Customize

anthropics/claude-for-legal/privacy-legal/skills/customize

作者 anthropics4a6c651889c97cc9140580363c73e0eb17379c2b无许可证9.6K 个星标收录于 2026年10月9日更新于 2026年10月9日仓库9天前更新

Guided customization of your privacy practice profile — change one thing without re-running the whole cold-start interview. Adjust risk posture, escalation contacts, DPA playbook, privacy policy commitments, PIA house style, DSAR process, or matter workspace paths. Use when the user says "change my [thing]", "update my profile", "edit my playbook", or "customize".

AI 生成的概览

引导式修改已有的隐私法律实践配置,一次只改一个部分,无需重新运行完整设置访谈。

功能
该技能引导用户调整此前创建的隐私实践配置,配置存放在插件配置文件中。它会读取现有配置,按分组展示可自定义的部分,例如风险姿态、升级联系人、DPA 手册、隐私政策承诺、PIA 内部风格、DSAR 流程和工作区路径,然后应用用户请求的单次修改,并说明下游会有什么变化。涉及共享公司配置的修改会写入单独的公司配置文件,并提示会影响所有插件。它产出的是更新后的配置值,而不是文档。
适用场景
当用户想修改已配置好的隐私配置中的某一项时使用,例如风险姿态、升级联系人、DPA 立场、PIA 章节或 DSAR 时限。它面向已经存在的配置;尚未完成设置的用户会被引导先运行冷启动访谈。
运行要求
需要已有的隐私法律插件配置,包括 privacy-legal 的 CLAUDE.md 配置文件以及上一级的共享 company-profile.md 文件,且占位符值已被替换。该技能仅为说明性指令,不附带脚本。

/customize

When this runs

The user typed /privacy-legal:customize. They want to change something in their privacy profile — a risk posture, an escalation contact, a DPA position, a PIA section, a DSAR timeline — without re-running the whole cold-start interview and without hand-editing YAML.

What to do

  1. Read the config. Read ~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md (and ~/.claude/plugins/config/claude-for-legal/company-profile.md one level up). If the plugin config does not exist or still contains [PLACEHOLDER] values, say:

    You haven't run setup yet. Run /privacy-legal:cold-start-interview first — customize is for adjusting a profile you already have.

  2. Show the customizable map. List what's in the profile, grouped, with a one-line summary of the current value:

    • Company / who you are — name, industry, jurisdictions, stage, practice setting, controller vs. processor orientation (shared across all 12 plugins — changes flow through company-profile.md)
    • Risk posture — conservative / middle / aggressive, what each means for processor obligations, cross-border transfers, and retention
    • People — DPO, privacy team, engineering liaison, outside counsel, escalation chain
    • DPA playbook — positions on sub-processor notice, deletion, audit, liability, international transfers, SCCs — as processor and as controller
    • Privacy policy commitments — the commitments your privacy notice has made that /policy-monitor watches practice against
    • PIA house style — section order, risk scoring, stakeholder framing, when DPIA triggers apply
    • DSAR process — verification, statutory timelines per regime, exemption application, template response structure
    • Workflow — intake path, matter workspaces, policy-monitor sweep cadence
    • Integrations — document storage / privacy tool / Slack status, fallbacks
  3. Ask what they want to change.

    What would you like to adjust? Pick a section, or describe the change in your own words.

  4. Make the change. Show the current value, ask for the new value, explain what changes downstream, confirm, write it to the config.

    Examples:

    • Sub-processor notice 30 days → 14 days: "/dpa-review will now flag anything shorter than 14 days as a deviation. Existing DPAs stay as logged."
    • New DSAR exemption in the playbook: "/dsar-response will surface this exemption in the assessment step where the facts match."
    • Risk posture middle → conservative: "I'll flag more activities for PIA escalation, recommend stricter SCC clauses, and be more conservative on retention."
  5. For shared-profile changes (company name, industry, jurisdictions, practice setting, stage): write to ~/.claude/plugins/config/claude-for-legal/company-profile.md and note:

    This change affects all 12 plugins — any plugin that reads your jurisdiction footprint now sees [new value].

  6. Close.

    Done. Your next output will reflect the change. Anything else? You can run /privacy-legal:customize anytime.

Guardrails

  • Never delete a section. If the user wants to "remove" a regime from scope, offer to mark it [Not currently in scope] and explain what flagging drops.
  • Flag internal inconsistency. If the change would make the profile inconsistent (e.g., "processor only" + controller playbook positions active; or "no EU nexus" + SCCs in the default template), flag the tension.
  • Flag guardrail degradation. The [review] flag, source attribution tags, [verify] tags on cited regulations, and the DPIA-trigger mandatory-check on /use-case-triage are load-bearing — do not remove. If statutory DSAR timelines are adjusted below the regulatory minimum, refuse and explain why.
  • One change at a time. Don't re-ask the whole interview.

来源与署名

来源:anthropics/claude-for-legal位于privacy-legal/skills/customize提交4a6c651

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架