project-compliance — community project-compliance, political-authority-highlighter, community, ide skills

v1.0.0

Acerca de este Skill

Perfecto para Agentes de Cumplimiento Normativo que necesitan capacidades avanzadas de protección de datos y transparencia de Brasil. Legal compliance enforcement for LGPD, LAI, Marco Civil da Internet, and security standards. Use when handling personal data, creating privacy-related features, or configuring security.

rodrigorjsf rodrigorjsf
[1]
[0]
Updated: 3/16/2026

Killer-Skills Review

Decision support comes first. Repository text comes second.

Reference-Only Page Review Score: 7/11

This page remains useful for operators, but Killer-Skills treats it as reference material instead of a primary organic landing page.

Original recommendation layer Concrete use-case guidance Explicit limitations and caution
Review Score
7/11
Quality Score
47
Canonical Locale
en
Detected Body Locale
en

Perfecto para Agentes de Cumplimiento Normativo que necesitan capacidades avanzadas de protección de datos y transparencia de Brasil. Legal compliance enforcement for LGPD, LAI, Marco Civil da Internet, and security standards. Use when handling personal data, creating privacy-related features, or configuring security.

¿Por qué usar esta habilidad?

Habilita a los agentes a hacer cumplir la conformidad con las leyes brasileñas como LGPD, LAI y Marco Civil, proporcionando un marco sólido para la protección de datos personales y el acceso a la información pública, utilizando protocolos como la anonimización de datos y el almacenamiento seguro de datos.

Mejor para

Perfecto para Agentes de Cumplimiento Normativo que necesitan capacidades avanzadas de protección de datos y transparencia de Brasil.

Casos de uso accionables for project-compliance

Hacer cumplir la conformidad con LGPD para el procesamiento de datos personales
Generar informes de transparencia para las autoridades públicas
Validar las solicitudes de los usuarios para acceder a la información pública bajo LAI

! Seguridad y limitaciones

  • Requiere conocimiento de las leyes brasileñas de protección de datos y transparencia
  • Limitado al marco jurídico brasileño
  • Necesita integración con los sistemas de almacenamiento y procesamiento de datos existentes

Why this page is reference-only

  • - Current locale does not satisfy the locale-governance contract.
  • - The underlying skill quality score is below the review floor.

Source Boundary

The section below is imported from the upstream repository and should be treated as secondary evidence. Use the Killer-Skills review above as the primary layer for fit, risk, and installation decisions.

After The Review

Decide The Next Action Before You Keep Reading Repository Material

Killer-Skills should not stop at opening repository instructions. It should help you decide whether to install this skill, when to cross-check against trusted collections, and when to move into workflow rollout.

Labs Demo

Browser Sandbox Environment

⚡️ Ready to unleash?

Experience this Agent in a zero-setup browser environment powered by WebContainers. No installation required.

Boot Container Sandbox

FAQ & Installation Steps

These questions and steps mirror the structured data on this page for better search understanding.

? Frequently Asked Questions

What is project-compliance?

Perfecto para Agentes de Cumplimiento Normativo que necesitan capacidades avanzadas de protección de datos y transparencia de Brasil. Legal compliance enforcement for LGPD, LAI, Marco Civil da Internet, and security standards. Use when handling personal data, creating privacy-related features, or configuring security.

How do I install project-compliance?

Run the command: npx killer-skills add rodrigorjsf/political-authority-highlighter/project-compliance. It works with Cursor, Windsurf, VS Code, Claude Code, and 19+ other IDEs.

What are the use cases for project-compliance?

Key use cases include: Hacer cumplir la conformidad con LGPD para el procesamiento de datos personales, Generar informes de transparencia para las autoridades públicas, Validar las solicitudes de los usuarios para acceder a la información pública bajo LAI.

Which IDEs are compatible with project-compliance?

This skill is compatible with Cursor, Windsurf, VS Code, Trae, Claude Code, OpenClaw, Aider, Codex, OpenCode, Goose, Cline, Roo Code, Kiro, Augment Code, Continue, GitHub Copilot, Sourcegraph Cody, and Amazon Q Developer. Use the Killer-Skills CLI for universal one-command installation.

Are there any limitations for project-compliance?

Requiere conocimiento de las leyes brasileñas de protección de datos y transparencia. Limitado al marco jurídico brasileño. Necesita integración con los sistemas de almacenamiento y procesamiento de datos existentes.

How To Install

  1. 1. Open your terminal

    Open the terminal or command line in your project directory.

  2. 2. Run the install command

    Run: npx killer-skills add rodrigorjsf/political-authority-highlighter/project-compliance. The CLI will automatically detect your IDE or AI agent and configure the skill.

