Agent skill

Implementing Compliance

by ancoleman in ancoleman/ai-design-components

Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

MITAuto-check passedLegal & Compliance

Install Implementing Compliance

skills CLI
$ npx skills add ancoleman/ai-design-components --skill implementing-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ancoleman/ai-design-components implementing-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-compliance .claude/skills/implementing-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-compliance
GitHub stars
526
Token cost
~4k tokens
SKILL.md length
1,223 words
Files
20 (incl. references)
Skills in repo
75
Repo updated
First seen
Licence
MIT

At a glance

Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

  • Works in 5 steps: Encryption (ENC-001, ENC-002): AES-256… → Access Control (MFA-001, RBAC-001): MFA,… → Audit Logging (LOG-001): Centralized,… → …
  • Building systems requiring regulatory compliance
  • SKILL.md covers Purpose, When to Use, Framework Selection and Universal Control Implementation, plus 10 more sections
  • Runs Python scripts from its folder; calls terraform, git and aws

What it does

Implementing Compliance is an agent skill from ancoleman/ai-design-components. Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection. Use when building systems requiring regulatory compliance, implementing security controls across multiple frameworks, or automating audit preparation.

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including reference files (for example `examples/evidence-collection/evidence_collector.py`, `examples/evidence-collection/report_generator.py` and `examples/mfa-implementation.py`).

It sits in Legal & Compliance, covering Healthcare and finance regulation, SOC 2 and security compliance and Privacy and GDPR. The repository describes itself as: Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude. The licence is MIT.

When your agent uses it

  • Building systems requiring regulatory compliance
  • Implementing security controls across multiple frameworks
  • Automating audit preparation

Example prompts

  • “/implementing-compliance”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Encryption (ENC-001, ENC-002): AES-256 at rest, TLS 1.3 in transit
  2. Access Control (MFA-001, RBAC-001): MFA, RBAC, least privilege
  3. Audit Logging (LOG-001): Centralized, immutable, 7-year retention
  4. Monitoring (MON-001): SIEM, intrusion detection, alerting
  5. Incident Response (IR-001): Detection, escalation, breach notification

What it can do on your machine

Read from SKILL.md and the folder at commit 76551b7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • terraform
    • git
    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Compliance loads about 4k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 85 tokens; SKILL.md has 1,223 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ancoleman/ai-design-components at commit 76551b7, republished under its MIT licence (© ancoleman). 1,223 words, ~4,040 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-compliance/SKILL.md (or your agent's skills folder). This skill also uses 19 other files; get the full folder from GitHub.
name
implementing-compliance
description
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection. Use when building systems requiring regulatory compliance, implementing security controls across multiple frameworks, or automating audit preparation.

Compliance Frameworks

Implement continuous compliance with major regulatory frameworks through unified control mapping, policy-as-code enforcement, and automated evidence collection.

Purpose

Modern compliance is a continuous engineering discipline requiring technical implementation of security controls. This skill provides patterns for SOC 2 Type II, HIPAA, PCI-DSS 4.0, and GDPR compliance using infrastructure-as-code, policy automation, and evidence collection. Focus on unified controls that satisfy multiple frameworks simultaneously to reduce implementation effort by 60-80%.

When to Use

Invoke when:

  • Building SaaS products requiring SOC 2 Type II for enterprise sales
  • Handling healthcare data (PHI) requiring HIPAA compliance
  • Processing payment cards requiring PCI-DSS validation
  • Serving EU residents and processing personal data under GDPR
  • Implementing security controls that satisfy multiple compliance frameworks
  • Automating compliance evidence collection and audit preparation
  • Enforcing compliance policies in CI/CD pipelines

Framework Selection

Tier 1: Trust & Security Certifications

SOC 2 Type II

  • Audience: SaaS vendors, cloud service providers
  • When required: Enterprise B2B sales, handling customer data
  • Timeline: 6-12 month observation period
  • 2025 updates: Monthly control testing, AI governance, 72-hour breach disclosure

