Iso42001
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.
$ npx skills add anthropics/claude-for-legal --skill ai-inventory -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install anthropics/claude-for-legal ai-inventory --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance-legal/skills/ai-inventory .claude/skills/ai-inventory && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ai-inventory" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/ai-inventory into .claude/skills/ai-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-inventory", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/ai-inventoryType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add anthropics/claude-for-legal --skill ai-inventory -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install anthropics/claude-for-legal ai-inventory --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ai-governance-legal/skills/ai-inventory .agents/skills/ai-inventory && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ai-inventory" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/ai-inventory into .agents/skills/ai-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-inventory", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/claude-for-legal --skill ai-inventory -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install anthropics/claude-for-legal ai-inventory --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ai-governance-legal/skills/ai-inventory .cursor/skills/ai-inventory && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ai-inventory" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/ai-inventory into .cursor/skills/ai-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-inventory", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/anthropics/claude-for-legal.git --path ai-governance-legal/skills/ai-inventory--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add anthropics/claude-for-legal --skill ai-inventory -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install anthropics/claude-for-legal ai-inventory --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ai-governance-legal/skills/ai-inventory .gemini/skills/ai-inventory && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ai-inventory" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/ai-inventory into .gemini/skills/ai-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-inventory", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install anthropics/claude-for-legal ai-inventoryInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add anthropics/claude-for-legal --skill ai-inventory -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .github/skills && cp -r skills-src/ai-governance-legal/skills/ai-inventory .github/skills/ai-inventory && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ai-inventory" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/ai-inventory into .github/skills/ai-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-inventory", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/claude-for-legal --skill ai-inventory -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install anthropics/claude-for-legal ai-inventory --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ai-governance-legal/skills/ai-inventory .opencode/skills/ai-inventory && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ai-inventory" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/ai-inventory into .opencode/skills/ai-inventory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-inventory", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ai-inventoryMaintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.
The core idea is that role and risk tier belong to the system, not the company: one organization can be provider of one system, deployer of another and importer of a third. The skill keeps those assessments in an ai-systems.yaml file so they can be found later, and it reads a plugin CLAUDE.md config first, sending you to the cold-start interview if that config is missing or still has placeholders.
It dispatches on the argument: list shows a table with ID, name, owner, status, EU nexus, role, tier and next review, plus counts by tier and systems due for review within 30 days; add runs an interview; edit changes one field after confirmation; classify walks through role and tier and records the basis for each; show prints a full record. After any write it offers to discuss obligations in conversation and flags where the AI Act article mapping needs a lawyer's verification, since it does not derive obligations from a table.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
EU AI Act System Inventory loads about 2.8k tokens when it runs. Until then it costs about 115 tokens; SKILL.md has 1,310 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 1,310 words, ~2,809 tokens.
.claude/skills/ai-inventory/SKILL.md (or your agent's skills folder).The user wants to manage their AI system inventory under the EU AI Act. The core idea the skill exists to enforce: role and tier are per-system, not per-company. A single organization can be a provider of System A, a deployer of System B, and an importer of System C. Each combination triggers a different set of obligations under the AI Act. The inventory exists so those assessments are tracked where you can find them — the obligations themselves are derived in conversation, not from a table.
Read the config. Read
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.
If it doesn't exist or still has [PLACEHOLDER] markers, direct the user
to /ai-governance-legal:cold-start-interview first.
Read the inventory. Inventory lives at
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/ai-systems.yaml.
If it doesn't exist, create it with an empty systems: list when the
first add runs.
Dispatch on the argument:
list → show the inventory table (see List below).add → run the Add flow.edit <id> → show the current record, ask what to change, update one
field, confirm, write.classify <id> → run the Classification walk-through on an
existing record, updating role, tier, role_basis, and tier_basis.show <id> → show the full record.On list, offer the dashboard: "Want the full dashboard? Filter by status / tier / EU nexus / owner. Say the word."
Close every action with a hook into the lawyer's work. After any write, say:
Recorded. When you're ready to walk through obligations for this system, just ask — I'll do it in-conversation and flag where the AI Act article mapping needs your verification. I don't derive obligations from a table because the mapping is complex and changing.
Render as a compact table:
| ID | Name | Owner | Status | EU nexus | Role | Tier | Next review |
|---|---|---|---|---|---|---|---|
| sys-001 | Resume screening | HR / Jamie | in_production | yes | deployer | high_risk | 2026-08-01 |
| sys-002 | Email drafting assistant | IT / Priya | in_production | no | deployer | limited | 2026-12-01 |
Under the table, show counts by tier and a line: "N systems flagged for review within 30 days."
Ask, one field at a time (or accept a paste). The required fields are
name, owner, description, status, eu_nexus. The rest can be
deferred — say so explicitly: "you can come back to classification with
/ai-governance-legal:ai-inventory classify <id>."
planned | in_development | in_production | deprecated.Assign an ID: sys-NNN where NNN is the next integer in the file.
The walk-through produces role, role_basis, tier, tier_basis. Both
bases are tagged [verify against current AI Act text] — not because the
skill is hedging, but because the article mapping is complex and the AI
Act is still phasing in. The lawyer owns verification.
Who does what to this system?
Options, with the distinguishing test:
Dual-role flag. If the user substantially modifies a vendor system
(fine-tunes on their own data, changes the intended purpose, rebrands),
they may become a provider of the modified system even if they started
as a deployer. Call this out when they describe any modification beyond
configuration. [verify against current AI Act text — Article 25, provider obligations and substantial modification]
Write the role. Write role_basis in one sentence.
