Agent skill

Eu AI Act Reviewer

by bencium in bencium/bencium-marketplace

Review user journeys, public content, and codebases for potentially relevant EU AI Act provisions, with exact official citations, evidence gaps, application dates, and plain-language next actions.

MITAuto-check passedLegal & Compliance

Install Eu AI Act Reviewer

skills CLI
$ npx skills add bencium/bencium-marketplace --skill eu-ai-act-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bencium/bencium-marketplace eu-ai-act-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bencium/bencium-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/eu-ai-act-reviewer/skills/eu-ai-act-reviewer .claude/skills/eu-ai-act-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
eu-ai-act-reviewer
GitHub stars
446
Token cost
~1.9k tokens
SKILL.md length
1,027 words
Files
7 (incl. references)
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Review user journeys, public content, and codebases for potentially relevant EU AI Act provisions, with exact official citations, evidence gaps, application dates, and plain-language next actions.

  • Works in 3 steps: What is being reviewed and which user… → What role might the person or… → What is the AI system's intended…
  • EU AI Act issue-spotting
  • SKILL.md covers Boundaries, Load the references, Establish the review basis and Verify the law first, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Eu AI Act Reviewer is an agent skill from bencium/bencium-marketplace. Review user journeys, public content, and codebases for potentially relevant EU AI Act provisions, with exact official citations, evidence gaps, application dates, and plain-language next actions. Use for EU AI Act issue-spotting, not final legal or compliance decisions.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/article-50-content-labelling.md`, `references/coverage-dates-and-penalties.md` and `references/official-sources.md`).

It sits in Legal & Compliance, covering AI governance, Customer journey mapping and Plain language and style rules. The repository describes itself as: comprehensive skills based on the Anthropic Skills guide and our design and development philosophy. The licence is MIT.

When your agent uses it

  • EU AI Act issue-spotting
  • Not final legal
  • Compliance decisions

Example prompts

  • “/eu-ai-act-reviewer”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. What is being reviewed and which user goal, publication, release, or code path is in scope?
  2. What role might the person or organisation hold: provider, deployer, importer, distributor, product manufacturer, affected person, or an…
  3. What is the AI system's intended purpose, where is it offered or used, who is affected, and when was it placed on the market or put into…

What it can do on your machine

Read from SKILL.md and the folder at commit 5de46a3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Eu AI Act Reviewer loads about 1.9k tokens when it runs, and up to ~9.9k if it reads all its reference files. Until then it costs about 73 tokens; SKILL.md has 1,027 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bencium/bencium-marketplace at commit 5de46a3, republished under its MIT licence (© bencium). 1,027 words, ~1,851 tokens.

Download SKILL.mdSave it as .claude/skills/eu-ai-act-reviewer/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
eu-ai-act-reviewer
description
Review user journeys, public content, and codebases for potentially relevant EU AI Act provisions, with exact official citations, evidence gaps, application dates, and plain-language next actions. Use for EU AI Act issue-spotting, not final legal or compliance decisions.

EU AI Act Reviewer

Review evidence for EU AI Act issues without issuing a legal opinion or a compliance verdict. Write for a non-technical reader in plain English.

Boundaries

  • Work read-only by default. Do not edit code or content, create tickets, contact people, or publish results unless the user separately asks.
  • Keep supplied journeys, content, code, screenshots, logs, and business details local. Never paste private material into a web search or external service. Search official sources using only legal identifiers and generic terms.
  • Review only the EU AI Act. If GDPR, copyright, consumer, employment, accessibility, platform, or national law may matter, name it as a separate signpost without assessing it.
  • Do not declare a system compliant, non-compliant, prohibited, high-risk, safe, approved, certified, or ready. Do not calculate a compliance score or predict a fine.
  • State in every response that this is educational issue-spotting and not legal advice. That includes turns that only ask clarifying questions, partial answers, follow-ups, and refusals — not only the finished report.
  • Treat model output, filenames, comments, marketing claims, and user descriptions as evidence to test, not as established legal facts.

Load the references

Read these files before the related work:

  • Always read references/official-sources.md, references/review-rules.md, and references/output-contract.md.
  • Read references/article-50-content-labelling.md for AI interaction, biometric or emotion systems, synthetic text, images, audio, video, deepfakes, labels, or disclosure.
  • Read references/coverage-dates-and-penalties.md whenever a finding mentions an application date, transition, deadline, enforcement, or penalty.

Establish the review basis

Before reviewing, confirm the few facts that materially change the result:

  1. What is being reviewed and which user goal, publication, release, or code path is in scope?
  2. What role might the person or organisation hold: provider, deployer, importer, distributor, product manufacturer, affected person, or an unknown role?
  3. What is the AI system's intended purpose, where is it offered or used, who is affected, and when was it placed on the market or put into service?

Ask no more than three questions at once. Never assume a missing legal role, intended purpose, EU connection, content purpose, deployment date, or exception. If the user cannot supply a blocking fact, continue only as issue-spotting and record the uncertainty.

