Fmx Respond
kunchenguid/firstmate
Agent-only playbook for handling Relay mentions and follow-ups.
SaaS vendor data processing inventory management. An agent skill from mukul975/Privacy-Data-Protection-Skills.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills saas-vendor-inventory --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/saas-vendor-inventory .claude/skills/saas-vendor-inventory && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "saas-vendor-inventory" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/saas-vendor-inventory into .claude/skills/saas-vendor-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saas-vendor-inventory", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/saas-vendor-inventoryType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills saas-vendor-inventory --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/saas-vendor-inventory .agents/skills/saas-vendor-inventory && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "saas-vendor-inventory" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/saas-vendor-inventory into .agents/skills/saas-vendor-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saas-vendor-inventory", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills saas-vendor-inventory --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/saas-vendor-inventory .cursor/skills/saas-vendor-inventory && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "saas-vendor-inventory" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/saas-vendor-inventory into .cursor/skills/saas-vendor-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saas-vendor-inventory", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/saas-vendor-inventory--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills saas-vendor-inventory --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/saas-vendor-inventory .gemini/skills/saas-vendor-inventory && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "saas-vendor-inventory" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/saas-vendor-inventory into .gemini/skills/saas-vendor-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saas-vendor-inventory", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills saas-vendor-inventoryInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/saas-vendor-inventory .github/skills/saas-vendor-inventory && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "saas-vendor-inventory" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/saas-vendor-inventory into .github/skills/saas-vendor-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saas-vendor-inventory", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills saas-vendor-inventory --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/saas-vendor-inventory .opencode/skills/saas-vendor-inventory && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "saas-vendor-inventory" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/saas-vendor-inventory into .opencode/skills/saas-vendor-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saas-vendor-inventory", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
saas-vendor-inventorySaaS vendor data processing inventory management. An agent skill from mukul975/Privacy-Data-Protection-Skills.
SaaS Vendor Inventory is an agent skill from mukul975/Privacy-Data-Protection-Skills. SaaS vendor data processing inventory management. Covers shadow IT discovery, API-based data flow detection, processing purpose mapping, contract status tracking, and continuous inventory reconciliation for cloud service providers.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Business, Finance & HR, covering Accounting and bookkeeping, Project management and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
SaaS Vendor Inventory loads about 2.3k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 920 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 920 words, ~2,259 tokens.
.claude/skills/saas-vendor-inventory/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Modern organizations rely on dozens to hundreds of SaaS applications, many of which process personal data. GDPR Article 30 requires controllers to maintain records of processing activities, which includes documenting all processors. Shadow IT — SaaS applications adopted by business units without formal procurement or privacy review — creates significant compliance risk because unrecorded processing cannot be properly governed.
The EDPB Guidelines 07/2020 emphasize that controllers cannot claim ignorance of processing performed by vendors they engage, even if the engagement happened informally. Summit Cloud Partners maintains a comprehensive SaaS Vendor Data Processing Inventory to track all cloud services processing personal data, including those discovered through shadow IT detection.
Applications that have gone through formal procurement, privacy review, and DPA execution.
| Field | Description |
|---|---|
| Vendor name | Legal entity name |
| Product/service name | SaaS product name |
| Category | CRM, HR, Analytics, Communication, DevOps, etc. |
| Business owner | Department and named individual |
| Procurement date | When the service was contracted |
| DPA status | Executed / In negotiation / Not required |
| DPA reference | DPA document reference number |
| Privacy review status | Completed / In progress / Pending |
| Risk tier | Per vendor risk scoring model |
| Personal data categories | What personal data is processed |
| Data subjects | Whose data is processed |
| Processing purposes | Why data is processed |
| Processing locations | Where data is stored/processed |
| Integration method | SSO, API, manual upload, etc. |
| Data flow direction | Inbound / Outbound / Bidirectional |
| Contract expiry | When the contract term ends |
| Auto-renewal date | When auto-renewal triggers |
| Annual cost | Total annual spend |
| License count | Number of active users/seats |
Applications detected through discovery tools that lack formal procurement or privacy review.
| Field | Description |
|---|---|
| Application name | As detected |
| Detection method | CASB, DNS, expense, SSO log, etc. |
| Detection date | When first observed |
| Usage scope | Estimated users and frequency |
| Likely data categories | Inferred from application type |
| Risk assessment | Preliminary risk level |
| Remediation status | Under review / Sanctioning in progress / Blocked / Accepted |
| Business unit | Department(s) using the application |
Applications evaluated and determined to not process personal data.
| Field | Description |
|---|---|
| Application name | Product name |
| Evaluation date | When reviewed |
| Determination | No personal data processing |
| Rationale | Why excluded from inventory |
| Next review date | When to re-evaluate |
Deploy a CASB solution to monitor network traffic and identify cloud service usage.
Detection Capabilities:
Implementation at Summit Cloud Partners:
| Component | Detail |
|---|---|
| CASB vendor | Deployed as inline proxy and API connector |
| Coverage | All corporate network egress and managed endpoints |
| Discovery scope | HTTP/HTTPS traffic to known SaaS domains |
| Update frequency | Real-time discovery, weekly consolidated reporting |
| Integration | Feeds into SaaS inventory system via API |
Analyze DNS resolution logs and firewall traffic logs to identify connections to SaaS providers.
Process:
Review identity provider (IdP) logs for OAuth consent grants and SAML integrations.
Detection Signals:
Review corporate expense reports and credit card statements for SaaS subscriptions.
