Agent skill

Regulatory Audit Generator

by zebbern in zebbern/claude-code-guide

Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws.

MITAuto-check passedLegal & Compliance

Install Regulatory Audit Generator

skills CLI
$ npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zebbern/claude-code-guide regulatory-audit-generator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/regulatory-audit-generator .claude/skills/regulatory-audit-generator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
regulatory-audit-generator
GitHub stars
4.7k
Used in
1 other repo
Token cost
~3.5k tokens
SKILL.md length
1,474 words
Files
2
Skills in repo
46
Repo updated
First seen
Licence
MIT

At a glance

Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws.

  • Works in 6 steps: Supported Regulatory Frameworks → Compliance Check Procedure (SOP) → Common Business Scenario Check Points → …
  • Tasks that involve Regulatory compliance
  • SKILL.md covers Quick Start, 1. Supported Regulatory…, 2. Compliance Check Procedure… and 3. Common Business Scenario…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Regulatory Audit Generator is an agent skill from zebbern/claude-code-guide. Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like "run a compliance check," "GDPR/PIPL compliance," "pre-launch review," "privacy impact assessment (PIA/DPIA)," or asking if a feature is compliant.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

It sits in Legal & Compliance, covering Regulatory compliance and Privacy and GDPR. The repository describes itself as: Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user! The licence is MIT.

When your agent uses it

  • Tasks that involve Regulatory compliance
  • Tasks that involve Privacy and GDPR

Example prompts

  • “run a compliance check,”
  • “GDPR/PIPL compliance,”
  • “pre-launch review,”
  • “/regulatory-audit-generator”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Supported Regulatory Frameworks
  2. Compliance Check Procedure (SOP)
  3. Common Business Scenario Check Points
  4. Risk Level Criteria
  5. Deliverables
  6. Disclaimers

What it can do on your machine

Read from SKILL.md and the folder at commit 7ff9fbb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Regulatory Audit Generator loads about 3.5k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 1,474 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zebbern/claude-code-guide at commit 7ff9fbb, republished under its MIT licence (© zebbern). 1,474 words, ~3,500 tokens.

Download SKILL.mdSave it as .claude/skills/regulatory-audit-generator/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
regulatory-audit-generator
description
Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like "run a compliance check," "GDPR/PIPL compliance," "pre-launch review," "privacy impact assessment (PIA/DPIA)," or asking if a feature is compliant.
license
MIT

Regulatory Audit Generator — Business Scenario Compliance Checklist Builder

Identifies applicable laws and regulations based on the user's business scenario description, and outputs a structured compliance checklist covering major regulations such as GDPR, PIPL (Personal Information Protection Law), Advertising Law, Cybersecurity Law, and Data Security Law.

Quick Start

Users simply describe their business scenario, and the Agent will:

  1. Identify applicable regulations: Determine which laws and regulations apply based on the business scenario
  2. Generate a checklist: Output a structured list of check items
  3. Label risk levels: Prioritize by severity, marking high/medium/low risk
  4. Provide remediation recommendations: Offer actionable remediation guidance for each compliance risk

Users just need to say:

"We're launching a user profiling feature — help me create a compliance checklist."

The Agent will guide the user to provide necessary information, then output a complete compliance checklist.


1. Supported Regulatory Frameworks

Core Regulations
RegulationAbbreviationScopeKey Focus Areas
Personal Information Protection LawPIPLProcessing personal information within ChinaInformed consent, data minimization, cross-border data transfer
General Data Protection RegulationGDPRInvolving EU user dataLawful basis, data subject rights, DPO, DPIA
Data Security LawDSLData processing activities within ChinaData classification & grading, security assessment, important data export
Cybersecurity LawCSLNetwork operatorsMulti-Level Protection Scheme (MLPS), log retention, security incident reporting
Advertising Law—Advertising publishing and operationsProhibited superlative claims, false advertising, medical advertising
E-Commerce Law—E-commerce operatorsInformation disclosure, user reviews, bundled sales
Anti-Unfair Competition Law—Market business activitiesCommercial bribery, false advertising, trade secret infringement
Consumer Protection Law—Consumer rights relatedRight to know, fair trade rights, personal information
Industry-Specific Regulations
IndustryRelevant Regulations / Standards
FinanceTechnical Specification for Personal Financial Information Protection (JR/T 0171), Data Security Management Measures for Banking and Insurance Institutions
HealthcarePopulation Health Information Management Measures, Medical Big Data Standards
EducationOnline Protection Chapter of the Minors Protection Law, Provisions on Protection of Children's Personal Information Online
AutomotiveSeveral Provisions on Automobile Data Security Management
Mobile AppsMethods for Identifying Illegal Collection and Use of Personal Information by Apps, Provisions on the Scope of Necessary Personal Information for Common Types of Mobile Applications

