Iso42001
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and vendor reviews to find policy drift, or direct query for a proposed new AI practice.
$ npx skills add anthropics/claude-for-legal --skill policy-monitor -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install anthropics/claude-for-legal policy-monitor --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance-legal/skills/policy-monitor .claude/skills/policy-monitor && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "policy-monitor" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/policy-monitor into .claude/skills/policy-monitor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "policy-monitor", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/policy-monitorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add anthropics/claude-for-legal --skill policy-monitor -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install anthropics/claude-for-legal policy-monitor --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ai-governance-legal/skills/policy-monitor .agents/skills/policy-monitor && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "policy-monitor" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/policy-monitor into .agents/skills/policy-monitor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "policy-monitor", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/claude-for-legal --skill policy-monitor -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install anthropics/claude-for-legal policy-monitor --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ai-governance-legal/skills/policy-monitor .cursor/skills/policy-monitor && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "policy-monitor" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/policy-monitor into .cursor/skills/policy-monitor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "policy-monitor", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/anthropics/claude-for-legal.git --path ai-governance-legal/skills/policy-monitor--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add anthropics/claude-for-legal --skill policy-monitor -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install anthropics/claude-for-legal policy-monitor --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ai-governance-legal/skills/policy-monitor .gemini/skills/policy-monitor && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "policy-monitor" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/policy-monitor into .gemini/skills/policy-monitor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "policy-monitor", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install anthropics/claude-for-legal policy-monitorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add anthropics/claude-for-legal --skill policy-monitor -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .github/skills && cp -r skills-src/ai-governance-legal/skills/policy-monitor .github/skills/policy-monitor && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "policy-monitor" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/policy-monitor into .github/skills/policy-monitor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "policy-monitor", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/claude-for-legal --skill policy-monitor -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install anthropics/claude-for-legal policy-monitor --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ai-governance-legal/skills/policy-monitor .opencode/skills/policy-monitor && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "policy-monitor" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/policy-monitor into .opencode/skills/policy-monitor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "policy-monitor", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
policy-monitorKeep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and vendor reviews to find policy drift, or direct query for a proposed new AI practice.
Policy Monitor is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and vendor reviews to find policy drift, or direct query for a proposed new AI practice. Use when user says "policy sweep", "does our AI policy cover this", "we want to start doing X — does the policy need updating", "run the policy monitor", or on a recurring schedule.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering AI governance. The repository describes itself as: A suite of plugins for legal workflows. The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Policy Monitor loads about 3.7k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 1,544 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 1,544 words, ~3,744 tokens.
.claude/skills/policy-monitor/SKILL.md (or your agent's skills folder).Sweep mode (no argument or --sweep):
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → outputs folder path, AI policy document, last sweep date.~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md registry.Last policy sweep and gaps_found in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.Direct query mode (with description argument):
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → current policy commitments, use case registry, actual policy document.Recurring runs:
Set up a recurring reminder in your own scheduler to run /ai-governance-legal:policy-monitor weekly. Scheduled execution requires a scheduled-tasks integration, which is not bundled with this plugin.
/ai-governance-legal:policy-monitor
/ai-governance-legal:policy-monitor "We want to use AI to automatically flag expense reports for review"AI policies drift from practice faster than almost any other policy document — the field moves quickly, use cases multiply, and each approved AIA or triage result represents a new commitment the policy may not have caught up with. An AIA approves a new AI use case with a human-oversight condition. A vendor AI agreement permits data processing the policy doesn't mention. A triage result marks a new category of deployment as conditional with a disclosure requirement. The policy sits there unchanged.
This skill catches the drift — either by crawling the outputs folder weekly, or by answering the direct question: "we're about to start doing X, what does that mean for our AI policy?"
The output is always the same: here's the gap, here's the suggested language.
Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md:
## AI policy commitments — commitments extracted from the published policy## Use case registry — approved, conditional, and never use cases## Outputs — outputs folder path, AI policy document location, last sweep dateIf ## Outputs contains [PLACEHOLDER]:
"Outputs aren't configured yet. I can still run a direct-query check — describe what you're planning to do and I'll diff it against your current AI policy. To enable the crawl sweep, run
/ai-governance-legal:cold-start-interviewand provide the outputs folder path."
Read the actual AI or acceptable use policy document from the path in ## Outputs
→ AI policy document. The commitments in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md are a summary; the actual
document is authoritative for suggesting edits.
Sweep mode: No argument, --sweep, or triggered by schedule.
