Agent skill

Compliance Check

by 686f6c61 in 686f6c61/alfred-dev

Usar para verificar cumplimiento RGPD, NIS2 y CRA. An agent skill from 686f6c61/alfred-dev.

MITAuto-check passedLegal & Compliance

Install Compliance Check

skills CLI
$ npx skills add 686f6c61/alfred-dev --skill compliance-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install 686f6c61/alfred-dev compliance-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/686f6c61/alfred-dev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/compliance-check .claude/skills/compliance-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance-check
GitHub stars
117
Token cost
~1.3k tokens
SKILL.md length
666 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Usar para verificar cumplimiento RGPD, NIS2 y CRA. An agent skill from 686f6c61/alfred-dev.

  • Works in 5 steps: Determinar qué normativas aplican. No… → Checklist RGPD → Checklist NIS2 → …
  • Tasks that involve Regulatory compliance
  • SKILL.md covers Resumen, Proceso, Criterios de éxito and Paso final: registro en memoria, plus 2 more sections
  • Calls python3

What it does

Compliance Check is an agent skill from 686f6c61/alfred-dev. Usar para verificar cumplimiento RGPD, NIS2 y CRA. También: verificar RGPD, cumplimiento normativo, NIS2, CRA, Cyber Resilience Act, protección de datos, regulación europea.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Regulatory compliance. The repository describes itself as: Tu equipo de desarrolladores en un plugin. 10 agentes, 11 skills planas, 18 comandos /alfred-dev:. Memoria persistente, quality gates con evidencia y MCP local. The licence is MIT.

When your agent uses it

  • Tasks that involve Regulatory compliance

Example prompts

  • “/compliance-check”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Determinar qué normativas aplican. No todos los proyectos están sujetos a las tres
  2. Checklist RGPD
  3. Checklist NIS2
  4. Checklist CRA (Cyber Resilience Act)
  5. Escribir el registro vivo. No dejes el resultado solo en el chat.

What it can do on your machine

Read from SKILL.md and the folder at commit be0b51e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance Check loads about 1.3k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 666 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from 686f6c61/alfred-dev at commit be0b51e, republished under its MIT licence (© 686f6c61). 666 words, ~1,336 tokens.

Download SKILL.mdSave it as .claude/skills/compliance-check/SKILL.md (or your agent's skills folder).
name
compliance-check
description
Usar para verificar cumplimiento RGPD, NIS2 y CRA. También: verificar RGPD, cumplimiento normativo, NIS2, CRA, Cyber Resilience Act, protección de datos, regulación europea.

Verificación de cumplimiento normativo

Resumen

Este skill evalúa el proyecto contra tres marcos regulatorios europeos fundamentales: RGPD (protección de datos), NIS2 (ciberseguridad de infraestructuras) y CRA (Cyber Resilience Act, seguridad de productos con elementos digitales). El resultado es un informe de conformidad con el estado actual del proyecto frente a cada requisito y las acciones necesarias para alcanzar el cumplimiento.

No se trata de un dictamen jurídico, sino de una evaluación técnica que identifica las lagunas y orienta las acciones de desarrollo necesarias.

Proceso

  1. Determinar qué normativas aplican. No todos los proyectos están sujetos a las tres:

    • RGPD: aplica si el software trata datos personales de personas en la UE.
    • NIS2: aplica si la organización opera en sectores críticos o es proveedor de servicios digitales.
    • CRA: aplica a productos con elementos digitales comercializados en la UE (incluyendo software open source con uso comercial).
  2. Checklist RGPD:

    • Base jurídica para el tratamiento de datos (consentimiento, interés legítimo, contrato, etc.).
    • Minimización de datos: solo se recogen los datos estrictamente necesarios.
    • Evaluación de impacto (DPIA) para tratamientos de alto riesgo.
    • Registro de actividades de tratamiento documentado.
    • Derecho de acceso: el usuario puede consultar sus datos.
    • Derecho de rectificación: el usuario puede corregir sus datos.
    • Derecho al olvido: el usuario puede solicitar la eliminación de sus datos.
    • Portabilidad: el usuario puede exportar sus datos en formato estándar.
    • Notificación de brechas en 72 horas.
    • Cifrado de datos personales en tránsito y en reposo.
    • Delegado de Protección de Datos (DPO) designado si aplica.
  3. Checklist NIS2:

    • Gestión de riesgos de ciberseguridad documentada.
    • Política de seguridad de la información aprobada por la dirección.
    • Notificación de incidentes: alerta temprana en 24h, informe completo en 72h.
    • Seguridad de la cadena de suministro: evaluación de proveedores.
    • Gobernanza: responsabilidades de ciberseguridad asignadas.
    • Plan de continuidad de negocio y recuperación ante desastres.
    • Formación en ciberseguridad para el personal.
    • Gestión de vulnerabilidades y actualizaciones.
    • Autenticación multifactor para accesos críticos.
  4. Checklist CRA (Cyber Resilience Act):

    • SBOM (Software Bill of Materials) generado y mantenido.
    • Actualizaciones de seguridad disponibles durante todo el ciclo de vida.
    • Diseño seguro por defecto (secure by default).
    • Documentación técnica del producto disponible.
    • Gestión de vulnerabilidades con proceso de reporte.
    • Notificación de vulnerabilidades activamente explotadas en 24h a ENISA.
    • Evaluación de conformidad (autoevaluación o certificación según categoría).
    • Marcado CE para productos conformes.
  5. Escribir el registro vivo. No dejes el resultado solo en el chat. El destino canónico es docs/project/compliance.md. Si no existe, créalo antes con python3 .claude/alfred-continuity.py sync-project-docs "$PWD". Usa templates/compliance.md como forma. Para cada control: estado, evidencia (ruta de código, test o config) y acciones. Sin evidencia no marques cumple. Sustituye <!-- alfred-doc:scaffold --> por <!-- alfred-doc:filled -->.