2. Compliance Check Procedure (SOP)

Step 1: Gather Business Scenario Information

Confirm the following key information with the user:

DimensionInformation to ConfirmExample
Business DescriptionSpecific content of the feature/service"User profiling feature that recommends products based on behavioral data"
User GroupGeographic region and demographics of target audience"Mainland China users, including minors"
Data TypesWhat data is collected/processed"Name, phone number, browsing history, location data"
Data FlowData storage, transmission, and sharing details"Stored on Alibaba Cloud East China nodes, shared with third-party ad platforms"
Business StageNew launch / existing system needing remediation / M&A due diligence"New feature, planned for launch next month"
Existing MeasuresCurrent compliance measures already in place"Has a privacy policy, but no DPIA completed"

If the user has not provided certain information, the Agent should proactively ask follow-up questions rather than assume or skip.

Step 2: Identify Applicable Regulations

Based on collected information, determine applicable regulations using the following rules:

IF processing personal information → PIPL
IF involving EU users → GDPR
IF involving data storage/transmission → Data Security Law + Cybersecurity Law
IF involving advertising/marketing content → Advertising Law
IF involving e-commerce transactions → E-Commerce Law
IF involving minors → Minors Protection Law + Provisions on Protection of Children's Personal Information Online
IF cross-border data transfer (overseas storage/transmission/access) → PIPL Chapter 3 + Measures for Security Assessment of Data Export
IF involving sensitive personal information → PIPL Chapter 2 Section 2 (separate consent + PIIA)
IF involving automated decision-making → PIPL Article 24 (transparency + right to refuse)
IF involving financial data → JR/T 0171
Step 3: Generate the Compliance Checklist

Output the checklist in the following structure:

Checklist Output Format
markdown
# [Business Scenario Name] Compliance Checklist

**Assessment Date**: YYYY-MM-DD
**Business Description**: [Brief description]
**Applicable Regulations**: [List of regulations]

## Checklist

| No. | Check Item | Legal Basis | Risk Level | Current Status | Remediation Advice |
|-----|-----------|-------------|------------|----------------|-------------------|
| 1 | [Check item description] | [Regulation name + article number] | High/Medium/Low | Compliant/Non-compliant/To be confirmed | [Specific advice] |

## Risk Summary

- High-risk items: X items
- Medium-risk items: X items
- Low-risk items: X items

## Priority Remediation Recommendations

1. [Highest priority remediation item and rationale]
2. [Second highest priority item and rationale]
Step 4: Output Remediation Priorities

Prioritize remediation actions according to the following rules:

PriorityCriteriaDescription
P0 — Immediate ActionHigh risk + currently non-compliantMay face administrative penalties, service shutdown
P1 — Complete This WeekHigh risk + to be confirmed, or medium risk + non-compliantSignificant compliance exposure
P2 — Complete This MonthMedium risk + to be confirmedRequires further assessment and improvement
P3 — Ongoing OptimizationLow riskRecommended improvement but not urgent

