Iso42001
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Classify a proposed AI use case against your registry — approved, conditional, or not approved — and produce required conditions and next steps.
$ npx skills add anthropics/claude-for-legal --skill use-case-triage -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install anthropics/claude-for-legal use-case-triage --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance-legal/skills/use-case-triage .claude/skills/use-case-triage && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "use-case-triage" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/use-case-triage into .claude/skills/use-case-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "use-case-triage", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/use-case-triageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add anthropics/claude-for-legal --skill use-case-triage -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install anthropics/claude-for-legal use-case-triage --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ai-governance-legal/skills/use-case-triage .agents/skills/use-case-triage && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "use-case-triage" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/use-case-triage into .agents/skills/use-case-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "use-case-triage", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/claude-for-legal --skill use-case-triage -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install anthropics/claude-for-legal use-case-triage --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ai-governance-legal/skills/use-case-triage .cursor/skills/use-case-triage && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "use-case-triage" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/use-case-triage into .cursor/skills/use-case-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "use-case-triage", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/anthropics/claude-for-legal.git --path ai-governance-legal/skills/use-case-triage--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add anthropics/claude-for-legal --skill use-case-triage -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install anthropics/claude-for-legal use-case-triage --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ai-governance-legal/skills/use-case-triage .gemini/skills/use-case-triage && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "use-case-triage" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/use-case-triage into .gemini/skills/use-case-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "use-case-triage", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install anthropics/claude-for-legal use-case-triageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add anthropics/claude-for-legal --skill use-case-triage -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .github/skills && cp -r skills-src/ai-governance-legal/skills/use-case-triage .github/skills/use-case-triage && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "use-case-triage" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/use-case-triage into .github/skills/use-case-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "use-case-triage", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add anthropics/claude-for-legal --skill use-case-triage -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install anthropics/claude-for-legal use-case-triage --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ai-governance-legal/skills/use-case-triage .opencode/skills/use-case-triage && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "use-case-triage" agent skill from https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/use-case-triage into .opencode/skills/use-case-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "use-case-triage", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
use-case-triageClassify a proposed AI use case against your registry — approved, conditional, or not approved — and produce required conditions and next steps.
Use Case Triage is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Classify a proposed AI use case against your registry — approved, conditional, or not approved — and produce required conditions and next steps. Flags cross-plugin handoffs to privacy or product counsel. Use when user says "triage this use case", "can we use AI for X", "is this approved", "what do we need to do to use AI for X".
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering AI governance. The repository describes itself as: A suite of plugins for legal workflows. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Use Case Triage loads about 4.8k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 2,568 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 2,568 words, ~4,789 tokens.
.claude/skills/use-case-triage/SKILL.md (or your agent's skills folder).~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. Confirm registry is populated — if not, stop and direct to setup./ai-governance-legal:use-case-triage "Sales team wants to score leads with AI automatically"Matter context. Check ## Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run /ai-governance-legal:matter-workspace switch <slug> or say practice-level." Load the active matter's matter.md for matter-specific context and overrides. Write outputs to the matter folder at ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/. Never read another matter's files unless Cross-matter context is on.
Stop the conversation that happens in a hallway and starts as "can we just use AI for this?" Give a fast, calibrated answer from the registry — and if the answer is conditional, make the conditions concrete and the next step obvious.
The triage skill is a gateway, not a destination. Its job is to classify, flag what's required, and route. The aia-generation skill does the deep work.
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md firstBefore triaging, always read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. The use case registry and red lines there
are authoritative. Generic AI ethics reasoning is not a substitute for what this
company has actually decided.
If ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md contains [PLACEHOLDER], surface this bounce:
I notice you haven't configured your practice profile yet — that's how I tailor the use case registry, red lines, and governance tiers to your practice.
Two choices:
- Run
/ai-governance-legal:cold-start-interview(2 minutes) to configure your profile, then I'll triage tailored to YOUR practice.- Say "provisional" and I'll triage against generic defaults — US jurisdiction, middle risk appetite, lawyer role, no playbook — and tag every output
[PROVISIONAL — configure your profile for tailored output]so you can see what I do before committing.
If the user says "provisional," run triage normally using these generic defaults: middle risk appetite, lawyer role, US jurisdiction, no registry (classify by general AI governance principles rather than matching to a registered entry). Tag the reviewer note and every finding block with [PROVISIONAL]. At the end of the output, append:
"That was a generic run against default assumptions. Run
/ai-governance-legal:cold-start-interviewto get output calibrated to YOUR practice — your registry, your jurisdiction, your risk appetite. 2 minutes."
