Agent skill

Compliance Scan

by AojdevStudio in AojdevStudio/Finance-Guru

Privacy and security compliance scanner for the Finance Guru repo.

Custom licenceAuto-check: notesBackend & APIs

Install Compliance Scan

skills CLI
$ npx skills add AojdevStudio/Finance-Guru --skill compliance-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install AojdevStudio/Finance-Guru compliance-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/AojdevStudio/Finance-Guru.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/compliance-scan .claude/skills/compliance-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance-scan
GitHub stars
322
Token cost
~2.6k tokens
SKILL.md length
1,019 words
Files
8 (incl. scripts, references)
Skills in repo
18
Repo updated
First seen
Licence
Custom licence

At a glance

Privacy and security compliance scanner for the Finance Guru repo.

  • Works in 4 steps: Identifies the smallest containing… → Appends / to .gitignore under a #… → Re-runs git check-ignore to verify the… → …
  • The user says compliance scan
  • SKILL.md covers When to invoke, What it checks (seven layers), What counts as private and Severity gate, plus 12 more sections
  • Runs Shell and Python scripts from its folder; calls git, uv and bash

What it does

Compliance Scan is an agent skill from AojdevStudio/Finance-Guru. Privacy and security compliance scanner for the Finance Guru repo. Catches API tokens, account numbers, dispatcher URLs, owner-name leaks, untracked sensitive files, and gitignore gaps before they reach GitHub. Use this skill whenever the user says "compliance scan", "is this safe to push", "scan for PII", "secrets check", "pre-commit security", "pre-push security", "check for leaks", "PRIVACY.md compliance", "audit privacy", "any leaks", "check before push", or wants a sanity check before git push. Also run it…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `allowlist.json`, `references/DataClassification.md` and `references/secret-patterns.md`).

It sits in Backend & APIs, covering Webhooks and SOC 2 and security compliance. It works with GitHub and Git. The repository describes itself as: Self-hosted family office engine: typed Python calculators, a private SQLite ledger, and specialist agents for Claude Code and Codex. Agents propose. Typed code computes.

When your agent uses it

  • The user says compliance scan
  • Is this safe to push
  • Pre-commit security
  • Pre-push security

Example prompts

  • “compliance scan”
  • “is this safe to push”
  • “scan for PII”
  • “/compliance-scan”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identifies the smallest containing directory that's a sensible ignore unit (the immediate parent under .claude/skills/, the file itself…
  2. Appends / to .gitignore under a # Compliance scan auto-remediation block, creating the block if absent
  3. Re-runs git check-ignore to verify the path is now shielded
  4. Reports what was added so you can review the diff

What it can do on your machine

Read from SKILL.md and the folder at commit 90c235e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • uv
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance Scan loads about 2.6k tokens when it runs, and up to ~7k if it reads all its reference files. Until then it costs about 206 tokens; SKILL.md has 1,019 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~206
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:27
    s/`, `notebooks/`, `fin-guru-private/`, `.env*`) | `scripts/scan.py` |
  • NoteMentions a .env fileSKILL.md:78
    s/`, `notebooks/`, `fin-guru-private/`, `.env*`). Idempotent — re-running won't create duplicate entries.
  • NoteMentions a .env fileSKILL.md:123
    `.claude/skills/`, the file itself for `.env*`, etc.)
  • NoteMentions a .env fileSKILL.md:177
    - `.env`, `.env.*`, `*.env`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,019 words (~2,627 tokens).

“The repo's last line of defense before something compromising hits GitHub. Layered scanner that runs the existing privacy tests, looks for new patterns of leakage, and (optionally) wires itself into git push so a failed scan blocks the push.”

— opening of SKILL.md by AojdevStudio, Custom licence
name
compliance-scan

Read the full SKILL.md on GitHub

Files

SKILL.md and 7 other files (scripts, references) in .claude/skills/compliance-scan of AojdevStudio/Finance-Guru.

  • SKILL.md
  • allowlist.json
  • references/DataClassification.md
  • references/secret-patterns.md
  • references/severity-guide.md
  • references/test-pii-pattern.md
  • scripts/install-pre-push.sh
  • scripts/scan.py

Open the folder on GitHubat commit 90c235e

Compare with similar skills

Compliance Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compliance Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compliance Scan this skillAojdevStudio/Finance-Guru322—~2.6kAutomated safety check: NotesCustom licence
Gpg SigningProrise-cool/Claude-Code-Multi-Agent305—~3.9kAutomated safety check: WarnNone
Create Triggerharness/harness-skills115—~1.5kAutomated safety check: PassApache-2.0
GitHub OAuth Nango IntegrationAgentWorkforce/relay8651 repos~3.4kAutomated safety check: PassApache-2.0
Squash BugbotLFDT-Lineth/lineth-monorepo126—~3.3kAutomated safety check: PassApache-2.0
Frontmcp Channelsagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Gpg Signing

    Prorise-cool/Claude-Code-Multi-Agent

    Comprehensive guide to GPG commit signing. An agent skill from Prorise-cool/Claude-Code-Multi-Agent.

