Healthcare Phi Compliance
affaan-m/ECC
Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…
Design and implement Purpose-Based Access Control (PBAC) architecture including purpose ontology definition, policy engine configuration, audit logging of purpose verification at query time, and…
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill purpose-based-access -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills purpose-based-access --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/purpose-based-access .claude/skills/purpose-based-access && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "purpose-based-access" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/purpose-based-access into .claude/skills/purpose-based-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "purpose-based-access", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/purpose-based-accessType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill purpose-based-access -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills purpose-based-access --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/purpose-based-access .agents/skills/purpose-based-access && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "purpose-based-access" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/purpose-based-access into .agents/skills/purpose-based-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "purpose-based-access", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill purpose-based-access -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills purpose-based-access --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/purpose-based-access .cursor/skills/purpose-based-access && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "purpose-based-access" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/purpose-based-access into .cursor/skills/purpose-based-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "purpose-based-access", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/purpose-based-access--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill purpose-based-access -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills purpose-based-access --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/purpose-based-access .gemini/skills/purpose-based-access && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "purpose-based-access" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/purpose-based-access into .gemini/skills/purpose-based-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "purpose-based-access", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills purpose-based-accessInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill purpose-based-access -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/purpose-based-access .github/skills/purpose-based-access && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "purpose-based-access" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/purpose-based-access into .github/skills/purpose-based-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "purpose-based-access", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill purpose-based-access -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills purpose-based-access --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/purpose-based-access .opencode/skills/purpose-based-access && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "purpose-based-access" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/purpose-based-access into .opencode/skills/purpose-based-access/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "purpose-based-access", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
purpose-based-accessDesign and implement Purpose-Based Access Control (PBAC) architecture including purpose ontology definition, policy engine configuration, audit logging of purpose verification at query time, and…
Purpose Based Access is an agent skill from mukul975/Privacy-Data-Protection-Skills. Design and implement Purpose-Based Access Control (PBAC) architecture including purpose ontology definition, policy engine configuration, audit logging of purpose verification at query time, and integration with existing IAM systems. Enforces GDPR Article 5(1)(b) purpose limitation technically.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Authorization and RBAC and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Purpose Based Access loads about 3.9k tokens when it runs, and up to ~4.4k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 322 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 322 words, ~3,929 tokens.
.claude/skills/purpose-based-access/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Purpose-Based Access Control (PBAC) extends traditional access control models (RBAC, ABAC) by adding purpose as a mandatory dimension in every access decision. Under PBAC, data access is granted only when the requester can demonstrate a valid, pre-authorized purpose that aligns with the basis under which the data was collected. This directly implements GDPR Article 5(1)(b) purpose limitation, CCPA purpose restrictions, and similar requirements across global privacy regulations.