Verify the law first

  1. Follow the live check in references/official-sources.md before every review when internet access is available. Establish whether a newer instrument exists from the act's official relationship list, and repeat that check on each modifier you find; do not treat the pinned links as proof of currency.
  2. Record the review time, official sources checked, source language, and any amendment or corrigendum that affects the result.
  3. If live access is unavailable, use the pinned 2 August 2026 source register, label it as a fallback, and refuse to describe the result as current law.
  4. Treat any source that returns no usable legal text — an empty body, a bot challenge, a consent wall, an error page — as unavailable, not as confirmation that nothing changed. Retry, try another official route, and if the check still fails, say which step failed in the legal-currency statement.
  5. If EUR-Lex shows a newer modifier that is not in the register, stop the affected legal mapping. Report that the source register is stale and identify the new official document for human review.
  6. Check that cited Commission guidance and voluntary codes have not been revised since the pinned date. Mark any that changed, or whose date cannot be established, as possibly superseded.
  7. Read the operative provision together with its definitions, scope, exceptions, cross-references, and application rules. Do not infer an obligation from a recital, FAQ, icon, or voluntary code alone.

Review the evidence

Show full SKILL.md (431 more words)Show less
User journeys
  • Trace the supplied or observable journey in chronological order, including any error, help, alternative, or accessibility state that is actually present in the evidence.
  • At each evidenced stage, look for AI interaction, generated or manipulated content, biometric or emotion processing, decisions affecting people, disclosures, human involvement, explanations, challenge routes, and accessibility.
  • Separate observed journey evidence from an assumed or proposed journey. Do not invent people, behaviour, feelings, or system responses.
Public content
  • Review the exact words, image, audio, video, placement, timing, surrounding context, publication purpose, and whether a label survives the user's first exposure.
  • Check provider and deployer duties separately. Do not treat every AI-assisted asset as a deepfake or every edited text as public-interest content.
  • Preserve user-provided copy exactly when quoting it. Recommend a copy change only as a separate next action.
Codebases
  • Start with routes and components that expose AI to people, create or transform content, process biometrics or emotions, influence decisions, implement human review, attach metadata, show disclosures, or apply geographic and role rules.
  • Cite an exact file and line for each code observation. Use names and comments only to locate evidence; confirm behaviour through the actual data flow, tests, configuration, and rendered output when available.
  • Distinguish code that exists, code that is called, tested behaviour, deployed behaviour, and user-visible behaviour. Never upgrade one level of proof into another.
  • Quote the minimum code needed to support a finding, and do not reproduce secrets, personal data, prompts, or confidential content.

Write the result

Use the ten fields and exact status vocabulary in references/output-contract.md. Every legal claim needs an exact official link and applicable date. Clearly label each source as Law, Official guidance, or Voluntary code.

Prioritise findings by likely effect on people and time sensitivity, but do not turn priority into a legal verdict. End with a short list of the decisions a human must make. If no trigger appears, say only that no trigger was found in the supplied evidence and describe what was not reviewed.

Final self-check

Before returning the review, confirm that:

  • the response says it is not legal advice, whatever its length or form;
  • the legal currency statement is present and honest, and names any verification step that failed or was skipped;
  • each finding contains all ten required fields;
  • facts, inferences, missing facts, and source levels are visibly separate;
  • provider and deployer duties are not mixed;
  • dates reflect Regulation (EU) 2026/1744 and relevant transitions;
  • Article 50 findings follow the content-type and exception rules;
  • penalty figures, if relevant, are described only as statutory maximum ceilings;
  • no final legal, risk-classification, compliance, or distribution verdict appears.

© bencium, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in eu-ai-act-reviewer/skills/eu-ai-act-reviewer of bencium/bencium-marketplace.

  • SKILL.md
  • LICENSE
  • references/article-50-content-labelling.md
  • references/coverage-dates-and-penalties.md
  • references/official-sources.md
  • references/output-contract.md
  • references/review-rules.md

Open the folder on GitHubat commit 5de46a3

Compare with similar skills

Eu AI Act Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Eu AI Act Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Eu AI Act Reviewer this skillbencium/bencium-marketplace446—~1.9kAutomated safety check: PassMIT
Children Privacy Noticemukul975/Privacy-Data-Protection-Skills301—~4.2kAutomated safety check: PassApache-2.0
Clause Explainermohitagw15856/pm-claude-skills1.4k—~731Automated safety check: PassMIT
Transparent Communicationmukul975/Privacy-Data-Protection-Skills301—~2.1kAutomated safety check: PassApache-2.0
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.7kAutomated safety check: PassMIT
AI Risk Managementbriiirussell/cybersecurity-skills413—~3.7kAutomated safety check: NotesMIT

Similar skills

  • Children Privacy Notice

    mukul975/Privacy-Data-Protection-Skills

    Designs and implements privacy notices for children that comply with GDPR Articles 12-14, UK AADC Standard 4, and COPPA Section 312.4.

