Official agent skill

Policy Diff

by anthropics in anthropics/claude-for-legal

Diff a specific regulatory change against the indexed policy library.

OfficialApache-2.0Auto-check passed

Install Policy Diff

skills CLI
$ npx skills add anthropics/claude-for-legal --skill policy-diff -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install anthropics/claude-for-legal policy-diff --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/regulatory-legal/skills/policy-diff .claude/skills/policy-diff && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
policy-diff
GitHub stars
9.6k
Used in
1 other repo
Token cost
~3k tokens
SKILL.md length
1,302 words
Files
1
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Diff a specific regulatory change against the indexed policy library.

  • Works in 5 steps: Verify rule status before you diff → Extract the new requirements → Map to policies → …
  • A reg has changed and you need to know which policies it touches and what the gap is
  • SKILL.md covers Matter context, Purpose, Load context and Scope integrity, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Policy Diff is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Diff a specific regulatory change against the indexed policy library. Use when a reg has changed and you need to know which policies it touches and what the gap is, when the user says "diff this reg against our policies", "which policy does this affect", or "gap analysis", or when reg-feed-watcher hands off a material item.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: A suite of plugins for legal workflows. The licence is Apache-2.0.

When your agent uses it

  • A reg has changed and you need to know which policies it touches and what the gap is
  • The user says diff this reg against our policies
  • Which policy does this affect
  • Reg-feed-watcher hands off a material item

Example prompts

  • “diff this reg against our policies”
  • “which policy does this affect”
  • “gap analysis”
  • “/policy-diff”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Verify rule status before you diff
  2. Extract the new requirements
  3. Map to policies
  4. Diff
  5. No-match gaps

What it can do on your machine

Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Policy Diff loads about 3k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 1,302 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 1,302 words, ~2,956 tokens.

Download SKILL.mdSave it as .claude/skills/policy-diff/SKILL.md (or your agent's skills folder).
name
policy-diff
description
Diff a specific regulatory change against the indexed policy library. Use when a reg has changed and you need to know which policies it touches and what the gap is, when the user says "diff this reg against our policies", "which policy does this affect", or "gap analysis", or when reg-feed-watcher hands off a material item.
argument-hint
[reg name, or paste reg text/summary]

/policy-diff

  1. Load ~/.claude/plugins/config/claude-for-legal/regulatory-legal/CLAUDE.md → policy library index.
  2. Use the workflow below.
  3. Extract requirements from the reg. Match to indexed policies.
  4. Output: per-requirement gap analysis, which policy needs updating.

Matter context

Matter context. Check ## Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run /regulatory-legal:matter-workspace switch <slug> or say practice-level." Load the active matter's matter.md for matter-specific context and overrides. Write outputs to the matter folder at ~/.claude/plugins/config/claude-for-legal/regulatory-legal/matters/<matter-slug>/. Never read another matter's files unless Cross-matter context is on.


Purpose

A reg changed. You have policies. This skill finds which policies the change touches and what the gap is between "what the reg now requires" and "what the policy says."

Load context

~/.claude/plugins/config/claude-for-legal/regulatory-legal/CLAUDE.md → policy library index (policies, locations, owners).

Scope integrity

If the user asks you to exclude a policy section, requirement, or category from the diff:

  1. Do it — the user owns the scope.
  2. But flag it, loudly and permanently: "⚠️ SCOPE LIMITATION: Section [X] excluded at user request. This diff does not reflect the full policy. Gaps in the excluded area are NOT identified." Above the header, carried to every downstream artifact.
  3. Hand the flag to gap-surfacer: "This diff was scope-limited. Do not represent it as a complete compliance picture." Include the scope-limitation banner verbatim on any gap tracker entry derived from this diff.
  4. Note what the exclusion means: "Excluding vendor management means the diff will show 'no policy addresses vendor management' — which is worse than showing the gap."

A compliance artifact built on an undisclosed scope exclusion looks like concealment in discovery. The flag is the difference between "we scoped the review" and "we hid the problem."

