Skip to content
Back to skills

Compliance Diff

ASecurity

Use when reviewing a pull request, branch, or release for launch and privacy impact: new vendors or third-party hosts, new personal-data fields or forms, new routes, changed consent or email behavior, new storage. It reads the change and lists what it introduces and which ReadyVibe specialists should recheck. Do not use it as a substitute for a full review or to approve a release as compliant.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agentsnoderefactoringgitapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 8 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add moh-obaida/ReadyVibe-Skills --skill compliance-diff --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Compliance Diff?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Compliance Diff
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/moh-obaida-compliance-diff/badge)](https://www.skillsdirectory.com/skills/moh-obaida-compliance-diff)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: compliance-diff
description: "Use when reviewing a pull request, branch, or release for launch and privacy impact: new vendors or third-party hosts, new personal-data fields or forms, new routes, changed consent or email behavior, new storage. It reads the change and lists what it introduces and which ReadyVibe specialists should recheck. Do not use it as a substitute for a full review or to approve a release as compliant."
license: Apache-2.0
metadata:
  kind: auditor
  helpers: "observe-runtime"
---

# compliance-diff

Launch readiness decays. A month after a clean review, someone adds a session-replay tool, a signup field, or a `/admin` route. This skill reads a *change* and says what it re-opens.

## Activate when

- A PR, branch, or release diff is under review, or the user asks "what does this change do to our launch/privacy posture?"
- A context note (`.readyvibe/context.md`), if one exists, has "NOT APPLICABLE" items whose recheck triggers might have fired.
- Not for a first full review (use `launch-all`).

## Inspect

Get the diff (`git diff <base>...HEAD`, or the PR files). Look for these introductions, in order of consequence:

| In the diff | Re-opens |
|---|---|
| new dependency or script tag for analytics, ads, replay, tag manager, chat, maps, fonts, embeds, captcha, payments | checks 3–5 (`analytics-privacy`, `third-party-privacy`, `cookie-and-storage-audit`) and the privacy disclosure |
| new form field, DB column, or API route accepting personal data (email, name, phone, location, DOB, IDs) | 1, 5, 6, 7 (`data-flow-mapping`, `privacy-policy`, `data-rights`) |
| new auth, account, role, or admin route | 7, 38 (`data-rights`, `web-security`, `admin-authorization`) |
| new email send, newsletter form, template, or list | 36–37 (`email-compliance`) |
| price, checkout, subscription, refund copy, billing code | `consumer-protection-readiness`, `subscription-readiness`, `payments-readiness` |
| new locale, currency, country selector, or shipping region | `jurisdiction-applicability`, `multilingual-readiness` |
| new public route, changed canonical/robots/sitemap, changed metadata | 9–18 (`seo-readiness`) |
| removed or changed legal/contact/footer links or pages | `legal-navigation`, `public-support` |
| changed consent code, cookie names, storage keys | `consent-management`, `cookie-and-storage-audit` |
| AI/model calls, prompts with user data | `ai-features-readiness` |
| user-generated content features | `user-content-safety` |
| age/DOB fields or child-oriented copy or features | `minors-readiness`, `regulated-domain-triggers` |
| new environment variable with a client prefix | `web-security` |
| removed features (data no longer collected) | disclosure may now overstate; `policy-consistency` |

Also look for *deletions* that reduce protection: removed consent gating, removed unsubscribe route, dropped auth check.

## Evidence that counts

Label each claim OBSERVED, SOURCE-INDICATED, DECLARED, INFERRED, UNKNOWN, or REVIEW REQUIRED. UNKNOWN is never a pass and never a failure.

- A diff shows SOURCE-INDICATED behavior. "This adds PostHog" is fact; "PostHog loads before consent" is unproven until the change is run.
- If you can run the branch, do a targeted runtime pass on the affected routes rather than guessing: `node scripts/observe-runtime.mjs --url <local-url>/<route> --block-third-party` (path relative to this skill's folder).

## May change

Nothing in the product. Produce a short review note (in the reply, or `.readyvibe/diff-review.md` if asked).

```
Changes with launch/privacy impact
  1. New third party: posthog-js (analytics + replay-capable). Runtime timing unproven.  -> analytics-privacy, cookie-and-storage-audit; privacy notice does not mention it.
  2. New field: phone on /signup. Stored in profiles.phone.  -> data-flow-mapping, privacy-policy, data-rights (deletion covers it?)
No impact found in: routes, metadata, email, payments.
```

## Must not claim

That the change is "approved", "compliant", or "safe to ship". Say what it introduces, what is unverified, and what to recheck.

## Verify

Confirm each listed introduction by locating the code (file and line), and confirm each "no impact" claim by searching for the corresponding patterns. For anything you can run, run it.

## Escalate

Regulated-domain or child-directed features appearing in a diff; exposure of credentials in the diff (report at once and do not copy the value); changes that silently contradict the published privacy notice or terms.

## No change is valid when

The diff is refactoring, styling, or copy that touches none of the surfaces above. Say "no launch or privacy impact found" and name the patterns you searched.

Files in this skill

  • SKILL.md4.6 KB
  • scripts/lib/browser.mjs3.3 KB
  • scripts/lib/canary.mjs1.5 KB
  • scripts/lib/html.mjs5.8 KB
  • scripts/lib/pages.mjs11.3 KB
  • scripts/lib/report.mjs3 KB
  • scripts/lib/trackers.mjs5.9 KB
  • scripts/observe-runtime.mjs25.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…