Agent skill

Data Flow Mapper

by revfactory in revfactory/harness-100

A data flow mapping tool that systematically maps personal information processing flows and identifies risk points.

Apache-2.0Auto-check passedLegal & Compliance

Install Data Flow Mapper

skills CLI
$ npx skills add revfactory/harness-100 --skill data-flow-mapper -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 data-flow-mapper --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/69-privacy-engineer/.claude/skills/data-flow-mapper .claude/skills/data-flow-mapper && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
data-flow-mapper
GitHub stars
1.3k
Token cost
~1.2k tokens
SKILL.md length
233 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

A data flow mapping tool that systematically maps personal information processing flows and identifies risk points.

  • Data flow analysis
  • SKILL.md covers Data Lifecycle Mapping Framework, Risk Point Identification…, Data Flow Diagram Creation and Risk Assessment Scoring, plus 1 more section
  • Calls aws
  • Processing activity mapping

What it does

Data Flow Mapper is an agent skill from revfactory/harness-100. A data flow mapping tool that systematically maps personal information processing flows and identifies risk points. The 'pia-assessor' and 'process-architect' agents must utilize this skill's mapping methodology and risk point identification patterns when analyzing data flows and designing protective measures. Use for 'data flow analysis', 'processing activity mapping', 'risk point identification', and similar tasks. Note that legal analysis or consent form drafting is outside the scope of this skill.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Data analysis and Legal research. The licence is Apache-2.0.

When your agent uses it

  • Data flow analysis
  • Processing activity mapping
  • Risk point identification

Example prompts

  • “pia-assessor”
  • “process-architect”
  • “data flow analysis”
  • “/data-flow-mapper”

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Data Flow Mapper loads about 1.2k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 233 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 233 words, ~1,169 tokens.

Download SKILL.mdSave it as .claude/skills/data-flow-mapper/SKILL.md (or your agent's skills folder).
name
data-flow-mapper
description
A data flow mapping tool that systematically maps personal information processing flows and identifies risk points. The 'pia-assessor' and 'process-architect' agents must utilize this skill's mapping methodology and risk point identification patterns when analyzing data flows and designing protective measures. Use for 'data flow analysis', 'processing activity mapping', 'risk point identification', and similar tasks. Note that legal analysis or consent form drafting is outside the scope of this skill.

Data Flow Mapper — Personal Information Data Flow Mapping Tool

Visualizes the complete lifecycle of personal information — collection → processing → storage → transfer → destruction — and identifies risk points.

Data Lifecycle Mapping Framework

6-Stage Lifecycle
Collection → Use → Storage → Sharing
    → Entrustment → Destruction

Checklist for each stage:
  Collection: items collected, collection channels, legal basis, consent method
  Use: processing purpose, processor, access permissions
  Storage: storage location, encryption, retention period
  Sharing: recipients, shared items, legal basis
  Entrustment: trustee, entrusted tasks, oversight and supervision
  Destruction: destruction timing, destruction method, destruction confirmation
Record of Processing Activities (RoPA) Template
| Activity ID | Processing Purpose | Data Items | Data Subject | Legal Basis | Retention Period | Trustee | Cross-border Transfer |
|------------|-------------------|------------|--------------|-------------|-----------------|---------|----------------------|
| PA-001 | Member registration | Name, email, phone | Member | Consent | Upon withdrawal | - | - |
| PA-002 | Payment processing | Card number, account | Purchaser | Contract | 5 years | PG company | - |
| PA-003 | Marketing | Email, purchase history | Member | Consent (optional) | Upon consent withdrawal | Ad agency | AWS (USA) |

Risk Point Identification Patterns

High-Risk Data Flow Patterns
Pattern IDPattern NameRisk DescriptionImpact
DF-01Excessive collectionCollecting unnecessary items beyond the stated purposeHigh
DF-02Use beyond purposeProcessing data for purposes other than the stated collection purposeHigh
DF-03Insufficient encryptionStoring/transmitting sensitive information in plaintextCritical
DF-04Undisclosed cross-border transferMissing notice/consent when using overseas serversHigh
DF-05Unmanaged trusteesAbsence of security management for entrusted vendorsHigh
DF-06Failure to destroyNot destroying data after the retention period expiresMedium
DF-07No audit logsFailure to record access/processing historyMedium
DF-08Excessive access privilegesPersonal information accessible to unrelated personnelHigh
Data Classification System
LevelData TypeProtection LevelExamples
Top SecretSensitive informationSeparate consent + mandatory encryptionHealth, beliefs, biometrics
Level 1Unique identifying informationSeparate consent + mandatory encryptionNational ID, passport, driver's license
Level 2General personal informationConsent + safety measuresName, email, phone
Level 3Pseudonymized informationSafety measuresPseudonymized data
Level 4Anonymized informationNo restrictionsStatistical data

Data Flow Diagram Creation

Text-Based DFD Notation
[Data Subject] ---(name, email)---> [Web Server]
[Web Server] ---(save to member DB)---> [RDS/MySQL]
[Web Server] ---(payment request)---> [PG Company API]
[RDS/MySQL] ---(backup)---> [S3 (Seoul Region)]
[RDS/MySQL] ---(analytics)---> [BigQuery (USA)] ⚠️ Cross-border transfer
[Batch Server] ---(marketing delivery)---> [Email Service] ⚠️ Entrustment

Risk Assessment Scoring

Risk Score = Data_Sensitivity(1-5) × Processing_Scale(1-5) × Control_Absence(1-5)

