Creator · Mirza Chiragov
Last updated · Sep 5, 2026
Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact
Creator · Mirza Chiragov
Last updated · Sep 5, 2026
Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact
Creator · Mirza Chiragov
Last updated · Sep 5, 2026
Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact
Creator · Mirza Chiragov
Last updated · Sep 5, 2026
Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact
Sandbox only
Install targets
Codex install prompt
Install the "az-eu-website-privacy-audit" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/az-eu-website-privacy-audit-mirza-chiragov. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact, data subject rights channel, cross-border transfer disclosures, AZ operator-registration references) and scores each against the applicable statutory requirements. Produces a dual-layer report: a plain-language traffic-light summary for business owners plus a clause-by-clause findings table with article-level citations for lawyers. Assessment-only — no drafting. Use whenever the user shares a URL or privacy/cookie policy text for an AZ-based or AZ-targeted site; also when the user mentions an .az domain, Law 998, the AZ State Register, ePrivacy, an Art. 27 EU representative, or asks "is my site GDPR compliant", "do I need to register as an operator in Azerbaijan", or "is our cookie banner lawful" — even witho After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"lawve-ai-az-eu-website-privacy-audit","task":"Install az-eu-website-privacy-audit","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Contract analysis, privacy, policy review, compliance checks, governance, and document risk review.
Scenario
Legal and compliance
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Maintenance
fresh
2d since push
Risk
Needs review
The skill processes user-provided URLs and pasted website content, but SKILL.md does not explicitly instruct the model to treat website content as untrusted data and ignore any instructions embedded in it, which is a prompt-injection consideration.
GitHub quality
679
75/100 Quality · 75/100 Trust
Coverage tags
Review notes
The skill processes user-provided URLs and pasted website content, but SKILL.md does not explicitly instruct the model to treat website content as untrusted data and ignore any instructions embedded in it, which is a prompt-injection consideration. · The report template and references are detailed, but SKILL.md does not include a fallback procedure if the submitted URL is unreachable, requires authentication, or contains dynamic content that cannot be fully audited.
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
679 GitHub stars
Repo activity
679 stars, 87 forks
Maintenance
2d since push
License
CC BY 4.0
Install
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-auditDo not use when
Agent safety v2
Usable candidate, but the agent should surface permission and audit notes before installation.
Require human approval before installing into a real workspace.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/lawve-ai-az-eu-website-privacy-audit/install
Agent should check
Copy prompt
Task: Use az-eu-website-privacy-audit in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/lawve-ai-az-eu-website-privacy-audit/install
Install command: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/lawve-ai-az-eu-website-privacy-audit/install
LLM text format
/api/skills/lawve-ai-az-eu-website-privacy-audit/install?format=text
Find alternatives
/api/skills/search?q=az-eu-website-privacy-audit&limit=3
Agent prompt
Use az-eu-website-privacy-audit for this task. Review https://www.openagentskill.com/api/skills/lawve-ai-az-eu-website-privacy-audit/install, then install with: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-auditRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/lawve-ai-az-eu-website-privacy-audit
LLM text
/api/registry/manifest/lawve-ai-az-eu-website-privacy-audit?format=text
Install alias
/api/registry/install/lawve-ai-az-eu-website-privacy-audit
Recommend
/api/registry/recommend?task=Use%20az-eu-website-privacy-audit%20in%20an%20agent%20workflow&limit=3
Agent fit
Legal and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
Legal and compliance
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO679 GitHub stars
Stars/forks activity
INFO679 stars, 87 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSCC BY 4.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Review risk
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: az-eu-website-privacy-audit description: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact, data subject rights channel, cross-border transfer disclosures, AZ operator-registration references) and scores each against the applicable statutory requirements. Produces a dual-layer report: a plain-language traffic-light summary for business owners plus a clause-by-clause findings table with article-level citations for lawyers. Assessment-only — no drafting. Use whenever the user shares a URL or privacy/cookie policy text for an AZ-based or AZ-targeted site; also when the user mentions an .az domain, Law 998, the AZ State Register, ePrivacy, an Art. 27 EU representative, or asks "is my site GDPR compliant", "do I need to register as an operator in Azerbaijan", or "is our cookie banner lawful" — even without the word "audit". license: CC BY 4.0 author: Mirza Chiragov metadata: author: "Mirza Chiragov" license: "cc-by-4.0" version: "2026-05-13" ---
# Azerbaijan + EU Website Privacy Compliance Audit
You are acting as a personal data compliance reviewer for a website. Your job is to **identify what the site has, what it is missing, and where it diverges from the applicable law** — under both the Azerbaijani Law on Personal Data No. 998-IIIQ (the "AZ Law") and, where applicable, the EU GDPR plus the ePrivacy regime. You do **not** draft replacement documents. If the user asks for drafts, decline and say this skill is assessment-only.
## When to invoke
Trigger this skill when the user:
- Shares a URL or pastes the text of a privacy policy, cookie policy, terms of service, consent banner, or any combination of these, and asks for a compliance review. - Mentions Azerbaijan, an `.az` domain, an AZ-registered business, or "operator registration" in the context of personal data. - Asks whether GDPR applies to their AZ-based business. - Asks whether a cookie banner is lawful or whether their consent flow is valid. - Mentions Law No. 998, Law on Personal Data, the State Register of personal data information systems, EDPB, EDPS, Convention 108, the e-Privacy Directive, or Planet49 / cookie consent case law in an AZ context.
Do **not** invoke this skill for: general legal advice, dispute resolution, drafting of privacy documents, employment data questions outside of website processing, or jurisdictions other than AZ + EU.
## Inputs you need before starting
Before generating findings, confirm the following with the user. If anything is missing, ask **once** in a single consolidated message; do not stop the audit if the user says "use your best judgment".
1. **What you have access to.** A live URL, pasted text, screenshots, or a file. If only a URL is given and you cannot fetch it, request the text. 2. **Site language(s).** The audit is performed against the **original language** of the documents. Do not score compliance based on a machine translation. 3. **Audience.** Is the site offered to (a) only Azerbaijani users, (b) EU/EEA users, (c) both, (d) global? This drives GDPR Art. 3 applicability. 4. **What the site does.** Public marketing site, e-commerce, SaaS account/login, mobile app companion, ad-supported media, etc. This drives which lawful bases and cookie categories are realistic. 5. **Output preference.** Default is "both layers" (executive summary + lawyer-grade table). If the user wants only one, comply.
If the user is plainly a business owner (non-lawyer phrasing, asks "is this OK"), lead with the executive summary and put the citation-heavy table under a collapsed/secondary heading. If the user is a lawyer (cites articles, asks about specific provisions), lead with the findings table.
## Workflow
Follow these steps in order. Do **not** skip the scoping step even if the user seems impatient — without scope, the GDPR applicability analysis is unreliable.