→ Scan the outputs folder. Diff all outputs since last sweep against current policy.
Direct query mode: User provides a description of a proposed new AI practice. → Diff that practice against current policy and use case registry. Suggest updates.
Read ## Outputs → Last policy sweep date. Scan for output files in the
outputs folder dated after that date. If no date is recorded, scan all files and
note: "First sweep — scanning all outputs."
If the outputs folder is empty or has no new files since the last sweep:
"No new outputs since [last sweep date]. AI policy appears current with recent practice. Next scheduled sweep: [date]."
Do not update Last policy sweep or gaps_found automatically. After the sweep results are presented, wait for the human to acknowledge them ("sweep acknowledged," "results reviewed," or equivalent). Only then update ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md:
Last policy sweep: [date of acknowledgment]gaps_found: [N] (number of REQUIRED + ADVISABLE gaps found in that sweep)Updating the stamp before acknowledgment would let an unreviewed sweep silently roll forward and suppress the next sweep's attention to the same gaps.
AIAs (AI Impact Assessments):
Triage results (CONDITIONAL / APPROVED outcomes):
Vendor AI reviews (signed / approved):
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.mdUse case registry updates:
For each flagged item, assess:
REQUIRED update — the policy makes a commitment that an output contradicts, or an approved use case has no policy coverage and affects external parties. Not updating creates a material misrepresentation.
Example: AI policy says "we do not use AI in employment decisions." An AIA approved an AI-assisted hiring screening tool with human review required. Policy needs updating — even with human review, AI is now involved in employment decisions. "We do not use AI" is no longer accurate.
ADVISABLE update — policy is silent but not in conflict. The practice is defensible without updating, but cleaner with it. Important when the practice affects external parties or creates a reasonable expectation.
Example: Policy says "we use AI to improve our products and services." An AIA approved an AI feature for customer support drafts. Policy technically covers it but is vague. Advisable to be more specific so customers know what they're interacting with.
[WORK-PRODUCT HEADER — per plugin config ## Outputs — differs by role; see `## Who's using this`]
*This sweep is derived from AIAs, triage results, and vendor AI reviews that carry the plugin's privilege/confidentiality marking. The sweep inherits that status. Distribute deliberately — forwarding gap findings outside the privilege circle can waive privilege on the underlying assessments.*
# AI Policy Monitor — Sweep Report
**Date:** [date]
**Outputs scanned:** [N files] | **New since last sweep:** [N files]
**Gaps found:** [N] REQUIRED | [N] ADVISABLE
---
## REQUIRED updates
### [Gap 1 short name]
**Source:** [filename / output type that triggered this]
**What's happening:** [plain description of the new practice]
**Current policy:** [quote the relevant section — or "No coverage"]
**Gap:** [what's missing or inconsistent]
**Suggested language:**
> *Add to / update [section name]:*
> "[Drafted policy text — specific, consistent with house style of the actual policy]"
---
[repeat for each REQUIRED gap]
---
## ADVISABLE updates
### [Gap name]
**Source:** [filename]
**What's happening:** [description]
**Current policy:** [quote or "Silent"]
**Suggested language:**
> *Add to / update [section]:*
> "[Drafted text]"
---
## No action needed
[List outputs scanned where no gaps were found]
---
## Use case registry sync
[Any use cases approved since the last sweep that aren't yet in the `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`
registry — suggest registry entries to add]
---
## Next steps
- [ ] Review REQUIRED updates — decisions needed before the associated use cases
go live (or immediately if already live)
- [ ] Review ADVISABLE updates — lower urgency, address at next policy refresh
- [ ] Add new use cases to registry (if any flagged above)
- [ ] Next scheduled sweep: [date]Extract from the user's description:
If the description is vague, ask one clarifying question. Don't run a long intake — direct query mode should be fast.
