project-compliance — for Claude Code project-compliance, political-authority-highlighter, community, for Claude Code, ide skills, Compliance, Enforcement, Purpose, Enforces, Brazilian

v1.0.0

このスキルについて

ブラジルのデータ保護と透明性の法律執行能力が必要な規制コンプライアンスエージェントに最適 ローカライズされた概要: Legal compliance enforcement for LGPD, LAI, Marco Civil da Internet, and security standards. This AI agent skill supports Claude Code, Cursor, and Windsurf workflows.

機能

Legal Compliance Enforcement
Law Scope Key Articles
----- ------- -------------
LGPD (Lei 13.709/2018) Personal data protection Art. 6, 7, 8, 9, 10, 37, 41, 46
LAI (Lei 12.527/2011) Access to public information Art. 3, 8

# Core Topics

rodrigorjsf rodrigorjsf
[1]
[0]
Updated: 3/16/2026

Killer-Skills Review

Decision support comes first. Repository text comes second.

Reference-Only Page Review Score: 8/11

This page remains useful for teams, but Killer-Skills treats it as reference material instead of a primary organic landing page.

Original recommendation layer Concrete use-case guidance Explicit limitations and caution
Review Score
8/11
Quality Score
47
Canonical Locale
en
Detected Body Locale
en

ブラジルのデータ保護と透明性の法律執行能力が必要な規制コンプライアンスエージェントに最適 ローカライズされた概要: Legal compliance enforcement for LGPD, LAI, Marco Civil da Internet, and security standards. This AI agent skill supports Claude Code, Cursor, and Windsurf workflows.

このスキルを使用する理由

エージェントにLGPD、LAI、Marco Civilなどのブラジル法律に準拠したコンプライアンスを実施する能力を提供し、個人データ保護と公共情報へのアクセスに強力なフレームワークを提供することで、データ匿名化やセキュアなデータストレージなどのプロトコルを利用する

おすすめ

ブラジルのデータ保護と透明性の法律執行能力が必要な規制コンプライアンスエージェントに最適

実現可能なユースケース for project-compliance

個人データの処理のためのLGPDコンプライアンスの実施
公共機関向けの透明性レポートの生成
LAIに基づく公共情報へのアクセス要求のユーザー検証

! セキュリティと制限

  • ブラジルのデータ保護と透明性の法律を理解する必要がある
  • ブラジルの法律フレームワークに限定される
  • 既存のデータストレージと処理システムとの統合が必要

Why this page is reference-only

  • - Current locale does not satisfy the locale-governance contract.
  • - The underlying skill quality score is below the review floor.

Source Boundary

The section below is imported from the upstream repository and should be treated as secondary evidence. Use the Killer-Skills review above as the primary layer for fit, risk, and installation decisions.

After The Review

Decide The Next Action Before You Keep Reading Repository Material

Killer-Skills should not stop at opening repository instructions. It should help you decide whether to install this skill, when to cross-check against trusted collections, and when to move into workflow rollout.

Labs Demo

Browser Sandbox Environment

⚡️ Ready to unleash?

Experience this Agent in a zero-setup browser environment powered by WebContainers. No installation required.

Boot Container Sandbox

FAQ & Installation Steps

These questions and steps mirror the structured data on this page for better search understanding.

? Frequently Asked Questions

What is project-compliance?

ブラジルのデータ保護と透明性の法律執行能力が必要な規制コンプライアンスエージェントに最適 ローカライズされた概要: Legal compliance enforcement for LGPD, LAI, Marco Civil da Internet, and security standards. This AI agent skill supports Claude Code, Cursor, and Windsurf workflows.

How do I install project-compliance?

Run the command: npx killer-skills add rodrigorjsf/political-authority-highlighter/project-compliance. It works with Cursor, Windsurf, VS Code, Claude Code, and 19+ other IDEs.

What are the use cases for project-compliance?

Key use cases include: 個人データの処理のためのLGPDコンプライアンスの実施, 公共機関向けの透明性レポートの生成, LAIに基づく公共情報へのアクセス要求のユーザー検証.

Which IDEs are compatible with project-compliance?

This skill is compatible with Cursor, Windsurf, VS Code, Trae, Claude Code, OpenClaw, Aider, Codex, OpenCode, Goose, Cline, Roo Code, Kiro, Augment Code, Continue, GitHub Copilot, Sourcegraph Cody, and Amazon Q Developer. Use the Killer-Skills CLI for universal one-command installation.

Are there any limitations for project-compliance?

ブラジルのデータ保護と透明性の法律を理解する必要がある. ブラジルの法律フレームワークに限定される. 既存のデータストレージと処理システムとの統合が必要.

How To Install

  1. 1. Open your terminal

    Open the terminal or command line in your project directory.

  2. 2. Run the install command

    Run: npx killer-skills add rodrigorjsf/political-authority-highlighter/project-compliance. The CLI will automatically detect your IDE or AI agent and configure the skill.

