Operational Design
magnus919/agent-skills
Design and improve operational processes, controls, metrics, vendors, and scaling models through bounded pilots and evidence.
Ongoing vendor privacy compliance monitoring program. An agent skill from mukul975/Privacy-Data-Protection-Skills.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-monitoring-program -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-monitoring-program --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/vendor-monitoring-program .claude/skills/vendor-monitoring-program && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vendor-monitoring-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-monitoring-program into .claude/skills/vendor-monitoring-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-monitoring-program", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-monitoring-programType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-monitoring-program -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-monitoring-program --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/vendor-monitoring-program .agents/skills/vendor-monitoring-program && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vendor-monitoring-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-monitoring-program into .agents/skills/vendor-monitoring-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-monitoring-program", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-monitoring-program -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-monitoring-program --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/vendor-monitoring-program .cursor/skills/vendor-monitoring-program && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vendor-monitoring-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-monitoring-program into .cursor/skills/vendor-monitoring-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-monitoring-program", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/vendor-monitoring-program--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-monitoring-program -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-monitoring-program --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/vendor-monitoring-program .gemini/skills/vendor-monitoring-program && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vendor-monitoring-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-monitoring-program into .gemini/skills/vendor-monitoring-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-monitoring-program", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-monitoring-programInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-monitoring-program -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/vendor-monitoring-program .github/skills/vendor-monitoring-program && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vendor-monitoring-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-monitoring-program into .github/skills/vendor-monitoring-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-monitoring-program", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-monitoring-program -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills vendor-monitoring-program --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/vendor-monitoring-program .opencode/skills/vendor-monitoring-program && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vendor-monitoring-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/vendor-monitoring-program into .opencode/skills/vendor-monitoring-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vendor-monitoring-program", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vendor-monitoring-programOngoing vendor privacy compliance monitoring program. An agent skill from mukul975/Privacy-Data-Protection-Skills.
Vendor Monitoring Program is an agent skill from mukul975/Privacy-Data-Protection-Skills. Ongoing vendor privacy compliance monitoring program. Covers annual reassessment procedures, continuous monitoring signals, contract renewal privacy triggers, performance metrics, KPIs, and vendor governance reporting dashboards.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering OKRs and executive reporting and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vendor Monitoring Program loads about 2.1k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 856 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 856 words, ~2,108 tokens.
.claude/skills/vendor-monitoring-program/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.GDPR Article 28(1) imposes a continuing obligation on controllers to ensure that processors maintain sufficient guarantees. This is not a one-time assessment — the EDPB Guidelines 07/2020 (paragraph 87) explicitly state that the controller's assessment obligation is ongoing. The Vendor Privacy Monitoring Program at Summit Cloud Partners implements continuous oversight proportionate to the risk each vendor presents.
| Activity | Tier 1 (High Risk) | Tier 2 (Standard) | Tier 3 (Low Risk) |
|---|---|---|---|
| Full reassessment | Annual | Biennial | Triennial |
| Privacy audit | Annual (Type 2/3) | Annual (Type 1) | Biennial (Type 1) |
| Sub-processor list verification | Quarterly | Semi-annual | Annual |
| DPA compliance review | Annual | Biennial | Triennial |
| Risk score recalculation | Semi-annual | Annual | Biennial |
| Certification status check | Quarterly | Semi-annual | Annual |
| Breach monitoring | Continuous | Continuous | Monthly check |
| Contract renewal privacy gate | 120 days before | 90 days before | 90 days before |
Automated or semi-automated monitoring sources that provide ongoing visibility:
| Signal Source | What It Monitors | Frequency | Alert Trigger |
|---|---|---|---|
| Vendor risk intelligence platform | Public breach disclosures, enforcement actions, news | Daily | New incident involving a monitored vendor |
| Certification monitoring | ISO/SOC certificate validity and scope changes | Monthly | Certificate approaching expiry (60 days) |
| CASB/DLP | Data flows to vendor — volume and category anomalies | Continuous | Data transfer exceeding baseline by 200% |
| DNS/network monitoring | Connectivity patterns to vendor endpoints | Continuous | New endpoints, geographic changes |
| Vendor security scorecard | External security posture assessment | Monthly | Score drops below threshold |
| Regulatory database monitoring | New enforcement decisions involving vendor | Weekly | New published enforcement action |
| Sub-processor registry monitoring | Vendor-published sub-processor list changes | Weekly | New or changed sub-processor detected |
For each vendor due for reassessment:
Phase 1: Preparation (30 days before reassessment)
| Activity | Responsible |
|---|---|
| Pull current vendor profile and risk score | Privacy Team |
| Review monitoring signals from prior period | Privacy Team |
| Compile open audit findings and remediation status | Privacy Team |
| Identify changes since last assessment | Privacy Team |
| Send reassessment questionnaire to vendor | Privacy Team |
Phase 2: Assessment (Assessment month)
| Activity | Responsible |
|---|---|
| Review vendor's updated questionnaire responses | Privacy Team |
| Verify current certifications | Privacy Team |