  3. 3. Start using the skill

    The skill is now active. Your AI agent can use project-compliance immediately in the current project.

! Reference-Only Mode

This page remains useful for installation and reference, but Killer-Skills no longer treats it as a primary indexable landing page. Read the review above before relying on the upstream repository instructions.

Upstream Repository Material

The section below is imported from the upstream repository and should be treated as secondary evidence. Use the Killer-Skills review above as the primary layer for fit, risk, and installation decisions.

Upstream Source

project-compliance

Install project-compliance, an AI agent skill for AI agent workflows and automation. Review the use cases, limitations, and setup path before rollout.

SKILL.md
Readonly
Upstream Repository Material
The section below is imported from the upstream repository and should be treated as secondary evidence. Use the Killer-Skills review above as the primary layer for fit, risk, and installation decisions.
Supporting Evidence

Legal Compliance Enforcement

Purpose

Enforces compliance with Brazilian data protection and transparency laws applicable to the Political Authority Highlighter platform.

Applicable Laws

LawScopeKey Articles
LGPD (Lei 13.709/2018)Personal data protectionArt. 6, 7, 8, 9, 10, 37, 41, 46
LAI (Lei 12.527/2011)Access to public informationArt. 3, 8
Marco Civil (Lei 12.965/2014)Internet frameworkArt. 7, 15
Lei da Ficha Limpa (LC 135/2010)Electoral ineligibilityUsed as exclusion filter input
Lei 14.129/2021Digital Government / Open DataArt. 29, 30

LGPD Compliance Checklist

  • Legal basis documented: Legitimate Interest (Art. 7, IX) combined with Publicly Accessible Data (Art. 7, par. 3)
  • LIA (Legitimate Interest Assessment) document exists at docs/compliance/LIA.md
  • LIA includes three-phase balancing test: (i) legitimate purpose, (ii) necessity, (iii) rights balancing + safeguards
  • Processing purpose aligned with public interest and transparency (Art. 7, par. 3)
  • No purpose deviation: data NOT used for marketing, political campaigns, or profiling

B. Privacy Policy

  • Privacy policy page exists at /privacidade (or /privacy)
  • Written in pt-BR, clear and accessible language
  • Content includes:
    • Data controller identity and contact
    • DPO (encarregado) contact information
    • Data sources listed (all 6 government APIs)
    • Processing purposes described
    • Legal basis stated (Art. 7, IX + Art. 7, par. 3)
    • Data categories processed
    • Data retention periods
    • Data subject rights (Art. 18): access, correction, deletion, portability
    • Cookie policy
  • Linked from every page (footer)
  • Last update date displayed

C. DPO (Data Protection Officer / Encarregado)

  • DPO contact information published on the platform
  • Accessible from privacy policy page
  • Email address functional and monitored
  • If qualifying for simplified regime (Resolution CD/ANPD n. 2/2022): alternative contact channel documented

D. CPF Data Protection

  • CPFs stored encrypted using AES-256-GCM in internal_data.politician_identifiers
  • Encryption key stored as environment variable (CPF_ENCRYPTION_KEY)
  • SHA-256 hash used for cross-source matching (no decryption needed for matching)
  • api_reader database role has ZERO permissions on internal_data schema
  • No CPF in API responses, frontend code, URLs, or accessible logs
  • CPF decryption confined to apps/pipeline/src/crypto/cpf.ts only

E. Data Processing Records (Art. 37)

  • Processing activities documented in docs/compliance/ROPA.md (Record of Processing Activities)
  • Each processing activity includes: purpose, legal basis, data categories, recipients, retention, security measures
  • Updated when new data sources are added or processing changes
  • If analytics/tracking cookies are used: consent banner shown BEFORE cookies are set
  • Essential cookies (no consent needed): session, preferences
  • Non-essential cookies (consent required): analytics (Google Analytics, Plausible, etc.)
  • User can reject non-essential cookies and still use the platform
  • Cookie preferences stored and respected

G. Data Subject Rights (Art. 18)

If user registration is added post-MVP:

  • Right to access: users can view their data
  • Right to correction: users can update their data
  • Right to deletion: users can delete their account
  • Right to portability: users can export their data
  • Right to revoke consent: clear and accessible procedure
  • Requests processed within 15 days (ANPD recommended timeline)

LAI Compliance Checklist

Source Attribution

  • Every data point displayed on the platform references its official government source
  • Source URLs point to official .gov.br, .leg.br, or .jus.br domains
  • Data freshness indicator shows when each source was last updated (RF-014)
  • No data from unofficial or private sources (DR-003)

