AGENT SKILL
Security36 compliance frameworks as individual .skill packages, with a published eval
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
911 stars, MIT, v2.0.0, updated monthly. Information security covers ISO 27001, SOC 2, FedRAMP, NIST CSF, NIST SP 800-53 and CIS Controls v8; privacy covers GDPR, ISO 27701, CCPA/CPRA, LGPD and DPDPA; AI governance covers ISO 42001, NIST AI RMF and the EU AI Act; sector and country law covers HIPAA, PCI DSS, DORA, SWIFT CSP, TISAX, SOX ITGC, EU NIS2/CRA/CSRD and ITAR/EAR.
Our takeMost compliance prompt packs only claim expert level; this one ships numbers — 180 test cases, 902 verifiable assertions, graded by independent agents, 89% with the skill against a 57% baseline. That gap says general models are shaky on fine-grained control mapping, which is the daily work of compliance. It carries its own disclaimer: not a substitute for licensed legal or audit opinion. Its value is making the first draft complete and correct, and a human still signs.
/plugin marketplace add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance36 compliance frameworks in one repo
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance (911 stars / 184 forks, MIT, v2.0.0, updated monthly) packages the 36 frameworks enterprises actually meet as individual .skill bundles, spanning information security, privacy, AI governance, sector regulation and country law.
| Area | Frameworks |
|---|---|
| ISMS | ISO 27001, SOC 2, FedRAMP, NIST CSF, NIST SP 800-53, CIS Controls v8 (Top 18), Cyber Essentials / CE Plus |
| Privacy | GDPR, ISO 27701, CCPA/CPRA, LGPD, DPDPA (India), Vietnam PDPL, Saudi PDPL, UAE Federal/DIFC/ADGM PDPL |
| AI governance | ISO 42001 (AI management), NIST AI RMF, EU AI Act (Regulation (EU) 2024/1689) |
| Sector & resilience | HIPAA, PCI DSS, TSA Cybersecurity, DORA, SWIFT CSP, TISAX (VDA ISA / ENX automotive), SOX ITGC, TPRM (third-party risk) |
| Country / export control | Australian ISM, NZISM, EU NIS2, EU CRA (Cyber Resilience Act), EU CSRD, ITAR, EAR, Saudi GRC (NCA ECC/SAMA/CST), Section 508, WCAG |
It publishes an eval, and the methodology is inspectable
Most compliance prompt packs just claim "expert level". This one ships numbers: 180 test cases, each graded against at least 5 verifiable assertions by independent agents — 902 assertions in total; 89% with the skills versus a 57% baseline. The eval framework is in the repo, the assertions are checkable rather than subjective, and the graders are independent agents, which avoids self-scoring bias.
What 89% vs 57% actually says is that general models are shaky on fine-grained clause mapping — which specific NIST 800-53 controls apply to a given scenario, which GDPR articles govern an international transfer. That mapping is the daily work of compliance, and it is the layer the skills add.
How it works, and the auto-trigger
Its explanation of the mechanism is worth keeping: a .skill file is a bundled archive holding one primary SKILL.md plus reference files loaded on demand; upload it once and it works across every conversation; once the topic touches that domain the skill activates automatically — no naming it, no special command. That is progressive disclosure applied to compliance: context carries only the slice currently needed.
Its "use when" test is stated cleanly: consistent expert-level answers on a specialised topic, outputs formatted to professional or regulatory standards (audit-ready control narratives, policy templates with the right clauses), and domain knowledge beyond general LLM training. Otherwise you do not need it.
Two install paths
# A. Claude web app: Customize → Skills → upload the .skill file
# one .skill per framework, e.g. iso27001.skill / soc2.skill / gdpr-compliance.skill
# (individual accounts must enable code execution and file creation under Settings → Capabilities)
# B. Claude Code: via marketplace, with version pinning and updates
/plugin marketplace add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
# then install the plugin for each framework
The repo root has INSTALLATION.md and a per-framework download table (generated in the README by GEN:readme-download-table).
The one thing to know before using it
The repo carries its own disclaimer: this is a compliance aid, not a substitute for licensed legal or audit opinion. Its value is getting clause mapping, control narratives and first drafts of policy templates complete and correct, freeing people to exercise judgement; the sign-off still belongs to a human. And "updated monthly" is a genuine requirement — the EU AI Act and EU CRA phase in over time, so a static prompt is stale within six months.