3. Common Business Scenario Check Points

Scenario 1: User Registration and Login
Check ItemLegal BasisDescription
Is there a privacy policy / user agreement?PIPL Art. 17Must be displayed and consent obtained before registration
Is only necessary personal information collected?PIPL Art. 6Registration stage should only require phone number/email; should not mandate ID numbers, etc.
Does third-party login disclose data sharing?PIPL Art. 23Login via WeChat/Alipay must disclose what information is shared
Are passwords stored encrypted?CSL Art. 21Plaintext password storage is prohibited
Is account deletion supported?PIPL Art. 47A convenient account deletion channel must be provided
Scenario 2: Marketing and Advertising
Check ItemLegal BasisDescription
Is consent obtained for marketing SMS/emails?PIPL Art. 13, Advertising Law Art. 43Explicit user consent is required
Is an unsubscribe mechanism provided?Advertising Law Art. 43Each marketing message must include an opt-out method
Does ad copy contain prohibited superlative terms?Advertising Law Art. 9Absolute terms like "best," "number one," "national-level" are prohibited
Can profiling-based recommendations be disabled?PIPL Art. 24An option for non-personalized content must be provided
Are advertisements clearly labeled as "Ad"?Advertising Law Art. 14Mass media channels must clearly mark advertisements
Scenario 3: Cross-Border Data Transfer
Check ItemLegal BasisDescription
Does it meet the security assessment filing threshold?Measures for Security Assessment of Data Export Art. 4Processing personal information of 1M+ individuals, or cumulative export of 100K individuals / 10K sensitive records
Has the standard contract been signed?Standard Contract Measures for Personal Information ExportCan sign the standard contract if below the filing threshold
Has a Personal Information Protection Impact Assessment been completed?PIPL Art. 55PIIA must be completed before data export
Has the user been informed and separate consent obtained?PIPL Art. 39Must disclose overseas recipient information
Overseas recipient's data protection capabilityPIPL Art. 38Must assess the recipient's data protection standards
Show full SKILL.md (563 more words)Show less
Scenario 4: User Profiling and Personalized Recommendations
Check ItemLegal BasisDescription
Is the automated decision-making logic disclosed?PIPL Art. 24Must be transparent to users
Is an option to disable personalized recommendations provided?PIPL Art. 24Users have the right to refuse
Has a PIIA been conducted for user profiling?PIPL Art. 55Assessment is required when using personal information for automated decision-making
Do profiling tags involve sensitive information?PIPL Art. 28Tags related to religion, health, finance, etc. are classified as sensitive information
Is the use scope of profiling results restricted?PIPL Art. 24Must not impose unreasonable differential treatment in areas such as transaction pricing
Scenario 5: GDPR Compliance (for EU Users)
Check ItemLegal BasisDescription
Has a lawful basis for processing been established?GDPR Art. 6One of six bases: consent, contract, legal obligation, legitimate interest, etc.
Has a DPO been appointed?GDPR Art. 37Required for large-scale processing or processing of special category data
Has a DPIA been completed?GDPR Art. 35Required for high-risk processing activities
Is the right to data portability supported?GDPR Art. 20Data must be provided in a structured, machine-readable format
Can data breaches be reported within 72 hours?GDPR Art. 33Supervisory authority must be notified within 72 hours of discovering a breach
Is the cookie banner compliant?GDPR + ePrivacyActive consent required; pre-checked boxes are not permitted
Are records of processing activities maintained?GDPR Art. 30Required for organizations with 250+ employees or non-occasional processing

4. Risk Level Criteria

Risk LevelCriteriaPotential Consequences
HighViolation of mandatory legal provisions; unlawful processing of sensitive personal information; lack of lawful basis; data export without assessmentAdministrative penalties (fines), service shutdown, criminal liability
MediumCompliance measures incomplete but foundational; insufficient notice; flawed consent mechanism; partial security measure gapsRegulatory interview, ordered remediation within deadline, user complaints
LowBest practices not met but not unlawful; incomplete documentation; processes can be optimizedAudit findings, internal improvements

5. Deliverables

The Agent should ultimately deliver the following to the user:

  1. Compliance Checklist Table: All check items with legal basis, risk levels, current status, and remediation advice
  2. Risk Summary: Count of high/medium/low risk items
  3. Priority Remediation Roadmap: Remediation action list ordered by P0–P3
  4. Supplementary Notes: Plain-language explanations of key compliance requirements to help non-legal staff understand

6. Disclaimers

  1. Regulatory Currency: Laws and regulations are continuously updated. Regulation references in the checklist should be verified against the latest versions. The Agent should remind users to check for the most recent regulatory developments.
  2. Not Legal Advice: This checklist is for reference only and does not constitute legal advice. For significant compliance decisions, consultation with a qualified attorney is recommended.
  3. Industry Variations: Different industries have specific regulatory requirements. The checklist should be adapted to account for industry-specific considerations.
  4. Ongoing Compliance: Compliance is not a one-time effort. Regular reassessment (at least every six months) is recommended.