Respect API Terms

  • Portal da Transparencia rate limits respected: 90 req/min (peak), 300 req/min (off-peak)
  • API key used as required by Portal da Transparencia
  • No scraping of HTML pages when APIs are available
  • Bulk CSV downloads used for large datasets (TSE, CGU-PAD)

Marco Civil da Internet Compliance

Content Policy

  • No user-generated content about politicians in MVP (out of scope)
  • No comment sections, ratings, or social features
  • If UGC is added post-MVP: implement notice-and-takedown per Art. 19-21

Log Retention

  • If user authentication is added: server access logs retained for 6 months (Art. 15)
  • Logs stored securely with restricted access
  • Log retention policy documented

Security Baseline

Transport Security

  • All traffic over HTTPS (TLS 1.2+)
  • Automatic certificate renewal (Supabase managed TLS + Vercel managed TLS)
  • HSTS header enabled (max-age: 31536000, includeSubDomains)
  • SSL Labs grade A or above

API Security

  • Rate limiting: 60 req/min per IP on all public endpoints
  • Input validation via TypeBox schemas on all parameters
  • Response schemas defined (prevent field leakage via fast-json-stringify)
  • Security headers via Helmet (CSP, X-Frame-Options, etc.)
  • No CORS for API (same-origin) or restricted CORS for frontend domain only

Secret Management

  • Database passwords in environment variables, never in code
  • Portal da Transparencia API key in environment variable
  • CPF encryption key in environment variable
  • No secrets in git history (git log -p -- '*.env*' returns nothing)
  • .env files in .gitignore
  • Secret scanning enabled in CI/CD pipeline

Database Security

  • Two PostgreSQL roles enforced:
    • api_reader: SELECT only on public schema
    • pipeline_admin: ALL on both schemas
  • No superuser credentials in application code (note: Supabase service role key restricted to pipeline)
  • Database access controlled via Supabase platform security + RLS policies
  • Encrypted connections to database (sslmode=require, enforced by Supabase)

Frontend Security Baseline

  • Content-Security-Policy header configured in next.config.ts headers() (RNF-SEC-011)
  • CSP deployed as Content-Security-Policy-Report-Only initially, then enforced after validation
  • CSP policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: https:; font-src 'self'; connect-src 'self' {API_URL}; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests
  • server-only package installed and imported in all packages/db/src/ modules
  • ESLint no-restricted-imports forbids @pah/db, pg, drizzle-orm in apps/web/
  • CI post-build scan: grep .next/static/chunks/ for forbidden patterns
  • Only NEXT_PUBLIC_API_URL uses NEXT_PUBLIC_ prefix
  • All error.tsx boundaries show generic messages only
  • Pipeline transformers strip HTML tags from government source text before storing in public schema
  • No external scripts without SRI attributes
  • Future auth implementation: httpOnly Secure SameSite=Strict cookies, CSRF protection, RS256 JWT, <=24h session

Backup and Recovery

  • Supabase automatic daily backups (Free tier) + supplementary GitHub Actions pg_dump
  • Supabase managed backup storage + GitHub Actions backup to external storage
  • 7-day retention minimum
  • Restore procedure documented and tested
  • RPO: 24 hours (Supabase daily backup). RTO: 1 hour (Supabase restore).

Compliance Audit Schedule

CheckFrequency
Privacy policy reviewQuarterly
LIA reviewQuarterly or on methodology change
Secret scanEvery commit (CI/CD)
Dependency audit (npm audit)Weekly
CPF leakage checkEvery PR (automated)
Backup restore testMonthly
SSL certificate validityManaged by Supabase/Vercel
Frontend CSP validationEvery deploy (CI)
Client bundle leak scanEvery build (CI)

Changelog

DatePRD VersionSummary
2026-02-281.0Initial compliance enforcement skill
2026-03-071.1Add Frontend Security Baseline section
2026-03-091.2Migrate from VPS/Caddy to Supabase, schema rename public_data→public

Habilidades relacionadas

Looking for an alternative to project-compliance or another community skill for your workflow? Explore these related open-source skills.

Ver todo

openclaw-release-maintainer

Logo of openclaw
openclaw

Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞

333.8k
0
Inteligencia Artificial

widget-generator

Logo of f
f

Generar complementos de widgets personalizables para el sistema de feeds de prompts.chat

149.6k
0
Inteligencia Artificial

flags

Logo of vercel
vercel

El Marco de React

138.4k
0
Navegador

pr-review

Logo of pytorch
pytorch

Tensores y redes neuronales dinámicas en Python con fuerte aceleración de GPU

98.6k
0
Desarrollador