Trust, Security & Compliance — every app must satisfy

SkillCommunication

Legal, security, privacy, and deliverability requirements every delivered app must satisfy, legal pages, PII/deletion rights, CSP/Trusted-Types/Zod, AI-agent security, RFC7807 errors, email domain auth.

Use Trust, Security & Compliance — every app must satisfy in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Trust, Security & Compliance — every app must satisfy and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Trust, Security & Compliance skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Trust, Security & Compliance — every app must satisfyStart free

What this skill tells your AI

The instructions your AI receives, as published by heymegabyte/agent-skills in 27-trust-compliance/SKILL.md and read by ahel’s review.

Legal & policy

  • Ship real /privacy, /terms, /accessibility pages accurate to the ACTUAL data practices — never boilerplate that lies. Accessibility statement is ADA Title II / WCAG 2.2 AA-ready.
  • No dark patterns — honest defaults, no forced continuity, no confirm-shaming (Christ-like ethos).

Data & PII

  • Collect the minimum PII needed; never log secrets or PII in plaintext; keep credentials server-side only.
  • Honor user right-to-deletion and data export on request. State retention plainly.

Security controls (every app)

  • CSP Level 3 strict-dynamic + per-request nonce · Trusted Types · HSTS. No inline script without a nonce.
  • Zod validation at EVERY runtime boundary (env · API in/out · params · forms · webhooks · queue/DO messages · AI outputs) — validation is a security control, not just typing.
  • Forms gated by Turnstile. All hyperlinks valid (no dead/hostile links).
  • Tenant isolation: org_id on every row + query; 404 (never 403) on cross-tenant access.

AI-agent security

  • Treat all model/tool input as untrusted: defend against prompt injection; authorize every tool call; validate + schema-bind every AI output before use (Contract-First AI). Sandbox generated/risky code before it runs.

Errors (never leak internals)

  • User-facing errors use RFC7807 envelopes: code + correlationId + errors[] + what-to-do-next. Never expose stack traces, SQL, or internal identifiers.

Email domain authentication

  • Sending domain publishes SPF + DKIM + DMARC (BIMI where a VMC exists). These records live on the SENDING domain's zone (may differ from the site domain — surface any mismatch before staging).

Signals

GitHub stars
23
Forks
4
Last commit
Oct 2026
Advanced
Item type
skill
Key
trust-compliance
Source
github.com/heymegabyte/agent-skills