Workflow

Step 0: Verify rule status before you diff

Before diffing a rule against policy, confirm the rule is actually in force. Red flags that the rule may not be in force:

  • The applicability/compliance date has passed by more than 30 days but you have no confirmation it wasn't delayed
  • The rule is more than 12 months old
  • The rule is a politically contentious final rule (major rulemakings are frequently challenged)

When you see a red flag, check (via research MCP, web search if enabled, or the Federal Register docket) for: delays, stays, injunctions, rescission proposals, vacatur, or amendments. If you can check and the rule is confirmed in force, proceed. If you cannot verify (no tools connected), emit this banner ABOVE the header, before any content:

⚠️ RULE STATUS UNVERIFIED — I could not confirm this rule is currently in force. Final rules are frequently stayed, enjoined, delayed, or rescinded after publication. Do not treat any compliance date below as binding until you confirm the rule's status at the Federal Register docket or with outside counsel.

Tag every due date in the output: [due date per published rule — status unverified].

Rule-status uncertainty travels downstream. When handing off a gap to gap-surfacer, mark the item status_verified: false so it never gets routed to an Overdue bucket on the strength of a published date alone.

Step 1: Extract the new requirements

No silent supplement. If the regulatory change text is partial or ambiguous and the fuller rule isn't available from the indexed source, stop and ask. Do NOT fill the gap from web search or model knowledge without asking. Say: "I have [what you have]. To extract requirements accurately I'd need [what's missing]. Options: (1) paste the full text, (2) point me at the primary source, (3) search the web for the rule — results will be tagged [web search — verify] and should be checked against the issuing authority before relying, or (4) stop here. Which would you like?" A lawyer decides whether to accept lower-confidence sources; Claude does not decide for them.

Source attribution. Tag every citation — the regulatory citation, any cross-references, any policy excerpts — with where it came from: [<regulator or research tool>] for items retrieved from a primary source, policy library, or MCP; [web search — verify] for items pulled from web search; [model knowledge — verify] for items recalled from the model's training data; [user provided] for items pasted in by the user. Items tagged verify carry higher fabrication risk and should be checked first. Never strip or collapse the tags in the output.

Read the regulatory change. List each discrete new or changed requirement:

#RequirementEffectiveCitation
1[what it requires][date][section]

Be specific. "Enhanced disclosure requirements" is not a requirement. "Must disclose X in Y format at Z point in the flow" is.

Show full SKILL.md (530 more words)Show less
Step 2: Map to policies

For each requirement, which indexed policy is closest?

  • Direct hit: policy explicitly covers this topic
  • Indirect: policy covers a related topic, this is a new sub-issue
  • No match: no policy addresses this — gap is "policy doesn't exist"
Step 3: Diff

For each direct or indirect hit, read the policy and compare:

markdown
### Requirement [N]: [name]

**New rule requires:** [requirement]

**Our policy ([name], last updated [date]) says:**
> "[relevant excerpt]"

**Gap:** [None — policy already covers this | Partial — policy addresses X but not Y | Full — policy contradicts or doesn't address]

**Change needed:** [specific — "add a paragraph on X" not "update the policy"]

**Policy owner:** [from index]
Step 4: No-match gaps

Requirements with no policy match get called out separately:

markdown
### New policy needed

Requirement [N]: [requirement]

No existing policy covers this. Options:
- Draft new policy (suggested owner: [whoever owns the closest topic])
- Add to existing [related policy] as a new section
- Determine this doesn't need a policy (one-off compliance, not ongoing)

Branches by regulatory input type

Pre-rule branch (ANPR / RFI)

If the regulatory input is an ANPR or RFI (no imposed requirements), do NOT run a full gap-closure diff. Instead, produce a pre-positioning analysis:

  • Name the policies that will likely need to change once a final rule issues (not today).
  • Flag whether any of the ANPR's issue areas intersect with the company's practice in a way that warrants a comment letter.
  • Note the comment deadline and the team's comment-decision owner from ~/.claude/plugins/config/claude-for-legal/regulatory-legal/CLAUDE.md.
  • Do NOT produce per-requirement "no gap" rows for an ANPR — there are no requirements to diff against. Produce one paragraph naming the future exposure and the policies it would touch.
Negative-finding branch (final rule / NPRM diffed against a policy that isn't the right target)

If every requirement in the extracted list comes out as "no gap against [the named policy]," do NOT produce the full per-requirement analysis — compress to a single short paragraph:

markdown
## Policy Diff: [Regulation name] — [Policy name]

[REGULATION] doesn't appear to require a change to [POLICY NAME]. [POLICY NAME]
§[X] already covers [Y]. The policies this regulation actually touches are
[other-policy-1] and [other-policy-2] — rerun `/regulatory-legal:policy-diff` against those.