ISO 27001

  • Audience: Global enterprises
  • When required: International business, government contracts
  • Timeline: 3-6 month certification, annual surveillance
Tier 2: Industry-Specific Regulations

HIPAA (Healthcare)

  • Audience: Healthcare providers, health tech handling PHI
  • When required: Processing Protected Health Information
  • 2025 focus: Zero Trust Architecture, EDR/XDR, AI assessments

PCI-DSS 4.0 (Payment Card Industry)

  • Audience: Merchants, payment processors
  • When required: Processing, storing, transmitting cardholder data
  • Effective: April 1, 2025 (mandatory)
  • Key changes: Client-side security, 12-char passwords, enhanced MFA
Tier 3: Privacy Regulations

GDPR (EU Privacy)

  • Audience: Organizations processing EU residents' data
  • When required: EU customers/users (extraterritorial)
  • 2025 updates: 48-hour breach reporting, 6% revenue fines, AI transparency

CCPA/CPRA (California Privacy)

  • Audience: Businesses serving California residents
  • When required: Revenue >$25M, or 100K+ CA residents, or 50%+ revenue from data sales

For detailed framework requirements, see references/soc2-controls.md, references/hipaa-safeguards.md, references/pci-dss-requirements.md, and references/gdpr-articles.md.

Universal Control Implementation

Unified Control Strategy

Implement controls once, map to multiple frameworks. Reduces effort by 60-80%.

Implementation Priority:

  1. Encryption (ENC-001, ENC-002): AES-256 at rest, TLS 1.3 in transit
  2. Access Control (MFA-001, RBAC-001): MFA, RBAC, least privilege
  3. Audit Logging (LOG-001): Centralized, immutable, 7-year retention
  4. Monitoring (MON-001): SIEM, intrusion detection, alerting
  5. Incident Response (IR-001): Detection, escalation, breach notification
Control Categories

Identity & Access:

  • Multi-factor authentication for privileged access
  • Role-based access control with least privilege
  • Quarterly access reviews
  • Password policy: 12+ characters, complexity

Data Protection:

  • Encryption: AES-256 (rest), TLS 1.3 (transit)
  • Data classification and tagging
  • Retention policies aligned with regulations
  • Data minimization

Logging & Monitoring:

  • Centralized audit logging (all auth and data access)
  • 7-year retention (satisfies all frameworks)
  • Immutable storage (S3 Object Lock)
  • Real-time alerting

Network Security:

  • Network segmentation and VPC isolation
  • Firewalls with deny-by-default
  • Intrusion detection/prevention
  • Regular vulnerability scanning

Incident Response:

  • Documented incident response plan
  • Automated detection and alerting
  • Breach notification: HIPAA 60d, GDPR 48h, SOC 2 72h, PCI-DSS immediate

Business Continuity:

  • Automated backups with defined RPO/RTO
  • Multi-region disaster recovery
  • Regular failover testing

For complete control implementations, see references/control-mapping-matrix.md.

Compliance as Code

Policy Enforcement with OPA

Enforce compliance policies in CI/CD before infrastructure deployment.

Architecture:

Git Push → Terraform Plan → JSON → OPA Evaluation
                                    ├─► Pass → Deploy
                                    └─► Fail → Block

Example: Encryption Policy

Enforce encryption requirements (SOC 2 CC6.1, HIPAA §164.312(a)(2)(iv), PCI-DSS Req 3.4):

See examples/opa-policies/encryption.rego for complete implementation.

CI/CD Integration:

bash
terraform plan -out=tfplan.binary
terraform show -json tfplan.binary > tfplan.json
opa eval --data policies/ --input tfplan.json 'data.compliance.main.deny'

For complete CI/CD patterns, see references/cicd-integration.md.

Static Analysis with Checkov

Scan IaC with built-in compliance framework support:

bash
checkov -d ./terraform \
  --check SOC2 --check HIPAA --check PCI --check GDPR \
  --output cli --output json

Create custom policies for organization-specific requirements. See examples/checkov-policies/ for examples.