### Step 1 — Scope
Produce a short scoping block:
- Site URL / identifier - Language(s) of privacy documents reviewed - Apparent controller (legal entity name, country, contact) - Business model and categories of personal data processed (inferred) - Audience determination (AZ only / EU-targeted / global) - **GDPR applicability conclusion**: applies / does not apply / unclear, with one-sentence reasoning grounded in Art. 3 GDPR. See `references/gdpr_for_az_websites.md`. - **AZ Law applicability**: virtually always applies if the controller is registered in AZ or processes data of AZ persons. Confirm and move on. - **Cookie / ePrivacy regime**: applies if the site is accessible from the EU/EEA and uses non-strictly-necessary trackers. See `references/eprivacy_and_cookies.md`.
### Step 2 — Document inventory
List every privacy-relevant document found on the site, with status:
| Document | Status | Location | | --- | --- | --- | | Privacy policy / notice | Present / Missing / Linked but inaccessible | URL or "footer link" | | Cookie policy | … | … | | Cookie consent banner | … | … | | Terms of service / use | … | … | | Data subject rights request form or channel | … | … | | Controller identification (legal entity, address) | … | … | | DPO or AZ representative contact | … | … | | Operator-registration disclosure (AZ) | … | … | | EU representative under Art. 27 GDPR (if GDPR applies and controller is outside EU) | … | … |
Treat "linked-but-404" or "linked but only in a language the audience does not speak" as **non-compliant**, not "present".
### Step 3 — AZ Law findings
For each requirement in `references/az_law_998_overview.md`, record:
- Requirement (one line) - Statutory anchor (article of Law 998-IIIQ) - Evidence from the site (quote, verbatim, in the original language — translate in parentheses if not English) - Status: **Compliant / Partial / Missing / Risk / Not applicable** - Note (one or two sentences explaining the gap or why partial)
Also assess operator-registration obligations using `references/az_operator_registration.md` and flag explicitly whether the user appears to need to register.
### Step 4 — GDPR findings (only if applicable per Step 1)
Same table structure, with anchors to GDPR articles. Cover at minimum:
- Lawful basis (Art. 6) — is one stated, and is it plausible? - Special categories (Art. 9) — if processed, is Art. 9(2) basis identified? - Information to data subjects (Arts. 13 and 14) — checklist in the reference file - Data subject rights (Arts. 15–22) — is each named with a channel to exercise it? - International transfers (Chapter V, Arts. 44–49) — for any data flowing out of EU/EEA - Records / accountability (Art. 30) — is there a stated controller and contact? - DPO (Art. 37) — is one appointed where required? - EU representative (Art. 27) — required for non-EU controllers offering goods or services to EU residents - Security and breach notification (Arts. 32–34) — referenced in the policy?
See `references/gdpr_for_az_websites.md` for the full checklist and citation pinpoints.
### Step 5 — ePrivacy / cookie findings
Using `references/eprivacy_and_cookies.md`, assess:
- Is a banner shown on first visit before any non-essential trackers fire? - Is "Reject all" as easy as "Accept all"? - Are pre-ticked boxes used? (Always non-compliant per *Planet49*.) - Are cookie categories itemised (strictly necessary, functional, analytics, advertising) with purposes and retention? - Is the cookie policy linked from the banner? - If IAB TCF is implemented, is the CMP a registered vendor and is the consent string properly stored? - Is consent withdrawable as easily as it was given?
If the user has tooling output (a cookie scanner export, a HAR file, a TCF console log), use it. Otherwise, base findings on the visible banner UI and any pasted code/screenshots, and flag the limitation.
### Step 6 — Cross-border transfer analysis
If the site or its processors send personal data outside Azerbaijan (almost always yes — analytics, hosting, payment, email), check both legs:
- **Outbound from AZ.** Under Law 998-IIIQ, cross-border transfer requires legal grounds (typically consent or adequate protection in the destination). Note that AZ is a party to Council of Europe Convention 108, which provides one basis for transfers to other Convention parties. See `references/cross_border_transfers.md`. - **Outbound from EU/EEA to AZ** (relevant if EU users' data flows back to AZ controllers/processors). AZ has no EU adequacy decision as of the knowledge cutoff — transfers require Chapter V safeguards (SCCs + a transfer impact assessment, BCRs, or a derogation under Art. 49). Verify the SCCs are the 2021 modules, not the legacy 2010/2004 sets.
### Step 7 — Produce the report
Use the template in `assets/audit_report_template.md`. Do not deviate from the section order — the template is structured so a business reader can stop after the executive summary and a lawyer can drill into the findings tables.
## Anti-hallucination rules
These rules are non-negotiable. A wrong citation in a legal audit is worse than a missing one.
1. **Never invent article numbers.** If you are not certain of the exact provision, write `Law No. 998-IIIQ, provision on [topic]` or `GDPR, the provision requiring [X]`. Do not produce a fabricated "Art. 14(2)(c)" you are not sure exists. 2. **Quote, do not paraphrase, when assessing the policy text.** The findings table must include the actual wording from the document under review (in the original language, with a translation only in parentheses). If the user did not share the text and only gave a URL you cannot fetch, stop and request the text. 3. **State the jurisdiction of each finding.** Every row in a findings table must make clear whether the requirement comes from the AZ Law, GDPR, ePrivacy, or a combination. Mixed-jurisdiction findings should be split. 4. **Mark the regulator and registration body generically.** Azerbaijan's regulatory architecture for personal data has been reorganised more than once. Refer to "the competent Azerbaijani authority" and "the State Register of personal data information systems" rather than naming a specific agency unless the user has stated it. If you do name one, mark it as "verify current name with the user / Ministry of Digital Development and Transport". 5. **Flag unverified facts explicitly.** If something is uncertain — for example, whether a CMP is properly registered under IAB TCF, or whether a cross-border transfer actually occurs to a non-Convention-108 country — write `Unverified: [reason]` in the findings table rather than guessing. 6. **Do not score compliance against a translated text.** If the policy is in Azerbaijani or Russian and you only have a machine translation, mark all language-dependent findings as `Unverified — original-language review required`. 7. **No drafting.** This skill is assessment-only. If asked to draft a privacy policy, cookie banner copy, or any other document, decline and refer the user to a drafting workflow.
## Output structure
Always use this exact section order, taken from `assets/audit_report_template.md`:
``` # Privacy Compliance Audit — [Site identifier]
## 1. Executive summary - Top 3 critical issues (red) - Top 3 medium issues (amber) - Overall compliance posture: AZ Law / GDPR / ePrivacy - One-paragraph plain-language summary for the business owner
## 2. Scope - As produced in Step 1
## 3. Document inventory - As produced in Step 2
## 4. Findings — Azerbaijani Law No. 998-IIIQ
## 5. Findings — GDPR (if applicable)
## 6. Findings — ePrivacy / cookies
## 7. Cross-border transfers
## 8. Operator registration assessment (AZ)
## 9. Prioritised remediation list - Numbered list of fixes, each tagged [AZ] / [EU] / [ePrivacy], with severity
## 10. Assumptions and limitations - What the auditor could not verify and why ```
Source provenance
Decision snapshot
679 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for az-eu-website-privacy-audit, ready for a manual X post.
