Official agent skill

Policy Starter

by anthropics in anthropics/claude-for-legal

Draft a firm AI usage policy from published model policies, adapted to your practice profile — a research-and-synthesis tool whose output is a draft for attorney review and adoption, not a finished…

OfficialApache-2.0Auto-check passedLegal & Compliance

Install Policy Starter

skills CLI
$ npx skills add anthropics/claude-for-legal --skill policy-starter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install anthropics/claude-for-legal policy-starter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance-legal/skills/policy-starter .claude/skills/policy-starter && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
policy-starter
GitHub stars
9.6k
Used in
3 other repos
Token cost
~3.9k tokens
SKILL.md length
2,086 words
Files
1
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Draft a firm AI usage policy from published model policies, adapted to your practice profile — a research-and-synthesis tool whose output is a draft for attorney review and adoption, not a finished…

  • Works in 7 steps: Read… → Use the framework below. → Run the scope interview — which sections… → …
  • User says draft an AI policy
  • SKILL.md covers Matter context, Purpose, Read… and Scope interview (do this…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Policy Starter is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Draft a firm AI usage policy from published model policies, adapted to your practice profile — a research-and-synthesis tool whose output is a draft for attorney review and adoption, not a finished policy. Use when user says "draft an AI policy", "we need an AI policy", "build an AI usage policy", "our firm needs a GenAI policy", or similar requests to generate a first-cut internal AI policy.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering AI governance. The repository describes itself as: A suite of plugins for legal workflows. The licence is Apache-2.0.

When your agent uses it

  • User says draft an AI policy
  • We need an AI policy
  • Build an AI usage policy
  • Our firm needs a GenAI policy

Example prompts

  • “draft an AI policy”
  • “we need an AI policy”
  • “build an AI usage policy”
  • “/policy-starter”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If the practice profile is unpopulated, stop and direct to…
  2. Use the framework below.
  3. Run the scope interview — which sections does the policy need to cover, who's the audience, what's the deployment context. Do not skip to…
  4. Web search for the current published model policies and guidance relevant to the deployment context (ABA, state bars, ILTA, CLOC, NIST…
  5. Draft the selected sections, sourced from the model policies, with [review] flags on every choice point and [review] open questions at the…
  6. Output with the draft header ("DRAFT FOR INTERNAL LEGAL REVIEW — NOT FOR DISTRIBUTION"), the sources block, the reviewer note, and the…
  7. Close with the next-steps decision tree.

What it can do on your machine

Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Policy Starter loads about 3.9k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 2,086 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 2,086 words, ~3,922 tokens.

Download SKILL.mdSave it as .claude/skills/policy-starter/SKILL.md (or your agent's skills folder).
name
policy-starter
description
Draft a firm AI usage policy from published model policies, adapted to your practice profile — a research-and-synthesis tool whose output is a draft for attorney review and adoption, not a finished policy. Use when user says "draft an AI policy", "we need an AI policy", "build an AI usage policy", "our firm needs a GenAI policy", or similar requests to generate a first-cut internal AI policy.
argument-hint
[optional — scope hint, e.g. 'firm-wide', 'legal team only', 'update existing']

/policy-starter

  1. Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If the practice profile is unpopulated, stop and direct to /ai-governance-legal:cold-start-interview.
  2. Use the framework below.
  3. Run the scope interview — which sections does the policy need to cover, who's the audience, what's the deployment context. Do not skip to drafting.
  4. Web search for the current published model policies and guidance relevant to the deployment context (ABA, state bars, ILTA, CLOC, NIST, peer-firm / peer-company policies, current state AI laws, EU AI Act, sector regulators as applicable).
  5. Draft the selected sections, sourced from the model policies, with [review] flags on every choice point and [review] open questions at the bottom of each section.
  6. Output with the draft header ("DRAFT FOR INTERNAL LEGAL REVIEW — NOT FOR DISTRIBUTION"), the sources block, the reviewer note, and the adoption checklist.
  7. Close with the next-steps decision tree.
/ai-governance-legal:policy-starter
/ai-governance-legal:policy-starter "we need an AI policy for our 30-lawyer firm"
/ai-governance-legal:policy-starter "update our existing policy for the 2026 state AI laws"

Matter context

Matter context. Check ## Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run /ai-governance-legal:matter-workspace switch <slug> or say practice-level." Load the active matter's matter.md for matter-specific context and overrides. Write outputs to the matter folder at ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/. Never read another matter's files unless Cross-matter context is on.


Purpose

A lot of firms and in-house teams don't have a written AI usage policy yet, or are running on a 2024-vintage one that doesn't mention the state AI laws, the EU AI Act implementing acts, the 2025 COPPA amendments, or what they actually ended up doing with Copilot and Claude for Work. This skill produces a draft policy to bring to the decision-maker — GC, managing partner, executive committee, board, head of IT, head of HR — not a finished policy to circulate.