Detection Signals:
Scan internal systems for outbound API connections to third-party services.
Detection Signals:
For each sanctioned SaaS vendor, document the complete data flow:
Data Flow Template:
Summit Cloud Partners Internal Systems
│
├─► [SaaS Application Name]
│ │
│ ├─ Integration: [SSO/API/Manual Upload/Browser Plugin]
│ ├─ Authentication: [SAML SSO / OAuth 2.0 / Username-Password]
│ ├─ Encryption in transit: [TLS version]
│ ├─ Data categories sent: [list]
│ ├─ Data categories received: [list]
│ ├─ Data categories stored by vendor: [list]
│ ├─ Vendor processing locations: [locations]
│ ├─ Vendor sub-processors: [per sub-processor register]
│ ├─ Data retention at vendor: [period]
│ └─ Data deletion capability: [Yes/No — method]
│
└─► [Next SaaS Application]| Step | Activity | Responsible |
|---|---|---|
| 1 | Extract current CASB discovery report | InfoSec |
| 2 | Extract current sanctioned vendor list | Privacy Team |
| 3 | Compare: identify new unsanctioned applications | Privacy Team |
| 4 | Compare: identify sanctioned apps no longer in use | Privacy Team |
| 5 | Verify DPA status for all sanctioned vendors | Privacy Team |
| 6 | Check contract expiry dates (90-day lookahead) | Legal/Procurement |
| 7 | Update inventory records | Privacy Team |
| 8 | Report to DPO | Privacy Team Lead |
| Finding | Action |
|---|---|
| New unsanctioned SaaS discovered | Initiate shadow IT remediation workflow |
| Sanctioned SaaS no longer in use | Initiate vendor termination data workflow |
| DPA expired or missing | Expedite DPA execution or service suspension |
| Contract approaching expiry | Trigger renewal privacy review |
| Data processing scope change detected | Initiate DPA amendment review |
| Status | Definition | Action Required |
|---|---|---|
| Active — Compliant | Contract active, DPA executed, privacy review current | Standard monitoring |
| Active — DPA Pending | Contract active, DPA in negotiation | Expedite DPA; restrict data sharing if > 30 days |
| Active — Review Overdue | Contract active, privacy review past due | Schedule immediate review |
| Expiring (< 90 days) | Contract approaching expiry | Initiate renewal assessment |
| Expired | Contract term ended | Initiate termination data workflow |
| Suspended | Service suspended pending privacy issue resolution | Track resolution |
| Terminated | Contract terminated, data return/deletion in progress | Track deletion certification |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/saas-vendor-inventory of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
SaaS Vendor Inventory next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| SaaS Vendor Inventory this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Fmx Respondkunchenguid/firstmate | 7.8k | — | ~10k | Automated safety check: Notes | MIT | |
| Accounting Audit System Buildersickn33/agentic-awesome-skills | 47k | 1 repos | ~3.3k | Automated safety check: Pass | MIT | |
| Accounting Software Selectionsickn33/agentic-awesome-skills | 47k | 1 repos | ~7.4k | Automated safety check: Pass | MIT | |
| Research Financealirezarezvani/claude-skills | 28k | — | ~2.7k | Automated safety check: Pass | MIT | |
| Fin Close Managementevolution-foundation/evo-nexus | 545 | 1 repos | ~2.5k | Automated safety check: Pass | Custom licence |
kunchenguid/firstmate
Agent-only playbook for handling Relay mentions and follow-ups.
sickn33/agentic-awesome-skills
Routes an accounting or audit request to the right module skill, from software selection through monthly closing, asking only what is missing.
sickn33/agentic-awesome-skills
Scores shortlisted accounting packages against 57 evidence-backed fields, emitted as CSV, SQL, JSON Schema or Notion on request.
alirezarezvani/claude-skills
A skill your agent uses when managing the money for an internal R&D program or portfolio — building a multi-period program budget with the F&A (indirect) split, tracking burn rate and runway against…
evolution-foundation/evo-nexus
Manage the month-end close process with task sequencing, dependencies, and status tracking.
agentii-ai/agentii-investment-intelligence
Vaccine catalyst analysis across the two-gate path: CBER BLA review and the ACIP recommendation gate that turns FDA approval into commercial availability.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
SaaS vendor data processing inventory management. An agent skill from mukul975/Privacy-Data-Protection-Skills. SaaS Vendor Inventory is an agent skill from mukul975/Privacy-Data-Protection-Skills. SaaS vendor data processing inventory management.
SaaS Vendor Inventory fits situations like: tasks that involve Accounting and bookkeeping; tasks that involve Project management; tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a claude-code`. Or copy the skill folder (skills/privacy/saas-vendor-inventory in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/saas-vendor-inventory in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a codex`. Or copy the skill folder (skills/privacy/saas-vendor-inventory in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/saas-vendor-inventory in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill saas-vendor-inventory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/saas-vendor-inventory, .gemini/skills/saas-vendor-inventory, .github/skills/saas-vendor-inventory and .opencode/skills/saas-vendor-inventory in your project.
Going by SKILL.md and its folder, SaaS Vendor Inventory needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
SaaS Vendor Inventory is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with SaaS Vendor Inventory: Fmx Respond (kunchenguid/firstmate, 7.8k stars), Accounting Audit System Builder (sickn33/agentic-awesome-skills, 47k stars), Accounting Software Selection (sickn33/agentic-awesome-skills, 47k stars) and Research Finance (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.