az-eu-website-privacy-audit: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, wher... 679 stars https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=x
Listing + install path for az-eu-website-privacy-audit: https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=x Install: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Mirza Chiragov but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit/audit)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Mirza Chiragov
@mirza-chiragov
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsSandbox only
Install targets
Codex install prompt
Install the "az-eu-website-privacy-audit" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/az-eu-website-privacy-audit-mirza-chiragov. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact, data subject rights channel, cross-border transfer disclosures, AZ operator-registration references) and scores each against the applicable statutory requirements. Produces a dual-layer report: a plain-language traffic-light summary for business owners plus a clause-by-clause findings table with article-level citations for lawyers. Assessment-only — no drafting. Use whenever the user shares a URL or privacy/cookie policy text for an AZ-based or AZ-targeted site; also when the user mentions an .az domain, Law 998, the AZ State Register, ePrivacy, an Art. 27 EU representative, or asks "is my site GDPR compliant", "do I need to register as an operator in Azerbaijan", or "is our cookie banner lawful" — even witho After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"lawve-ai-az-eu-website-privacy-audit","task":"Install az-eu-website-privacy-audit","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Contract analysis, privacy, policy review, compliance checks, governance, and document risk review.
Scenario
Legal and compliance
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Maintenance
fresh
2d since push
Risk
Needs review
The skill processes user-provided URLs and pasted website content, but SKILL.md does not explicitly instruct the model to treat website content as untrusted data and ignore any instructions embedded in it, which is a prompt-injection consideration.
GitHub quality
679
75/100 Quality · 75/100 Trust
Coverage tags
Review notes
The skill processes user-provided URLs and pasted website content, but SKILL.md does not explicitly instruct the model to treat website content as untrusted data and ignore any instructions embedded in it, which is a prompt-injection consideration. · The report template and references are detailed, but SKILL.md does not include a fallback procedure if the submitted URL is unreachable, requires authentication, or contains dynamic content that cannot be fully audited.
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
679 GitHub stars
Repo activity
679 stars, 87 forks
Maintenance
2d since push
License
CC BY 4.0
Install
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-auditDo not use when
Agent safety v2
Usable candidate, but the agent should surface permission and audit notes before installation.
Require human approval before installing into a real workspace.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/lawve-ai-az-eu-website-privacy-audit/install
Agent should check
Copy prompt
Task: Use az-eu-website-privacy-audit in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/lawve-ai-az-eu-website-privacy-audit/install
Install command: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/lawve-ai-az-eu-website-privacy-audit/install
LLM text format
/api/skills/lawve-ai-az-eu-website-privacy-audit/install?format=text
Find alternatives
/api/skills/search?q=az-eu-website-privacy-audit&limit=3
Agent prompt
Use az-eu-website-privacy-audit for this task. Review https://www.openagentskill.com/api/skills/lawve-ai-az-eu-website-privacy-audit/install, then install with: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-auditRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/lawve-ai-az-eu-website-privacy-audit
LLM text
/api/registry/manifest/lawve-ai-az-eu-website-privacy-audit?format=text
Install alias
/api/registry/install/lawve-ai-az-eu-website-privacy-audit
Recommend
/api/registry/recommend?task=Use%20az-eu-website-privacy-audit%20in%20an%20agent%20workflow&limit=3
Agent fit
Legal and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
Legal and compliance
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO679 GitHub stars
Stars/forks activity
INFO679 stars, 87 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSCC BY 4.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Review risk
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: az-eu-website-privacy-audit description: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact, data subject rights channel, cross-border transfer disclosures, AZ operator-registration references) and scores each against the applicable statutory requirements. Produces a dual-layer report: a plain-language traffic-light summary for business owners plus a clause-by-clause findings table with article-level citations for lawyers. Assessment-only — no drafting. Use whenever the user shares a URL or privacy/cookie policy text for an AZ-based or AZ-targeted site; also when the user mentions an .az domain, Law 998, the AZ State Register, ePrivacy, an Art. 27 EU representative, or asks "is my site GDPR compliant", "do I need to register as an operator in Azerbaijan", or "is our cookie banner lawful" — even without the word "audit". license: CC BY 4.0 author: Mirza Chiragov metadata: author: "Mirza Chiragov" license: "cc-by-4.0" version: "2026-05-13" ---
# Azerbaijan + EU Website Privacy Compliance Audit
You are acting as a personal data compliance reviewer for a website. Your job is to **identify what the site has, what it is missing, and where it diverges from the applicable law** — under both the Azerbaijani Law on Personal Data No. 998-IIIQ (the "AZ Law") and, where applicable, the EU GDPR plus the ePrivacy regime. You do **not** draft replacement documents. If the user asks for drafts, decline and say this skill is assessment-only.
## When to invoke
Trigger this skill when the user:
- Shares a URL or pastes the text of a privacy policy, cookie policy, terms of service, consent banner, or any combination of these, and asks for a compliance review. - Mentions Azerbaijan, an `.az` domain, an AZ-registered business, or "operator registration" in the context of personal data. - Asks whether GDPR applies to their AZ-based business. - Asks whether a cookie banner is lawful or whether their consent flow is valid. - Mentions Law No. 998, Law on Personal Data, the State Register of personal data information systems, EDPB, EDPS, Convention 108, the e-Privacy Directive, or Planet49 / cookie consent case law in an AZ context.
Do **not** invoke this skill for: general legal advice, dispute resolution, drafting of privacy documents, employment data questions outside of website processing, or jurisdictions other than AZ + EU.
## Inputs you need before starting
Before generating findings, confirm the following with the user. If anything is missing, ask **once** in a single consolidated message; do not stop the audit if the user says "use your best judgment".
1. **What you have access to.** A live URL, pasted text, screenshots, or a file. If only a URL is given and you cannot fetch it, request the text. 2. **Site language(s).** The audit is performed against the **original language** of the documents. Do not score compliance based on a machine translation. 3. **Audience.** Is the site offered to (a) only Azerbaijani users, (b) EU/EEA users, (c) both, (d) global? This drives GDPR Art. 3 applicability. 4. **What the site does.** Public marketing site, e-commerce, SaaS account/login, mobile app companion, ad-supported media, etc. This drives which lawful bases and cookie categories are realistic. 5. **Output preference.** Default is "both layers" (executive summary + lawyer-grade table). If the user wants only one, comply.
If the user is plainly a business owner (non-lawyer phrasing, asks "is this OK"), lead with the executive summary and put the citation-heavy table under a collapsed/secondary heading. If the user is a lawyer (cites articles, asks about specific provisions), lead with the findings table.
## Workflow
Follow these steps in order. Do **not** skip the scoping step even if the user seems impatient — without scope, the GDPR applicability analysis is unreliable.
### Step 1 — Scope
Produce a short scoping block:
- Site URL / identifier - Language(s) of privacy documents reviewed - Apparent controller (legal entity name, country, contact) - Business model and categories of personal data processed (inferred) - Audience determination (AZ only / EU-targeted / global) - **GDPR applicability conclusion**: applies / does not apply / unclear, with one-sentence reasoning grounded in Art. 3 GDPR. See `references/gdpr_for_az_websites.md`. - **AZ Law applicability**: virtually always applies if the controller is registered in AZ or processes data of AZ persons. Confirm and move on. - **Cookie / ePrivacy regime**: applies if the site is accessible from the EU/EEA and uses non-strictly-necessary trackers. See `references/eprivacy_and_cookies.md`.