| Review sub-processor list for changes | Privacy Team |
| Assess any processing scope changes | Privacy Team |
| Conduct audit (per tier schedule) | Audit Team |
| Recalculate risk score | Privacy Team |
Phase 3: Decision and Documentation
| Activity | Responsible |
|---|---|
| Update sufficiency determination | DPO |
| Update vendor risk tier (if changed) | Privacy Team Lead |
| Update monitoring schedule | Privacy Team |
| Communicate outcomes to business unit | Privacy Team |
| File reassessment documentation | Privacy Team |
When a vendor contract approaches renewal, a privacy gate ensures continued compliance:
| Timing | Activity |
|---|---|
| 120 days before renewal (Tier 1) / 90 days (Tier 2/3) | Privacy Team notified of upcoming renewal |
| 90 days before renewal | Review current privacy compliance status |
| 60 days before renewal | Complete any required reassessment |
| 30 days before renewal | Issue renewal privacy recommendation (Renew / Renew with conditions / Do not renew) |
| At renewal | Execute any required DPA amendments |
Renewal Privacy Decision Matrix:
| Compliance Status | Audit Status | Risk Trend | Recommendation |
|---|---|---|---|
| Fully compliant | Clean audit | Stable/improving | Renew |
| Minor gaps | Minor findings only | Stable | Renew with conditions |
| Material gaps | Major findings pending | Deteriorating | Renew with conditions + accelerated audit |
| Significant non-compliance | Critical findings open | Deteriorating | Do not renew (initiate termination planning) |
| KPI | Target | Measurement | Frequency |
|---|---|---|---|
| DPA coverage rate | 100% of data-processing vendors | Active DPAs / vendors processing personal data | Quarterly |
| Reassessment completion rate | 100% on schedule | Completed on time / due | Quarterly |
| Audit completion rate | 100% per tier schedule | Audits completed / audits due | Annual |
| Average vendor risk score | Trending downward | Mean weighted score across all vendors | Semi-annual |
| Open audit findings (Critical) | 0 past deadline | Count of overdue Critical findings | Monthly |
| Open audit findings (Major) | 0 past deadline | Count of overdue Major findings | Monthly |
| Sub-processor notification compliance | 100% | Changes notified before engagement / total changes | Quarterly |
| Mean time to acknowledge breach | < 2 hours | Average time from vendor notification to acknowledgment | Per incident |
| Deletion certification rate | 100% within DPA timeline | Certifications received on time / terminations | Annual |
| Shadow IT detection-to-remediation | < 30 days | Average days from detection to sanctioned/blocked | Quarterly |
Each vendor receives a quarterly privacy scorecard:
| Dimension | Weight | Score (1-5) | Trend |
|---|---|---|---|
| DPA compliance | 25% | [X] | [Up/Down/Stable] |
| Audit performance | 20% | [X] | [Up/Down/Stable] |
| Breach history (rolling 12 months) | 15% | [X] | [Up/Down/Stable] |
| Sub-processor management compliance | 15% | [X] | [Up/Down/Stable] |
| Certification currency | 15% | [X] | [Up/Down/Stable] |
| Cooperation and responsiveness | 10% | [X] | [Up/Down/Stable] |
| Weighted Total | 100% | [X.X] |
| Section | Content |
|---|---|
| Vendor count and tier distribution | Current state |
| New vendors onboarded | Privacy review outcomes |
| Vendors terminated | Deletion certification status |
| Open audit findings by severity | Remediation timeline |
| Monitoring alerts actioned | Signal source and resolution |
| Shadow IT detections | Discovery and remediation |
| Upcoming deadlines | Reassessments, renewals, audits due |
| Section | Content |
|---|---|
| Program KPIs vs targets | Dashboard with trend analysis |
| Risk tier changes | Escalations and de-escalations with rationale |
| Significant vendor events | Breaches, enforcement, certification changes |
| Regulatory developments | New guidance affecting vendor management |
| Recommendations | Program improvements, resource needs |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/vendor-monitoring-program of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Vendor Monitoring Program next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vendor Monitoring Program this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Operational Designmagnus919/agent-skills | 115 | — | ~1.4k | Automated safety check: Pass | MIT | |
| SEO Analiticaricneves-ai/flowgrammers-skills | 115 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Operational Designmagnus919/hermes-profiles | 289 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Analyticsericrisco/rsc-harness | 190 | — | ~2.8k | Automated safety check: Pass | MIT | |
| Quality Manager Qmralirezarezvani/claude-skills | 28k | — | ~4.7k | Automated safety check: Pass | MIT |
magnus919/agent-skills
Design and improve operational processes, controls, metrics, vendors, and scaling models through bounded pilots and evidence.
ricneves-ai/flowgrammers-skills
Skills para otimização de SEO técnico, análise de dados, criação de dashboards e inteligência de negócio para empresas brasileiras.
magnus919/hermes-profiles
COO methodology for process design, organizational scaling, operational metrics, compliance and audit, vendor management, and team topology.
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
alirezarezvani/claude-skills
Senior Quality Manager Responsible Person (QMR) for HealthTech and MedTech companies.
minhnv0807/ai-business-skills
A skill your agent uses when starting work on a new product, client, or market — this skill creates the file .agents/product-marketing-context-global.md that 60+ other global skills read before they…
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Ongoing vendor privacy compliance monitoring program. An agent skill from mukul975/Privacy-Data-Protection-Skills. Vendor Monitoring Program is an agent skill from mukul975/Privacy-Data-Protection-Skills. Ongoing vendor privacy compliance monitoring program.
Vendor Monitoring Program fits situations like: tasks that involve OKRs and executive reporting; tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-monitoring-program -a claude-code`. Or copy the skill folder (skills/privacy/vendor-monitoring-program in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/vendor-monitoring-program in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-monitoring-program -a codex`. Or copy the skill folder (skills/privacy/vendor-monitoring-program in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/vendor-monitoring-program in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill vendor-monitoring-program -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vendor-monitoring-program, .gemini/skills/vendor-monitoring-program, .github/skills/vendor-monitoring-program and .opencode/skills/vendor-monitoring-program in your project.
Going by SKILL.md and its folder, Vendor Monitoring Program needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Vendor Monitoring Program is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Vendor Monitoring Program: Operational Design (magnus919/agent-skills, 115 stars), SEO Analitica (ricneves-ai/flowgrammers-skills, 115 stars), Operational Design (magnus919/hermes-profiles, 289 stars) and Analytics (ericrisco/rsc-harness, 190 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.