project-compliance — community project-compliance, political-authority-highlighter, community, ide skills, Claude Code, Cursor, Windsurf

v1.0.0

关于此技能

非常适合需要高级巴西数据保护和透明度法律执行能力的监管合规代理 Legal compliance enforcement for LGPD, LAI, Marco Civil da Internet, and security standards. Use when handling personal data, creating privacy-related features, or configuring security.

rodrigorjsf rodrigorjsf
[1]
[0]
更新于: 3/16/2026

Killer-Skills Review

Decision support comes first. Repository text comes second.

Reference-Only Page Review Score: 4/11

This page remains useful for operators, but Killer-Skills treats it as reference material instead of a primary organic landing page.

Concrete use-case guidance Explicit limitations and caution
Review Score
4/11
Quality Score
47
Canonical Locale
en
Detected Body Locale
en

非常适合需要高级巴西数据保护和透明度法律执行能力的监管合规代理 Legal compliance enforcement for LGPD, LAI, Marco Civil da Internet, and security standards. Use when handling personal data, creating privacy-related features, or configuring security.

核心价值

赋予代理人执行符合LGPD、LAI和Marco Civil的法律能力,提供强大的个人数据保护和公共信息访问框架,利用数据匿名化和安全数据存储等协议

适用 Agent 类型

非常适合需要高级巴西数据保护和透明度法律执行能力的监管合规代理

赋予的主要能力 · project-compliance

执行LGPD合规性以处理个人数据
为公共机构生成透明度报告
验证用户根据LAI请求访问公共信息

! 使用限制与门槛

  • 需要了解巴西数据保护和透明度法律
  • 仅限巴西法律框架
  • 需要与现有的数据存储和处理系统集成

Why this page is reference-only

  • - Current locale does not satisfy the locale-governance contract.
  • - The page lacks a strong recommendation layer.
  • - The underlying skill quality score is below the review floor.

Source Boundary

The section below is supporting source material from the upstream repository. Use the Killer-Skills review above as the primary decision layer.

实验室 Demo

Browser Sandbox Environment

⚡️ Ready to unleash?

Experience this Agent in a zero-setup browser environment powered by WebContainers. No installation required.

Boot Container Sandbox

常见问题与安装步骤

以下问题与步骤与页面结构化数据保持一致,便于搜索引擎理解页面内容。

? FAQ

project-compliance 是什么?

非常适合需要高级巴西数据保护和透明度法律执行能力的监管合规代理 Legal compliance enforcement for LGPD, LAI, Marco Civil da Internet, and security standards. Use when handling personal data, creating privacy-related features, or configuring security.

如何安装 project-compliance?

运行命令:npx killer-skills add rodrigorjsf/political-authority-highlighter/project-compliance。支持 Cursor、Windsurf、VS Code、Claude Code 等 19+ IDE/Agent。

project-compliance 适用于哪些场景?

典型场景包括:执行LGPD合规性以处理个人数据、为公共机构生成透明度报告、验证用户根据LAI请求访问公共信息。

project-compliance 支持哪些 IDE 或 Agent?

该技能兼容 Cursor, Windsurf, VS Code, Trae, Claude Code, OpenClaw, Aider, Codex, OpenCode, Goose, Cline, Roo Code, Kiro, Augment Code, Continue, GitHub Copilot, Sourcegraph Cody, and Amazon Q Developer。可使用 Killer-Skills CLI 一条命令通用安装。

project-compliance 有哪些限制?

需要了解巴西数据保护和透明度法律;仅限巴西法律框架;需要与现有的数据存储和处理系统集成。

安装步骤

  1. 1. 打开终端

    在你的项目目录中打开终端或命令行。

  2. 2. 执行安装命令

    运行:npx killer-skills add rodrigorjsf/political-authority-highlighter/project-compliance。CLI 会自动识别 IDE 或 AI Agent 并完成配置。

  3. 3. 开始使用技能

    project-compliance 已启用,可立即在当前项目中调用。

! 参考页模式

此页面仍可作为安装与查阅参考,但 Killer-Skills 不再把它视为主要可索引落地页。请优先阅读上方评审结论,再决定是否继续查看上游仓库说明。

Imported Repository Instructions

The section below is supporting source material from the upstream repository. Use the Killer-Skills review above as the primary decision layer.

