152-FZ website audit skill

audit-152fz

A Claude skill that audits a website and its documents against Federal Law 152-FZ using a 55-point checklist, with fine estimates and a fix plan

Skill

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Reads and parses site content and uploaded documents
  • Gives fine and risk estimates that should not be submitted as a finished legal opinion
All reasons and checks
Russian stack

qlasse/claude-skill-152fz

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add skills/audit-152fz

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run in a terminal in the project folder

npx skills add qlasse/claude-skill-152fz --skill audit-152fz -a claude-code -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add qlasse/claude-skill-152fz --skill audit-152fz -a cursor -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add qlasse/claude-skill-152fz --skill audit-152fz -a github-copilot -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add qlasse/claude-skill-152fz --skill audit-152fz -a codex -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add qlasse/claude-skill-152fz --skill audit-152fz -a gemini-cli -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add qlasse/claude-skill-152fz --skill audit-152fz -a cline -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add qlasse/claude-skill-152fz --skill audit-152fz -a roo -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

A fork of Roo Code, same .roo folders.

Run in a terminal in the project folder

npx skills add qlasse/claude-skill-152fz --skill audit-152fz -a opencode -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

You will need: Node.js

Checked against the repository on Sep 25, 2026, commit 28fa4c2.

Text for your agent

Clone the skill with git clone https://github.com/Qlasse/claude-skill-152fz.git ~/.claude/skills/audit-152fz; for Claude.ai, build a .skill archive and upload it in settings.

Other ways from the author
git clone https://github.com/Qlasse/claude-skill-152fz.git ~/.claude/skills/audit-152fz

Install into the Claude Code skills directory.

This is third-party code. Review the repository files before installing.

What it does

When asked to audit a site for 152-FZ compliance, the skill technically examines the site: forms and their fields, pre-checked checkboxes, hidden inputs, third-party trackers and pixels with the jurisdiction their data actually goes to. It checks documents: the personal-data processing policy against Roskomnadzor's recommendations and consent texts against Article 9 of the law. Each finding gets a status, a reference to the norm, and a fine range under the current version of Article 13.11 of the Administrative Code, including turnover-based fines for repeat leaks. What cannot be verified externally (database location, contractor agreements) is marked unverified with a specific question for the owner, rather than reported as a violation. The response format adapts to the request: a short question gets a conversational answer, a full pre-inspection audit gets a report across every block.

Who it is for. For site owners, lawyers and developers who need to check 152-FZ compliance ahead of a Roskomnadzor inspection.

Good fit when

  • You want a quick check of a site or privacy policy against 152-FZ
  • You are preparing for a Roskomnadzor inspection and want to estimate the risk in rubles beforehand
  • You need to know whether cookie consent is required with Yandex Metrika installed

Not a fit when

  • You need a legal opinion to submit to a court or Roskomnadzor: the skill gives an expert assessment, not a lawyer's opinion
  • You need to verify internal organizational measures and actual database location: the skill cannot see this from outside

Example request

Check example.ru for 152-FZ compliance

Limitations

Gives an expert assessment based on externally visible signs, not a legal opinion. Cannot verify actual database location, contractor agreements or internal documents, and honestly marks such points as unverified. The law changes several times a year, the reference is current as of August 2026, and findings should be checked with a specialized lawyer before filing anything with Roskomnadzor.

How to disable. Delete the ~/.claude/skills/audit-152fz folder, or remove the uploaded .skill file in Claude.ai settings.

Security check

  • Reads and parses site content and uploaded documents
  • Gives fine and risk estimates that should not be submitted as a finished legal opinion

README in short

The README lists the 55-point checklist across nine blocks, describes the skill's files (audit rules, a norms-and-fines reference, a report template, an HTML-parsing script using only Python's standard library), and reports test results: 26 of 26 checks passed with the skill versus 19 of 26 without it, with examples of model errors when the reference is missing (wrong fine amounts, missing the separate consent-document requirement).

SKILL.md

# audit-152fz

Скилл для Claude: аудит сайта на соответствие Федеральному закону № 152-ФЗ «О персональных данных» и смежному регулированию.

По команде вроде «проверь мой сайт на 152-ФЗ» Claude проходит сайт и документы по чеклисту из 55 пунктов, ставит статус каждому требованию, считает риск в деньгах по ст. 13.11 КоАП и выдает план исправлений, разделенный по исполнителям.

Актуальность нормативной базы: август 2026. Учтены поправки 2025 года — реформа штрафов от 30.05.2025 (ФЗ № 420-ФЗ), уточнение локализации с 01.07.2025 (ФЗ № 23-ФЗ), требование оформлять согласие отдельным документом с 01.09.2025.

## Что делает

- Разбирает сайт технически — формы и их поля, преднажатые чекбоксы, скрытые input, сторонние счетчики и пиксели.
- Проверяет документы — политику обработки ПДн и тексты согласий.
- Квалифицирует находки — каждое нарушение с нормой и вилкой штрафа.
- Разделяет факт и гипотезу — непроверенное помечается как вопрос владельцу.

FAQ

Does the skill give a legal opinion?

No, it is an expert assessment based on open signs; findings should be checked with a lawyer before filing with Roskomnadzor.

What if the site data is not directly accessible?

The skill asks what is available: a URL, a saved HTML page or documents, and gathers data by whatever means fits.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AI152-FZ website audit skill

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.