Agent skill

Privacy Engineer

by revfactory in revfactory/harness-100

Full privacy engineering pipeline. An agent skill from revfactory/harness-100.

Apache-2.0Auto-check passedLegal & Compliance

Install Privacy Engineer

skills CLI
$ npx skills add revfactory/harness-100 --skill privacy-engineer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 privacy-engineer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/69-privacy-engineer/.claude/skills/privacy-engineer .claude/skills/privacy-engineer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
privacy-engineer
GitHub stars
1.3k
Token cost
~1.7k tokens
SKILL.md length
635 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

Full privacy engineering pipeline. An agent skill from revfactory/harness-100.

  • Works in 3 steps: Preparation (Orchestrator performs… → Team Assembly and Execution → Integration and Final Deliverables
  • All privacy-related needs including: privacy by design
  • SKILL.md covers Execution Mode, Agent Composition, Workflow and Modes by Task Scope, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Privacy Engineer is an agent skill from revfactory/harness-100. Full privacy engineering pipeline. An agent team collaborates to perform GDPR/PIPA analysis → PIA → consent forms → process design in a single run. Use this skill for all privacy-related needs including: 'privacy by design', 'GDPR compliance', 'privacy impact assessment', 'PIA execution', 'consent form drafting', 'privacy policy', 'privacy design', 'personal data protection law compliance', 'PIPA response', 'data protection framework', etc. Note: actual submissions to the Personal Information Protection…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Privacy and GDPR. The licence is Apache-2.0.

When your agent uses it

  • All privacy-related needs including: privacy by design
  • GDPR compliance
  • Privacy impact assessment
  • Consent form drafting

Example prompts

  • “privacy by design”
  • “GDPR compliance”
  • “privacy impact assessment”
  • “/privacy-engineer”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Preparation (Orchestrator performs directly)
  2. Team Assembly and Execution
  3. Integration and Final Deliverables

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Privacy Engineer loads about 1.7k tokens when it runs. Until then it costs about 170 tokens; SKILL.md has 635 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~170
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 635 words, ~1,700 tokens.

Download SKILL.mdSave it as .claude/skills/privacy-engineer/SKILL.md (or your agent's skills folder).
name
privacy-engineer
description
Full privacy engineering pipeline. An agent team collaborates to perform GDPR/PIPA analysis → PIA → consent forms → process design in a single run. Use this skill for all privacy-related needs including: 'privacy by design', 'GDPR compliance', 'privacy impact assessment', 'PIA execution', 'consent form drafting', 'privacy policy', 'privacy design', 'personal data protection law compliance', 'PIPA response', 'data protection framework', etc. Note: actual submissions to the Personal Information Protection Commission, legal litigation representation, ISMS-P certification audits, and physical security system implementation are outside the scope of this skill.

Privacy Engineer — Privacy Engineering Pipeline

Systematically builds a service's privacy protection framework from legal analysis through process design.

Execution Mode

Agent Team — 4 agents communicate directly via SendMessage and perform cross-validation.

Agent Composition

AgentFileRoleType
privacy-law-analyst.claude/agents/privacy-law-analyst.mdGDPR/PIPA analysis, applicability determinationgeneral-purpose
pia-assessor.claude/agents/pia-assessor.mdPrivacy impact assessment, risk scoringgeneral-purpose
consent-designer.claude/agents/consent-designer.mdConsent form design, notices, privacy policygeneral-purpose
process-architect.claude/agents/process-architect.mdProcessing workflows, technical safeguardsgeneral-purpose

Workflow

Phase 1: Preparation (Orchestrator performs directly)
  1. Extract from user input:
    • Service name/type: web, app, SaaS, e-commerce, etc.
    • Data processed: personal data items collected
    • User regions: domestic, EU, US, etc.
    • Service scale: number of users, data volume
    • Existing materials (optional): current privacy policy, consent forms, system architecture diagrams
  2. Create a _workspace/ directory at the project root
  3. Organize inputs and save to _workspace/00_input.md
  4. Determine execution mode based on request scope
Phase 2: Team Assembly and Execution
StepTaskOwnerDepends OnOutput
1Legal analysisprivacy-law-analystNone_workspace/01_privacy_law_analysis.md
2PIA executionpia-assessorStep 1_workspace/02_pia_report.md
3aConsent form draftingconsent-designerSteps 1, 2_workspace/03_consent_documents.md
3bProcess designprocess-architectSteps 1, 2_workspace/04_process_design.md

Steps 3a (consent) and 3b (process) run in parallel. Both depend on legal analysis and PIA, so they can start simultaneously after Step 2 completes.