Supporting Evidence

project-compliance

安装 project-compliance,这是一款面向AI agent workflows and automation的 AI Agent Skill。支持 Claude Code、Cursor、Windsurf,一键安装。

SKILL.md
Readonly
Imported Repository Instructions
The section below is supporting source material from the upstream repository. Use the Killer-Skills review above as the primary decision layer.
Supporting Evidence

Legal Compliance Enforcement

Purpose

Enforces compliance with Brazilian data protection and transparency laws applicable to the Political Authority Highlighter platform.

Applicable Laws

LawScopeKey Articles
LGPD (Lei 13.709/2018)Personal data protectionArt. 6, 7, 8, 9, 10, 37, 41, 46
LAI (Lei 12.527/2011)Access to public informationArt. 3, 8
Marco Civil (Lei 12.965/2014)Internet frameworkArt. 7, 15
Lei da Ficha Limpa (LC 135/2010)Electoral ineligibilityUsed as exclusion filter input
Lei 14.129/2021Digital Government / Open DataArt. 29, 30

LGPD Compliance Checklist

  • Legal basis documented: Legitimate Interest (Art. 7, IX) combined with Publicly Accessible Data (Art. 7, par. 3)
  • LIA (Legitimate Interest Assessment) document exists at docs/compliance/LIA.md
  • LIA includes three-phase balancing test: (i) legitimate purpose, (ii) necessity, (iii) rights balancing + safeguards
  • Processing purpose aligned with public interest and transparency (Art. 7, par. 3)
  • No purpose deviation: data NOT used for marketing, political campaigns, or profiling

B. Privacy Policy

  • Privacy policy page exists at /privacidade (or /privacy)
  • Written in pt-BR, clear and accessible language
  • Content includes:
    • Data controller identity and contact
    • DPO (encarregado) contact information
    • Data sources listed (all 6 government APIs)
    • Processing purposes described
    • Legal basis stated (Art. 7, IX + Art. 7, par. 3)
    • Data categories processed
    • Data retention periods
    • Data subject rights (Art. 18): access, correction, deletion, portability
    • Cookie policy
  • Linked from every page (footer)
  • Last update date displayed

C. DPO (Data Protection Officer / Encarregado)

  • DPO contact information published on the platform
  • Accessible from privacy policy page
  • Email address functional and monitored
  • If qualifying for simplified regime (Resolution CD/ANPD n. 2/2022): alternative contact channel documented

D. CPF Data Protection

  • CPFs stored encrypted using AES-256-GCM in internal_data.politician_identifiers
  • Encryption key stored as environment variable (CPF_ENCRYPTION_KEY)
  • SHA-256 hash used for cross-source matching (no decryption needed for matching)
  • api_reader database role has ZERO permissions on internal_data schema
  • No CPF in API responses, frontend code, URLs, or accessible logs
  • CPF decryption confined to apps/pipeline/src/crypto/cpf.ts only

E. Data Processing Records (Art. 37)

  • Processing activities documented in docs/compliance/ROPA.md (Record of Processing Activities)
  • Each processing activity includes: purpose, legal basis, data categories, recipients, retention, security measures
  • Updated when new data sources are added or processing changes
  • If analytics/tracking cookies are used: consent banner shown BEFORE cookies are set
  • Essential cookies (no consent needed): session, preferences
  • Non-essential cookies (consent required): analytics (Google Analytics, Plausible, etc.)
  • User can reject non-essential cookies and still use the platform
  • Cookie preferences stored and respected

G. Data Subject Rights (Art. 18)

If user registration is added post-MVP:

  • Right to access: users can view their data
  • Right to correction: users can update their data
  • Right to deletion: users can delete their account
  • Right to portability: users can export their data
  • Right to revoke consent: clear and accessible procedure
  • Requests processed within 15 days (ANPD recommended timeline)

LAI Compliance Checklist

Source Attribution

  • Every data point displayed on the platform references its official government source
  • Source URLs point to official .gov.br, .leg.br, or .jus.br domains
  • Data freshness indicator shows when each source was last updated (RF-014)
  • No data from unofficial or private sources (DR-003)

Respect API Terms

  • Portal da Transparencia rate limits respected: 90 req/min (peak), 300 req/min (off-peak)
  • API key used as required by Portal da Transparencia
  • No scraping of HTML pages when APIs are available
  • Bulk CSV downloads used for large datasets (TSE, CGU-PAD)