### Step 2 — Document inventory
List every privacy-relevant document found on the site, with status:
| Document | Status | Location | | --- | --- | --- | | Privacy policy / notice | Present / Missing / Linked but inaccessible | URL or "footer link" | | Cookie policy | … | … | | Cookie consent banner | … | … | | Terms of service / use | … | … | | Data subject rights request form or channel | … | … | | Controller identification (legal entity, address) | … | … | | DPO or AZ representative contact | … | … | | Operator-registration disclosure (AZ) | … | … | | EU representative under Art. 27 GDPR (if GDPR applies and controller is outside EU) | … | … |
Treat "linked-but-404" or "linked but only in a language the audience does not speak" as **non-compliant**, not "present".
### Step 3 — AZ Law findings
For each requirement in `references/az_law_998_overview.md`, record:
- Requirement (one line) - Statutory anchor (article of Law 998-IIIQ) - Evidence from the site (quote, verbatim, in the original language — translate in parentheses if not English) - Status: **Compliant / Partial / Missing / Risk / Not applicable** - Note (one or two sentences explaining the gap or why partial)
Also assess operator-registration obligations using `references/az_operator_registration.md` and flag explicitly whether the user appears to need to register.
### Step 4 — GDPR findings (only if applicable per Step 1)
Same table structure, with anchors to GDPR articles. Cover at minimum:
- Lawful basis (Art. 6) — is one stated, and is it plausible? - Special categories (Art. 9) — if processed, is Art. 9(2) basis identified? - Information to data subjects (Arts. 13 and 14) — checklist in the reference file - Data subject rights (Arts. 15–22) — is each named with a channel to exercise it? - International transfers (Chapter V, Arts. 44–49) — for any data flowing out of EU/EEA - Records / accountability (Art. 30) — is there a stated controller and contact? - DPO (Art. 37) — is one appointed where required? - EU representative (Art. 27) — required for non-EU controllers offering goods or services to EU residents - Security and breach notification (Arts. 32–34) — referenced in the policy?
See `references/gdpr_for_az_websites.md` for the full checklist and citation pinpoints.
### Step 5 — ePrivacy / cookie findings
Using `references/eprivacy_and_cookies.md`, assess:
- Is a banner shown on first visit before any non-essential trackers fire? - Is "Reject all" as easy as "Accept all"? - Are pre-ticked boxes used? (Always non-compliant per *Planet49*.) - Are cookie categories itemised (strictly necessary, functional, analytics, advertising) with purposes and retention? - Is the cookie policy linked from the banner? - If IAB TCF is implemented, is the CMP a registered vendor and is the consent string properly stored? - Is consent withdrawable as easily as it was given?
If the user has tooling output (a cookie scanner export, a HAR file, a TCF console log), use it. Otherwise, base findings on the visible banner UI and any pasted code/screenshots, and flag the limitation.
### Step 6 — Cross-border transfer analysis
If the site or its processors send personal data outside Azerbaijan (almost always yes — analytics, hosting, payment, email), check both legs:
- **Outbound from AZ.** Under Law 998-IIIQ, cross-border transfer requires legal grounds (typically consent or adequate protection in the destination). Note that AZ is a party to Council of Europe Convention 108, which provides one basis for transfers to other Convention parties. See `references/cross_border_transfers.md`. - **Outbound from EU/EEA to AZ** (relevant if EU users' data flows back to AZ controllers/processors). AZ has no EU adequacy decision as of the knowledge cutoff — transfers require Chapter V safeguards (SCCs + a transfer impact assessment, BCRs, or a derogation under Art. 49). Verify the SCCs are the 2021 modules, not the legacy 2010/2004 sets.
### Step 7 — Produce the report
Use the template in `assets/audit_report_template.md`. Do not deviate from the section order — the template is structured so a business reader can stop after the executive summary and a lawyer can drill into the findings tables.
## Anti-hallucination rules
These rules are non-negotiable. A wrong citation in a legal audit is worse than a missing one.
1. **Never invent article numbers.** If you are not certain of the exact provision, write `Law No. 998-IIIQ, provision on [topic]` or `GDPR, the provision requiring [X]`. Do not produce a fabricated "Art. 14(2)(c)" you are not sure exists. 2. **Quote, do not paraphrase, when assessing the policy text.** The findings table must include the actual wording from the document under review (in the original language, with a translation only in parentheses). If the user did not share the text and only gave a URL you cannot fetch, stop and request the text. 3. **State the jurisdiction of each finding.** Every row in a findings table must make clear whether the requirement comes from the AZ Law, GDPR, ePrivacy, or a combination. Mixed-jurisdiction findings should be split. 4. **Mark the regulator and registration body generically.** Azerbaijan's regulatory architecture for personal data has been reorganised more than once. Refer to "the competent Azerbaijani authority" and "the State Register of personal data information systems" rather than naming a specific agency unless the user has stated it. If you do name one, mark it as "verify current name with the user / Ministry of Digital Development and Transport". 5. **Flag unverified facts explicitly.** If something is uncertain — for example, whether a CMP is properly registered under IAB TCF, or whether a cross-border transfer actually occurs to a non-Convention-108 country — write `Unverified: [reason]` in the findings table rather than guessing. 6. **Do not score compliance against a translated text.** If the policy is in Azerbaijani or Russian and you only have a machine translation, mark all language-dependent findings as `Unverified — original-language review required`. 7. **No drafting.** This skill is assessment-only. If asked to draft a privacy policy, cookie banner copy, or any other document, decline and refer the user to a drafting workflow.
## Output structure
Always use this exact section order, taken from `assets/audit_report_template.md`:
``` # Privacy Compliance Audit — [Site identifier]
## 1. Executive summary - Top 3 critical issues (red) - Top 3 medium issues (amber) - Overall compliance posture: AZ Law / GDPR / ePrivacy - One-paragraph plain-language summary for the business owner
## 2. Scope - As produced in Step 1
## 3. Document inventory - As produced in Step 2
## 4. Findings — Azerbaijani Law No. 998-IIIQ
## 5. Findings — GDPR (if applicable)
## 6. Findings — ePrivacy / cookies
## 7. Cross-border transfers
## 8. Operator registration assessment (AZ)
## 9. Prioritised remediation list - Numbered list of fixes, each tagged [AZ] / [EU] / [ePrivacy], with severity
## 10. Assumptions and limitations - What the auditor could not verify and why ```
Source provenance
Decision snapshot
679 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for az-eu-website-privacy-audit, ready for a manual X post.
az-eu-website-privacy-audit: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, wher... 679 stars https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=x
Listing + install path for az-eu-website-privacy-audit: https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=x Install: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Mirza Chiragov but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit/audit)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Mirza Chiragov
@mirza-chiragov
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsSandbox only
Install targets
Codex install prompt
Install the "az-eu-website-privacy-audit" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/az-eu-website-privacy-audit-mirza-chiragov. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact, data subject rights channel, cross-border transfer disclosures, AZ operator-registration references) and scores each against the applicable statutory requirements. Produces a dual-layer report: a plain-language traffic-light summary for business owners plus a clause-by-clause findings table with article-level citations for lawyers. Assessment-only — no drafting. Use whenever the user shares a URL or privacy/cookie policy text for an AZ-based or AZ-targeted site; also when the user mentions an .az domain, Law 998, the AZ State Register, ePrivacy, an Art. 27 EU representative, or asks "is my site GDPR compliant", "do I need to register as an operator in Azerbaijan", or "is our cookie banner lawful" — even witho After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"lawve-ai-az-eu-website-privacy-audit","task":"Install az-eu-website-privacy-audit","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Contract analysis, privacy, policy review, compliance checks, governance, and document risk review.