Show full SKILL.md (232 more words)Show less

Criterios de éxito

  • Se han identificado las normativas aplicables al proyecto.
  • Cada checklist se ha revisado punto por punto con estado documentado.
  • Las acciones necesarias están priorizadas por riesgo e impacto.
  • El informe es accionable: un desarrollador puede tomar cada acción y ejecutarla.
  • El registro vive en docs/project/compliance.md con marcador filled.
  • El estado de cumplimiento se ha registrado en la memoria del proyecto.

Paso final: registro en memoria

Registrar el estado de cumplimiento en la memoria del proyecto con memory_log_decision para seguimiento entre sesiones. Esto permite comparar la evolución del cumplimiento a lo largo del tiempo y detectar regresiones normativas.

Nota de versión

Este skill se basa en RGPD (Reglamento 2016/679), NIS2 (Directiva 2022/2555) y CRA (Reglamento 2024/2847). Verificar si han entrado en vigor actualizaciones posteriores a estas referencias antes de dar por válida la evaluación.

Qué NO hacer

  • No tratar esta evaluación como sustituto de asesoría legal. Es una evaluación técnica que identifica lagunas, pero las decisiones jurídicas requieren un profesional cualificado.
  • No marcar un requisito como cumplido sin evidencia técnica que lo respalde (código, configuración, documentación verificable).
  • No ignorar el CRA por tratarse de software open source. El CRA aplica a OSS con uso comercial; la exención solo cubre al software libre sin ánimo de lucro ni actividad comercial.
  • No dar por cerrada la evaluación sin documentar los requisitos que no aplican y la justificación de por qué no aplican.

© 686f6c61, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/compliance-check of 686f6c61/alfred-dev.

Open the folder on GitHubat commit be0b51e

Compare with similar skills

Compliance Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compliance Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compliance Check this skill686f6c61/alfred-dev117—~1.3kAutomated safety check: PassMIT
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.7kAutomated safety check: PassMIT
Legal Compliance SearchSerein-81/financial_rag148—~1.6kAutomated safety check: NotesNone

Similar skills

  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Legal Compliance Search

    Serein-81/financial_rag

    Looks up current company registration rules, industry licences and compliance obligations in China through live web search, tailored to the business profile.

    148 GitHub stars~1.6k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes
  • Ad Compliance Review

    zh-xx/legal-assistant-skills

    广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。

    174 GitHub stars~1.2k tokensUpdated 5 mo ago
    Legal & ComplianceAuto-check passed

More from 686f6c61/alfred-dev

All 11 skills in this repo
  • Incident Response

    686f6c61/alfred-dev

    Protocolo de respuesta ante incidentes en produccion: triaje, mitigacion, causa raiz y postmortem.

    117 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Memory

    686f6c61/alfred-dev

    This skill should be used when the user asks to record a design decision, search past project decisions, inspect the Alfred memory timeline, or work with the alfred-memory MCP server.

    117 GitHub stars~601 tokensUpdated 1 mo ago
    Auto-check passed
  • PR Workflow

    686f6c61/alfred-dev

    Crear pull requests completas con descripcion, labels y reviewers

    117 GitHub stars~777 tokensUpdated 1 mo ago
    Auto-check passed
  • Sonarqube

    686f6c61/alfred-dev

    Levantar SonarQube con Docker, analizar el código y proponer mejoras.

    117 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Style Direction

    686f6c61/alfred-dev

    Abrir y operar el companion visual de Selina para elegir una direccion de estilo en proyectos con interfaz.

    117 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Sync Project Docs

    686f6c61/alfred-dev

    Usar para sincronizar la documentación viva del proyecto después de una fase.

    117 GitHub stars~382 tokensUpdated 1 mo ago
    Auto-check passed

Questions about Compliance Check

What does Compliance Check do?

Usar para verificar cumplimiento RGPD, NIS2 y CRA. An agent skill from 686f6c61/alfred-dev. Compliance Check is an agent skill from 686f6c61/alfred-dev. Usar para verificar cumplimiento RGPD, NIS2 y CRA.

When should I use Compliance Check?

Compliance Check fits situations like: tasks that involve Regulatory compliance.

How do I install Compliance Check in Claude Code?

Run `npx skills add 686f6c61/alfred-dev --skill compliance-check -a claude-code`. Or copy the skill folder (skills/compliance-check in 686f6c61/alfred-dev) into .claude/skills/compliance-check in your project. Claude Code loads it when a task matches its description.

How do I install Compliance Check in Codex?

Run `npx skills add 686f6c61/alfred-dev --skill compliance-check -a codex`. Or copy the skill folder (skills/compliance-check in 686f6c61/alfred-dev) into .agents/skills/compliance-check in your project. Codex loads it when a task matches its description.

Can I use Compliance Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 686f6c61/alfred-dev --skill compliance-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-check, .gemini/skills/compliance-check, .github/skills/compliance-check and .opencode/skills/compliance-check in your project.

What does Compliance Check need to run?

Going by SKILL.md and its folder, Compliance Check needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Compliance Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Compliance Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Compliance Check use?

Compliance Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compliance Check use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Compliance Check?

Skills that share tags, products or a category with Compliance Check: HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars) and Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compliance Check?

686f6c61 (a GitHub user) maintains it in 686f6c61/alfred-dev, which has 117 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on August 15, 2026.

Source: 686f6c61/alfred-dev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.