forge-privacylisted
Install: claude install-skill seroneyemmanuel4-afk/fullstack-forge-skill
# forge-privacy: Privacy
## Purpose
Inspect personal-data inventory, purpose, minimization, consent, retention, access, deletion, export, and logging.
Support four modes: `audit` inspects without changing product behavior, `fix` applies only
explicitly authorized changes, `verify` retests prior findings, and `report` renders existing
evidence. If no mode is supplied, use `audit`.
## Trigger conditions
Use this module when a request names `forge-privacy`, asks about privacy, or
discovery finds an applicable boundary. Run it from the repository root after project discovery.
## When it applies
- Applications processing personal, device, behavioral, or sensitive data
## When it does not apply
- Systems proven to process no data linkable to a person
Do not silently skip it. Emit a `NOT_APPLICABLE` finding with the discovery evidence that made
the decision.
## Inputs from project discovery
- data inventory
- schemas
- analytics and integration flows
- privacy documentation
Prefer `.forge/project-profile.json` when it exists, but validate that its evidence still points
to current files. Read `../fullstack-forge/references/PROTOCOL.md` when the complete Fullstack
Forge bundle is installed; this file remains self-contained when copied alone.
## Inspection procedure
1. Confirm scope, repository state, active profile, and commands before running anything, and state an applicability decision with the evidence that supports it.
2. Inventory personal-data fields across the s