Review on [next cycle — e.g., "at the next annual policy review"] or if
[trigger — e.g., "the rule is finalized or amended"].

One paragraph, one recommendation, routing note. Don't repeat the "no gap" finding for every requirement — the summary table handles that. A negative finding against the wrong target policy is a routing problem, not a compliance analysis.

Gap branch (final rule / NPRM with at least one gap against the target policy)

Full per-requirement analysis as specified below. The detailed diff format is for diffs that actually find gaps.

Output

markdown
[WORK-PRODUCT HEADER — per plugin config ## Outputs — differs by role; see `## Who's using this`]

## Policy Diff: [Regulation name]

**Regulation:** [name, link]
**Effective:** [date]
**Requirements extracted:** [N]

### Bottom line

[N gaps need action by [date] — top 3: X, Y, Z]

### Summary

| # | Requirement | Policy affected | Gap | Owner |
|---|---|---|---|---|
| 1 | [short] | [policy name or "none"] | None/Partial/Full | [name] |

### Detailed diffs

[Each requirement block from Step 3]

### New policies needed

[From Step 4, if any]

### No-gap requirements

[List — useful to know what's already covered]

---

**Verify citations before relying on them.** The regulatory citations and policy references above were AI-generated and have not been checked against a primary source. Before acting on any requirement here, confirm the rule against Westlaw, your firm's research platform, or the issuing authority's website — check accuracy, effective date, and current status. AI-generated regulatory citations are sometimes fabricated, misquoted, or stale. Source tags on each requirement (e.g., `[Federal Register]`, `[web search — verify]`) show where the citation came from; `verify` tags carry higher fabrication risk and should be checked first.

Config-dependent fallbacks

This skill reads the policy library index from ~/.claude/plugins/config/claude-for-legal/regulatory-legal/CLAUDE.md. When the index is empty or still [PLACEHOLDER]:

  • Policy library empty: flag every requirement as "no policy match" by default and append to the output: "The policy library in your configuration is empty, so every requirement is flagged as a new-policy gap. If you have policies that address these requirements, add them to the library with /regulatory-legal:cold-start-interview --redo or by editing ~/.claude/plugins/config/claude-for-legal/regulatory-legal/CLAUDE.md, then re-run the diff."
  • Owner missing for a matched policy: leave the Owner cell blank in the summary and append: "Policy owners aren't set for [list]. Assign them with /regulatory-legal:cold-start-interview --redo or by editing the policy library in ~/.claude/plugins/config/claude-for-legal/regulatory-legal/CLAUDE.md so gap-surfacer can route."

Say nothing about config when the library is populated and owners are set.

Handoff

To gap-surfacer: every Partial or Full gap becomes a tracked item with owner and deadline.

Close with the next-steps decision tree

End with the next-steps decision tree per CLAUDE.md ## Outputs. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.

What this skill does not do

  • Draft the policy updates. It identifies what needs updating; policy-drafting (or a human) drafts.
  • Interpret ambiguous regulatory text definitively. If the reg could be read two ways, say so and flag for counsel.

© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in regulatory-legal/skills/policy-diff of anthropics/claude-for-legal.

Open the folder on GitHubat commit 4a6c651

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Policy Diff next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Policy Diff compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Policy Diff this skillanthropics/claude-for-legal9.6k1 repos~3kAutomated safety check: PassApache-2.0
Implementing Policy As Code With Open Policy Agentmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: NotesApache-2.0
Indexabilitythedaviddias/Front-End-Checklist74k—~814Automated safety check: PassMIT
Indexability Conflictsthedaviddias/Front-End-Checklist74k—~876Automated safety check: PassMIT
Policy Acknowledgementsickn33/agentic-awesome-skills47k1 repos~3.4kAutomated safety check: PassMIT
Accesslint Diffsickn33/agentic-awesome-skills47k1 repos~1.2kAutomated safety check: PassMIT

