{"id":17114,"plugin_id":"plugins_6a57ac5ce65c8191ae7bd0a51160eb7d","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:13:57.262Z","digest":"38649d6347fd369ac6abf4bf5b0799eede70c25f7b951ac65ec9066bbafe0a5c","against":null,"payload":{"name":"privacy-surface-review","description":"Use when adding, changing, reviewing, or releasing a Vera workflow or shared service to record model-context, provider-account, external-data, and security boundaries before packaging.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":265},{"relative_path":"references/manifest-contract.md","size_in_bytes":4811},{"relative_path":"scripts/validate_privacy_surfaces.py","size_in_bytes":36349}],"skill_md_contents":"---\nname: privacy-surface-review\ndescription: Use when adding, changing, reviewing, or releasing a Vera workflow or shared service to record model-context, provider-account, external-data, and security boundaries before packaging.\n---\n\n# External Boundary Review\n\nAfter substantive use of this workflow, read and follow the `Plugin Improvement Feedback` section in `../vera/SKILL.md`.\n\nThis is a developer and release workflow, not a customer-case intake step. A\nnormal Vera run does not show a privacy notice or request privacy confirmation\nmerely because the selected model runtime reads professional case data.\n\n## Review workflow\n\n1. Resolve the Vera root and read `components.json`, including registered\n   workstreams and shared services.\n2. Select the changed workstream and resolve its source as\n   `modules/<workstream>` in an installed package or `../<workstream>` beside\n   Vera in repository source. Treat that resolved root as the plugin working\n   directory for the review.\n3. Read that module's complete workflow skill and the relevant scripts, schemas,\n   MCP tools, and review-payload builders.\n4. Record the classes of information the workflow can place in model context.\n   Real client and case data may enter the selected runtime's model context. Do\n   not promise local-only processing when OpenAI Codex or Anthropic Cowork reads\n   the material.\n5. Read `privacy/runtime-profiles.json`. Each workstream references both\n   `openai-codex` and `anthropic-cowork` rather than duplicating provider copies\n   of the workstream manifest. The shared profiles state the selected account,\n   provider model-processing destination, absence of automatic anonymization,\n   and absence of a local-only guarantee.\n6. Record every external boundary: public research or URL fetching, a\n   hosted service, an external connector, or a send/publish action. An empty\n   list is a valid and useful result.\n7. For each external boundary, state the destination, purpose, content,\n   applicable runtime profiles, whether it is optional, whether confirmation is\n   required, and the controls enforced by the workflow. A separate confirmation\n   is required only when the route is optional and the user has not already\n   chosen it. Reuse the user's explicit route choice only where the host permits prior\n   approval; it never overrides action-time confirmation or a denied operation.\n8. Record only concrete security controls and the account boundary selected by\n   the firm or user. An empty security-control array is more accurate than\n   relabelling local processing, draft status, or policy wording as security.\n   Vera cannot inspect or enforce the user's plan, model-training data controls,\n   or retention/deletion controls. The firm or user checks those before\n   professional use and when the account or terms change, not in a per-case form.\n   For ordinary model processing, record that the selected OpenAI Codex or\n   Anthropic Cowork account arrangement applies, Vera is not a separate\n   recipient, nothing is automatically anonymized, processing is not local\n   only, and local filtering or aggregation is used only when it helps the\n   work.\n9. If the workstream has a public process page or named product-page section,\n   read `../vera/references/public-process-page-contract.md` and apply it. Every public\n   process explanation has one localized “Quali dati arrivano al modello” /\n   “What data reaches the model” block. Choose `relevant` or `not-relevant`\n   from the inspected workflow evidence. Do not use `not-relevant` as a\n   fallback for an incomplete review. Place the entire block last in the public\n   process explanation, after every description, step, output, review boundary\n   and call to action; no process content may follow it. Keep `/data-handling`\n   as the global boundary explanation rather than recreating a central\n   per-process register.\n10. Update `privacy/workstreams/<workstream>.json` or\n   `privacy/services/<service>.json` using `references/manifest-contract.md`,\n   then refresh its source fingerprint:\n\n```bash\npython skills/privacy-surface-review/scripts/validate_privacy_surfaces.py \\\n  --refresh <workstream>\n\npython skills/privacy-surface-review/scripts/validate_privacy_surfaces.py \\\n  --refresh-service <service>\n```\n\n11. Validate the complete register, run the Vera package tests, and rebuild the\n   plugin ZIP:\n\n```bash\npython skills/privacy-surface-review/scripts/validate_privacy_surfaces.py\n```\n\n## Judgment boundary\n\nUse deterministic code only for JSON shape, registered-workstream coverage,\nallowed boundary kinds, confirmation consistency, exact file hashing,\nstale-review detection, and mechanically verifiable public-block presence,\nstatus values, order and localization coverage. Whether the public block is\n`relevant` or `not-relevant`, and whether its reason is professionally sound,\nremain model-led judgments based on inspected evidence.\n\nGDPR data minimisation remains a legal principle. Do not implement it here as\ndeterministic deletion, automatic anonymisation, personal-data detection, or a\n`minimum useful context` classifier. Whether a fact is relevant to the\nprofessional purpose is semantic, case-specific judgment outside the\nvalidator. A name or tax identifier may be relevant and may be read by the\nselected model runtime.\n\nThe register is an engineering boundary review. It is not legal advice, a DPIA,\nan account-configuration audit, or proof or certification of GDPR compliance.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}