Automated Testing

Integrate compliance validation into test suites:

python
def test_s3_encrypted(terraform_plan):
    """SOC2:CC6.1, HIPAA:164.312(a)(2)(iv)"""
    buckets = get_resources(terraform_plan, "aws_s3_bucket")
    encrypted = get_encryption_configs(terraform_plan)
    assert all_buckets_encrypted(buckets, encrypted)

def test_opa_policies():
    result = subprocess.run(["opa", "eval", "--data", "policies/",
        "--input", "tfplan.json", "data.compliance.main.deny"])
    assert not json.loads(result.stdout)

For complete test patterns, see references/compliance-testing.md.

Technical Control Implementations

Encryption at Rest

Standards: AES-256, managed KMS, automatic rotation

AWS Example:

hcl
resource "aws_kms_key" "data" {
  enable_key_rotation = true
  tags = { Compliance = "ENC-001" }
}

resource "aws_s3_bucket_server_side_encryption_configuration" "data" {
  bucket = aws_s3_bucket.data.id
  rule {
    apply_server_side_encryption_by_default {
      sse_algorithm     = "aws:kms"
      kms_master_key_id = aws_kms_key.data.arn
    }
  }
}

resource "aws_db_instance" "main" {
  storage_encrypted = true
  kms_key_id       = aws_kms_key.data.arn
}

For complete encryption implementations including Azure and GCP, see references/encryption-implementations.md.

Encryption in Transit

Standards: TLS 1.3 (TLS 1.2 minimum), strong ciphers, HSTS

ALB Example:

hcl
resource "aws_lb_listener" "https" {
  port       = 443
  protocol   = "HTTPS"
  ssl_policy = "ELBSecurityPolicy-TLS13-1-2-2021-06"
}
Multi-Factor Authentication

Standards: TOTP, hardware tokens, biometric for privileged access

AWS IAM Enforcement:

hcl
resource "aws_iam_policy" "require_mfa" {
  policy = jsonencode({
    Statement = [{
      Effect = "Deny"
      NotAction = ["iam:CreateVirtualMFADevice", "iam:EnableMFADevice"]
      Resource = "*"
      Condition = {
        BoolIfExists = { "aws:MultiFactorAuthPresent" = "false" }
      }
    }]
  })
}

For application-level MFA (TOTP), see examples/mfa-implementation.py.

Role-Based Access Control

Standards: Least privilege, job function-based roles, quarterly reviews

Kubernetes Example:

yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: developer
  namespace: development
rules:
- apiGroups: ["", "apps"]
  resources: ["pods", "deployments", "services"]
  verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: [""]
  resources: ["secrets"]
  verbs: ["get", "list"]  # Read-only

For complete RBAC patterns including AWS IAM and OPA policies, see references/access-control-patterns.md.

Audit Logging

Standards: Structured JSON, 7-year retention, immutable storage

Required Events: Authentication, authorization, data access, administrative actions, security events

Python Example:

python
class AuditLogger:
    def log_event(self, event_type, user_id, resource_type,
                  resource_id, action, result, ip_address):
        audit_event = {
            "timestamp": datetime.utcnow().isoformat() + "Z",
            "event_type": event_type.value,
            "user_id": user_id,
            "action": action,
            "result": result,
            "resource": {"type": resource_type, "id": resource_id},
            "source": {"ip": ip_address}
        }
        self.logger.info(json.dumps(audit_event))

Log Retention:

hcl
resource "aws_cloudwatch_log_group" "audit" {
  retention_in_days = 2555  # 7 years
  kms_key_id        = aws_kms_key.logs.arn
}

resource "aws_s3_bucket_object_lock_configuration" "audit" {
  bucket = aws_s3_bucket.audit_logs.id
  rule {
    default_retention { mode = "COMPLIANCE"; years = 7 }
  }
}

For complete audit logging patterns including HIPAA PHI access logging, see references/audit-logging-patterns.md.

