Trust, Security & Compliance — every app must satisfy
SkillCommunicationLegal, security, privacy, and deliverability requirements every delivered app must satisfy, legal pages, PII/deletion rights, CSP/Trusted-Types/Zod, AI-agent security, RFC7807 errors, email domain auth.
Use Trust, Security & Compliance — every app must satisfy in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Trust, Security & Compliance — every app must satisfy and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Trust, Security & Compliance skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by heymegabyte/agent-skills in 27-trust-compliance/SKILL.md and read by ahel’s review.
Legal & policy
- Ship real
/privacy,/terms,/accessibilitypages accurate to the ACTUAL data practices — never boilerplate that lies. Accessibility statement is ADA Title II / WCAG 2.2 AA-ready. - No dark patterns — honest defaults, no forced continuity, no confirm-shaming (Christ-like ethos).
Data & PII
- Collect the minimum PII needed; never log secrets or PII in plaintext; keep credentials server-side only.
- Honor user right-to-deletion and data export on request. State retention plainly.
Security controls (every app)
- CSP Level 3
strict-dynamic+ per-request nonce · Trusted Types · HSTS. No inline script without a nonce. - Zod validation at EVERY runtime boundary (env · API in/out · params · forms · webhooks · queue/DO messages · AI outputs) — validation is a security control, not just typing.
- Forms gated by Turnstile. All hyperlinks valid (no dead/hostile links).
- Tenant isolation:
org_idon every row + query; 404 (never 403) on cross-tenant access.
AI-agent security
- Treat all model/tool input as untrusted: defend against prompt injection; authorize every tool call; validate + schema-bind every AI output before use (Contract-First AI). Sandbox generated/risky code before it runs.
Errors (never leak internals)
- User-facing errors use RFC7807 envelopes:
code+correlationId+errors[]+ what-to-do-next. Never expose stack traces, SQL, or internal identifiers.
Email domain authentication
- Sending domain publishes SPF + DKIM + DMARC (BIMI where a VMC exists). These records live on the SENDING domain's zone (may differ from the site domain — surface any mismatch before staging).
Signals
- GitHub stars
- 23
- Forks
- 4
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
trust-compliance- Source
- github.com/heymegabyte/agent-skills
github.com/heymegabyte/agent-skills
More in Communication
Skill · anthropics
More in Communicationerror-handling
Skill · affaan-m
More in Communicationemails
Skill · coreyhaines31
More in Communicationwait-what
Skill · mattpocock
More in Communicationcold-email
Skill · coreyhaines31
More in Communicationazure-messaging
Skill · microsoft
More in Communication