The discipline of this skill:

  1. Source from published model policies, not from invention. Search for and read the ABA AI Toolkit, state bar guidance, ILTA's model policy, CLOC's templates, and peer-firm / peer-company policies that are public. Cite what each source says and adapt it — don't generate policy language out of thin air.
  2. Decision-tree the scope before drafting. A policy that tries to cover everything covers nothing. Ask the user what sections the policy needs. Let them pick. Then build each picked section with [review] flags on every choice point.
  3. Flag every judgment call. The output is a draft the attorney reviews and adopts; every threshold, every named tool, every disclosure trigger, every enforcement consequence is a [review] line.
  4. Header signals the scope of the audience. This output may be read beyond legal — by HR, IT, all staff. The header is adapted accordingly.

This skill does NOT finalize, distribute, publish, or even recommend a specific position on the hard calls. It produces a draft and surfaces the choices.

Before drafting, always read the practice profile. The sections that drive the draft:

  • ## Company profile — AI role (Builder / Deployer / Both), regulatory footprint, external commitments, practice setting
  • ## Use case registry — what's already approved, conditional, or a red line
  • ## AI policy commitments — what a prior or current policy already says
  • ## Vendor AI governance — what the team already requires from vendors
  • ## Governance team and escalation — who approves, who escalates
  • ## Who's using this — Role (lawyer / non-lawyer) governs the header and the "adopt this" framing

If ## AI policy commitments is populated, this is an UPDATE, not a new draft — treat the existing policy as the base and propose changes. If it's empty, this is a first-cut draft.

Scope interview (do this BEFORE drafting)

Ask the user which sections the policy should cover. Present as a checklist — the user picks, you build. Do not pre-decide.

What should the AI policy cover? Pick the sections you want in the draft:

  1. Scope — who the policy applies to (all staff, certain roles, contractors), what tools it covers (GenAI only, all AI, specific vendors), what data is in/out of scope.
  2. Permitted and prohibited uses — the approved categories, the red lines, the "ask first" cases.
  3. Approval and review — who approves a new tool, who approves a new use case, how the review request is filed, what the SLA is.
  4. Disclosure — to clients (for firms), to courts, to counterparties, to employees, to end users of an AI feature.
  5. Data handling — what confidential/client/privileged data can go where, data residency, vendor retention terms, training-on-data posture.
  6. Training and certification — who has to take training, on what cadence, consequences for non-completion.
  7. Incidents and reporting — what counts as an AI incident, how to report, who handles.
  8. Enforcement — what happens when the policy is violated, link to disciplinary framework.
  9. Review cadence and ownership — how often the policy gets updated, who owns updates, how changes are communicated.
  10. Glossary — defined terms (GenAI, approved tool, high-risk use, consequential decision, confidential data, etc.).

Default starter pack for a firm / in-house legal team that's never had a policy: 1, 2, 3, 4, 5, 9. Skip the rest for v1.

After the user picks, ask the second question:

Two more inputs before I draft:

  • Audience — who's reading this? (All staff / legal team only / attorneys plus staff / client-facing version also needed) This drives tone and the glossary.
  • Deployment context — (a) law firm, (b) in-house legal at a company (policy covers legal or company-wide?), (c) legal aid / clinic, (d) government. This drives which model policies I search.

Source the model policies

Before drafting, run web searches for the most recent published model AI policies and guidance.

Derive the model policy sources from the practice profile's ## Regulatory footprint. Don't hardcode US sources for a global user.

JurisdictionModel policy sources
USABA Formal Opinion 512, state bar guidance (CA, FL, NY, TX all have published AI guidance), ILTA model policy, CLOC templates, peer firm published AI policies
UKSolicitors Regulation Authority risk outlook, Law Society AI principles, ICO AI guidance, Bar Council guidance
EUEU AI Act compliance framework (Article 4 AI literacy, Article 17 quality management), national DPA AI guidance (CNIL, DSB, Garante, AEPD), EDPB guidelines, EU institutions' AI policies
AustraliaLaw Council of Australia AI guidelines, OAIC AI guidance, state law society guidance, Australian AI Ethics Framework
SingaporePDPC Model AI Governance Framework, MinLaw guidance, MAS AI fairness principles (for financial services)
CanadaLaw Society of Ontario/BC/Alberta AI guidance, OPC AI guidance, TBS Directive on Automated Decision-Making
Multi-jurisdictionUse all applicable, and note where they diverge (e.g., EU requires human oversight documentation US doesn't; Australia focuses on voluntary ethics frameworks; Singapore focuses on sectoral regulation)

If the practice profile's footprint is empty or [PLACEHOLDER], ask: "What jurisdiction(s) does your organization operate in? I'll draft from the model policies that match your regulatory environment and professional responsibility framework, not a US-centric template."