Sensitivity: 5=Sensitive info  4=Unique identifier  3=General personal  2=Pseudonymized  1=Anonymized
Processing Scale: 5=1M+  4=100K+  3=10K+  2=1K+  1=Under 100
Control Absence: 5=No protective measures  4=Partial  3=Basic level  2=Good  1=Best-in-class

Risk Levels:
  75-125: 🔴 Immediate protective measures required
  40-74: 🟡 Improvement needed
  15-39: 🟢 Acceptable
  1-14: ⚪ Good

References

  • Based on GDPR Article 30 (RoPA) and Personal Information Protection Act Article 30
  • Detailed mapping guide: see references/data-flow-guide.md

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/69-privacy-engineer/.claude/skills/data-flow-mapper of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Data Flow Mapper next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Data Flow Mapper compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Data Flow Mapper this skillrevfactory/harness-1001.3k—~1.2kAutomated safety check: PassApache-2.0
2026 Legal Research Agentcuriositech/some_claude_skills2431 repos~2.6kAutomated safety check: PassMIT
Skill Auditoraipoch/medical-research-skills2k—~6.9kAutomated safety check: PassMIT
Protocol Deviation Classifieraipoch/medical-research-skills2k—~3.5kAutomated safety check: PassMIT
Respol Data Analysisbrycewang-stanford/Awesome-Journal-Skills1.2k—~1.5kAutomated safety check: PassMIT
Respol Tables Figuresbrycewang-stanford/Awesome-Journal-Skills1.2k—~1.4kAutomated safety check: PassMIT

Similar skills

  • 2026 Legal Research Agent

    curiositech/some_claude_skills

    Expert legal research agent for finding and scraping expungement data state by state.

    243 GitHub starsUsed in 1 repo~2.6k tokens
    Legal & ComplianceAuto-check passed
  • Skill Auditor

    aipoch/medical-research-skills

    A comprehensive auditor for any agent skill — including Manus, OpenClaw/ClawHub, Claude, LobeHub, or custom SKILL.md-based skills.

    2k GitHub stars~6.9k tokensUpdated 20 days ago
    Legal & ComplianceAuto-check passed
  • Protocol Deviation Classifier

    aipoch/medical-research-skills

    Classify clinical trial protocol deviations as major or minor based on ICH E6/GCP guidelines.

    2k GitHub stars~3.5k tokensUpdated 20 days ago
    Legal & ComplianceAuto-check passed
  • Respol Data Analysis

    brycewang-stanford/Awesome-Journal-Skills

    A skill your agent uses when executing and stress-testing the empirical analysis for a Research Policy (RP) manuscript — building bibliometric/patent variables, running estimation or qualitative…

    1.2k GitHub stars~1.5k tokensUpdated 10 days ago
    Legal & ComplianceAuto-check passed
  • Respol Tables Figures

    brycewang-stanford/Awesome-Journal-Skills

    A skill your agent uses when exhibits are the bottleneck for a Research Policy (RP) manuscript — designing tables and figures (regression tables, patent/bibliometric maps, event-study plots, case…

    1.2k GitHub stars~1.4k tokensUpdated 10 days ago
    Legal & ComplianceAuto-check passed
  • Tw Legal RAG

    aa0101181514/tw-legal-rag

    Retrieve real Taiwan court judgments with verifiable citations before answering any question about Taiwan law or case law.

    327 GitHub stars~580 tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Data Flow Mapper

What does Data Flow Mapper do?

A data flow mapping tool that systematically maps personal information processing flows and identifies risk points. Data Flow Mapper is an agent skill from revfactory/harness-100. A data flow mapping tool that systematically maps personal information processing flows and identifies risk points.

When should I use Data Flow Mapper?

Data Flow Mapper fits situations like: data flow analysis; processing activity mapping; risk point identification.

How do I install Data Flow Mapper in Claude Code?

Run `npx skills add revfactory/harness-100 --skill data-flow-mapper -a claude-code`. Or copy the skill folder (en/69-privacy-engineer/.claude/skills/data-flow-mapper in revfactory/harness-100) into .claude/skills/data-flow-mapper in your project. Claude Code loads it when a task matches its description.

How do I install Data Flow Mapper in Codex?

Run `npx skills add revfactory/harness-100 --skill data-flow-mapper -a codex`. Or copy the skill folder (en/69-privacy-engineer/.claude/skills/data-flow-mapper in revfactory/harness-100) into .agents/skills/data-flow-mapper in your project. Codex loads it when a task matches its description.

Can I use Data Flow Mapper in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill data-flow-mapper -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/data-flow-mapper, .gemini/skills/data-flow-mapper, .github/skills/data-flow-mapper and .opencode/skills/data-flow-mapper in your project.

What does Data Flow Mapper need to run?

Going by SKILL.md and its folder, Data Flow Mapper needs the command-line tools its instructions call (aws).

Does Data Flow Mapper access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Data Flow Mapper safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Data Flow Mapper use?

Data Flow Mapper is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Data Flow Mapper use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Data Flow Mapper?

Skills that share tags, products or a category with Data Flow Mapper: 2026 Legal Research Agent (curiositech/some_claude_skills, 243 stars), Skill Auditor (aipoch/medical-research-skills, 2k stars), Protocol Deviation Classifier (aipoch/medical-research-skills, 2k stars) and Respol Data Analysis (brycewang-stanford/Awesome-Journal-Skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Data Flow Mapper?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.