy the skill folder (skills/privacy/privacy-api-design in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/privacy-api-design in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-api-design -a codex`. Or copy the skill folder (skills/privacy/privacy-api-design in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/privacy-api-design in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill privacy-api-design -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-api-design, .gemini/skills/privacy-api-design, .github/skills/privacy-api-design and .opencode/skills/privacy-api-design in your project.
Going by SKILL.md and its folder, Privacy API Design needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md names 3 domains. In commands or code: auth.cipherengineeringlabs.com, api.cipherengineeringlabs.com and support.cipherengineeringlabs.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Privacy API Design is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 7.1k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 588 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Privacy API Design: API Design (WrongStack/WrongStack, 370 stars), API Architect (curiositech/some_claude_skills, 243 stars), API Patterns (softspark/ai-toolkit, 179 stars) and API Forge (EliasOulkadi/shokunin, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.