Jurisdictional scope. Triage applies the registry, red lines, and governance tiers configured for the regulatory footprint in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. AI rules vary materially by jurisdiction — an APPROVED classification in one footprint may be CONDITIONAL or prohibited in another. If deployment touches a jurisdiction not in the footprint, surface that and re-triage rather than extending by analogy.
Before classifying, make sure you understand what's actually being proposed. If the description is vague, ask:
Don't let "we want to use AI for [vague thing]" go untriaged. Get specific enough to classify accurately.
Check the use case registry in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md for a direct or close match.
Direct match: If the registry has a directly matching entry, apply it.
Near match: If the use case is similar to a registry entry but not identical, flag this: "This looks like [registered use case] — I'm applying that classification, but if the scope is meaningfully different, it may need its own assessment."
No match: If the use case isn't in the registry, default to CONDITIONAL pending an AI impact assessment. Surface the preliminary read on risk and route to the AIA.
"This use case isn't in your registry yet. Defaulting to CONDITIONAL pending an AI impact assessment. Here's my preliminary read on risk: [preliminary read]. Next step: run the impact assessment, and I'll add the use case to the registry once classification is settled."
Triage typically stays high-level, but if the classification depends on citing a regulation, statute, rule, directive, standard, or guidance — tag the citation. Do not output untagged regulatory citations in the triage reasoning, the red-line explanation, or the conditions list. A triage that says "Art. 22(1)" without a tag is exactly where a fabricated pinpoint slips past the reader.
Source attribution tiering. For model-knowledge citations, use one of three tiers:
[settled] — stable, well-known statutory and regulatory references unlikely to have changed (e.g., GDPR Art. 22 as a concept, the existence of Regulation (EU) 2024/1689 as the EU AI Act). Still verify before certifying, but lower priority.[verify] — model-knowledge citations that are real but should be verified: specific delegated / implementing acts, regulator guidance, standards, effective dates, thresholds, post-2023 amendments.[verify-pinpoint] — pinpoint citations (specific article numbers, annex references, subsection letters, paragraph numbers) carry the highest fabrication risk and should ALWAYS be verified against a primary source. EU AI Act article numbers in particular shifted during consolidation; every pinpoint cite to the Act should be verified against the Official Journal text.Other sources keep their own tags: [registry] when drawn from the practice profile's use case registry; [Westlaw], [EUR-Lex], [regulator site], or the MCP tool name when retrieved from a connected legal research tool; [web search — verify] for web-search citations; [user provided] for user-supplied citations. The tiering surfaces the real verification work — a reader who verifies everything verifies nothing. Never strip or collapse the tags.
For non-lawyer users, uncertain dates and thresholds go in a confirm-list, not inline. A [verify] tag on "effective February 1, 2026" reads as "effective February 1, 2026" to someone who doesn't know what the tag means. Read ## Who's using this in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If Role is Non-lawyer and an effective date, phase-in, threshold, or deadline is uncertain (would carry [verify] or [verify-pinpoint] if inline), replace the inline assertion with "effective date: confirm with counsel" (or "threshold: confirm with counsel") and collect all uncertain assertions in a final triage section titled: "Things I'm not certain about — ask your attorney to confirm before relying on this:" with each item listed (what I said, what's uncertain, why it matters). Lawyer-role users keep the inline [verify] treatment.
Before going further, check the red lines in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.
If the use case triggers a red line — even partially, even in a charitable reading — say so immediately.
"This use case touches [red line]. Your red lines treat this as an automatic no. If there's something different about this situation, that's a conversation for legal sign-off — not a triage call."
Do not soften red line outcomes. If it's a no, it's a no.
Jurisdictional scope. Ask: "Who's affected, and where are they? (Employees / customers / the general public / specific groups.) Which jurisdictions? (Not just where your company is — where the affected people are.)"
Then check the use case against EVERY regime in the practice profile's ## Regulatory footprint, not just the primary one. Flag conflicts:
A use case that crosses jurisdictions gets the strictest applicable treatment, not the most convenient one.
The APPROVED / CONDITIONAL / NOT APPROVED buckets, the red-line definitions, and the CONDITIONAL required-controls list all come from ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → ## AI use case triage criteria and ## Use case registry. If the playbook doesn't define a criterion the use case turns on, ask the user: "Your playbook doesn't cover [specific question]. What's your default position? I'll add it to ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md so the next triage is consistent."
