← Cursor Slash Commands · ENGINEERING
/compliance-audit
GDPR & SOC2 Privacy Compliance Auditor
Data retention check, encryption audit, user data deletion, and access logs.
/compliance-audit Audit user data deletion flow and encryption standards for GDPR complianceWhere it installs
# .cursor/commands/compliance-audit.md
# no frontmatter, the file opens with its H1 title# .claude/commands/compliance-audit.md
---
description: ...
argument-hint: [framework and scope, e.g. SOC2 CC6 access]
allowed-tools: Read, Grep, Glob, Skill, TodoWrite, Task, ...
---What it does
/compliance-audit is a Cursor slash command. Type it in chat to run a saved workflow: GDPR & SOC2 Privacy Compliance Auditor.
Audits systems against GDPR, SOC2, and HIPAA rules: verifies data encryption, user data deletion pipelines, audit logging, and cookie consent.
Data retention check, encryption audit, user data deletion, and access logs. Unlike a skill, a command is something you invoke on purpose. The agent does not decide to run /compliance-audit for you.
Why it exists
Founders retype the same multi-step prompt until it rots. /compliance-audit exists so the pipeline, all 4 steps of it, is a file in .cursor/commands, versioned with the repo.
It ships in the Engineering Kit. It is wired to the SOC2 & Compliance Expert (compliance-engineer) and App Security Auditor (security-auditor) agents. Required skills: SOC2 Compliance & Data Privacy Controls; Web Security Fundamentals & OWASP Defense.
When to use it
- Use when preparing for enterprise compliance reviews or privacy audits.
- Use /compliance-audit when you want that pipeline, not a freeform chat. If you only need one step, use a narrower command or a single agent.
- Start a new chat. Do not run this command in a thread that just wrote marketing copy.
When not to use it
- Do not run /compliance-audit as a substitute for reading the diff. The command produces files; you still gate them.
- Do not chain it into a 40-turn chat. Fresh context is part of the design.
- Do not run it if you have not filled CURSOR.md. The pipeline will invent a stack.
Example workflow
- Inspect database tables for PII encryption at rest and in transit
- Verify user data export and account deletion API endpoints
- Check audit log completeness for administrative actions
- Generate compliance gap report with required code fixes
Example usage
Type this in Cursor chat: /compliance-audit Audit user data deletion flow and encryption standards for GDPR compliance
The command file tells the session which agents to adopt and which skills to read. You should see phase headers, not a single dump of code.
If a phase fails its gate, stop. Do not add 'just continue'.
Example output
- Expected artifact: docs/compliance/gdpr-audit.md
Best practices
- Keep the prompt specific. /compliance-audit Audit user data deletion flow and encryption standards for GDPR compliance is the shape: object, constraint, and outcome.
- Let the listed agents work in order: compliance-engineer → security-auditor.
- Save outputs in the repo. Chat-only answers evaporate.
- Engineering commands should leave tests or an audit note, not only implementation files.
Common mistakes
- Typing /compliance-audit with no object ('do the thing'). The pipeline will guess.
- Re-running the command in the same chat after a failed gate instead of fixing the failing file.
- Editing the command file to skip review so it 'goes faster'.
- Skipping the SOC2 Compliance & Data Privacy Controls skill that the command depends on.
Frequently asked questions
What does /compliance-audit do in Cursor?
Audits systems against GDPR, SOC2, and HIPAA rules: verifies data encryption, user data deletion pipelines, audit logging, and cookie consent.When should I run /compliance-audit?
Use when preparing for enterprise compliance reviews or privacy audits.What is an example /compliance-audit prompt?
/compliance-audit Audit user data deletion flow and encryption standards for GDPR complianceWhich skills does /compliance-audit load?
SOC2 Compliance & Data Privacy Controls; Web Security Fundamentals & OWASP DefenseIs /compliance-audit a Cursor skill?
No. /compliance-audit is a slash command you type. Skills are playbooks the agent may load. Use both: the command runs the workflow, the skills constrain how it writes.
Run /compliance-audit from your own repo
AgenticKit installs 47 slash commands, 46 agents, and 61 skills. One command installation.