Check the proposed practice against the current policy and use case registry:
| Check | Current policy / registry | Proposed practice | Verdict |
|---|---|---|---|
| Use case category | [registry — approved / conditional / never / not present] | [new use case] | 🟢 Covered / 🟡 Gap / 🔴 Conflict |
| Scope of AI use | [what policy says AI is used for] | [new use] | |
| Automated decisions | [policy position on automation] | [is this automated?] | |
| Disclosure to affected parties | [what policy commits to] | [what this requires] | |
| Vendor data use | [policy position on vendor AI] | [this vendor's terms] | |
| Human oversight | [policy statement if any] | [what's actually in place] |
# AI Policy Check: [Proposed practice in one line]
**Bottom line:** [POLICY UPDATE REQUIRED / ADVISABLE / NO UPDATE NEEDED]
---
## What's covered
[Aspects of the proposed practice already addressed — brief, confirms no change needed]
## What's missing
### [Gap 1]
**Current policy:** [quote or "Silent"]
**What's needed:** [why this gap matters — legal, reputational, or expectation reason]
**Suggested language:**
> *Add to [section]:*
> "[Drafted text]"
### [Gap 2]
[same format]
## What conflicts
### [Conflict 1 — if any]
**Current policy says:** [quote]
**Proposed practice does:** [what conflicts]
**Resolution:** [which one needs to change — usually practice adjusts to match policy,
or policy is updated to a defensible new position; never silently accept both]
---
## Use case registry
[If this use case isn't in the registry: "Add to `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` → Use case registry:"]| [use case] | [Approved/Conditional] | [conditions] | — |
---
## Timing
[REQUIRED: "Policy update should happen before this practice goes live — or
immediately if it's already running."
ADVISABLE: "Can proceed; update at next policy refresh."]AI policy language is unusually prone to becoming outdated — the field moves fast and vague language ages better than specific commitments. When drafting:
Always say which section to add to. If the right section doesn't exist, suggest creating it and draft the header.
The weekly sweep is designed to run on a recurring cadence. Set up a recurring reminder in your own scheduler to run /ai-governance-legal:policy-monitor weekly. Scheduled execution requires a scheduled-tasks integration, which is not bundled with this plugin.
After each sweep, the Last policy sweep and gaps_found fields in ## Outputs are updated only once the human has acknowledged the sweep results (see "Determine scope" above).
End with the next-steps decision tree per CLAUDE.md ## Outputs. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.
reg-gap-analysis. This skill
monitors internal practice drift, not external legal changes.© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in ai-governance-legal/skills/policy-monitor of anthropics/claude-for-legal.
Open the folder on GitHubat commit 4a6c651
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.
Policy Monitor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Policy Monitor this skillanthropics/claude-for-legal | 9.6k | 3 repos | ~3.7k | Automated safety check: Pass | Apache-2.0 | |
| Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| AI Risk Managementbriiirussell/cybersecurity-skills | 413 | — | ~3.7k | Automated safety check: Notes | MIT | |
| Eu AI Act Readinessseb1n/awesome-ai-agent-skills | 206 | — | ~3.3k | Automated safety check: Pass | MIT | |
| AI GovernanceHack23/cia | 239 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Compliance Testingpetrkindlmann/qa-skills | 170 | — | ~4.6k | Automated safety check: Pass | MIT |
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
briiirussell/cybersecurity-skills
Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…
seb1n/awesome-ai-agent-skills
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
petrkindlmann/qa-skills
Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…
cbrock84/headcount
Governs models and AI systems in production — intended use, evaluation, monitoring, human oversight, documentation, and the decision to deploy or retire.
anthropics/claude-for-legal
Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.
anthropics/claude-for-legal
Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.
anthropics/claude-for-legal
Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.
anthropics/claude-for-legal
Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.
anthropics/claude-for-legal
Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.
anthropics/claude-for-legal
Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.
Categories
Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and vendor reviews to find policy drift, or direct query for a proposed new AI practice. Policy Monitor is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and vendor reviews to find policy drift, or direct query for a proposed new AI practice.
Policy Monitor fits situations like: user says policy sweep; does our AI policy cover this; we want to start doing X — does the policy need updating; run the policy monitor.
Run `npx skills add anthropics/claude-for-legal --skill policy-monitor -a claude-code`. Or copy the skill folder (ai-governance-legal/skills/policy-monitor in anthropics/claude-for-legal) into .claude/skills/policy-monitor in your project. Claude Code loads it when a task matches its description.
Run `npx skills add anthropics/claude-for-legal --skill policy-monitor -a codex`. Or copy the skill folder (ai-governance-legal/skills/policy-monitor in anthropics/claude-for-legal) into .agents/skills/policy-monitor in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill policy-monitor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/policy-monitor, .gemini/skills/policy-monitor, .github/skills/policy-monitor and .opencode/skills/policy-monitor in your project.
SKILL.md names no scripts, command-line tools or credentials: Policy Monitor is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Policy Monitor is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Policy Monitor: Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), AI Risk Management (briiirussell/cybersecurity-skills, 413 stars), Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars) and AI Governance (Hack23/cia, 239 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,633 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.
Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.