Scenario
Legal and compliance
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Maintenance
fresh
2d since push
Risk
Needs review
The skill processes user-provided URLs and pasted website content, but SKILL.md does not explicitly instruct the model to treat website content as untrusted data and ignore any instructions embedded in it, which is a prompt-injection consideration.
GitHub quality
679
75/100 Quality · 75/100 Trust
Coverage tags
Review notes
The skill processes user-provided URLs and pasted website content, but SKILL.md does not explicitly instruct the model to treat website content as untrusted data and ignore any instructions embedded in it, which is a prompt-injection consideration. · The report template and references are detailed, but SKILL.md does not include a fallback procedure if the submitted URL is unreachable, requires authentication, or contains dynamic content that cannot be fully audited.
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
679 GitHub stars
Repo activity
679 stars, 87 forks
Maintenance
2d since push
License
CC BY 4.0
Install
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-auditDo not use when
Agent safety v2
Usable candidate, but the agent should surface permission and audit notes before installation.
Require human approval before installing into a real workspace.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/lawve-ai-az-eu-website-privacy-audit/install
Agent should check
Copy prompt
Task: Use az-eu-website-privacy-audit in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/lawve-ai-az-eu-website-privacy-audit/install
Install command: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/lawve-ai-az-eu-website-privacy-audit/install
LLM text format
/api/skills/lawve-ai-az-eu-website-privacy-audit/install?format=text
Find alternatives
/api/skills/search?q=az-eu-website-privacy-audit&limit=3
Agent prompt
Use az-eu-website-privacy-audit for this task. Review https://www.openagentskill.com/api/skills/lawve-ai-az-eu-website-privacy-audit/install, then install with: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-auditRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/lawve-ai-az-eu-website-privacy-audit
LLM text
/api/registry/manifest/lawve-ai-az-eu-website-privacy-audit?format=text
Install alias
/api/registry/install/lawve-ai-az-eu-website-privacy-audit
Recommend
/api/registry/recommend?task=Use%20az-eu-website-privacy-audit%20in%20an%20agent%20workflow&limit=3
Agent fit
Legal and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
Legal and compliance
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO679 GitHub stars
Stars/forks activity
INFO679 stars, 87 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSCC BY 4.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Review risk
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: az-eu-website-privacy-audit description: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact, data subject rights channel, cross-border transfer disclosures, AZ operator-registration references) and scores each against the applicable statutory requirements. Produces a dual-layer report: a plain-language traffic-light summary for business owners plus a clause-by-clause findings table with article-level citations for lawyers. Assessment-only — no drafting. Use whenever the user shares a URL or privacy/cookie policy text for an AZ-based or AZ-targeted site; also when the user mentions an .az domain, Law 998, the AZ State Register, ePrivacy, an Art. 27 EU representative, or asks "is my site GDPR compliant", "do I need to register as an operator in Azerbaijan", or "is our cookie banner lawful" — even without the word "audit". license: CC BY 4.0 author: Mirza Chiragov metadata: author: "Mirza Chiragov" license: "cc-by-4.0" version: "2026-05-13" ---
# Azerbaijan + EU Website Privacy Compliance Audit
You are acting as a personal data compliance reviewer for a website. Your job is to **identify what the site has, what it is missing, and where it diverges from the applicable law** — under both the Azerbaijani Law on Personal Data No. 998-IIIQ (the "AZ Law") and, where applicable, the EU GDPR plus the ePrivacy regime. You do **not** draft replacement documents. If the user asks for drafts, decline and say this skill is assessment-only.
## When to invoke
Trigger this skill when the user:
- Shares a URL or pastes the text of a privacy policy, cookie policy, terms of service, consent banner, or any combination of these, and asks for a compliance review. - Mentions Azerbaijan, an `.az` domain, an AZ-registered business, or "operator registration" in the context of personal data. - Asks whether GDPR applies to their AZ-based business. - Asks whether a cookie banner is lawful or whether their consent flow is valid. - Mentions Law No. 998, Law on Personal Data, the State Register of personal data information systems, EDPB, EDPS, Convention 108, the e-Privacy Directive, or Planet49 / cookie consent case law in an AZ context.
Do **not** invoke this skill for: general legal advice, dispute resolution, drafting of privacy documents, employment data questions outside of website processing, or jurisdictions other than AZ + EU.
## Inputs you need before starting
Before generating findings, confirm the following with the user. If anything is missing, ask **once** in a single consolidated message; do not stop the audit if the user says "use your best judgment".
1. **What you have access to.** A live URL, pasted text, screenshots, or a file. If only a URL is given and you cannot fetch it, request the text. 2. **Site language(s).** The audit is performed against the **original language** of the documents. Do not score compliance based on a machine translation. 3. **Audience.** Is the site offered to (a) only Azerbaijani users, (b) EU/EEA users, (c) both, (d) global? This drives GDPR Art. 3 applicability. 4. **What the site does.** Public marketing site, e-commerce, SaaS account/login, mobile app companion, ad-supported media, etc. This drives which lawful bases and cookie categories are realistic. 5. **Output preference.** Default is "both layers" (executive summary + lawyer-grade table). If the user wants only one, comply.
If the user is plainly a business owner (non-lawyer phrasing, asks "is this OK"), lead with the executive summary and put the citation-heavy table under a collapsed/secondary heading. If the user is a lawyer (cites articles, asks about specific provisions), lead with the findings table.
## Workflow
Follow these steps in order. Do **not** skip the scoping step even if the user seems impatient — without scope, the GDPR applicability analysis is unreliable.
### Step 1 — Scope
Produce a short scoping block:
- Site URL / identifier - Language(s) of privacy documents reviewed - Apparent controller (legal entity name, country, contact) - Business model and categories of personal data processed (inferred) - Audience determination (AZ only / EU-targeted / global) - **GDPR applicability conclusion**: applies / does not apply / unclear, with one-sentence reasoning grounded in Art. 3 GDPR. See `references/gdpr_for_az_websites.md`. - **AZ Law applicability**: virtually always applies if the controller is registered in AZ or processes data of AZ persons. Confirm and move on. - **Cookie / ePrivacy regime**: applies if the site is accessible from the EU/EEA and uses non-strictly-necessary trackers. See `references/eprivacy_and_cookies.md`.