| Dimension | RBAC | ABAC | PBAC |
|---|---|---|---|
| Access decision based on | Role membership | Attributes (user, resource, environment) | Purpose + attributes |
| Answers the question | "Who can access?" | "Under what conditions?" | "Why is this access needed?" |
| Purpose enforcement | None (implicit) | Possible as attribute | Core requirement |
| Audit trail | Who accessed what | Who, what, when, where | Who, what, when, where, WHY |
| Privacy alignment | Low | Medium | High |
| Consent integration | None | Possible | Native |
Root Purpose
├── Service Delivery
│ ├── Order Fulfillment
│ │ ├── Payment Processing
│ │ ├── Shipping Logistics
│ │ └── Order Confirmation
│ ├── Account Management
│ │ ├── Account Creation
│ │ ├── Account Maintenance
│ │ └── Account Recovery
│ └── Customer Support
│ ├── Ticket Resolution
│ └── Escalation Handling
├── Legal Compliance
│ ├── Regulatory Reporting
│ │ ├── Tax Reporting
│ │ ├── AML Compliance
│ │ └── Regulatory Audit
│ ├── Data Subject Rights
│ │ ├── Access Request
│ │ ├── Deletion Request
│ │ ├── Portability Request
│ │ └── Rectification Request
│ └── Litigation Hold
├── Analytics
│ ├── Product Analytics
│ │ ├── Feature Usage Analysis
│ │ └── UX Research
│ ├── Business Intelligence
│ │ ├── Revenue Reporting
│ │ └── Forecasting
│ └── Aggregate Reporting
│ ├── Board Reporting
│ └── Investor Reporting
├── Marketing
│ ├── Direct Marketing
│ │ ├── Email Campaigns
│ │ └── Personalized Offers
│ ├── Market Research
│ │ └── Survey Analysis
│ └── Advertising
│ ├── Audience Segmentation
│ └── Campaign Measurement
└── Security
├── Fraud Detection
├── Incident Investigation
└── Access Auditingfrom dataclasses import dataclass, field
from enum import Enum
from datetime import datetime
class LegalBasis(Enum):
CONSENT = "consent"
CONTRACT = "contract"
LEGAL_OBLIGATION = "legal_obligation"
VITAL_INTEREST = "vital_interest"
PUBLIC_INTEREST = "public_interest"
LEGITIMATE_INTEREST = "legitimate_interest"
class PurposeStatus(Enum):
ACTIVE = "active"
DEPRECATED = "deprecated"
PENDING_APPROVAL = "pending_approval"
@dataclass
class Purpose:
purpose_id: str
name: str
description: str
parent_purpose_id: str | None
legal_bases: list[LegalBasis]
data_categories_allowed: list[str]
retention_period_days: int
requires_consent: bool
status: PurposeStatus
owner: str
created_date: datetime
review_date: datetime
jurisdictions: list[str] = field(default_factory=lambda: ["global"])
compatible_purposes: list[str] = field(default_factory=list)
incompatible_purposes: list[str] = field(default_factory=list)Access Request
|
v
+-------------------+
| Request Parser |
| - Identity (who) |
| - Resource (what) |
| - Action (how) |
| - Purpose (why) |
| - Context (when/ |
| where) |
+-------------------+
|
v
+-------------------+ +--------------------+
| Purpose Validator |---->| Purpose Registry |
| - Purpose exists | | - Ontology tree |
| - Purpose active | | - Legal bases |
| - Purpose applies | | - Data categories |
| to data category| +--------------------+
+-------------------+
|
v
+-------------------+ +--------------------+
| Consent Checker |---->| Consent Store |
| - Consent exists | | - Data subject |
| - Consent active | | preferences |
| - Scope matches | | - Consent records |
+-------------------+ +--------------------+
|
v
+-------------------+ +--------------------+
| ABAC Policy |---->| Policy Repository |
| Evaluator | | - XACML policies |
| - Role check | | - Purpose-data |
| - Attribute check | | mappings |
| - Environment check| +--------------------+
+-------------------+
|
v
+-------------------+
| Decision Engine |
| - PERMIT / DENY |
| - Obligations |
| - Advice |
+-------------------+
|
+------+-------+
| |
v v
PERMIT DENY
+ Audit Log + Audit Log
+ Obligations + Denial Reason"""
Purpose-Based Access Control policy engine.
Evaluates access requests against purpose definitions,
consent records, and attribute-based policies.
"""
from dataclasses import dataclass
from datetime import datetime
from enum import Enum
from typing import Optional
class Decision(Enum):
PERMIT = "PERMIT"
DENY = "DENY"
@dataclass
class AccessRequest:
requester_id: str
requester_roles: list[str]
resource_id: str
data_category: str
action: str # read, write, delete, export
purpose_id: str
data_subject_id: Optional[str]
timestamp: datetime
source_ip: str
justification: str
@dataclass
class AccessDecision:
decision: Decision
reason: str
obligations: list[str]
request: AccessRequest
evaluated_at: datetime
policy_version: str
class PurposeBasedAccessController:
"""
Core PBAC engine that evaluates access requests against
purpose definitions, consent records, and organizational policies.
"""
def __init__(
self,
purpose_registry,
consent_store,
policy_repository,
audit_logger
):
self.purpose_registry = purpose_registry
self.consent_store = consent_store
self.policy_repository = policy_repository
self.audit_logger = audit_logger
def evaluate(self, request: AccessRequest) -> AccessDecision:
"""
Evaluate an access request through the PBAC pipeline.
