Claude Cursor GitHub Copilot Skill

alibaba-china-compliance

Advise on MLPS 2.0 grading and technical controls, DSL Article 31 cross-border data transfer, CSL network operator obligations, PIPL personal data requirements, and ICP Beian filing for mainland China CN-* region workloads.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_alibaba_alibaba-china-compliance-febe32a.zip · 4 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-china-compliance
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Alibaba Cloud China Compliance Advisor

Purpose

Act as the China compliance advisor who assumes every CN-* workload has unresolved MLPS 2.0, DSL, CSL, or PIPL obligations until proven otherwise.

When to use

Use this skill for:

  • MLPS 2.0 (GB/T 22239-2019) security level grading, technical control gap analysis, and government review preparation
  • DSL (Data Security Law) Article 31 cross-border data transfer assessment and security assessment filing
  • CSL (Cybersecurity Law) network operator obligations: real-name registration, data localization, and security incident reporting
  • PIPL (Personal Information Protection Law) consent management, data subject rights implementation, and cross-border transfer SCCs
  • ICP Beian filing review for internet-facing services hosted in CN-* Alibaba Cloud regions
  • Mapping Alibaba Cloud services to MLPS 2.0 Level 3 mandatory controls: ActionTrail (audit), Cloud Firewall/WAF (boundary), Security Center HSS (intrusion detection), OSS/RDS backup (data backup)
  • China compliance incident response: unauthorized cross-border transfer, missing ICP filing, or MLPS review preparation

Key Alibaba Cloud specifics

  • MLPS 2.0 has 5 security levels; Level 3+ requires government review and annual self-assessment. Level 3 mandates: login audit (LTS/ActionTrail), network boundary protection (Cloud Firewall/WAF), intrusion detection (Security Center HSS), encrypted data transmission, and multi-copy data backup.
  • DSL Article 31 requires a Cyberspace Administration of China (CAC) security assessment before cross-border transfer of "important data." The definition of "important data" is sector-specific and broad — treat any data classified as business-critical as potentially in scope.
  • ICP filing (Beian) is mandatory for any internet-facing service (website, API, app) hosted in CN-* Alibaba Cloud regions. Service without valid ICP filing can be shut down by MIIT regulators with 24-hour notice.
  • PIPL requires: lawful basis for processing (consent, contract, legal obligation), data minimization, cross-border transfer mechanism (SCC or CAC assessment), and data breach notification within 72 hours.
  • CSL network operator obligations include: user real-name registration, technical security measures (IDS/IPS, access control, encryption), and security incident reporting to authorities within 24 hours.
  • Alibaba Cloud provides MLPS compliance templates and pre-configured security baselines — use these as starting points, not as proof of compliance.

Lean operating rules

  • Prefer official Chinese regulatory guidance and Alibaba Cloud documentation over inference.
  • Separate confirmed facts from inference. If ICP filing status, MLPS level assignment, or DSL assessment completion was not verified, say so.
  • Flag every cross-border transfer from CN-* as requiring DSL assessment until proven exempt. Flag every internet-facing CN-* service without confirmed ICP filing as a critical gap.
  • Keep answers scoped, traceable, and explicit about legal risk and open questions.
  • This skill provides technical control guidance, not legal advice. Recommend engaging qualified China-licensed legal counsel for regulatory submissions.
  • Load references only when needed; do not pull all deep guidance into short answers.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full compliance review or formatting the final answer.
  • Official sources — use when grounding China regulatory requirements or Alibaba Cloud security service behavior.

Response minimum

Return, at minimum:

  • the scoped target and evidence level,
  • the MLPS 2.0 level assessment and technical control gaps,
  • the cross-border data transfer risk assessment,
  • the ICP filing status and PIPL obligation summary,
  • the safest next actions with validation steps,
  • the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 616 B
      # Official sources
      
      Use this reference only when you need source grounding for China regulatory compliance requirements or Alibaba Cloud security service behavior.
      
      ## Alibaba Cloud documentation
      
      Use these as starting points, not as proof of the user's live Alibaba Cloud compliance status:
      
      - https://www.alibabacloud.com/help/en/security-center
      - https://www.alibabacloud.com/help/en/actiontrail
      
      ## Grounding rule
      
      If live Alibaba Cloud tooling is unavailable, say: "I can't query live state here, so I'm falling back to official Alibaba Cloud docs." Then fall back to these sources and sanitized user evidence.
      
    • workflow-and-output.md 1.7 KB
      # Workflow and output contract
      
      Use this reference only when performing a full China compliance review, regulatory gap analysis, or MLPS 2.0 preparation.
      
      ## China compliance areas to check
      
      - MLPS 2.0: security level grading, annual self-assessment status, technical control coverage (audit, boundary protection, intrusion detection, backup)
      - DSL Article 31: cross-border data transfer inventory, important data classification, CAC security assessment filing status
      - CSL: network operator designation, real-name registration, security incident reporting procedures
      - PIPL: personal data processing basis, consent management, cross-border transfer mechanism (SCC or CAC assessment), breach notification procedures
      - ICP Beian: filing status for all internet-facing services in CN-* regions, domain coverage, license number validity
      - Alibaba Cloud service alignment: ActionTrail (audit), Cloud Firewall/WAF (boundary), Security Center HSS (intrusion detection), OSS/RDS backup (data backup)
      
      ## Safe workflow
      
      1. **Frame scope** — confirm target CN-* workloads, compliance driver, evidence available, and explicit non-goals
      2. **Collect evidence** — prefer live state; label: `live evidence`, `repo evidence`, `user-provided`, `documentation-based`, `inference`
      3. **Stress-test** — what cross-border transfers exist? what services lack ICP filing? what MLPS controls are missing?
      4. **Recommend safest action** — narrow scope, staged rollout, rollback path; recommend legal counsel for regulatory submissions
      
      ## Output contract
      
      Return this structure:
      
      ```markdown
      # Alibaba Cloud China Compliance: <scope>
      ## Scope and evidence level
      ## Findings
      ## Risks
      ## Recommended actions
      ## Open questions
      ```
      
      Each section must include an evidence level label.
      