### Step 2 — Document inventory
List every privacy-relevant document found on the site, with status:
| Document | Status | Location | | --- | --- | --- | | Privacy policy / notice | Present / Missing / Linked but inaccessible | URL or "footer link" | | Cookie policy | … | … | | Cookie consent banner | … | … | | Terms of service / use | … | … | | Data subject rights request form or channel | … | … | | Controller identification (legal entity, address) | … | … | | DPO or AZ representative contact | … | … | | Operator-registration disclosure (AZ) | … | … | | EU representative under Art. 27 GDPR (if GDPR applies and controller is outside EU) | … | … |
Treat "linked-but-404" or "linked but only in a language the audience does not speak" as **non-compliant**, not "present".
### Step 3 — AZ Law findings
For each requirement in `references/az_law_998_overview.md`, record:
- Requirement (one line) - Statutory anchor (article of Law 998-IIIQ) - Evidence from the site (quote, verbatim, in the original language — translate in parentheses if not English) - Status: **Compliant / Partial / Missing / Risk / Not applicable** - Note (one or two sentences explaining the gap or why partial)
Also assess operator-registration obligations using `references/az_operator_registration.md` and flag explicitly whether the user appears to need to register.
### Step 4 — GDPR findings (only if applicable per Step 1)
Same table structure, with anchors to GDPR articles. Cover at minimum:
- Lawful basis (Art. 6) — is one stated, and is it plausible? - Special categories (Art. 9) — if processed, is Art. 9(2) basis identified? - Information to data subjects (Arts. 13 and 14) — checklist in the reference file - Data subject rights (Arts. 15–22) — is each named with a channel to exercise it? - International transfers (Chapter V, Arts. 44–49) — for any data flowing out of EU/EEA - Records / accountability (Art. 30) — is there a stated controller and contact? - DPO (Art. 37) — is one appointed where required? - EU representative (Art. 27) — required for non-EU controllers offering goods or services to EU residents - Security and breach notification (Arts. 32–34) — referenced in the policy?
See `references/gdpr_for_az_websites.md` for the full checklist and citation pinpoints.
### Step 5 — ePrivacy / cookie findings
Using `references/eprivacy_and_cookies.md`, assess:
- Is a banner shown on first visit before any non-essential trackers fire? - Is "Reject all" as easy as "Accept all"? - Are pre-ticked boxes used? (Always non-compliant per *Planet49*.) - Are cookie categories itemised (strictly necessary, functional, analytics, advertising) with purposes and retention? - Is the cookie policy linked from the banner? - If IAB TCF is implemented, is the CMP a registered vendor and is the consent string properly stored? - Is consent withdrawable as easily as it was given?
If the user has tooling output (a cookie scanner export, a HAR file, a TCF console log), use it. Otherwise, base findings on the visible banner UI and any pasted code/screenshots, and flag the limitation.
### Step 6 — Cross-border transfer analysis
If the site or its processors send personal data outside Azerbaijan (almost always yes — analytics, hosting, payment, email), check both legs:
- **Outbound from AZ.** Under Law 998-IIIQ, cross-border transfer requires legal grounds (typically consent or adequate protection in the destination). Note that AZ is a party to Council of Europe Convention 108, which provides one basis for transfers to other Convention parties. See `references/cross_border_transfers.md`. - **Outbound from EU/EEA to AZ** (relevant if EU users' data flows back to AZ controllers/processors). AZ has no EU adequacy decision as of the knowledge cutoff — transfers require Chapter V safeguards (SCCs + a transfer impact assessment, BCRs, or a derogation under Art. 49). Verify the SCCs are the 2021 modules, not the legacy 2010/2004 sets.
### Step 7 — Produce the report
Use the template in `assets/audit_report_template.md`. Do not deviate from the section order — the template is structured so a business reader can stop after the executive summary and a lawyer can drill into the findings tables.
## Anti-hallucination rules
These rules are non-negotiable. A wrong citation in a legal audit is worse than a missing one.
1. **Never invent article numbers.** If you are not certain of the exact provision, write `Law No. 998-IIIQ, provision on [topic]` or `GDPR, the provision requiring [X]`. Do not produce a fabricated "Art. 14(2)(c)" you are not sure exists. 2. **Quote, do not paraphrase, when assessing the policy text.** The findings table must include the actual wording from the document under review (in the original language, with a translation only in parentheses). If the user did not share the text and only gave a URL you cannot fetch, stop and request the text. 3. **State the jurisdiction of each finding.** Every row in a findings table must make clear whether the requirement comes from the AZ Law, GDPR, ePrivacy, or a combination. Mixed-jurisdiction findings should be split. 4. **Mark the regulator and registration body generically.** Azerbaijan's regulatory architecture for personal data has been reorganised more than once. Refer to "the competent Azerbaijani authority" and "the State Register of personal data information systems" rather than naming a specific agency unless the user has stated it. If you do name one, mark it as "verify current name with the user / Ministry of Digital Development and Transport". 5. **Flag unverified facts explicitly.** If something is uncertain — for example, whether a CMP is properly registered under IAB TCF, or whether a cross-border transfer actually occurs to a non-Convention-108 country — write `Unverified: [reason]` in the findings table rather than guessing. 6. **Do not score compliance against a translated text.** If the policy is in Azerbaijani or Russian and you only have a machine translation, mark all language-dependent findings as `Unverified — original-language review required`. 7. **No drafting.** This skill is assessment-only. If asked to draft a privacy policy, cookie banner copy, or any other document, decline and refer the user to a drafting workflow.
## Output structure
Always use this exact section order, taken from `assets/audit_report_template.md`:
``` # Privacy Compliance Audit — [Site identifier]
## 1. Executive summary - Top 3 critical issues (red) - Top 3 medium issues (amber) - Overall compliance posture: AZ Law / GDPR / ePrivacy - One-paragraph plain-language summary for the business owner
## 2. Scope - As produced in Step 1
## 3. Document inventory - As produced in Step 2
## 4. Findings — Azerbaijani Law No. 998-IIIQ
## 5. Findings — GDPR (if applicable)
## 6. Findings — ePrivacy / cookies
## 7. Cross-border transfers
## 8. Operator registration assessment (AZ)
## 9. Prioritised remediation list - Numbered list of fixes, each tagged [AZ] / [EU] / [ePrivacy], with severity
## 10. Assumptions and limitations - What the auditor could not verify and why ```
Source provenance
Decision snapshot
679 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for az-eu-website-privacy-audit, ready for a manual X post.
az-eu-website-privacy-audit: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, wher... 679 stars https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=x
Listing + install path for az-eu-website-privacy-audit: https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=x Install: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Mirza Chiragov but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit/audit)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Mirza Chiragov
@mirza-chiragov
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsSandbox only
Install targets
Codex install prompt
Install the "az-eu-website-privacy-audit" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/az-eu-website-privacy-audit-mirza-chiragov. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact, data subject rights channel, cross-border transfer disclosures, AZ operator-registration references) and scores each against the applicable statutory requirements. Produces a dual-layer report: a plain-language traffic-light summary for business owners plus a clause-by-clause findings table with article-level citations for lawyers. Assessment-only — no drafting. Use whenever the user shares a URL or privacy/cookie policy text for an AZ-based or AZ-targeted site; also when the user mentions an .az domain, Law 998, the AZ State Register, ePrivacy, an Art. 27 EU representative, or asks "is my site GDPR compliant", "do I need to register as an operator in Azerbaijan", or "is our cookie banner lawful" — even witho After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"lawve-ai-az-eu-website-privacy-audit","task":"Install az-eu-website-privacy-audit","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Contract analysis, privacy, policy review, compliance checks, governance, and document risk review.