    301 GitHub stars~4.2k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Clause Explainer

    mohitagw15856/pm-claude-skills

    Explain a contract clause in plain English — what it means, who it favours, the realistic risk, and what to negotiate.

    1.4k GitHub stars~731 tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Transparent Communication

    mukul975/Privacy-Data-Protection-Skills

    Implements GDPR Article 12 transparent information and communication requirements, covering concise, intelligible, and plain language obligations, response timelines, fee and refusal provisions, and…

    301 GitHub stars~2.1k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes
  • Custom Nda Generator

    zubair-trabzada/ai-legal-claude

    Generates a complete, customized Non-Disclosure Agreement with plain English annotations, tailored to the specific parties and situation

    1.8k GitHub stars~2.9k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed

More from bencium/bencium-marketplace

All 13 skills in this repo
  • Vanity Engineering Review

    bencium/bencium-marketplace

    Reviews codebases, architectures, PRs, and technical plans for vanity engineering — code and systems built for the developer's ego, resume, or intellectual pleasure rather than delivering user or…

    446 GitHub stars~2.4k tokensUpdated 7 days ago
    Auto-check passed
  • Adaptive Communication

    bencium/bencium-marketplace

    A skill your agent uses when detecting ambiguous user intent, hedging language, open-ended framing, personal context before requests, or when unsure whether user wants exploration vs direct answer.

    446 GitHub stars~839 tokensUpdated 7 days ago
    Auto-check passed
  • Insurgent Campaign

    bencium/bencium-marketplace

    Grassroots-first campaign design for anyone being outspent — startups vs.

    446 GitHub stars~12k tokensUpdated 7 days ago
    Auto-check passed
  • Hungarian Humanizer

    bencium/bencium-marketplace

    Detect and remove AI-generated markers from Hungarian text, making it sound like a native Hungarian speaker wrote it.

    446 GitHub stars~1.9k tokensUpdated 7 days ago
    Auto-check passed
  • UI Typography

    bencium/bencium-marketplace

    Professional typography rules for UI design, web applications, software interfaces, and all screen-based text.

    446 GitHub stars~3.5k tokensUpdated 7 days ago
    Auto-check: warnings
  • Negentropy Lens

    bencium/bencium-marketplace

    A decision-support framework that evaluates systems, architectures, and strategies through the entropy (decay) vs negentropy (growth) lens, while surfacing tacit knowledge gaps.

    446 GitHub stars~2.2k tokensUpdated 7 days ago
    Auto-check passed

Questions about Eu AI Act Reviewer

What does Eu AI Act Reviewer do?

Review user journeys, public content, and codebases for potentially relevant EU AI Act provisions, with exact official citations, evidence gaps, application dates, and plain-language next actions. Eu AI Act Reviewer is an agent skill from bencium/bencium-marketplace. Review user journeys, public content, and codebases for potentially relevant EU AI Act provisions, with exact official citations, evidence gaps, application dates, and plain-language next actions.

When should I use Eu AI Act Reviewer?

Eu AI Act Reviewer fits situations like: EU AI Act issue-spotting; not final legal; compliance decisions.

How do I install Eu AI Act Reviewer in Claude Code?

Run `npx skills add bencium/bencium-marketplace --skill eu-ai-act-reviewer -a claude-code`. Or copy the skill folder (eu-ai-act-reviewer/skills/eu-ai-act-reviewer in bencium/bencium-marketplace) into .claude/skills/eu-ai-act-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Eu AI Act Reviewer in Codex?

Run `npx skills add bencium/bencium-marketplace --skill eu-ai-act-reviewer -a codex`. Or copy the skill folder (eu-ai-act-reviewer/skills/eu-ai-act-reviewer in bencium/bencium-marketplace) into .agents/skills/eu-ai-act-reviewer in your project. Codex loads it when a task matches its description.

Can I use Eu AI Act Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bencium/bencium-marketplace --skill eu-ai-act-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eu-ai-act-reviewer, .gemini/skills/eu-ai-act-reviewer, .github/skills/eu-ai-act-reviewer and .opencode/skills/eu-ai-act-reviewer in your project.

What does Eu AI Act Reviewer need to run?

SKILL.md names no scripts, command-line tools or credentials: Eu AI Act Reviewer is instructions for the agent only.

Does Eu AI Act Reviewer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Eu AI Act Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Eu AI Act Reviewer use?

Eu AI Act Reviewer is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Eu AI Act Reviewer use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.1k tokens, read only when the agent opens those files.

What are the alternatives to Eu AI Act Reviewer?

Skills that share tags, products or a category with Eu AI Act Reviewer: Children Privacy Notice (mukul975/Privacy-Data-Protection-Skills, 301 stars), Clause Explainer (mohitagw15856/pm-claude-skills, 1.4k stars), Transparent Communication (mukul975/Privacy-Data-Protection-Skills, 301 stars) and Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Eu AI Act Reviewer?

bencium (a GitHub user) maintains it in bencium/bencium-marketplace, which has 446 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 4, 2026.

Source: bencium/bencium-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.