← Plugin catalog
Security

CertScore.ai Privacy Scanner

CertScore.ai, LLC v2.0.0

Scan public websites for fast preliminary cookie/tracker evidence, then continue to persisted privacy findings, typed GPC response comparisons, bounded Accept and Reject observations, policy signals, and HTTPS/TLS. Results preserve provenance and explicit coverage limitations for human review; they are not legal advice, certification, or a compliance determination.

Language: English · Automatically detected from descriptions.

Package details

Publisher declarations from the archived package. These are separate from our research and the live service's terms.

Package author
CertScore.ai, LLC

Package observed Sep 30, 2026.

Files & skills

File archives

Plugin package4 files · 2.92 KBBrowse files →
Skill instructions
website-privacy-preflight4.36 KB

View saved version →

---
name: website-privacy-preflight
description: Run an evidence-backed public-website privacy preflight with fast cookie and tracker previews, typed GPC comparisons, and eligible bounded Accept and Reject observations before launch, vendor review, audit triage, or human compliance review.
---

Use CertScore.ai MCP Light to review the public HTTP or HTTPS URL supplied by the user.

1. Call `certscore_scan_site` for the URL. Prefer the default `freshness=latest` so an eligible recent completed scan can be reused unless the user explicitly asks for a fresh or repeated scan.
2. Retain the returned `scanId` and report whether the result is new or reused. A new scan may also include `preConsentPreview`; surface that preview promptly, before waiting for full completion, and label it clearly as partial passive cookie/tracker evidence. Distinguish captured counts from bounded returned identity counts. Use `trackingVendorCount` for non-operational tracking vendors and treat `operationalVendors` separately; never compare the compatibility preview `trackerCount` directly with the completed inventory's broader `trackerCount`. Never present preview counts as final totals, and never stop the workflow because a preview was returned. If a retryable response contains no `scanId`, honor `retryAfterSeconds` and retry `certscore_scan_site`; do not poll status without an ID.
3. While the status is `queued`, `running`, or `finalizing`, poll `certscore_get_scan_status` using `scanId` only. Honor returned retry guidance, wait at least five seconds between polls, and stop after 60 polls or 15 minutes rather than looping indefinitely.
4. Stop immediately at `completed`, `completed_limited`, `failed`, `expired`, or `rate_limited`.
5. For `completed` or `completed_limited`, call `certscore_get_scan_bundle` with `detail=findings` and `maxBytes=8000` before reporting full scan results. Use that bundle—not `preConsentPreview`—for the completed scan's final returned cookie/tracker tally, canonical findings, and coverage limitations. Do not request a bundle for another terminal state unless a later tool response explicitly directs it.
6. Summarize the highest-value returned findings and evidence, including relevant pre-consent cookies or trackers, CMP or consent-control signals, the typed GPC response, bounded Accept and Reject Path observations, policy or disclosure observations, HTTPS/TLS observations, coverage limitations, provenance, useful evidence references, and the report URL.
7. Preserve truncation notices and use `nextRecommendedMaxBytes` only when more returned evidence is needed.

For `gpcResponse`, use only the returned typed status and finding title: `GPC response`, `No observable GPC response`, or `indeterminate`. Keep this jurisdiction-neutral comparison separate from any explicitly returned California scoring policy. Do not call it a GPC violation or claim that GPC was honored.

When `postAcceptObservation.status` is `confirmed_observation`, report its typed `interpretation` directly and explain that ordinary post-Accept activity is a score-neutral behavior baseline unless a separately projected finding says otherwise. When `postRefusalObservation.status` is `confirmed_observation`, report its typed `interpretation` directly. For either path, if `termination.kind` is `evidence_satisfied`, explain that the observer intentionally stopped after qualifying evidence was retained; do not characterize that stop as uncertainty about the confirmed observation. Treat every non-confirmed observation status as limited coverage rather than a pass. Keep `coverageLimitations` scoped to additional behavior or persistence that was not measured. Determine scan reuse only from returned provenance such as `executionMode`, `reused`, or `freshnessDecision`.

Do not independently browse the target or click its consent controls. Any eligible Accept or Reject action occurs only inside CertScore's separately authorized, bounded scanner lanes; report only the resulting persisted typed evidence.

Report only observed CertScore evidence and persisted CertScore classifications. Clearly distinguish the fast `preConsentPreview` from the canonical completed bundle, and tell the user when the preliminary evidence has been superseded by final returned totals. Do not infer unobserved technologies, post-consent behavior, legal violations, or compliance. Results are not legal advice, certification, or a compliance determination.

Referenced files: 1

Technical details
First seen
Sep 30, 2026 · 22:02 UTC
Last seen
Oct 1, 2026 · 12:00 UTC
Collection status
Collected

plugin_asdk_app_6a8359df23ac8191b557db3e6296b892

Download listing JSON