Pipeline stages:
1. Purpose validation
2. Consent verification
3. Attribute-based policy evaluation
4. Decision with obligations
"""
now = datetime.utcnow()
# Stage 1: Validate purpose
purpose = self.purpose_registry.get_purpose(request.purpose_id)
if purpose is None:
return self._deny(request, "Purpose not found in registry", now)
if purpose.status != PurposeStatus.ACTIVE:
return self._deny(request, f"Purpose is {purpose.status.value}", now)
if request.data_category not in purpose.data_categories_allowed:
return self._deny(
request,
f"Data category '{request.data_category}' not allowed for purpose '{purpose.name}'",
now
)
# Stage 2: Verify consent (if required)
if purpose.requires_consent and request.data_subject_id:
consent = self.consent_store.get_active_consent(
data_subject_id=request.data_subject_id,
purpose_id=request.purpose_id
)
if consent is None:
return self._deny(
request,
f"No active consent for purpose '{purpose.name}' from data subject",
now
)
# Stage 3: Evaluate attribute-based policies
policy_result = self.policy_repository.evaluate(
roles=request.requester_roles,
resource=request.resource_id,
action=request.action,
purpose=request.purpose_id,
data_category=request.data_category,
context={"source_ip": request.source_ip, "time": now}
)
if not policy_result.permitted:
return self._deny(request, policy_result.denial_reason, now)
# Stage 4: Permit with obligations
obligations = self._determine_obligations(purpose, request)
decision = AccessDecision(
decision=Decision.PERMIT,
reason=f"Access permitted for purpose '{purpose.name}'",
obligations=obligations,
request=request,
evaluated_at=now,
policy_version=self.policy_repository.version
)
self.audit_logger.log_access_decision(decision)
return decision
def _deny(
self, request: AccessRequest, reason: str, timestamp: datetime
) -> AccessDecision:
"""Create a DENY decision and log it."""
decision = AccessDecision(
decision=Decision.DENY,
reason=reason,
obligations=[],
request=request,
evaluated_at=timestamp,
policy_version=self.policy_repository.version
)
self.audit_logger.log_access_decision(decision)
return decision
def _determine_obligations(self, purpose, request: AccessRequest) -> list[str]:
"""Determine post-access obligations based on purpose and context."""
obligations = []
if request.action == "export":
obligations.append("LOG_DATA_EXPORT")
obligations.append("APPLY_ENCRYPTION_TO_EXPORT")
if request.action == "read" and request.data_category in [
"health_data", "financial_data", "biometric_data"
]:
obligations.append("MASK_SENSITIVE_FIELDS")
obligations.append(f"ENFORCE_RETENTION_{purpose.retention_period_days}_DAYS")
obligations.append("LOG_PURPOSE_USAGE")
return obligations"""
SQL proxy that intercepts database queries and enforces
purpose-based access control at the query level.
"""
import re
from datetime import datetime
class PurposeAwareSQLProxy:
"""
Intercepts SQL queries, validates purpose, and rewrites
queries to enforce data category restrictions.
"""
def __init__(self, pbac_controller, column_category_map: dict):
self.pbac = pbac_controller
self.column_category_map = column_category_map
def execute_query(
self,
sql: str,
requester_id: str,
requester_roles: list[str],
purpose_id: str,
justification: str
) -> tuple[bool, object]:
"""
Execute a SQL query with purpose verification.
Returns (success, result_or_error).
"""
# Parse referenced columns/tables from SQL
referenced_columns = self._extract_columns(sql)
referenced_categories = set()
for col in referenced_columns:
category = self.column_category_map.get(col, "general")
referenced_categories.add(category)
# Validate access for each data category
denied_categories = []
for category in referenced_categories:
request = AccessRequest(
requester_id=requester_id,
requester_roles=requester_roles,
resource_id="database",
data_category=category,
action="read",
purpose_id=purpose_id,
data_subject_id=None,
timestamp=datetime.utcnow(),
source_ip="internal",
justification=justification
)
decision = self.pbac.evaluate(request)
if decision.decision == Decision.DENY:
denied_categories.append((category, decision.reason))
if denied_categories:
reasons = "; ".join(
f"{cat}: {reason}" for cat, reason in denied_categories
)
return (False, f"Access denied for categories: {reasons}")
# Rewrite query to mask unauthorized columns if needed
rewritten_sql = self._apply_column_masking(sql, purpose_id)
# Execute the rewritten query (actual DB execution would go here)
return (True, rewritten_sql)
def _extract_columns(self, sql: str) -> list[str]:
"""Extract column references from SQL (simplified parser)."""
