AI Governance
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone.
$ npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install alirezarezvani/claude-skills agent-decision-receipts --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/skills/agent-decision-receipts .claude/skills/agent-decision-receipts && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "agent-decision-receipts" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/ra-qm-team/skills/agent-decision-receipts into .claude/skills/agent-decision-receipts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-decision-receipts", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/alirezarezvani/claude-skills/tree/main/ra-qm-team/skills/agent-decision-receiptsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install alirezarezvani/claude-skills agent-decision-receipts --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ra-qm-team/skills/agent-decision-receipts .agents/skills/agent-decision-receipts && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "agent-decision-receipts" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/ra-qm-team/skills/agent-decision-receipts into .agents/skills/agent-decision-receipts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-decision-receipts", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install alirezarezvani/claude-skills agent-decision-receipts --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ra-qm-team/skills/agent-decision-receipts .cursor/skills/agent-decision-receipts && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "agent-decision-receipts" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/ra-qm-team/skills/agent-decision-receipts into .cursor/skills/agent-decision-receipts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-decision-receipts", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/alirezarezvani/claude-skills.git --path ra-qm-team/skills/agent-decision-receipts--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install alirezarezvani/claude-skills agent-decision-receipts --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ra-qm-team/skills/agent-decision-receipts .gemini/skills/agent-decision-receipts && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "agent-decision-receipts" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/ra-qm-team/skills/agent-decision-receipts into .gemini/skills/agent-decision-receipts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-decision-receipts", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install alirezarezvani/claude-skills agent-decision-receiptsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/ra-qm-team/skills/agent-decision-receipts .github/skills/agent-decision-receipts && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "agent-decision-receipts" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/ra-qm-team/skills/agent-decision-receipts into .github/skills/agent-decision-receipts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-decision-receipts", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install alirezarezvani/claude-skills agent-decision-receipts --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ra-qm-team/skills/agent-decision-receipts .opencode/skills/agent-decision-receipts && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "agent-decision-receipts" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/ra-qm-team/skills/agent-decision-receipts into .opencode/skills/agent-decision-receipts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "agent-decision-receipts", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
agent-decision-receiptsMint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone.
Agent Decision Receipts is an agent skill from alirezarezvani/claude-skills. Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone. Use when an autonomous agent takes a side-effecting action that may need to be proven later, or when satisfying EU AI Act Article 12 record-keeping. Three decisions: whether an action needs a receipt, minting it, verifying it. Signing is delegated to the open-source OpenAgentOntology package. Not after-the-fact log analysis…
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/receipt-fields.md` and `scripts/build_action_manifest.py`).
It sits in Legal & Compliance, covering Cryptography, Legal research and AI governance. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pippythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Agent Decision Receipts loads about 2k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 146 tokens; SKILL.md has 886 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 886 words, ~1,980 tokens.
.claude/skills/agent-decision-receipts/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.A log says an action happened. A receipt is tamper-evident: it records who, what, and under which policy, and it is signed, so any later edit breaks the signature. This skill mints one for a consequential agent action and verifies it later from the certificate alone: no database, no network, no trusting the issuer.
The crypto is not in this skill. It is the open-source OpenAgentOntology receipt primitive (Apache-2.0), which signs every receipt with Ed25519 and the post-quantum legs ML-DSA-65 (FIPS 204) + SLH-DSA (FIPS 205) when the post-quantum backend is installed. This skill is the decision layer: when to mint, what to put in, how to verify. One install, no per-skill crypto.
Three decisions, nothing else:
This skill is NOT log analysis. Logs describe what happened and can be silently edited. A receipt is minted before/at execution and breaks if edited. Use logs for debugging; use receipts for evidence.
This skill is NOT a hosted notary. It mints a LOCAL, self-signed receipt anyone can verify offline. Cross-organization verification (one org proving to another) is a separate hosted service, out of scope here.
This skill is NOT a legal opinion. It produces evidence shaped to support FRE 902(13)/(14)-style certification and EU AI Act Article 12 record-keeping. Whether a given receipt is admitted is a question for counsel.
# Install the open-source receipt primitive (Apache-2.0). Add [pq] for the post-quantum legs.
pip install "openagentontology[pq]"
# 1. Build + validate an action manifest (stdlib only, no crypto, no network)
python scripts/build_action_manifest.py --agent my-deploy-agent --operation deploy \
--target prod/api --policy "EU AI Act Art 12" --out action.json
# 2. Mint the receipt over it (Ed25519 + post-quantum legs)
python -c "import json,openagentontology.receipt as r; \
print(json.dumps(r.mint_receipt(json.load(open('action.json')), decision='ACTION_GOVERNED')))" > receipt.json
# 3. Verify from the cert alone (no DB, no network)
python -c "import json,openagentontology.receipt as r; \
print(r.verify_receipt(json.load(open('receipt.json'))))"
# -> {'ok': True, 'sig_ok': True, ... 'reason': 'verified from the cert alone via: ed25519, ml_dsa, slh_dsa'}Dependency note. This skill delegates the signing to
openagentontology(Apache-2.0, opt-inpip install). The script shipped here is stdlib-only and adds no repo dependency; the package is installed by the operator (BYO-library pattern). If it is not installed, the build step still works — only minting/verifying require it.
The three decisions below are the skill: decide whether to receipt, mint, then verify.
Mint a receipt when the action is all three of:
| Test | Mint if... |
|---|---|
| Side-effecting | it writes, sends, deploys, deletes, pays, grants access, or changes external state |
| Consequential | a wrong call costs money, breaks compliance, or harms a person |
| Later-provable | someone (auditor, insurer, regulator, court, counterparty) may ask "what did the agent do and why?" |
Read-only, reversible, trivial actions do not need a receipt. Receipt everything and the signal drowns; receipt nothing and the one call that mattered cannot be proven.
High-signal triggers (mint by default): deploy, delete, pay/wire/refund, grant_access, export/egress, approve/deny a claim, any model decision that affects a person under a high-risk AI system.
The action manifest is any ASCII-safe dict describing what the agent did. Four keys are required — build_action_manifest.py rejects the manifest (exit 2) if any is missing. Two more are added automatically:
| Key | Required? | What it carries |
|---|---|---|
agent_id | required | the acting agent |
operation | required | the verb (deploy / delete / pay / decide / ...) |
target | required | what it acted on |
policy | required | the rule that governs it (e.g. "EU AI Act Art 12", "internal change-control") |
inputs_hash | auto-added | a hash of --inputs, so the full payload need not be stored in the clear (defaults to the hash of empty when --inputs is omitted) |
decision_label | auto-added | the receipt decision label (defaults to ACTION_GOVERNED) |
mint_receipt(manifest, decision=...) hashes the full manifest into the receipt evidence, signs the canonical body, and returns a receipt that carries: evidence_hash, signature_b64 (Ed25519), and — when [pq] is installed — ml_dsa_signature_b64 + slh_dsa_signature_b64. Each leg signs the same bytes; any one verifying proves authenticity.
See references/receipt-fields.md for the full receipt schema and the post-quantum rationale.
verify_receipt(receipt) recomputes sha256(canonical(evidence)), compares it to evidence_hash, then checks every signature leg it has a backend for. It returns {ok, hash_ok, sig_ok, legs, reason}. A single edited byte anywhere in the action breaks hash_ok; a forged signature breaks the leg. Verification needs only the receipt — no call back to the issuer.
This is the property that makes it evidence: a reviewer who distrusts the issuer can still confirm the receipt is intact and authentic, entirely offline.
[pq].inputs_hash), not the cleartext.unsigned flag instead. Never present an unsigned receipt as signed.ra-qm-team/skills/eu-ai-act-specialist/ — decide the AI system's risk tier and Article 12 obligations; this skill mints the per-action record those obligations require.ra-qm-team/skills/iso42001-specialist/ — the AI management-system controls; receipts are the per-decision evidence those controls call for.pip install "openagentontology[pq]".© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts, references) in ra-qm-team/skills/agent-decision-receipts of alirezarezvani/claude-skills.
Open the folder on GitHubat commit 19392f7
Agent Decision Receipts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Agent Decision Receipts this skillalirezarezvani/claude-skills | 28k | — | ~2k | Automated safety check: Pass | MIT | |
| AI GovernanceHack23/cia | 239 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Hashicorp Vault Dynamic Secretsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~5.2k | Automated safety check: Pass | Apache-2.0 | |
| Detecting Ssl Cert Issuesjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Pseudonymization Riskmukul975/Privacy-Data-Protection-Skills | 297 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Agent Bom ComplianceLeoYeAI/openclaw-master-skills | 2.2k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 |
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
mukul975/Anthropic-Cybersecurity-Skills
Configures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates, with automatic generation, lease management, and rotation to eliminate static secrets…
jeremylongshore/tons-of-skills-marketplace
Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards.
mukul975/Privacy-Data-Protection-Skills
Assessment of pseudonymization techniques and re-identification risk.
LeoYeAI/openclaw-master-skills
AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.
mukul975/Privacy-Data-Protection-Skills
Guides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020.
alirezarezvani/claude-skills
Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.
alirezarezvani/claude-skills
OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.
alirezarezvani/claude-skills
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.
alirezarezvani/claude-skills
Design AWS architectures for startups using serverless patterns and IaC templates.
alirezarezvani/claude-skills
Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.
alirezarezvani/claude-skills
Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.
Categories
Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone. Agent Decision Receipts is an agent skill from alirezarezvani/claude-skills. Mint a tamper-evident, post-quantum-signed receipt for a consequential agent action (deploy, delete, pay, grant-access, model decision) so it can be verified later from the certificate alone.
Agent Decision Receipts fits situations like: an autonomous agent takes a side-effecting action that may need to be proven later; satisfying EU AI Act Article 12 record-keeping.
Run `npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts -a claude-code`. Or copy the skill folder (ra-qm-team/skills/agent-decision-receipts in alirezarezvani/claude-skills) into .claude/skills/agent-decision-receipts in your project. Claude Code loads it when a task matches its description.
Run `npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts -a codex`. Or copy the skill folder (ra-qm-team/skills/agent-decision-receipts in alirezarezvani/claude-skills) into .agents/skills/agent-decision-receipts in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill agent-decision-receipts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/agent-decision-receipts, .gemini/skills/agent-decision-receipts, .github/skills/agent-decision-receipts and .opencode/skills/agent-decision-receipts in your project.
Going by SKILL.md and its folder, Agent Decision Receipts needs Python for the scripts in its folder and the command-line tools its instructions call (pip and python). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Agent Decision Receipts is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Agent Decision Receipts: AI Governance (Hack23/cia, 239 stars), Implementing Hashicorp Vault Dynamic Secrets (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Ssl Cert Issues (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Pseudonymization Risk (mukul975/Privacy-Data-Protection-Skills, 297 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,891 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.
Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.