Before issuing an APPROVED classification (approving an AI use case for deployment): Read ## Who's using this in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If the Role is Non-lawyer:
Approving this use case for deployment has legal consequences. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:
[Generate a 1-page summary: the use case and its scope, how it maps to the registry, what policies or red lines it touches, what could go wrong in deployment, what to ask the attorney before green-lighting.]
If you need to find an attorney, solicitor, barrister, or other authorised legal professional: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent).
Do not proceed past this gate without an explicit yes. CONDITIONAL outputs do not require the gate.
Before issuing a NOT APPROVED classification that cuts off a proposed use case: Read ## Who's using this in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If the Role is Non-lawyer, a symmetric gate applies — wrongly rejecting a use case is also a consequential error, and the business will push back regardless of the triage call:
This is a full stop for a business ask. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:
[Generate a 1-page summary: the use case and its scope, the specific red line or registry entry that blocks it, what a narrower version could look like that might clear elevated tier (if anything), what the business will likely ask the attorney for, and the three questions to ask the attorney before accepting the no.]
If you need to find an attorney, solicitor, barrister, or other authorised legal professional: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent).
Do not proceed past this gate without an explicit yes. A non-lawyer issuing a hard no on the AI plugin's behalf, without an attorney in the loop, is the mirror failure of a non-lawyer issuing a hard yes.
Format for each triage output:
[WORK-PRODUCT HEADER — per plugin config ## Outputs — differs by role; see ## Who's using this]
USE CASE: [State the use case as you understand it]
CLASSIFICATION: [APPROVED / CONDITIONAL / NOT APPROVED]
Registry match: [Direct match / Near match — [name] / No match]
Reasoning: [1-3 sentences on why this classification. If approved, what makes it safe. If conditional, what creates the risk that conditions are managing. If not approved, what red line or policy position applies.]
Red lines triggered: [None / List any that apply]
If CONDITIONAL — required before proceeding:
| Requirement | Owner | Done? |
|---|---|---|
| [e.g., AI impact assessment] | [AI governance counsel] | ☐ |
| [e.g., Privacy review / PIA] | [Privacy counsel] | ☐ |
| [e.g., Human-in-the-loop requirement — no automated decisions] | [Product] | ☐ |
| [e.g., Disclosure to affected parties] | [Product / Legal] | ☐ |
| [e.g., Specific vendor only — [approved vendor name]] | [Procurement] | ☐ |
| [e.g., Legal sign-off] | [GC] | ☐ |
Governance tier: [Standard / Elevated / High — per ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md]
Approval path: [Who needs to sign off, per tier]
Next step — offer to continue:
After presenting a CONDITIONAL result, always end with:
"Want me to start the impact assessment now? I can run the intake questions and produce the assessment document without you needing to run a separate command."
If they say yes, load the aia-generation skill and continue in the same
conversation — no need to restart. Pass the use case description and governance
tier already determined.
If they say no (or don't respond), the triage result stands as a standalone output.
The AIA can be run any time with:
/ai-governance-legal:aia-generation [use case]
If NOT APPROVED:
Reason: [Specific red line, policy prohibition, or registry entry]
If there's a version of this that could work: [Optional — "A narrower version that keeps a human in the loop for every adverse decision might clear the elevated tier. That would require..."] Only include if genuinely true. Don't offer a workaround for every no.
Privacy handoff: If the use case involves personal data — employee data, customer data, behavioral data — flag it:
"This use case involves personal data. A PIA is likely required in addition to an AI impact assessment. Use
/privacy-legal:pia-generation [use case], if the plugin is installed, to run that in parallel."
Product counsel handoff: If this is a new product feature involving AI:
"If this use case is part of a product launch, loop in product counsel. Use
/product-legal:launch-review, if the plugin is installed — it will detect the AI component and route to this plugin."
Only flag handoffs that are actually relevant. Don't append both as boilerplate to every triage.
If this triage resulted in a classification that isn't in the registry yet — either a no-match or a near-match that revealed a gap:
"I'd suggest adding this to your use case registry. Proposed entry:"
| [Use case description] | [Approved/Conditional/Never] | [Conditions if any] | [Reason if Never] |"Add to
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md→ Use case registry. This means next time the same request comes up, the answer is documented and consistent."