Marco Civil da Internet Compliance

Content Policy

  • No user-generated content about politicians in MVP (out of scope)
  • No comment sections, ratings, or social features
  • If UGC is added post-MVP: implement notice-and-takedown per Art. 19-21

Log Retention

  • If user authentication is added: server access logs retained for 6 months (Art. 15)
  • Logs stored securely with restricted access
  • Log retention policy documented

Security Baseline

Transport Security

  • All traffic over HTTPS (TLS 1.2+)
  • Automatic certificate renewal (Supabase managed TLS + Vercel managed TLS)
  • HSTS header enabled (max-age: 31536000, includeSubDomains)
  • SSL Labs grade A or above

API Security

  • Rate limiting: 60 req/min per IP on all public endpoints
  • Input validation via TypeBox schemas on all parameters
  • Response schemas defined (prevent field leakage via fast-json-stringify)
  • Security headers via Helmet (CSP, X-Frame-Options, etc.)
  • No CORS for API (same-origin) or restricted CORS for frontend domain only

Secret Management

  • Database passwords in environment variables, never in code
  • Portal da Transparencia API key in environment variable
  • CPF encryption key in environment variable
  • No secrets in git history (git log -p -- '*.env*' returns nothing)
  • .env files in .gitignore
  • Secret scanning enabled in CI/CD pipeline

Database Security

  • Two PostgreSQL roles enforced:
    • api_reader: SELECT only on public schema
    • pipeline_admin: ALL on both schemas
  • No superuser credentials in application code (note: Supabase service role key restricted to pipeline)
  • Database access controlled via Supabase platform security + RLS policies
  • Encrypted connections to database (sslmode=require, enforced by Supabase)

Frontend Security Baseline

  • Content-Security-Policy header configured in next.config.ts headers() (RNF-SEC-011)
  • CSP deployed as Content-Security-Policy-Report-Only initially, then enforced after validation
  • CSP policy: default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' blob: data: https:; font-src 'self'; connect-src 'self' {API_URL}; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests
  • server-only package installed and imported in all packages/db/src/ modules
  • ESLint no-restricted-imports forbids @pah/db, pg, drizzle-orm in apps/web/
  • CI post-build scan: grep .next/static/chunks/ for forbidden patterns
  • Only NEXT_PUBLIC_API_URL uses NEXT_PUBLIC_ prefix
  • All error.tsx boundaries show generic messages only
  • Pipeline transformers strip HTML tags from government source text before storing in public schema
  • No external scripts without SRI attributes
  • Future auth implementation: httpOnly Secure SameSite=Strict cookies, CSRF protection, RS256 JWT, <=24h session

Backup and Recovery

  • Supabase automatic daily backups (Free tier) + supplementary GitHub Actions pg_dump
  • Supabase managed backup storage + GitHub Actions backup to external storage
  • 7-day retention minimum
  • Restore procedure documented and tested
  • RPO: 24 hours (Supabase daily backup). RTO: 1 hour (Supabase restore).

Compliance Audit Schedule

CheckFrequency
Privacy policy reviewQuarterly
LIA reviewQuarterly or on methodology change
Secret scanEvery commit (CI/CD)
Dependency audit (npm audit)Weekly
CPF leakage checkEvery PR (automated)
Backup restore testMonthly
SSL certificate validityManaged by Supabase/Vercel
Frontend CSP validationEvery deploy (CI)
Client bundle leak scanEvery build (CI)

Changelog

DatePRD VersionSummary
2026-02-281.0Initial compliance enforcement skill
2026-03-071.1Add Frontend Security Baseline section
2026-03-091.2Migrate from VPS/Caddy to Supabase, schema rename public_data→public

相关技能

寻找 project-compliance 的替代方案 (Alternative) 或可搭配使用的同类 community Skill?探索以下相关开源技能。

查看全部

openclaw-release-maintainer

Logo of openclaw
openclaw

Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞

333.8k
0
AI

widget-generator

Logo of f
f

为prompts.chat的信息反馈系统生成可定制的插件小部件

149.6k
0
AI

flags

Logo of vercel
vercel

React 框架

138.4k
0
浏览器

pr-review

Logo of pytorch
pytorch

Python中具有强大GPU加速的张量和动态神经网络

98.6k
0
开发者工具