Evidence Collection Automation

Continuous Monitoring

Automate evidence collection for continuous compliance validation.

Architecture:

AWS Config → EventBridge → Lambda → S3 (Evidence)
                                   → DynamoDB (Status)

Evidence Collection:

python
class EvidenceCollector:
    def collect_encryption_evidence(self):
        evidence = {
            "control_id": "ENC-001",
            "frameworks": ["SOC2-CC6.1", "HIPAA-164.312(a)(2)(iv)"],
            "timestamp": datetime.utcnow().isoformat(),
            "status": "PASS",
            "findings": []
        }
        # Check S3, RDS, EBS encryption status
        # Document findings
        return evidence

For complete evidence collector, see examples/evidence-collection/evidence_collector.py.

Audit Report Generation

Generate compliance reports automatically:

python
class AuditReportGenerator:
    def generate_soc2_report(self, start_date, end_date):
        controls = self.get_control_status("SOC2")
        return {
            "framework": "SOC 2 Type II",
            "compliance_score": self.calculate_score(controls),
            "trust_services_criteria": {...},
            "controls": self.format_controls(controls)
        }

For complete report generator, see examples/evidence-collection/report_generator.py.

Show full SKILL.md (511 more words)Show less

Control Mapping Matrix

Unified control mapping across frameworks:

ControlSOC 2HIPAAPCI-DSSGDPRISO 27001
MFACC6.1§164.312(d)Req 8.3Art 32A.9.4.2
Encryption at RestCC6.1§164.312(a)(2)(iv)Req 3.4Art 32A.10.1.1
Encryption in TransitCC6.1§164.312(e)(1)Req 4.1Art 32A.13.1.1
Audit LoggingCC7.2§164.312(b)Req 10.2Art 30A.12.4.1
Access ReviewsCC6.1§164.308(a)(3)(ii)(C)Req 8.2.4Art 32A.9.2.5
Vulnerability ScanningCC7.1§164.308(a)(8)Req 11.2Art 32A.12.6.1
Incident ResponseCC7.3§164.308(a)(6)Req 12.10Art 33A.16.1.1

Strategy: Implement once with proper tagging, map to all applicable frameworks.

For complete control mapping with 45+ controls, see references/control-mapping-matrix.md.

Breach Notification Requirements

Framework-Specific Timelines:

  • HIPAA: 60 days to HHS and affected individuals
  • GDPR: 48 hours to supervisory authority (2025 update)
  • SOC 2: 72 hours to affected customers
  • PCI-DSS: Immediate to payment brands

Required Elements:

  • Description of incident and data involved
  • Estimated number of affected individuals
  • Steps taken to mitigate harm
  • Contact information for questions
  • Remediation actions and timeline

For incident response templates, see references/incident-response-templates.md.

Vendor Management

Business Associate Agreements (HIPAA):

  • Required for all vendors handling PHI
  • Specify permitted uses and disclosures
  • Require appropriate safeguards
  • Annual review and renewal

Data Processing Agreements (GDPR):

  • Required for all vendors processing personal data
  • Process only on controller instructions
  • Implement appropriate technical measures
  • Sub-processor approval required

Assessment Process:

  1. Risk classification by data access level
  2. Security questionnaire evaluation
  3. BAA/DPA execution
  4. SOC 2 report collection (≤90 days old)
  5. Annual re-assessment

For vendor management templates, see references/vendor-management.md.

Tools & Libraries

Policy as Code:

  • Open Policy Agent (OPA): General-purpose policy engine
  • Checkov: IaC security scanning with compliance frameworks
  • tfsec: Terraform security scanner
  • Trivy: Container and IaC scanner

Compliance Automation:

  • AWS Config: AWS resource compliance monitoring
  • Cloud Custodian: Multi-cloud compliance automation
  • Drata/Vanta/Secureframe: Continuous compliance platforms

For tool selection guidance, see references/tool-recommendations.md.