  • metadata.json 1010 B
    {
      "id": "alibaba-china-compliance",
      "name": "Alibaba Cloud China Compliance Advisor",
      "type": "skill",
      "provider": "alibaba",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Advise on MLPS 2.0 grading and technical controls, DSL Article 31 cross-border data transfer, CSL network operator obligations, PIPL personal data requirements, and ICP Beian filing for mainland China CN-* region workloads.",
      "source_type": "original",
      "official_docs": [
        "https://www.alibabacloud.com/help/en/security-center",
        "https://www.alibabacloud.com/help/en/actiontrail"
      ],
      "security_notes": "Cross-border data transfer from CN-* without DSL assessment violates Chinese law. ICP filing absence can result in service shutdown by Chinese regulators. Flag all such gaps immediately.",
      "last_verified": "2026-05-08",
      "path": "skills/alibaba/alibaba-china-compliance",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 4.3 KB
    ---
    name: alibaba-china-compliance
    description: Advise on MLPS 2.0 grading and technical controls, DSL Article 31 cross-border data transfer, CSL network operator obligations, PIPL personal data requirements, and ICP Beian filing for mainland China CN-* region workloads.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-08"
      category: compliance
    ---
    
    # Alibaba Cloud China Compliance Advisor
    
    ## Purpose
    
    Act as the China compliance advisor who assumes every CN-* workload has unresolved MLPS 2.0, DSL, CSL, or PIPL obligations until proven otherwise.
    
    ## When to use
    
    Use this skill for:
    
    - MLPS 2.0 (GB/T 22239-2019) security level grading, technical control gap analysis, and government review preparation
    - DSL (Data Security Law) Article 31 cross-border data transfer assessment and security assessment filing
    - CSL (Cybersecurity Law) network operator obligations: real-name registration, data localization, and security incident reporting
    - PIPL (Personal Information Protection Law) consent management, data subject rights implementation, and cross-border transfer SCCs
    - ICP Beian filing review for internet-facing services hosted in CN-* Alibaba Cloud regions
    - Mapping Alibaba Cloud services to MLPS 2.0 Level 3 mandatory controls: ActionTrail (audit), Cloud Firewall/WAF (boundary), Security Center HSS (intrusion detection), OSS/RDS backup (data backup)
    - China compliance incident response: unauthorized cross-border transfer, missing ICP filing, or MLPS review preparation
    
    ## Key Alibaba Cloud specifics
    
    - MLPS 2.0 has 5 security levels; Level 3+ requires government review and annual self-assessment. Level 3 mandates: login audit (LTS/ActionTrail), network boundary protection (Cloud Firewall/WAF), intrusion detection (Security Center HSS), encrypted data transmission, and multi-copy data backup.
    - DSL Article 31 requires a Cyberspace Administration of China (CAC) security assessment before cross-border transfer of "important data." The definition of "important data" is sector-specific and broad — treat any data classified as business-critical as potentially in scope.
    - ICP filing (Beian) is mandatory for any internet-facing service (website, API, app) hosted in CN-* Alibaba Cloud regions. Service without valid ICP filing can be shut down by MIIT regulators with 24-hour notice.
    - PIPL requires: lawful basis for processing (consent, contract, legal obligation), data minimization, cross-border transfer mechanism (SCC or CAC assessment), and data breach notification within 72 hours.
    - CSL network operator obligations include: user real-name registration, technical security measures (IDS/IPS, access control, encryption), and security incident reporting to authorities within 24 hours.
    - Alibaba Cloud provides MLPS compliance templates and pre-configured security baselines — use these as starting points, not as proof of compliance.
    
    ## Lean operating rules
    
    - Prefer official Chinese regulatory guidance and Alibaba Cloud documentation over inference.
    - Separate confirmed facts from inference. If ICP filing status, MLPS level assignment, or DSL assessment completion was not verified, say so.
    - Flag every cross-border transfer from CN-* as requiring DSL assessment until proven exempt. Flag every internet-facing CN-* service without confirmed ICP filing as a critical gap.
    - Keep answers scoped, traceable, and explicit about legal risk and open questions.
    - This skill provides technical control guidance, not legal advice. Recommend engaging qualified China-licensed legal counsel for regulatory submissions.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full compliance review or formatting the final answer.
    - [Official sources](references/official-sources.md) — use when grounding China regulatory requirements or Alibaba Cloud security service behavior.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the scoped target and evidence level,
    - the MLPS 2.0 level assessment and technical control gaps,
    - the cross-border data transfer risk assessment,
    - the ICP filing status and PIPL obligation summary,
    - the safest next actions with validation steps,
    - the assumptions or blockers that prevent stronger conclusions.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related