For each source the draft uses, record it in a "Sources" block at the top of the output with: name, URL, date accessed, and what the draft took from it.

If a web search can't be run, note in the reviewer note: "Could not run web search — draft sourced from training knowledge alone, verify against current versions of the cited sources before adopting." The verification log applies.

The draft

Output follows a consistent structure. Every choice point gets a [review] flag. The user has to decide; the skill presents options.

Header
DRAFT FOR INTERNAL LEGAL REVIEW — NOT FOR DISTRIBUTION
Prepared for: [firm / company name from practice profile]
Date: [today's date]
Prepared by: ai-governance-legal policy-starter skill, adapted from published model policies
Not for adoption, distribution, posting, or reliance until reviewed, adapted, and approved by [attorney / GC / managing partner / executive committee per the governance team section of the practice profile].

When the Role in ## Who's using this is Non-lawyer: add a second line under the header — "If you are not a licensed attorney, solicitor, barrister, or other authorised legal professional in your jurisdiction, bring this draft to your attorney contact ([name from practice profile]) before using any of it. This is a starting draft for their review, not a policy you can adopt."

Show full SKILL.md (807 more words)Show less
Sources block (at the top, under the header)

A table of the model policies / guidance / regulations the draft drew from:

SourceURLAccessedWhat the draft took from it
ABA Formal Op. 512[url][date]Disclosure and competence framing
ILTA Model AI Policy v.[X][url][date]Approval workflow, data handling
[State] Bar Op. [X][url][date]Disclosure to clients
[peer firm] published AI policy[url][date]Scope language
Colorado SB 24-205[url][date]High-risk AI definition
EU AI Act, Art. [X][url][date]Vendor flow-down
Executive summary

Three paragraphs max. What the policy does, who it binds, what the reader has to do before it takes effect.

The sections

Only the sections the user picked, in the order above. For each:

  • A header and scope sentence.
  • The substantive rules, adapted from the cited model policies. Every specific threshold, number, named tool, named vendor, or escalation contact is [review]. Example: "Confidential client data may not be entered into [general-purpose consumer AI tools] [review — list tools, or reference the approved-tools list]. Use of such data in [approved firm-licensed tools] [review — list tools] is permitted subject to the data handling section."
  • Source attribution inline where a rule is adapted from a specific source. Example: "Attorneys must verify the accuracy of all AI-generated work product before using it in representation of a client [ABA Formal Op. 512]."
  • Open questions at the bottom of each section — 2-3 decisions the attorney needs to make before the section is ready. These are distinct from inline [review] flags — these are the "we don't have a position here yet" items, not the "fill in the specifics" items.
Adoption checklist

At the end of the draft, a checklist of the things that have to happen before the policy is adopted. Don't invent these — pull from the practice profile's governance team and escalation section. Typical items:

  • Review by GC / managing partner [review — name]
  • Review by IT / security [review — name]
  • Review by HR (for enforcement / training sections) [review — name]
  • Board / executive committee approval (if required) [review — confirm whether required]
  • Training materials drafted
  • Announcement drafted
  • Effective date set [review]
  • Review cadence calendared [review — annual is typical]
  • Add policy to the ## AI policy commitments section of the practice profile once adopted
Reviewer note

The standard reviewer note above the header, per the ## Outputs section of the practice profile. Use the block format:

⚠️ Reviewer note

  • Sources: web search ✓ / not connected — cites from training knowledge
  • Read: practice profile · [N] published model policies
  • Flagged for your judgment: [N] [review] items inline · [N] open questions per section
  • Currency: searched for developments since [date]
  • Before relying: this is a DRAFT — bring to [approver from practice profile], don't distribute until adopted

Don'ts

  • Don't invent policy language. Every substantive rule in the draft must be traceable to a cited source or flagged [review — adapted, no direct source].
  • Don't pick the hard calls for the attorney. "Should paralegals be permitted to use AI for first-draft work?" is a [review], not a recommended position.
  • Don't produce a finished-looking policy. The header, the reviewer note, and the [review] flags throughout are the signal that this is a draft. Do not soften them.
  • Don't skip the scope interview. If the user says "just draft a full policy," push back: "A policy that tries to cover everything covers nothing. Which sections do you want? Here's the checklist." One round of negotiation is fine — two is also fine. Drafting without scope is the failure mode.
  • Don't generate section content the user didn't ask for. If they picked 1, 2, 3, 4, 5, 9, do those. Don't add section 6 because "a real policy needs training."
  • Don't recommend a specific vendor, tool, or consequence. Flag those [review] with context on what a typical decision would be, not what the user's should be.
  • Don't promise legal sufficiency. The draft is a starting point for attorney review, not a tested policy.