    305 GitHub stars~3.9k tokensUpdated 21 days ago
    Backend & APIsAuto-check: warnings
  • Create Trigger

    harness/harness-skills

    Generate Harness Trigger YAML for automated pipeline execution and create via MCP.

    115 GitHub stars~1.5k tokensUpdated today
    Backend & APIsAuto-check passed
  • GitHub OAuth Nango Integration

    AgentWorkforce/relay

    A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling

    865 GitHub starsUsed in 1 repo~3.4k tokens
    Backend & APIsAuto-check passed
  • Squash Bugbot

    LFDT-Lineth/lineth-monorepo

    Triage unresolved bot review comments on a GitHub PR. An agent skill from LFDT-Lineth/lineth-monorepo.

    126 GitHub stars~3.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Frontmcp Channels

    agentfront/frontmcp

    A skill your agent uses when pushing real-time notifications or events into Claude Code (or another MCP client) sessions, or building two-way chat bridges.

    146 GitHub stars~3.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Add a new Rome-managed OAuth integration for a third-party service so a user can delegate access by clicking Connect, and Rome can act on the service with the delegated token (the GitHub/Slack model…

    717 GitHub stars~3.6k tokensUpdated today
    Backend & APIsAuto-check passed

More from AojdevStudio/Finance-Guru

All 18 skills in this repo
  • Dividend Tracking

    AojdevStudio/Finance-Guru

    Refresh the local DB, then read and analyze DIVIDEND rows from familyoffice.db for Layer 2 income tracking.

    322 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Fin Guru Compliance Review

    AojdevStudio/Finance-Guru

    Compliance review of a Finance Guru deliverable or a proposed position.

    322 GitHub stars~801 tokensUpdated today
    Auto-check passed
  • Fin Guru Output Contract

    AojdevStudio/Finance-Guru

    The six-part shape of every Finance Guru analysis answer: bottom line, a numbers table that names the source command, assumptions and gaps, confidence, evidence, and the disclaimer.

    322 GitHub stars~529 tokensUpdated today
    Auto-check passed
  • Fin Guru Quant Analysis

    AojdevStudio/Finance-Guru

    Quantitative analysis of tickers or the portfolio through the engine's calculators.

    322 GitHub stars~838 tokensUpdated today
    Auto-check passed
  • Fin Guru Strategize

    AojdevStudio/Finance-Guru

    Turn research and quantitative results into a portfolio strategy with allocation changes, entry timing, position sizing, margin and dividend tactics, and an implementation plan with triggers.

    322 GitHub stars~825 tokensUpdated today
    Auto-check passed
  • Finance Report

    AojdevStudio/Finance-Guru

    Generate institutional-quality PDF analysis reports for stocks and ETFs.

    322 GitHub stars~1.7k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Compliance Scan

What does Compliance Scan do?

Privacy and security compliance scanner for the Finance Guru repo. Compliance Scan is an agent skill from AojdevStudio/Finance-Guru. Privacy and security compliance scanner for the Finance Guru repo.

When should I use Compliance Scan?

Compliance Scan fits situations like: the user says compliance scan; is this safe to push; pre-commit security; pre-push security.

How do I install Compliance Scan in Claude Code?

Run `npx skills add AojdevStudio/Finance-Guru --skill compliance-scan -a claude-code`. Or copy the skill folder (.claude/skills/compliance-scan in AojdevStudio/Finance-Guru) into .claude/skills/compliance-scan in your project. Claude Code loads it when a task matches its description.

How do I install Compliance Scan in Codex?

Run `npx skills add AojdevStudio/Finance-Guru --skill compliance-scan -a codex`. Or copy the skill folder (.claude/skills/compliance-scan in AojdevStudio/Finance-Guru) into .agents/skills/compliance-scan in your project. Codex loads it when a task matches its description.

Can I use Compliance Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AojdevStudio/Finance-Guru --skill compliance-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-scan, .gemini/skills/compliance-scan, .github/skills/compliance-scan and .opencode/skills/compliance-scan in your project.

What does Compliance Scan need to run?

Going by SKILL.md and its folder, Compliance Scan needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (git, uv and bash). Our summary lists: Python 3; A Bash shell.

Does Compliance Scan access the network?

SKILL.md contains no URLs. Its commands use git and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Compliance Scan safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Compliance Scan use?

Compliance Scan has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Compliance Scan use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.4k tokens, read only when the agent opens those files.

What are the alternatives to Compliance Scan?

Skills that share tags, products or a category with Compliance Scan: Gpg Signing (Prorise-cool/Claude-Code-Multi-Agent, 305 stars), Create Trigger (harness/harness-skills, 115 stars), GitHub OAuth Nango Integration (AgentWorkforce/relay, 865 stars) and Squash Bugbot (LFDT-Lineth/lineth-monorepo, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compliance Scan?

AojdevStudio (a GitHub user) maintains it in AojdevStudio/Finance-Guru, which has 322 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 6, 2026.

Source: AojdevStudio/Finance-Guru on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.