Integration with Other Skills

Related Skills:

  • security-hardening: Technical security control implementation
  • secret-management: Secrets handling per HIPAA/PCI-DSS
  • infrastructure-as-code: IaC implementing compliance controls
  • kubernetes-operations: K8s RBAC, network policies
  • building-ci-pipelines: Policy enforcement in CI/CD
  • siem-logging: Audit logging and monitoring
  • incident-management: Incident response procedures

Quick Reference

Implementation Checklist:

  • Identify applicable frameworks
  • Implement encryption (AES-256, TLS 1.3)
  • Configure MFA for privileged access
  • Implement RBAC with least privilege
  • Set up audit logging (7-year retention)
  • Configure security monitoring/alerting
  • Create incident response plan
  • Execute vendor agreements (BAAs, DPAs)
  • Implement policy-as-code (OPA, Checkov)
  • Automate evidence collection
  • Conduct quarterly access reviews
  • Perform annual risk assessments

Common Mistakes:

  • Treating compliance as one-time project vs continuous process
  • Implementing per-framework vs unified controls
  • Manual evidence collection vs automation
  • Insufficient log retention (<7 years)
  • Missing MFA enforcement
  • Not encrypting backups/logs
  • Inadequate vendor due diligence

References

Framework Details:

  • references/soc2-controls.md - SOC 2 TSC control catalog
  • references/hipaa-safeguards.md - HIPAA safeguards
  • references/pci-dss-requirements.md - PCI-DSS 4.0 requirements
  • references/gdpr-articles.md - GDPR key articles

Implementation Patterns:

  • references/control-mapping-matrix.md - Unified control mapping
  • references/encryption-implementations.md - Encryption patterns
  • references/access-control-patterns.md - MFA, RBAC implementations
  • references/audit-logging-patterns.md - Logging requirements
  • references/incident-response-templates.md - IR procedures

Automation:

  • references/cicd-integration.md - OPA/Checkov CI/CD integration
  • references/compliance-testing.md - Automated test patterns
  • references/vendor-management.md - Vendor assessment templates
  • references/tool-recommendations.md - Tool selection guide

Code Examples:

  • examples/opa-policies/ - OPA policy examples
  • examples/terraform/ - Terraform control implementations
  • examples/evidence-collection/ - Evidence automation
  • examples/mfa-implementation.py - TOTP MFA implementation

Consult qualified legal counsel and auditors for legal interpretation and audit preparation.

© ancoleman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 19 other files (references) in skills/implementing-compliance of ancoleman/ai-design-components.

  • SKILL.md
  • examples/evidence-collection/evidence_collector.py
  • examples/evidence-collection/report_generator.py
  • examples/mfa-implementation.py
  • examples/opa-policies/access_control.rego
  • examples/opa-policies/encryption.rego
  • outputs.yaml
  • references/access-control-patterns.md
  • references/audit-logging-patterns.md
  • references/cicd-integration.md
  • references/compliance-testing.md
  • references/control-mapping-matrix.md
  • references/encryption-implementations.md
  • references/gdpr-articles.md
  • references/hipaa-safeguards.md
  • references/incident-response-templates.md
  • references/pci-dss-requirements.md
  • … and 3 more

Open the folder on GitHubat commit 76551b7

Compare with similar skills

Implementing Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Compliance this skillancoleman/ai-design-components526—~4kAutomated safety check: PassMIT
Compliance Checklistmohitagw15856/pm-claude-skills1.4k—~1.2kAutomated safety check: PassMIT
Compliance Checklist Generationseb1n/awesome-ai-agent-skills206—~2.5kAutomated safety check: PassMIT
Policy OpaAgentSecOps/SecOpsAgentKit2191 repos~3.5kAutomated safety check: PassCustom licence
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Security Compliance Compliance Checkaiskillstore/marketplace4307 repos~600Automated safety check: PassNone

Similar skills

  • Compliance Checklist

    mohitagw15856/pm-claude-skills

    Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Compliance Checklist Generation

    seb1n/awesome-ai-agent-skills

    Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities.