If the user presents multiple use cases at once — a list, a backlog, a product roadmap — run through each one and output a summary table first, then expand each conditional or not-approved entry:
| # | Use case | Classification | Key condition / blocker |
|---|---|---|---|
| 1 | [use case] | 🟢 Approved | — |
| 2 | [use case] | 🟡 Conditional | Impact assessment required |
| 3 | [use case] | 🔴 Not approved | Automated adverse decision — red line |
Then expand each row that isn't a clean approved.
"We're already doing this" triage: If someone is asking for retroactive triage — the use case is already deployed — say so plainly, and before classifying from scratch, search the registry for an existing entry covering the deployed version. Retroactive triages often surface a superseded registry entry whose conditions have drifted from current practice; updating that entry is usually the right follow-up rather than adding a new row.
"This looks like retroactive triage. If this is already running without an assessment, that's a gap to document, not to wave through. I'm searching the registry for any existing entry covering this deployment before running the triage fresh. Here's the classification: [run normal triage]. If it's conditional, those conditions should be confirmed in place now, not assumed. If the registry has an existing entry and the deployed version has drifted, the right follow-up is updating that entry rather than adding a new one."
"It's just internal" doesn't change the analysis: Internal AI use affecting employees (screening, monitoring, evaluation) is often higher-risk than customer-facing AI. Flag this if the user implies internal scope reduces risk.
"The vendor says it's safe": Vendor representations don't substitute for your own impact assessment. Flag it:
"The vendor's position doesn't substitute for your own assessment — especially for anything in the elevated or high tier."
"We're just piloting": A pilot that touches real employee or customer data is not exempt from triage or impact assessment. Apply the same classification; if conditions include an impact assessment, the pilot should have one too.
End with the next-steps decision tree per CLAUDE.md ## Outputs. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.
© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in ai-governance-legal/skills/use-case-triage of anthropics/claude-for-legal.
Open the folder on GitHubat commit 4a6c651
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.
Use Case Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Use Case Triage this skillanthropics/claude-for-legal | 9.6k | 2 repos | ~4.8k | Automated safety check: Pass | Apache-2.0 | |
| Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| AI Risk Managementbriiirussell/cybersecurity-skills | 413 | — | ~3.7k | Automated safety check: Notes | MIT | |
| Eu AI Act Readinessseb1n/awesome-ai-agent-skills | 206 | — | ~3.3k | Automated safety check: Pass | MIT | |
| AI GovernanceHack23/cia | 239 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Compliance Testingpetrkindlmann/qa-skills | 170 | — | ~4.6k | Automated safety check: Pass | MIT |
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
briiirussell/cybersecurity-skills
Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…
seb1n/awesome-ai-agent-skills
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
petrkindlmann/qa-skills
Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…
cbrock84/headcount
Governs models and AI systems in production — intended use, evaluation, monitoring, human oversight, documentation, and the decision to deploy or retire.
anthropics/claude-for-legal
Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.
anthropics/claude-for-legal
Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.
anthropics/claude-for-legal
Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.
anthropics/claude-for-legal
Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.
anthropics/claude-for-legal
Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.
anthropics/claude-for-legal
Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.
Categories
Classify a proposed AI use case against your registry — approved, conditional, or not approved — and produce required conditions and next steps. Use Case Triage is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Classify a proposed AI use case against your registry — approved, conditional, or not approved — and produce required conditions and next steps.
Use Case Triage fits situations like: user says triage this use case; can we use AI for X; is this approved; what do we need to do to use AI for X.
Run `npx skills add anthropics/claude-for-legal --skill use-case-triage -a claude-code`. Or copy the skill folder (ai-governance-legal/skills/use-case-triage in anthropics/claude-for-legal) into .claude/skills/use-case-triage in your project. Claude Code loads it when a task matches its description.
Run `npx skills add anthropics/claude-for-legal --skill use-case-triage -a codex`. Or copy the skill folder (ai-governance-legal/skills/use-case-triage in anthropics/claude-for-legal) into .agents/skills/use-case-triage in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill use-case-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/use-case-triage, .gemini/skills/use-case-triage, .github/skills/use-case-triage and .opencode/skills/use-case-triage in your project.
SKILL.md names no scripts, command-line tools or credentials: Use Case Triage is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Use Case Triage is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Use Case Triage: Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), AI Risk Management (briiirussell/cybersecurity-skills, 413 stars), Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars) and AI Governance (Hack23/cia, 239 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,633 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.
Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.