What does the system do, and does the use case fall into a regulated category?
Check in order:
A. Article 5 prohibited practices. [verify against current AI Act text — Article 5]
Summaries, not definitive text:
If matched → tier is prohibited. Flag the use case as stop and route to
the governance team's prohibited-practice workflow.
B. Annex III high-risk areas. [verify against current AI Act text — Annex III]
Summaries:
If matched → tier is high_risk. Note the Annex III area and subsection.
C. GPAI. [verify against current AI Act text — Article 51 and surrounding]
D. Limited risk. Chatbots interacting with natural persons, deepfakes, emotion recognition and biometric categorization systems outside Article 5 scope — transparency obligations apply.
E. Minimal risk. Everything else.
Write the tier. Write tier_basis in one sentence, citing the article or
Annex entry that matched, tagged [verify against current AI Act text].
Offer three next steps:
/ai-governance-legal:aia-generation to produce a full
impact assessment?"systems:
- id: sys-001
name: "Resume screening tool"
owner: "HR / Jamie"
description: "Filters inbound CVs against job criteria"
status: in_production # planned | in_development | in_production | deprecated
eu_nexus: true # deployed, offered, or affects people in the EU/EEA
role: deployer # provider | deployer | importer | distributor | authorized_rep | product_manufacturer
role_basis: "We license from VendorX and deploy internally [verify against current AI Act text]"
tier: high_risk # prohibited | high_risk | limited | minimal | gpai | gpai_systemic
tier_basis: "Annex III(4)(a) — employment, recruitment selection [verify against current AI Act text]"
obligations_assessed: false
obligations_note: "To assess: as deployer of a high-risk system — human oversight, input data quality, monitoring, record-keeping, informing workers, FRIA if public body/service — see Article 26 [verify against current AI Act text]"
next_review: "2026-08-01"
review_trigger: "on substantial modification or annually"
created: "2026-05-11"
updated: "2026-05-11"The inventory stores role, tier, and the basis for each. It does NOT contain a hardcoded role × tier → obligations table.
When the user asks "what are my obligations for System X?", the skill
does the analysis in conversation, tagged [verify], and routes to
/ai-governance-legal:aia-generation for the formal impact assessment
if needed.
This is deliberate:
[verify] tags stay. They are not hedging — they are the point.
Do not strip them in outputs./ai-inventory classify —
modification can change role./aia-generation for anything that needs
a formal record.© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in ai-governance-legal/skills/ai-inventory of anthropics/claude-for-legal.
Open the folder on GitHubat commit 4a6c651
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.
EU AI Act System Inventory next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| EU AI Act System Inventory this skillanthropics/claude-for-legal | 9.6k | 3 repos | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Eu AI Act Readinessseb1n/awesome-ai-agent-skills | 206 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Caio Reviewalirezarezvani/claude-skills | 28k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Ra Qm Skillsalirezarezvani/claude-skills | 28k | — | ~833 | Automated safety check: Pass | MIT | |
| Legal Risk AssessmentTHUYRan/Legal-Skills-Chinese | 873 | — | ~3.1k | Automated safety check: Pass | None |
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
seb1n/awesome-ai-agent-skills
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…
alirezarezvani/claude-skills
/cs:caio-review <plan — Eval-demanding Chief AI Officer interrogation of any plan that involves AI: model selection, risk classification, cost economics, or AI hiring.
alirezarezvani/claude-skills
Router/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document control, ISO…
THUYRan/Legal-Skills-Chinese
Assess an enterprise’s regulatory penalty risk across four dimensions: licensing/qualifications, compliance with regulatory rules, and historical penalty/credit records.
rlaope/oh-my-hermes
[omh] Business contract, NDA, or policy with legal risk: surface contract and compliance risks, questions, and escalation points before a legal decision or action.
anthropics/claude-for-legal
Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.
anthropics/claude-for-legal
Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.
anthropics/claude-for-legal
Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.
anthropics/claude-for-legal
Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.
anthropics/claude-for-legal
Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.
anthropics/claude-for-legal
Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.
Categories
Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next. The core idea is that role and risk tier belong to the system, not the company: one organization can be provider of one system, deployer of another and importer of a third.md config first, sending you to the cold-start interview if that config is missing or still has placeholders.
EU AI Act System Inventory fits situations like: registering a new AI system and classifying its role and risk tier; reviewing which systems are high-risk or due for review; reclassifying a system after its use changes.
Run `npx skills add anthropics/claude-for-legal --skill ai-inventory -a claude-code`. Or copy the skill folder (ai-governance-legal/skills/ai-inventory in anthropics/claude-for-legal) into .claude/skills/ai-inventory in your project. Claude Code loads it when a task matches its description.
Run `npx skills add anthropics/claude-for-legal --skill ai-inventory -a codex`. Or copy the skill folder (ai-governance-legal/skills/ai-inventory in anthropics/claude-for-legal) into .agents/skills/ai-inventory in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill ai-inventory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-inventory, .gemini/skills/ai-inventory, .github/skills/ai-inventory and .opencode/skills/ai-inventory in your project.
SKILL.md names no scripts, command-line tools or credentials: EU AI Act System Inventory is instructions for the agent only. Our summary lists: The ai-governance-legal plugin config in the claude-for-legal setup; Write access to the ai-systems.yaml inventory file.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
EU AI Act System Inventory is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with EU AI Act System Inventory: Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars), Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars), Caio Review (alirezarezvani/claude-skills, 28k stars) and Ra Qm Skills (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,629 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.
Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.