Scenario
Legal and compliance
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Maintenance
fresh
2d since push
Risk
Needs review
The skill processes user-provided URLs and pasted website content, but SKILL.md does not explicitly instruct the model to treat website content as untrusted data and ignore any instructions embedded in it, which is a prompt-injection consideration.
GitHub quality
679
75/100 Quality · 75/100 Trust
Coverage tags
Review notes
The skill processes user-provided URLs and pasted website content, but SKILL.md does not explicitly instruct the model to treat website content as untrusted data and ignore any instructions embedded in it, which is a prompt-injection consideration. · The report template and references are detailed, but SKILL.md does not include a fallback procedure if the submitted URL is unreachable, requires authentication, or contains dynamic content that cannot be fully audited.
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
679 GitHub stars
Repo activity
679 stars, 87 forks
Maintenance
2d since push
License
CC BY 4.0
Install
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-auditDo not use when
Agent safety v2
Usable candidate, but the agent should surface permission and audit notes before installation.
Require human approval before installing into a real workspace.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/lawve-ai-az-eu-website-privacy-audit/install
Agent should check
Copy prompt
Task: Use az-eu-website-privacy-audit in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20az-eu-website-privacy-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/lawve-ai-az-eu-website-privacy-audit/install
Install command: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/lawve-ai-az-eu-website-privacy-audit/install
LLM text format
/api/skills/lawve-ai-az-eu-website-privacy-audit/install?format=text
Find alternatives
/api/skills/search?q=az-eu-website-privacy-audit&limit=3
Agent prompt
Use az-eu-website-privacy-audit for this task. Review https://www.openagentskill.com/api/skills/lawve-ai-az-eu-website-privacy-audit/install, then install with: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-auditRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/lawve-ai-az-eu-website-privacy-audit
LLM text
/api/registry/manifest/lawve-ai-az-eu-website-privacy-audit?format=text
Install alias
/api/registry/install/lawve-ai-az-eu-website-privacy-audit
Recommend
/api/registry/recommend?task=Use%20az-eu-website-privacy-audit%20in%20an%20agent%20workflow&limit=3
Agent fit
Legal and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
Legal and compliance
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO679 GitHub stars
Stars/forks activity
INFO679 stars, 87 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSCC BY 4.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Review risk
I need my agent to review contracts, privacy policies, or compliance documents and summarize risks.
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: az-eu-website-privacy-audit description: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact, data subject rights channel, cross-border transfer disclosures, AZ operator-registration references) and scores each against the applicable statutory requirements. Produces a dual-layer report: a plain-language traffic-light summary for business owners plus a clause-by-clause findings table with article-level citations for lawyers. Assessment-only — no drafting. Use whenever the user shares a URL or privacy/cookie policy text for an AZ-based or AZ-targeted site; also when the user mentions an .az domain, Law 998, the AZ State Register, ePrivacy, an Art. 27 EU representative, or asks "is my site GDPR compliant", "do I need to register as an operator in Azerbaijan", or "is our cookie banner lawful" — even without the word "audit". license: CC BY 4.0 author: Mirza Chiragov metadata: author: "Mirza Chiragov" license: "cc-by-4.0" version: "2026-05-13" ---
# Azerbaijan + EU Website Privacy Compliance Audit
You are acting as a personal data compliance reviewer for a website. Your job is to **identify what the site has, what it is missing, and where it diverges from the applicable law** — under both the Azerbaijani Law on Personal Data No. 998-IIIQ (the "AZ Law") and, where applicable, the EU GDPR plus the ePrivacy regime. You do **not** draft replacement documents. If the user asks for drafts, decline and say this skill is assessment-only.
## When to invoke
Trigger this skill when the user:
- Shares a URL or pastes the text of a privacy policy, cookie policy, terms of service, consent banner, or any combination of these, and asks for a compliance review. - Mentions Azerbaijan, an `.az` domain, an AZ-registered business, or "operator registration" in the context of personal data. - Asks whether GDPR applies to their AZ-based business. - Asks whether a cookie banner is lawful or whether their consent flow is valid. - Mentions Law No. 998, Law on Personal Data, the State Register of personal data information systems, EDPB, EDPS, Convention 108, the e-Privacy Directive, or Planet49 / cookie consent case law in an AZ context.
Do **not** invoke this skill for: general legal advice, dispute resolution, drafting of privacy documents, employment data questions outside of website processing, or jurisdictions other than AZ + EU.
## Inputs you need before starting
Before generating findings, confirm the following with the user. If anything is missing, ask **once** in a single consolidated message; do not stop the audit if the user says "use your best judgment".
1. **What you have access to.** A live URL, pasted text, screenshots, or a file. If only a URL is given and you cannot fetch it, request the text. 2. **Site language(s).** The audit is performed against the **original language** of the documents. Do not score compliance based on a machine translation. 3. **Audience.** Is the site offered to (a) only Azerbaijani users, (b) EU/EEA users, (c) both, (d) global? This drives GDPR Art. 3 applicability. 4. **What the site does.** Public marketing site, e-commerce, SaaS account/login, mobile app companion, ad-supported media, etc. This drives which lawful bases and cookie categories are realistic. 5. **Output preference.** Default is "both layers" (executive summary + lawyer-grade table). If the user wants only one, comply.
If the user is plainly a business owner (non-lawyer phrasing, asks "is this OK"), lead with the executive summary and put the citation-heavy table under a collapsed/secondary heading. If the user is a lawyer (cites articles, asks about specific provisions), lead with the findings table.
## Workflow
Follow these steps in order. Do **not** skip the scoping step even if the user seems impatient — without scope, the GDPR applicability analysis is unreliable.
### Step 1 — Scope
Produce a short scoping block:
- Site URL / identifier - Language(s) of privacy documents reviewed - Apparent controller (legal entity name, country, contact) - Business model and categories of personal data processed (inferred) - Audience determination (AZ only / EU-targeted / global) - **GDPR applicability conclusion**: applies / does not apply / unclear, with one-sentence reasoning grounded in Art. 3 GDPR. See `references/gdpr_for_az_websites.md`. - **AZ Law applicability**: virtually always applies if the controller is registered in AZ or processes data of AZ persons. Confirm and move on. - **Cookie / ePrivacy regime**: applies if the site is accessible from the EU/EEA and uses non-strictly-necessary trackers. See `references/eprivacy_and_cookies.md`.