    206 GitHub stars~2.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    219 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Security Compliance Compliance Check

    aiskillstore/marketplace

    You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards.

    430 GitHub starsUsed in 7 repos~600 tokens
    Legal & ComplianceAuto-check passed
  • Compliance Testing

    proffesor-for-testing/agentic-qe

    Regulatory compliance testing for GDPR, CCPA, HIPAA, SOC2, PCI-DSS and industry-specific regulations.

    494 GitHub stars~1.8k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed

More from ancoleman/ai-design-components

All 75 skills in this repo
  • Building AI Chat

    ancoleman/ai-design-components

    Builds AI chat interfaces and conversational UI with streaming responses, context management, and multi-modal support.

    526 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check passed
  • Building Forms

    ancoleman/ai-design-components

    Builds form components and data collection interfaces including contact forms, registration flows, checkout processes, surveys, and settings pages.

    526 GitHub stars~3.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Building Tables

    ancoleman/ai-design-components

    Builds tables and data grids for displaying tabular information, from simple HTML tables to complex enterprise data grids.

    526 GitHub stars~1.8k tokensUpdated 10 mo ago
    Auto-check passed
  • Creating Dashboards

    ancoleman/ai-design-components

    Creates comprehensive dashboard and analytics interfaces that combine data visualization, KPI cards, real-time updates, and interactive layouts.

    526 GitHub stars~3.5k tokensUpdated 10 mo ago
    Auto-check passed
  • Designing Layouts

    ancoleman/ai-design-components

    Designs layout systems and responsive interfaces including grid systems, flexbox patterns, sidebar layouts, and responsive breakpoints.

    526 GitHub stars~1.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Displaying Timelines

    ancoleman/ai-design-components

    Displays chronological events and activity through timelines, activity feeds, Gantt charts, and calendar interfaces.

    526 GitHub stars~2.7k tokensUpdated 10 mo ago
    Auto-check passed

Questions about Implementing Compliance

What does Implementing Compliance do?

Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection. Implementing Compliance is an agent skill from ancoleman/ai-design-components. Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

When should I use Implementing Compliance?

Implementing Compliance fits situations like: building systems requiring regulatory compliance; implementing security controls across multiple frameworks; automating audit preparation.

How do I install Implementing Compliance in Claude Code?

Run `npx skills add ancoleman/ai-design-components --skill implementing-compliance -a claude-code`. Or copy the skill folder (skills/implementing-compliance in ancoleman/ai-design-components) into .claude/skills/implementing-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Compliance in Codex?

Run `npx skills add ancoleman/ai-design-components --skill implementing-compliance -a codex`. Or copy the skill folder (skills/implementing-compliance in ancoleman/ai-design-components) into .agents/skills/implementing-compliance in your project. Codex loads it when a task matches its description.

Can I use Implementing Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ancoleman/ai-design-components --skill implementing-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-compliance, .gemini/skills/implementing-compliance, .github/skills/implementing-compliance and .opencode/skills/implementing-compliance in your project.

What does Implementing Compliance need to run?

Going by SKILL.md and its folder, Implementing Compliance needs Python for the scripts in its folder and the command-line tools its instructions call (terraform, git and aws). Our summary lists: Python 3.

Does Implementing Compliance access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Implementing Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Implementing Compliance use?

Implementing Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Compliance use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Compliance?

Skills that share tags, products or a category with Implementing Compliance: Compliance Checklist (mohitagw15856/pm-claude-skills, 1.4k stars), Compliance Checklist Generation (seb1n/awesome-ai-agent-skills, 206 stars), Policy Opa (AgentSecOps/SecOpsAgentKit, 219 stars) and Compliance Os (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Compliance?

ancoleman (a GitHub user) maintains it in ancoleman/ai-design-components, which has 526 GitHub stars. The repository holds 75 skills in this directory. The repository was last updated on December 11, 2025.

Source: ancoleman/ai-design-components on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.