← CertScore.ai Privacy ScannerCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to CertScore.ai Privacy Scanner
Snapshot Sep 30, 2026 · 22:54 UTC · version 2.0.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "website-privacy-preflight",
"description": "Run an evidence-backed public-website privacy preflight with fast cookie and tracker previews, typed GPC comparisons, and eligible bounded Accept and Reject observations before launch, vendor review, audit triage, or human compliance review.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 689
}
],
"skill_md_contents": "---\nname: website-privacy-preflight\ndescription: Run an evidence-backed public-website privacy preflight with fast cookie and tracker previews, typed GPC comparisons, and eligible bounded Accept and Reject observations before launch, vendor review, audit triage, or human compliance review.\n---\n\nUse CertScore.ai MCP Light to review the public HTTP or HTTPS URL supplied by the user.\n\n1. Call `certscore_scan_site` for the URL. Prefer the default `freshness=latest` so an eligible recent completed scan can be reused unless the user explicitly asks for a fresh or repeated scan.\n2. Retain the returned `scanId` and report whether the result is new or reused. A new scan may also include `preConsentPreview`; surface that preview promptly, before waiting for full completion, and label it clearly as partial passive cookie/tracker evidence. Distinguish captured counts from bounded returned identity counts. Use `trackingVendorCount` for non-operational tracking vendors and treat `operationalVendors` separately; never compare the compatibility preview `trackerCount` directly with the completed inventory's broader `trackerCount`. Never present preview counts as final totals, and never stop the workflow because a preview was returned. If a retryable response contains no `scanId`, honor `retryAfterSeconds` and retry `certscore_scan_site`; do not poll status without an ID.\n3. While the status is `queued`, `running`, or `finalizing`, poll `certscore_get_scan_status` using `scanId` only. Honor returned retry guidance, wait at least five seconds between polls, and stop after 60 polls or 15 minutes rather than looping indefinitely.\n4. Stop immediately at `completed`, `completed_limited`, `failed`, `expired`, or `rate_limited`.\n5. For `completed` or `completed_limited`, call `certscore_get_scan_bundle` with `detail=findings` and `maxBytes=8000` before reporting full scan results. Use that bundle—not `preConsentPreview`—for the completed scan's final returned cookie/tracker tally, canonical findings, and coverage limitations. Do not request a bundle for another terminal state unless a later tool response explicitly directs it.\n6. Summarize the highest-value returned findings and evidence, including relevant pre-consent cookies or trackers, CMP or consent-control signals, the typed GPC response, bounded Accept and Reject Path observations, policy or disclosure observations, HTTPS/TLS observations, coverage limitations, provenance, useful evidence references, and the report URL.\n7. Preserve truncation notices and use `nextRecommendedMaxBytes` only when more returned evidence is needed.\n\nFor `gpcResponse`, use only the returned typed status and finding title: `GPC response`, `No observable GPC response`, or `indeterminate`. Keep this jurisdiction-neutral comparison separate from any explicitly returned California scoring policy. Do not call it a GPC violation or claim that GPC was honored.\n\nWhen `postAcceptObservation.status` is `confirmed_observation`, report its typed `interpretation` directly and explain that ordinary post-Accept activity is a score-neutral behavior baseline unless a separately projected finding says otherwise. When `postRefusalObservation.status` is `confirmed_observation`, report its typed `interpretation` directly. For either path, if `termination.kind` is `evidence_satisfied`, explain that the observer intentionally stopped after qualifying evidence was retained; do not characterize that stop as uncertainty about the confirmed observation. Treat every non-confirmed observation status as limited coverage rather than a pass. Keep `coverageLimitations` scoped to additional behavior or persistence that was not measured. Determine scan reuse only from returned provenance such as `executionMode`, `reused`, or `freshnessDecision`.\n\nDo not independently browse the target or click its consent controls. Any eligible Accept or Reject action occurs only inside CertScore's separately authorized, bounded scanner lanes; report only the resulting persisted typed evidence.\n\nReport only observed CertScore evidence and persisted CertScore classifications. Clearly distinguish the fast `preConsentPreview` from the canonical completed bundle, and tell the user when the preliminary evidence has been superseded by final returned totals. Do not infer unobserved technologies, post-consent behavior, legal violations, or compliance. Results are not legal advice, certification, or a compliance determination.\n"
}SHA-256: 156ba7421d9fe912ec34bd89235b15473858952d8095ecf5211a743213f5077b