Similar skills

  • Implementing Policy As Code With Open Policy Agent

    mukul975/Anthropic-Cybersecurity-Skills

    Implements policy-as-code enforcement with Open Policy Agent (OPA) and Gatekeeper for Kubernetes and CI/CD pipelines, covering writing Rego policies, deploying OPA Gatekeeper as a Kubernetes…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Indexability

    thedaviddias/Front-End-Checklist

    A skill your agent uses when auditing a site for accidental noindex directives, investigating why important pages are not appearing in Google Search, or reviewing CMS settings that control indexing…

    74k GitHub stars~814 tokensUpdated yesterday
    Marketing & SEOAuto-check passed
  • Indexability Conflicts

    thedaviddias/Front-End-Checklist

    A skill your agent uses when auditing a site for indexability issues, investigating why pages appear in Google's index that should be excluded (or vice versa), or reviewing robots.txt and meta…

    74k GitHub stars~876 tokensUpdated yesterday
    Marketing & SEOAuto-check passed
  • Policy Acknowledgement

    sickn33/agentic-awesome-skills

    Policy acknowledgement register: employee, policy and version, sent and due dates, acknowledged date and flag, days overdue, reminder sent and status.

    47k GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check passed
  • Accesslint Diff

    sickn33/agentic-awesome-skills

    Diff a live page's accessibility violations against a baseline — by default compares uncommitted changes (stash-based), or pass --branch [<name] to diff against a branch.

    47k GitHub starsUsed in 1 repo~1.2k tokens
    Frontend & DesignAuto-check passed
  • Index Refresh

    paperclipai/paperclip

    A skill your agent uses when an LLM Wiki operation issue requests an index refresh.

    98k GitHub stars~994 tokensUpdated today
    Knowledge ManagementAuto-check passed

More from anthropics/claude-for-legal

All 147 skills in this repo
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Supervisor Review Queue

    anthropics/claude-for-legal

    Official

    Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.

    9.6k GitHub starsUsed in 3 repos~1.1k tokens
    Auto-check passed
  • Tabular Document Review

    anthropics/claude-for-legal

    Official

    Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.

    9.6k GitHub starsUsed in 3 repos~4.3k tokens
    Auto-check passed
  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Auto-check passed
  • Legal Skills Registry Browser

    anthropics/claude-for-legal

    Official

    Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.

    9.6k GitHub starsUsed in 2 repos~620 tokens
    Auto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Auto-check passed

Questions about Policy Diff

What does Policy Diff do?

Diff a specific regulatory change against the indexed policy library. Policy Diff is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Diff a specific regulatory change against the indexed policy library.

When should I use Policy Diff?

Policy Diff fits situations like: A reg has changed and you need to know which policies it touches and what the gap is; the user says diff this reg against our policies; which policy does this affect; reg-feed-watcher hands off a material item.

How do I install Policy Diff in Claude Code?

Run `npx skills add anthropics/claude-for-legal --skill policy-diff -a claude-code`. Or copy the skill folder (regulatory-legal/skills/policy-diff in anthropics/claude-for-legal) into .claude/skills/policy-diff in your project. Claude Code loads it when a task matches its description.

How do I install Policy Diff in Codex?

Run `npx skills add anthropics/claude-for-legal --skill policy-diff -a codex`. Or copy the skill folder (regulatory-legal/skills/policy-diff in anthropics/claude-for-legal) into .agents/skills/policy-diff in your project. Codex loads it when a task matches its description.

Can I use Policy Diff in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill policy-diff -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/policy-diff, .gemini/skills/policy-diff, .github/skills/policy-diff and .opencode/skills/policy-diff in your project.

What does Policy Diff need to run?

SKILL.md names no scripts, command-line tools or credentials: Policy Diff is instructions for the agent only.

Does Policy Diff access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Policy Diff safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Policy Diff use?

Policy Diff is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Policy Diff use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Policy Diff?

Skills that share tags, products or a category with Policy Diff: Implementing Policy As Code With Open Policy Agent (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Indexability (thedaviddias/Front-End-Checklist, 74k stars), Indexability Conflicts (thedaviddias/Front-End-Checklist, 74k stars) and Policy Acknowledgement (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Policy Diff?

anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,611 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.

Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.