Inter-agent communication flow:

  • privacy-law-analyst completes → sends processing activity list and risk factors to pia-assessor
  • pia-assessor completes → sends disclosure requirements to consent-designer, sends safeguard recommendations to process-architect
  • consent-designer → sends consent collection timing and management requirements to process-architect
  • process-architect cross-validates logical consistency across all outputs during final design
Phase 3: Integration and Final Deliverables
  1. Review all files in _workspace/
  2. Verify consistency across legal analysis → PIA → consent forms → process design
  3. Report final summary to user:
    • Legal analysis report — 01_privacy_law_analysis.md
    • PIA report — 02_pia_report.md
    • Consent forms and notices set — 03_consent_documents.md
    • Process design document — 04_process_design.md

Modes by Task Scope

User Request PatternExecution ModeAgents Engaged
"Design the full privacy protection framework", "Full privacy design"Full pipelineAll 4 agents
"Analyze whether GDPR applies"Legal analysis modeprivacy-law-analyst only
"Run PIA only" (legal analysis available)PIA modepia-assessor
"Just draft the consent form"Consent modeconsent-designer
"Just design the personal data processing workflow"Process modeprocess-architect

Data Handoff Protocol

StrategyMethodPurpose
File-based_workspace/ directoryStoring and sharing primary deliverables
Message-basedSendMessageReal-time key information delivery, revision requests

File naming convention: {sequence}_{agent}_{deliverable}.{extension}

Show full SKILL.md (248 more words)Show less

Error Handling

Error TypeStrategy
Web search failureLegal analyst works from general knowledge, notes "latest guidelines not verified"
Insufficient service informationAssumes standard web service baseline, notes "assumption-based"
Uncertain GDPR applicabilityProceeds assuming GDPR applies, recommends separate confirmation
Agent failureRetry once → if still failing, proceed without that deliverable, note omission in final report
Inconsistency between PIA and legal analysisprocess-architect identifies inconsistency, applies conservative judgment

Test Scenarios

Normal Flow

Prompt: "Design a privacy protection framework for a SaaS service that includes EU users. We process registration, payment, and marketing data." Expected result:

  • Legal analysis: simultaneous GDPR + PIPA application, mapping 10+ processing activities
  • PIA: 15+ risk assessments, safeguard recommendations
  • Consent forms: required/optional separation, GDPR valid consent requirements reflected, cross-border transfer consent
  • Process: full lifecycle, technical safeguards, incident response framework
Partial Flow

Prompt: "Just write a personal data collection consent form for our app" Expected result:

  • Switches to consent mode (consent-designer only)
  • Drafts based on standard consent form template, notes that specific items require confirmation
Error Flow

Prompt: "Design a privacy protection framework — we're a startup and don't know where to start" Expected result:

  • Full pipeline executes, asks follow-up questions due to insufficient service information
  • Proceeds with assumptions based on typical startup baseline, notes "requires review once service details are confirmed"
  • Prioritizes minimum legal obligations (publishing privacy policy, obtaining consent) as first steps

Per-Agent Extended Skills

AgentExtended SkillPurpose
pia-assessor, process-architectdata-flow-mapperData flow mapping, risk point identification
privacy-law-analyst, consent-designergdpr-pipa-cross-referenceGDPR/PIPA article mapping, integrated compliance guide

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/69-privacy-engineer/.claude/skills/privacy-engineer of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Privacy Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Privacy Engineer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Privacy Engineer this skillrevfactory/harness-1001.3k—~1.7kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    939 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    939 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Privacy Engineer

What does Privacy Engineer do?

Full privacy engineering pipeline. An agent skill from revfactory/harness-100. Privacy Engineer is an agent skill from revfactory/harness-100. Full privacy engineering pipeline.

When should I use Privacy Engineer?

Privacy Engineer fits situations like: all privacy-related needs including: privacy by design; GDPR compliance; privacy impact assessment; consent form drafting.

How do I install Privacy Engineer in Claude Code?

Run `npx skills add revfactory/harness-100 --skill privacy-engineer -a claude-code`. Or copy the skill folder (en/69-privacy-engineer/.claude/skills/privacy-engineer in revfactory/harness-100) into .claude/skills/privacy-engineer in your project. Claude Code loads it when a task matches its description.

How do I install Privacy Engineer in Codex?

Run `npx skills add revfactory/harness-100 --skill privacy-engineer -a codex`. Or copy the skill folder (en/69-privacy-engineer/.claude/skills/privacy-engineer in revfactory/harness-100) into .agents/skills/privacy-engineer in your project. Codex loads it when a task matches its description.

Can I use Privacy Engineer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill privacy-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-engineer, .gemini/skills/privacy-engineer, .github/skills/privacy-engineer and .opencode/skills/privacy-engineer in your project.

What does Privacy Engineer need to run?

SKILL.md names no scripts, command-line tools or credentials: Privacy Engineer is instructions for the agent only.

Does Privacy Engineer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Privacy Engineer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Privacy Engineer use?

Privacy Engineer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Privacy Engineer use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Privacy Engineer?

Skills that share tags, products or a category with Privacy Engineer: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Privacy Engineer?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.