  3. 3. Start using the skill

    The skill is now active. Your AI agent can use project-compliance immediately in the current project.

! Reference-Only Mode

This page remains useful for installation and reference, but Killer-Skills no longer treats it as a primary indexable landing page. Read the review above before relying on the upstream repository instructions.

Upstream Repository Material

The section below is imported from the upstream repository and should be treated as secondary evidence. Use the Killer-Skills review above as the primary layer for fit, risk, and installation decisions.

Upstream Source

project-compliance

ローカライズされた概要: Legal compliance enforcement for LGPD, LAI, Marco Civil da Internet, and security standards. This AI agent skill supports Claude Code, Cursor

SKILL.md
Readonly
Upstream Repository Material
The section below is imported from the upstream repository and should be treated as secondary evidence. Use the Killer-Skills review above as the primary layer for fit, risk, and installation decisions.
Supporting Evidence

Legal Compliance Enforcement

Purpose

Enforces compliance with Brazilian data protection and transparency laws applicable to the Political Authority Highlighter platform.

Applicable Laws

LawScopeKey Articles
LGPD (Lei 13.709/2018)Personal data protectionArt. 6, 7, 8, 9, 10, 37, 41, 46
LAI (Lei 12.527/2011)Access to public informationArt. 3, 8
Marco Civil (Lei 12.965/2014)Internet frameworkArt. 7, 15
Lei da Ficha Limpa (LC 135/2010)Electoral ineligibilityUsed as exclusion filter input
Lei 14.129/2021Digital Government / Open DataArt. 29, 30

LGPD Compliance Checklist

  • Legal basis documented: Legitimate Interest (Art. 7, IX) combined with Publicly Accessible Data (Art. 7, par. 3)
  • LIA (Legitimate Interest Assessment) document exists at docs/compliance/LIA.md
  • LIA includes three-phase balancing test: (i) legitimate purpose, (ii) necessity, (iii) rights balancing + safeguards
  • Processing purpose aligned with public interest and transparency (Art. 7, par. 3)
  • No purpose deviation: data NOT used for marketing, political campaigns, or profiling

B. Privacy Policy

  • Privacy policy page exists at /privacidade (or /privacy)
  • Written in pt-BR, clear and accessible language
  • Content includes:
    • Data controller identity and contact
    • DPO (encarregado) contact information
    • Data sources listed (all 6 government APIs)
    • Processing purposes described
    • Legal basis stated (Art. 7, IX + Art. 7, par. 3)
    • Data categories processed
    • Data retention periods
    • Data subject rights (Art. 18): access, correction, deletion, portability
    • Cookie policy
  • Linked from every page (footer)
  • Last update date displayed

C. DPO (Data Protection Officer / Encarregado)

  • DPO contact information published on the platform
  • Accessible from privacy policy page
  • Email address functional and monitored
  • If qualifying for simplified regime (Resolution CD/ANPD n. 2/2022): alternative contact channel documented

D. CPF Data Protection

  • CPFs stored encrypted using AES-256-GCM in internal_data.politician_identifiers
  • Encryption key stored as environment variable (CPF_ENCRYPTION_KEY)
  • SHA-256 hash used for cross-source matching (no decryption needed for matching)
  • api_reader database role has ZERO permissions on internal_data schema
  • No CPF in API responses, frontend code, URLs, or accessible logs
  • CPF decryption confined to apps/pipeline/src/crypto/cpf.ts only

E. Data Processing Records (Art. 37)

  • Processing activities documented in docs/compliance/ROPA.md (Record of Processing Activities)
  • Each processing activity includes: purpose, legal basis, data categories, recipients, retention, security measures
  • Updated when new data sources are added or processing changes
  • If analytics/tracking cookies are used: consent banner shown BEFORE cookies are set
  • Essential cookies (no consent needed): session, preferences
  • Non-essential cookies (consent required): analytics (Google Analytics, Plausible, etc.)
  • User can reject non-essential cookies and still use the platform
  • Cookie preferences stored and respected

G. Data Subject Rights (Art. 18)

If user registration is added post-MVP:

  • Right to access: users can view their data
  • Right to correction: users can update their data
  • Right to deletion: users can delete their account
  • Right to portability: users can export their data
  • Right to revoke consent: clear and accessible procedure
  • Requests processed within 15 days (ANPD recommended timeline)

LAI Compliance Checklist

Source Attribution

  • Every data point displayed on the platform references its official government source
  • Source URLs point to official .gov.br, .leg.br, or .jus.br domains
  • Data freshness indicator shows when each source was last updated (RF-014)
  • No data from unofficial or private sources (DR-003)

Respect API Terms

  • Portal da Transparencia rate limits respected: 90 req/min (peak), 300 req/min (off-peak)
  • API key used as required by Portal da Transparencia
  • No scraping of HTML pages when APIs are available
  • Bulk CSV downloads used for large datasets (TSE, CGU-PAD)