References

  • Personal Information Protection Law of the People's Republic of China (PIPL, 2021)
  • Data Security Law of the People's Republic of China (DSL, 2021)
  • Cybersecurity Law of the People's Republic of China (CSL, 2017)
  • Advertising Law of the People's Republic of China (2018 Amendment)
  • EU General Data Protection Regulation (GDPR, 2018)
  • Measures for Standard Contracts for Personal Information Export (2023)
  • Measures for Security Assessment of Data Export (2022)
  • GB/T 35273-2020 Information Security Technology — Personal Information Security Specification

© zebbern, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/regulatory-audit-generator of zebbern/claude-code-guide.

  • SKILL.md
  • LICENSE

Open the folder on GitHubat commit 7ff9fbb

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in zebbern/claude-code-guide, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Regulatory Audit Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Regulatory Audit Generator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Regulatory Audit Generator this skillzebbern/claude-code-guide4.7k1 repos~3.5kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
Age Gating Servicesmukul975/Privacy-Data-Protection-Skills301—~3.7kAutomated safety check: PassApache-2.0
Reg Gap Analysisanthropics/claude-for-legal9.6k2 repos~2.6kAutomated safety check: PassApache-2.0
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Compliance Checkjosstei/maestro-orchestrate465—~237Automated safety check: PassApache-2.0

Similar skills

  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Reg Gap Analysis

    anthropics/claude-for-legal

    Official

    Diff a new or changed regulation against current privacy policy and practice — outputs a gap list and a remediation plan with owners and dates.

    9.6k GitHub starsUsed in 2 repos~2.6k tokens
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Compliance Check

    josstei/maestro-orchestrate

    Run a Maestro-style regulatory compliance review for GDPR/CCPA, cookie consent, data handling, and licensing

    465 GitHub stars~237 tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed

More from zebbern/claude-code-guide

All 46 skills in this repo
  • Localization Toolkit

    zebbern/claude-code-guide

    This skill should be used when setting up, auditing, or enforcing internationalization/localization in UI codebases (React/TS, i18next or similar, JSON locales), including installing/configuring the…

    4.7k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Audit Flow

    zebbern/claude-code-guide

    Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

    4.7k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Chart Image

    zebbern/claude-code-guide

    Generate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts.

    4.7k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Code To Diagram

    zebbern/claude-code-guide

    Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts.

    4.7k GitHub stars~972 tokensUpdated today
    Auto-check passed
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.7k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Idor Testing

    zebbern/claude-code-guide

    This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

    4.7k GitHub starsUsed in 8 repos~3.1k tokens
    Auto-check passed

Questions about Regulatory Audit Generator

What does Regulatory Audit Generator do?

Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Regulatory Audit Generator is an agent skill from zebbern/claude-code-guide. Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws.

When should I use Regulatory Audit Generator?

Regulatory Audit Generator fits situations like: tasks that involve Regulatory compliance; tasks that involve Privacy and GDPR.

How do I install Regulatory Audit Generator in Claude Code?

Run `npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a claude-code`. Or copy the skill folder (skills/regulatory-audit-generator in zebbern/claude-code-guide) into .claude/skills/regulatory-audit-generator in your project. Claude Code loads it when a task matches its description.

How do I install Regulatory Audit Generator in Codex?

Run `npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a codex`. Or copy the skill folder (skills/regulatory-audit-generator in zebbern/claude-code-guide) into .agents/skills/regulatory-audit-generator in your project. Codex loads it when a task matches its description.

Can I use Regulatory Audit Generator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/regulatory-audit-generator, .gemini/skills/regulatory-audit-generator, .github/skills/regulatory-audit-generator and .opencode/skills/regulatory-audit-generator in your project.

What does Regulatory Audit Generator need to run?

SKILL.md names no scripts, command-line tools or credentials: Regulatory Audit Generator is instructions for the agent only.

Does Regulatory Audit Generator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Regulatory Audit Generator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Regulatory Audit Generator use?

Regulatory Audit Generator is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Regulatory Audit Generator use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Regulatory Audit Generator?

Skills that share tags, products or a category with Regulatory Audit Generator: Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Age Gating Services (mukul975/Privacy-Data-Protection-Skills, 301 stars), Reg Gap Analysis (anthropics/claude-for-legal, 9.6k stars) and Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Regulatory Audit Generator?

zebbern (a GitHub user) maintains it in zebbern/claude-code-guide, which has 4,650 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 10, 2026.

Source: zebbern/claude-code-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.