Handoffs

After the draft is produced, close with the decision tree from the practice profile. The most common next steps:

  1. Tune the draft — the user walks through the [review] flags and resolves them with the attorney; the skill re-runs with the decisions baked in.
  2. Stakeholder summary — produce a one-page version for the board or executive committee explaining what the policy does and doesn't do.
  3. Training materials — once the policy is adopted, /ai-governance-legal:aia-generation can be used to produce per-use-case training notes.
  4. Vendor sweep — once the policy is adopted, /ai-governance-legal:vendor-ai-review should be run against the vendors the policy references to check conformance.
  5. Gap check against new regulation — pair with /ai-governance-legal:reg-gap-analysis to test the draft against a specific regulation or guidance before adoption.

Output scope reminder

The document this skill produces reaches HR, IT, and the broader business — not just legal. Keep the language plain enough for non-lawyers to follow. The legal precision is in the [review] flags and the sources, not in jargon.

© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in ai-governance-legal/skills/policy-starter of anthropics/claude-for-legal.

Open the folder on GitHubat commit 4a6c651

Used in 3 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Policy Starter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Policy Starter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Policy Starter this skillanthropics/claude-for-legal9.6k3 repos~3.9kAutomated safety check: PassApache-2.0
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.7kAutomated safety check: PassMIT
AI Risk Managementbriiirussell/cybersecurity-skills413—~3.7kAutomated safety check: NotesMIT
Eu AI Act Readinessseb1n/awesome-ai-agent-skills206—~3.3kAutomated safety check: PassMIT
AI GovernanceHack23/cia239—~1.4kAutomated safety check: PassApache-2.0
Compliance Testingpetrkindlmann/qa-skills170—~4.6kAutomated safety check: PassMIT

Similar skills

  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Compliance Testing

    petrkindlmann/qa-skills

    Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…

    170 GitHub stars~4.6k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check passed
  • AI ML Governance

    cbrock84/headcount

    Governs models and AI systems in production — intended use, evaluation, monitoring, human oversight, documentation, and the decision to deploy or retire.

    2k GitHub stars~1k tokensUpdated 22 days ago
    Legal & ComplianceAuto-check passed

More from anthropics/claude-for-legal

All 147 skills in this repo
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Supervisor Review Queue

    anthropics/claude-for-legal

    Official

    Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.

    9.6k GitHub starsUsed in 3 repos~1.1k tokens
    Auto-check passed
  • Tabular Document Review

    anthropics/claude-for-legal

    Official

    Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.

    9.6k GitHub starsUsed in 3 repos~4.3k tokens
    Auto-check passed
  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Auto-check passed
  • Legal Skills Registry Browser

    anthropics/claude-for-legal

    Official

    Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.

    9.6k GitHub starsUsed in 2 repos~620 tokens
    Auto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Auto-check passed

Questions about Policy Starter

What does Policy Starter do?

Draft a firm AI usage policy from published model policies, adapted to your practice profile — a research-and-synthesis tool whose output is a draft for attorney review and adoption, not a finished…. Policy Starter is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Draft a firm AI usage policy from published model policies, adapted to your practice profile — a research-and-synthesis tool whose output is a draft for attorney review and adoption, not a finished policy.

When should I use Policy Starter?

Policy Starter fits situations like: user says draft an AI policy; we need an AI policy; build an AI usage policy; our firm needs a GenAI policy.

How do I install Policy Starter in Claude Code?

Run `npx skills add anthropics/claude-for-legal --skill policy-starter -a claude-code`. Or copy the skill folder (ai-governance-legal/skills/policy-starter in anthropics/claude-for-legal) into .claude/skills/policy-starter in your project. Claude Code loads it when a task matches its description.

How do I install Policy Starter in Codex?

Run `npx skills add anthropics/claude-for-legal --skill policy-starter -a codex`. Or copy the skill folder (ai-governance-legal/skills/policy-starter in anthropics/claude-for-legal) into .agents/skills/policy-starter in your project. Codex loads it when a task matches its description.

Can I use Policy Starter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill policy-starter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/policy-starter, .gemini/skills/policy-starter, .github/skills/policy-starter and .opencode/skills/policy-starter in your project.

What does Policy Starter need to run?

SKILL.md names no scripts, command-line tools or credentials: Policy Starter is instructions for the agent only.

Does Policy Starter access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Policy Starter safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Policy Starter use?

Policy Starter is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Policy Starter use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Policy Starter?

Skills that share tags, products or a category with Policy Starter: Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), AI Risk Management (briiirussell/cybersecurity-skills, 413 stars), Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars) and AI Governance (Hack23/cia, 239 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Policy Starter?

anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,633 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.

Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.