Marco Civil da Internet Compliance

Content Policy

  • No user-generated content about politicians in MVP (out of scope)
  • No comment sections, ratings, or social features
  • If UGC is added post-MVP: implement notice-and-takedown per Art. 19-21

Log Retention

  • If user authentication is added: server access logs retained for 6 months (Art. 15)
  • Logs stored securely with restricted access
  • Log retention policy documented

Security Baseline

Transport Security

  • All traffic over HTTPS (TLS 1.2+)
  • Automatic certificate renewal (Supabase managed TLS + Vercel managed TLS)
  • HSTS header enabled (max-age: 31536000, includeSubDomains)
  • SSL Labs grade A or above

API Security

  • Rate limiting: 60 req/min per IP on all public endpoints
  • Input validation via TypeBox schemas on all parameters
  • Response schemas defined (prevent field leakage via fast-json-stringify)
  • Security headers via Helmet (CSP, X-Frame-Options, etc.)
  • No CORS for API (same-origin) or restricted CORS for frontend domain only

Secret Management

  • Database passwords in environment variables, never in code
  • Portal da Transparencia API key in environment variable
  • CPF encryption key in environment variable
  • No secrets in git history (git log -p -- '*.env*' returns nothing)
  • .env files in .gitignore
  • Secret scanning enabled in CI/CD pipeline

Database Security

  • Two PostgreSQL roles enforced:
    • api_reader: SELECT only on public schema
    • pipeline_admin: ALL on both schemas
  • No superuser credentials in application code (note: Supabase service role key restricted to pipeline)
  • Database access controlled via Supabase platform security + RLS policies
  • Encrypted connections to database (sslmode=require, enforced by Supabase)

Frontend Security Baseline

  • Content-Security-Policy header configured in next.config.ts headers() (RNF-SEC-011)
  • CSP deployed as Content-Security-Policy-Report-Only initially, then enforced after validation
  • CSP policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: https:; font-src 'self'; connect-src 'self' {API_URL}; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests
  • server-only package installed and imported in all packages/db/src/ modules
  • ESLint no-restricted-imports forbids @pah/db, pg, drizzle-orm in apps/web/
  • CI post-build scan: grep .next/static/chunks/ for forbidden patterns
  • Only NEXT_PUBLIC_API_URL uses NEXT_PUBLIC_ prefix
  • All error.tsx boundaries show generic messages only
  • Pipeline transformers strip HTML tags from government source text before storing in public schema
  • No external scripts without SRI attributes
  • Future auth implementation: httpOnly Secure SameSite=Strict cookies, CSRF protection, RS256 JWT, <=24h session

Backup and Recovery

  • Supabase automatic daily backups (Free tier) + supplementary GitHub Actions pg_dump
  • Supabase managed backup storage + GitHub Actions backup to external storage
  • 7-day retention minimum
  • Restore procedure documented and tested
  • RPO: 24 hours (Supabase daily backup). RTO: 1 hour (Supabase restore).

Compliance Audit Schedule

CheckFrequency
Privacy policy reviewQuarterly
LIA reviewQuarterly or on methodology change
Secret scanEvery commit (CI/CD)
Dependency audit (npm audit)Weekly
CPF leakage checkEvery PR (automated)
Backup restore testMonthly
SSL certificate validityManaged by Supabase/Vercel
Frontend CSP validationEvery deploy (CI)
Client bundle leak scanEvery build (CI)

Changelog

DatePRD VersionSummary
2026-02-281.0Initial compliance enforcement skill
2026-03-071.1Add Frontend Security Baseline section
2026-03-091.2Migrate from VPS/Caddy to Supabase, schema rename public_data→public

関連スキル

Looking for an alternative to project-compliance or another community skill for your workflow? Explore these related open-source skills.

すべて表示

openclaw-release-maintainer

Logo of openclaw
openclaw

ローカライズされた概要: 🦞 # OpenClaw Release Maintainer Use this skill for release and publish-time workflow. It covers ai, assistant, crustacean workflows. This AI agent skill supports Claude Code, Cursor, and Windsurf workflows.

333.8k
0
AI

widget-generator

Logo of f
f

ローカライズされた概要: Generate customizable widget plugins for the prompts.chat feed system # Widget Generator Skill This skill guides creation of widget plugins for prompts.chat . It covers ai, artificial-intelligence, awesome-list workflows. This AI agent skill supports Claude Code, Cursor, and Windsurf

149.6k
0
AI

flags

Logo of vercel
vercel

ローカライズされた概要: The React Framework # Feature Flags Use this skill when adding or changing framework feature flags in Next.js internals. It covers blog, browser, compiler workflows. This AI agent skill supports Claude Code, Cursor, and Windsurf workflows.

138.4k
0
ブラウザ

pr-review

Logo of pytorch
pytorch

ローカライズされた概要: Usage Modes No Argument If the user invokes /pr-review with no arguments, do not perform a review . It covers autograd, deep-learning, gpu workflows. This AI agent skill supports Claude Code, Cursor, and Windsurf workflows.

98.6k
0
開発者