select_pattern = re.compile(
r"SELECT\s+(.+?)\s+FROM", re.IGNORECASE | re.DOTALL
)
match = select_pattern.search(sql)
if not match:
return []
columns_str = match.group(1)
if columns_str.strip() == "*":
return list(self.column_category_map.keys())
columns = [
col.strip().split(".")[-1].split(" ")[0]
for col in columns_str.split(",")
]
return columns
def _apply_column_masking(self, sql: str, purpose_id: str) -> str:
"""Rewrite query to mask columns not needed for the given purpose."""
return sql # Production implementation would rewrite SELECT columns| Field | Type | Description |
|---|---|---|
| audit_id | UUID | Unique audit record identifier |
| timestamp | DateTime | When the access decision was made |
| requester_id | String | Identity of the requester |
| requester_roles | Array[String] | Roles held by requester |
| resource_id | String | Resource being accessed |
| data_category | String | Category of data being accessed |
| action | String | Type of access (read/write/delete/export) |
| purpose_id | String | Stated purpose for access |
| purpose_name | String | Human-readable purpose name |
| decision | Enum | PERMIT or DENY |
| denial_reason | String | Reason for denial (if denied) |
| obligations | Array[String] | Post-access obligations applied |
| justification | String | Free-text justification from requester |
| policy_version | String | Version of policy used for decision |
Existing IAM (RBAC/ABAC)
|
v
+---------------------------+
| PBAC Middleware Layer |
| (intercepts access calls) |
+---------------------------+
|
+-- Purpose verification
+-- Consent validation
+-- Data category mapping
+-- Obligation enforcement
+-- Enhanced audit logging
|
v
Resource (Database / API / File System)© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/purpose-based-access of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Purpose Based Access next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Purpose Based Access this skillmukul975/Privacy-Data-Protection-Skills | 295 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Healthcare Phi Complianceaffaan-m/ECC | 274k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 939 | 1 repos | ~4.2k | Automated safety check: Pass | MIT | |
| Tos Clause Scannerzebbern/claude-code-guide | 4.6k | 1 repos | ~3.3k | Automated safety check: Pass | MIT | |
| Reidentifying Textmaziyarpanahi/openmed | 5.5k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Policy OpaAgentSecOps/SecOpsAgentKit | 219 | 1 repos | ~3.5k | Automated safety check: Pass | Custom licence |
affaan-m/ECC
Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…
zebbern/claude-code-guide
Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues.
maziyarpanahi/openmed
Reversibly de-identify clinical text with OpenMed and later restore the original PHI from a saved mapping.
AgentSecOps/SecOpsAgentKit
Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).
qualixar/superlocalmemory
Enterprise compliance and governed workspace behavior for SuperLocalMemory.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
mukul975/Privacy-Data-Protection-Skills
Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.
Categories
Design and implement Purpose-Based Access Control (PBAC) architecture including purpose ontology definition, policy engine configuration, audit logging of purpose verification at query time, and…. Purpose Based Access is an agent skill from mukul975/Privacy-Data-Protection-Skills. Design and implement Purpose-Based Access Control (PBAC) architecture including purpose ontology definition, policy engine configuration, audit logging of purpose verification at query time, and integration with existing IAM systems.
Purpose Based Access fits situations like: tasks that involve Authorization and RBAC; tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill purpose-based-access -a claude-code`. Or copy the skill folder (skills/privacy/purpose-based-access in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/purpose-based-access in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill purpose-based-access -a codex`. Or copy the skill folder (skills/privacy/purpose-based-access in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/purpose-based-access in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill purpose-based-access -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/purpose-based-access, .gemini/skills/purpose-based-access, .github/skills/purpose-based-access and .opencode/skills/purpose-based-access in your project.
Going by SKILL.md and its folder, Purpose Based Access needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Purpose Based Access is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 492 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Purpose Based Access: Healthcare Phi Compliance (affaan-m/ECC, 274k stars), Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars), Tos Clause Scanner (zebbern/claude-code-guide, 4.6k stars) and Reidentifying Text (maziyarpanahi/openmed, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.