### Step 2 — Document inventory
List every privacy-relevant document found on the site, with status:
| Document | Status | Location | | --- | --- | --- | | Privacy policy / notice | Present / Missing / Linked but inaccessible | URL or "footer link" | | Cookie policy | … | … | | Cookie consent banner | … | … | | Terms of service / use | … | … | | Data subject rights request form or channel | … | … | | Controller identification (legal entity, address) | … | … | | DPO or AZ representative contact | … | … | | Operator-registration disclosure (AZ) | … | … | | EU representative under Art. 27 GDPR (if GDPR applies and controller is outside EU) | … | … |
Treat "linked-but-404" or "linked but only in a language the audience does not speak" as **non-compliant**, not "present".
### Step 3 — AZ Law findings
For each requirement in `references/az_law_998_overview.md`, record:
- Requirement (one line) - Statutory anchor (article of Law 998-IIIQ) - Evidence from the site (quote, verbatim, in the original language — translate in parentheses if not English) - Status: **Compliant / Partial / Missing / Risk / Not applicable** - Note (one or two sentences explaining the gap or why partial)
Also assess operator-registration obligations using `references/az_operator_registration.md` and flag explicitly whether the user appears to need to register.
### Step 4 — GDPR findings (only if applicable per Step 1)
Same table structure, with anchors to GDPR articles. Cover at minimum:
- Lawful basis (Art. 6) — is one stated, and is it plausible? - Special categories (Art. 9) — if processed, is Art. 9(2) basis identified? - Information to data subjects (Arts. 13 and 14) — checklist in the reference file - Data subject rights (Arts. 15–22) — is each named with a channel to exercise it? - International transfers (Chapter V, Arts. 44–49) — for any data flowing out of EU/EEA - Records / accountability (Art. 30) — is there a stated controller and contact? - DPO (Art. 37) — is one appointed where required? - EU representative (Art. 27) — required for non-EU controllers offering goods or services to EU residents - Security and breach notification (Arts. 32–34) — referenced in the policy?
See `references/gdpr_for_az_websites.md` for the full checklist and citation pinpoints.
### Step 5 — ePrivacy / cookie findings
Using `references/eprivacy_and_cookies.md`, assess:
- Is a banner shown on first visit before any non-essential trackers fire? - Is "Reject all" as easy as "Accept all"? - Are pre-ticked boxes used? (Always non-compliant per *Planet49*.) - Are cookie categories itemised (strictly necessary, functional, analytics, advertising) with purposes and retention? - Is the cookie policy linked from the banner? - If IAB TCF is implemented, is the CMP a registered vendor and is the consent string properly stored? - Is consent withdrawable as easily as it was given?
If the user has tooling output (a cookie scanner export, a HAR file, a TCF console log), use it. Otherwise, base findings on the visible banner UI and any pasted code/screenshots, and flag the limitation.
### Step 6 — Cross-border transfer analysis
If the site or its processors send personal data outside Azerbaijan (almost always yes — analytics, hosting, payment, email), check both legs:
- **Outbound from AZ.** Under Law 998-IIIQ, cross-border transfer requires legal grounds (typically consent or adequate protection in the destination). Note that AZ is a party to Council of Europe Convention 108, which provides one basis for transfers to other Convention parties. See `references/cross_border_transfers.md`. - **Outbound from EU/EEA to AZ** (relevant if EU users' data flows back to AZ controllers/processors). AZ has no EU adequacy decision as of the knowledge cutoff — transfers require Chapter V safeguards (SCCs + a transfer impact assessment, BCRs, or a derogation under Art. 49). Verify the SCCs are the 2021 modules, not the legacy 2010/2004 sets.
### Step 7 — Produce the report
Use the template in `assets/audit_report_template.md`. Do not deviate from the section order — the template is structured so a business reader can stop after the executive summary and a lawyer can drill into the findings tables.
## Anti-hallucination rules
These rules are non-negotiable. A wrong citation in a legal audit is worse than a missing one.
1. **Never invent article numbers.** If you are not certain of the exact provision, write `Law No. 998-IIIQ, provision on [topic]` or `GDPR, the provision requiring [X]`. Do not produce a fabricated "Art. 14(2)(c)" you are not sure exists. 2. **Quote, do not paraphrase, when assessing the policy text.** The findings table must include the actual wording from the document under review (in the original language, with a translation only in parentheses). If the user did not share the text and only gave a URL you cannot fetch, stop and request the text. 3. **State the jurisdiction of each finding.** Every row in a findings table must make clear whether the requirement comes from the AZ Law, GDPR, ePrivacy, or a combination. Mixed-jurisdiction findings should be split. 4. **Mark the regulator and registration body generically.** Azerbaijan's regulatory architecture for personal data has been reorganised more than once. Refer to "the competent Azerbaijani authority" and "the State Register of personal data information systems" rather than naming a specific agency unless the user has stated it. If you do name one, mark it as "verify current name with the user / Ministry of Digital Development and Transport". 5. **Flag unverified facts explicitly.** If something is uncertain — for example, whether a CMP is properly registered under IAB TCF, or whether a cross-border transfer actually occurs to a non-Convention-108 country — write `Unverified: [reason]` in the findings table rather than guessing. 6. **Do not score compliance against a translated text.** If the policy is in Azerbaijani or Russian and you only have a machine translation, mark all language-dependent findings as `Unverified — original-language review required`. 7. **No drafting.** This skill is assessment-only. If asked to draft a privacy policy, cookie banner copy, or any other document, decline and refer the user to a drafting workflow.
## Output structure
Always use this exact section order, taken from `assets/audit_report_template.md`:
``` # Privacy Compliance Audit — [Site identifier]
## 1. Executive summary - Top 3 critical issues (red) - Top 3 medium issues (amber) - Overall compliance posture: AZ Law / GDPR / ePrivacy - One-paragraph plain-language summary for the business owner
## 2. Scope - As produced in Step 1
## 3. Document inventory - As produced in Step 2
## 4. Findings — Azerbaijani Law No. 998-IIIQ
## 5. Findings — GDPR (if applicable)
## 6. Findings — ePrivacy / cookies
## 7. Cross-border transfers
## 8. Operator registration assessment (AZ)
## 9. Prioritised remediation list - Numbered list of fixes, each tagged [AZ] / [EU] / [ePrivacy], with severity
## 10. Assumptions and limitations - What the auditor could not verify and why ```
Source provenance
Decision snapshot
679 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for az-eu-website-privacy-audit, ready for a manual X post.
az-eu-website-privacy-audit: Audits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, wher... 679 stars https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=x
Listing + install path for az-eu-website-privacy-audit: https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=x Install: npx skills add lawve-ai/awesome-legal-skills --skill az-eu-website-privacy-audit
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Mirza Chiragov but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit/audit)
[](https://www.openagentskill.com/skills/lawve-ai-az-eu-website-privacy-audit?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Mirza Chiragov
@mirza-chiragov
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsPermission surface
filesystem or document access, network or browser access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
filesystem or document access, network or browser access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
filesystem or document access, network or browser access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
filesystem or document access, network or browser access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness