Agent skill

Compliance Os

by alirezarezvani in alirezarezvani/claude-skills

Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

MITAuto-check passedLegal & Compliance

Install Compliance Os

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill compliance-os -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills compliance-os --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/compliance-os/skills/compliance-os .claude/skills/compliance-os && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance-os
GitHub stars
28k
Token cost
~3.3k tokens
SKILL.md length
913 words
Files
14 (incl. scripts, references, assets)
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

  • Works in 4 steps: Framework Selection → Cross-Framework Control Mapping → Audit Simulation → …
  • Standing up a multi-framework program
  • SKILL.md covers Keywords, Quick Start, Key Questions (ask these first) and Core Responsibilities, plus 5 more sections
  • Runs Python scripts from its folder; calls python

What it does

Compliance Os is an agent skill from alirezarezvani/claude-skills. Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across multiple frameworks. Four decisions: (1) Given a company profile, which of the 12 supported frameworks apply (ISO 27001/13485/42001/14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR, NIST CSF 2.0, NIS2, HIPAA)? (2) Across selected frameworks, which controls overlap and how much evidence reuses? (3) For a given framework +…

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 16 other files, including scripts, reference files and assets (for example `assets/company_profile_template.json`, `assets/control_library_template.json` and `assets/mock_audit_library.json`).

It sits in Legal & Compliance, covering SOC 2 and security compliance, Healthcare and finance regulation and AI governance. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • Standing up a multi-framework program
  • Planning the annual audit calendar
  • Preparing for certification stage 1

Example prompts

  • “/compliance-os”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Framework Selection
  2. Cross-Framework Control Mapping
  3. Audit Simulation
  4. Evidence Pool

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance Os loads about 3.3k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 223 tokens; SKILL.md has 913 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~223
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 913 words, ~3,264 tokens.

Download SKILL.mdSave it as .claude/skills/compliance-os/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
compliance-os
description
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across multiple frameworks. Four decisions: (1) Given a company profile, which of the 12 supported frameworks apply (ISO 27001/13485/42001/14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR, NIST CSF 2.0, NIS2, HIPAA)? (2) Across selected frameworks, which controls overlap and how much evidence reuses? (3) For a given framework + scope, what does a realistic mock audit produce — drawing from the 205-scenario library? (4) Across selected frameworks, what's the unified evidence checklist with reuse map? Use when standing up a multi-framework program, planning the annual audit calendar, or preparing for certification stage 1. Does NOT replace per-framework skills (it orchestrates them).
license
MIT
metadata.version
1.0.0
metadata.author
Alireza Rezvani
metadata.category
compliance-os
metadata.domain
multi-framework-compliance-orchestration
metadata.updated
2026-05-13
metadata.python-tools
framework_selector.py, cross_framework_mapper.py, audit_simulator.py, evidence_pool_generator.py
metadata.frameworks
iso-27001, iso-13485, iso-42001, iso-14971, eu-ai-act, eu-mdr-745, gdpr, soc-2, fda-qsr, nist-csf, nis2, hipaa

Compliance OS — Meta-Orchestrator

Multi-framework compliance program orchestration. Four decisions, no per-framework deep-dive:

  1. Which frameworks apply to this company? — framework_selector.py ranks the 12 supported frameworks against a company profile (industry, geography, AI use, medical, financial, headcount, customers, healthcare-PHI, NIS2 essential/important entity, US gov contractor) and returns applicable ones with dependency graph
  2. How much do selected frameworks overlap? — cross_framework_mapper.py computes control-level overlap with confidence rating; outputs unified control matrix + evidence-reuse opportunities
  3. What does a mock audit produce? — audit_simulator.py generates 8–15 finding scenarios with severity distribution matching IIA expectations + interview questions per control
  4. What's the unified evidence checklist? — evidence_pool_generator.py consolidates evidence across enabled frameworks; outputs which artefact satisfies which controls across which frameworks

This skill is NOT a per-framework deep-dive. The per-framework skills (ra-qm-team/skills/iso42001-specialist/, compliance-team-eu-ai-act/, ra-qm-team/skills/gdpr-dsgvo-expert/, etc.) do the operational work. Compliance OS orchestrates them.

This skill is NOT a substitute for binding legal advice. Cross-framework mappings reflect published guidance (ISO standards, regulations, EDPB/Commission guidance, IIA / AICPA professional standards). Novel cross-walks should be reviewed with counsel.

Keywords

compliance orchestration, multi-framework compliance, compliance OS, cross-framework mapping, control overlap, evidence pool, evidence reuse, audit simulation, mock audit, internal audit programme, GRC, governance risk compliance, framework selector, compliance program, integrated compliance, ISO 19011, IIA IPPF, AICPA AT-C, NIST CSF profile, multi-cert program, SOC 2 + ISO 27001, ISO 27001 + ISO 42001, ISO 13485 + MDR 745, AI Act + ISO 42001, GDPR + ISO 27001, compliance officer, compliance team workflow, certification readiness

Quick Start

bash
# Decision A: Which frameworks apply for the company?
python scripts/framework_selector.py                          # embedded mid-stage AI SaaS sample
python scripts/framework_selector.py path/to/profile.json

# Decision B: Compute cross-framework overlap
python scripts/cross_framework_mapper.py                      # embedded ISO 27001 + SOC 2 sample
python scripts/cross_framework_mapper.py path/to/control_libs.json

# Decision C: Simulate an audit
python scripts/audit_simulator.py                             # embedded ISO 27001 sample
python scripts/audit_simulator.py path/to/audit_scope.json

# Decision D: Consolidate evidence checklist across frameworks
python scripts/evidence_pool_generator.py                     # embedded 3-framework sample
python scripts/evidence_pool_generator.py path/to/program.json

Key Questions (ask these first)

  • Have you named every applicable framework? Forgetting one means rebuilding the audit program later. Run framework_selector.py with your profile.
  • What's the most certificate / regulation your company already operates? That's your reuse anchor. Map every new framework against it.
  • What's the audit calendar? A multi-framework program means surveillance audits stacked through the year — plan auditor independence + capacity.
  • Where is evidence stored? Multi-framework programs collapse when evidence lives in one team's drive without an index. Run evidence_pool_generator.py to surface the reuse opportunities.
  • What's the management-review cadence across frameworks? Each framework wants its own management review, but a single integrated review (per ISO Annex SL) typically satisfies all of them with one calendar slot.
  • Who owns the meta-program? If no single accountable role, the program fragments.

Core Responsibilities

1. Framework Selection

The framework: company-profile JSON in → applicable-framework list out with dependency graph.

Deterministic logic:

  • Medical device → ISO 13485 + ISO 14971 + (EU MDR 745 if EU market) + (FDA QSR if US market)
  • Customer-facing AI → ISO 42001 + EU AI Act (if EU users) + GDPR (if personal data)
  • B2B SaaS with enterprise customers → SOC 2 + ISO 27001 (often required for procurement)
  • EU customers + personal data → GDPR mandatory
  • Highly regulated industry (financial, health) → additional sectoral overlays

Run framework_selector.py to apply the decision rules.

2. Cross-Framework Control Mapping

The framework: for each selected framework, parse its control library; compute overlap with other selected frameworks.

Per merged-control output:

  • Mapping confidence (HIGH / MEDIUM / LOW)
  • Evidence-reuse opportunity (single artefact satisfies N controls)
  • Per-framework citation
  • Implementation guidance reusable across frameworks

Densest known overlap: ISO 27001 Annex A ↔ SOC 2 Trust Services Criteria — historically ~75% control coverage shared. Adding ISO 42001 brings AI-specific controls; adding GDPR brings privacy-specific.

Run cross_framework_mapper.py with framework control libraries.

Show full SKILL.md (389 more words)Show less
3. Audit Simulation

The framework: generate a realistic mock internal audit per ISO 19011 + IIA IPPF standards.

Per audit output:

  • 8–15 finding scenarios per ISO 19011 typical depth
  • Severity distribution: ≥ 40% observations/OFI, ≤ 15% critical/major (IIA expectation for healthy programs)
  • Interview questions per scoped control (3–5 questions per control)
  • Document-review request list
  • Walk-through requests where applicable

Run audit_simulator.py with framework + scope.

4. Evidence Pool

The framework: consolidate evidence requirements across enabled frameworks; identify reuse opportunities.

Output:

  • Evidence artefact list (e.g., access-review log, supplier risk register, incident log)
  • Per artefact: list of (framework, control) tuples it satisfies
  • Reuse-leverage score (artefact A satisfies N controls across M frameworks)
  • Acquisition cost estimate (effort to produce + maintain)

Run evidence_pool_generator.py with program config.

Workflows

Workflow 1: Program Bootstrap (multi-framework, 4–8 weeks)

Goal: stand up a compliance program covering 2–4 frameworks simultaneously.

bash
# 1. Run framework selector with company profile
python scripts/framework_selector.py profile.json
# 2. For each applicable framework, identify the per-framework skill and run its gap analysis
# 3. Run cross-framework mapper to identify reuse opportunities
python scripts/cross_framework_mapper.py control_libs.json
# 4. Run evidence pool generator to consolidate
python scripts/evidence_pool_generator.py program.json
# 5. Cross-check with cs-compliance-officer agent
# 6. Output: prioritized program backlog with owners + dates
Workflow 2: Annual Audit Calendar (yearly)

Goal: plan internal audit cycles covering all applicable frameworks.

bash
# 1. Refresh framework selector if profile changed
python scripts/framework_selector.py profile.json
# 2. For each framework, run its internal-audit-plan tool
#    (e.g., aims_audit_scheduler.py for ISO 42001; isms_audit_scheduler.py for ISO 27001)
# 3. Coordinate the audit calendar across frameworks (auditor independence + capacity)
# 4. Run audit simulator for each framework to prep auditors
python scripts/audit_simulator.py scope.json
# 5. Output: integrated audit calendar with owners + auditor assignments
Workflow 3: Pre-Certification Readiness (per new framework, 6–12 weeks)

Goal: prepare for an external certification audit.

bash
# 1. Run gap analysis for the new framework
#    (ISO 42001: aims_gap_analyzer.py; ISO 27001: compliance_checker.py; SOC 2: gap_analyzer.py)
# 2. Run cross-framework mapper against already-certified frameworks
python scripts/cross_framework_mapper.py control_libs.json
# 3. Reuse evidence for HIGH-confidence mappings; build new for MEDIUM/LOW
# 4. Run audit simulator to dry-run the certification audit
python scripts/audit_simulator.py scope.json
# 5. Close remaining gaps before external auditor stage 1
Workflow 4: Evidence Pool Consolidation (quarterly)

Goal: keep the unified evidence pool fresh + reusable.

bash
# 1. Refresh evidence pool generator
python scripts/evidence_pool_generator.py program.json
# 2. Identify HIGH-reuse-leverage artefacts (1 evidence -> 5+ controls)
# 3. Confirm evidence freshness (within retention requirement per framework)
# 4. Audit the evidence pool itself (no orphan controls, no stale evidence)

Output Standards

**Bottom Line:** [one sentence — what's the multi-framework picture + biggest reuse opportunity]
**The Decision:** [one of: framework-set | overlap-map | audit-plan | evidence-consolidation]
**The Evidence:** [framework names + control IDs from the tool, not adjectives]
**How to Act:** [3 concrete next steps with owners + dates]
**Your Decision:** [the call only the compliance officer can make — which frameworks to pursue, audit cycle priority, evidence-reuse policy]

Adjacent Skills

  • ra-qm-team/skills/iso42001-specialist/ — ISO 42001 deep-dive (paired with compliance-team-iso42001 plugin)
  • ra-qm-team/skills/eu-ai-act-specialist/ — EU AI Act deep-dive (paired with compliance-team-eu-ai-act plugin)
  • ra-qm-team/skills/information-security-manager-iso27001/ — ISO 27001 ISMS deep-dive
  • ra-qm-team/skills/quality-manager-qms-iso13485/ — ISO 13485 QMS deep-dive
  • ra-qm-team/skills/gdpr-dsgvo-expert/ — GDPR deep-dive
  • ra-qm-team/skills/soc2-compliance/ — SOC 2 deep-dive
  • ra-qm-team/skills/fda-consultant-specialist/ — FDA QSR deep-dive
  • ra-qm-team/skills/mdr-745-specialist/ — EU MDR 745 deep-dive
  • ra-qm-team/skills/risk-management-specialist/ — ISO 14971 deep-dive
  • c-level-advisor/chief-ai-officer-advisor/ — Executive AI risk decisions (build-vs-buy, model selection)
  • c-level-advisor/skills/general-counsel-advisor/ — Legal review for novel cases

References

Phase 3 Asset: Mock Audit Scenario Library

assets/mock_audit_library.json — 205 pre-built finding scenarios spanning 12 frameworks + 26 themes + 4 severity levels (34 critical, 88 major, 54 minor, 29 observation). Each scenario tags applicable frameworks; cross-reference scripts/cross_framework_mapper.py merged-controls catalogue to resolve framework-specific control IDs. Use as input to enrich audit_simulator.py mock audits, as a training resource for new internal auditors, or as the seed for finding-pattern detection across multi-framework programmes.


Version: 1.2.0 Status: Production Ready

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (scripts, references, assets) in compliance-os/skills/compliance-os of alirezarezvani/claude-skills.

  • SKILL.md
  • assets/company_profile_template.json
  • assets/control_library_template.json
  • assets/mock_audit_library.json
  • references/audit_simulation_methodology.md
  • references/compliance_os_pattern.md
  • references/cross_framework_overlap.md
  • references/evidence_artifact_reuse_index.md
  • references/evidence_management.md
  • references/multi_framework_audit_playbook.md
  • scripts/audit_simulator.py
  • scripts/cross_framework_mapper.py
  • scripts/evidence_pool_generator.py
  • scripts/framework_selector.py

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Compliance Os next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compliance Os compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compliance Os this skillalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Implementing Complianceancoleman/ai-design-components525—~4kAutomated safety check: PassMIT
Complianceericrisco/rsc-harness180—~2.4kAutomated safety check: PassMIT
Compliance Checklistmohitagw15856/pm-claude-skills1.4k—~1.2kAutomated safety check: PassMIT
Compliance Checklist Generationseb1n/awesome-ai-agent-skills206—~2.5kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance

    ericrisco/rsc-harness

    A skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or…

    180 GitHub stars~2.4k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Compliance Checklist

    mohitagw15856/pm-claude-skills

    Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

    1.4k GitHub stars~1.2k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Compliance Checklist Generation

    seb1n/awesome-ai-agent-skills

    Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Questions about Compliance Os

What does Compliance Os do?

Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…. Compliance Os is an agent skill from alirezarezvani/claude-skills. Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across multiple frameworks.

When should I use Compliance Os?

Compliance Os fits situations like: standing up a multi-framework program; planning the annual audit calendar; preparing for certification stage 1.

How do I install Compliance Os in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill compliance-os -a claude-code`. Or copy the skill folder (compliance-os/skills/compliance-os in alirezarezvani/claude-skills) into .claude/skills/compliance-os in your project. Claude Code loads it when a task matches its description.

How do I install Compliance Os in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill compliance-os -a codex`. Or copy the skill folder (compliance-os/skills/compliance-os in alirezarezvani/claude-skills) into .agents/skills/compliance-os in your project. Codex loads it when a task matches its description.

Can I use Compliance Os in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill compliance-os -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-os, .gemini/skills/compliance-os, .github/skills/compliance-os and .opencode/skills/compliance-os in your project.

What does Compliance Os need to run?

Going by SKILL.md and its folder, Compliance Os needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Compliance Os access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Compliance Os safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Compliance Os use?

Compliance Os is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compliance Os use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.

What are the alternatives to Compliance Os?

Skills that share tags, products or a category with Compliance Os: Implementing Compliance (ancoleman/ai-design-components, 525 stars), Compliance (ericrisco/rsc-harness, 180 stars), Compliance Checklist (mohitagw15856/pm-claude-skills, 1.4k stars) and Compliance Checklist Generation (seb1n/awesome-ai-agent-skills, 206 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compliance Os?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,938 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.