Agent skill

Dora Compliance Expert

by borghei in borghei/Claude-Skills

DORA (EU 2022/2554) digital operational resilience compliance for financial entities, covering all 5 pillars.

MITAuto-check passedLegal & Compliance

Install Dora Compliance Expert

skills CLI
$ npx skills add borghei/Claude-Skills --skill dora-compliance-expert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills dora-compliance-expert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/dora-compliance-expert .claude/skills/dora-compliance-expert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dora-compliance-expert
GitHub stars
886
Token cost
~1.9k tokens
SKILL.md length
792 words
Files
9 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

DORA (EU 2022/2554) digital operational resilience compliance for financial entities, covering all 5 pillars.

  • DORA readiness assessments
  • SKILL.md covers Core Capabilities, When to Use, Clarify First and Quick Start, plus 3 more sections
  • Runs Python scripts from its folder; calls python
  • ICT risk management

What it does

Dora Compliance Expert is an agent skill from borghei/Claude-Skills. DORA (EU 2022/2554) digital operational resilience compliance for financial entities, covering all 5 pillars. Use for DORA readiness assessments, ICT risk management, incident classification, and third-party ICT oversight.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `references/dora-five-pillars-guide.md`, `references/dora-third-party-management.md` and `references/five-pillars-detail.md`).

It sits in Legal & Compliance, covering Audit readiness. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • DORA readiness assessments
  • ICT risk management
  • Incident classification
  • Third-party ICT oversight

Example prompts

  • “/dora-compliance-expert”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dora Compliance Expert loads about 1.9k tokens when it runs, and up to ~20k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 792 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~20k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 792 words, ~1,947 tokens.

Download SKILL.mdSave it as .claude/skills/dora-compliance-expert/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
dora-compliance-expert
description
DORA (EU 2022/2554) digital operational resilience compliance for financial entities, covering all 5 pillars. Use for DORA readiness assessments, ICT risk management, incident classification, and third-party ICT oversight.
license
MIT + Commons Clause
metadata.version
1.1.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
financial-resilience
metadata.updated
2026-06-15
metadata.tags
dora, ict-risk, resilience-testing, financial-services

DORA Compliance Expert

Tools and guidance for Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (Digital Operational Resilience Act — DORA). DORA is a directly applicable EU regulation (applicable since January 17, 2025) covering 20 types of financial entities and their critical ICT third-party providers. This skill assesses readiness against the five pillars, classifies ICT incidents and computes reporting deadlines, and structures third-party risk and resilience-testing programs.

Core Capabilities

  • 5-pillar readiness assessment — score ICT risk management, incident management, resilience testing, third-party risk, and information sharing (0–100 per pillar) with gap analysis and prioritized remediation
  • Incident classification & reporting — classify ICT incidents per Article 18 criteria, determine major-incident status, and compute the 4h / 72h / 1-month reporting deadlines
  • Third-party ICT risk — register structure, Article 30 contractual provisions, exit strategies, and concentration-risk assessment
  • Resilience testing program design — basic testing (12 test types) plus advanced Threat-Led Penetration Testing (TLPT) per the TIBER-EU framework

When to Use

  • Running a DORA gap assessment or readiness scorecard for a financial entity
  • Classifying an ICT incident and confirming reporting obligations to a competent authority
  • Building or auditing an ICT third-party register and contracts
  • Designing a digital operational resilience testing program (basic + TLPT)
  • Determining whether and how DORA applies to your entity

Clarify First

Before running the assessment, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Entity scope — whether the organization is one of DORA's 20 financial-entity types (determines applicability and proportionality)
  • Task — 5-pillar readiness, incident classification, third-party register, or testing-program design (picks the tool and workflow)
  • Incident facts (if classifying) — clients affected, duration, data loss, criticality, economic impact (drives major-incident determination and the 4h/72h/1-month deadlines)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the assessment.

Quick Start

bash
# Generate and run a 5-pillar readiness assessment
python scripts/dora_readiness_checker.py --template > assessment.json
python scripts/dora_readiness_checker.py --config assessment.json --json

# Classify an ICT incident and get reporting deadlines
python scripts/dora_incident_classifier.py --clients-affected 5000 --duration-hours 4 \
  --data-loss yes --services-critical yes --economic-impact 500000

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • references/framework-overview.md — DORA background, legal nature, relationship to NIS2/GDPR/PSD2/MiCA/ISO 27001, the 20 in-scope entity types, proportionality, CTPP designation, and the penalty/enforcement regime. Read when scoping applicability or assessing enforcement exposure.
  • references/five-pillars-detail.md — article-by-article requirements for all 5 pillars (Articles 5–45), incident classification & reporting deadlines, testing/TLPT, and third-party contractual provisions. Read when assessing a specific pillar or mapping a requirement to its article.
  • references/dora-five-pillars-guide.md — complete implementation guidance for all 5 pillars with ISO 27001 control mapping, financial-sector-specific requirements, and RTS/ITS references. Read when implementing controls aligned to ISO 27001.
  • references/dora-third-party-management.md — ICT third-party register template, contractual requirements checklist, exit strategy framework, concentration-risk methodology, and critical-provider oversight. Read when building the register or reviewing contracts.
  • references/implementation-and-infrastructure.md — 9-month implementation roadmap, quick wins, infrastructure verification checklists, troubleshooting table, and success criteria. Read when planning the program or diagnosing assessment results.
  • references/tools-and-cli.md — full command examples, feature lists, and flag-by-flag reference for both Python scripts. Read when running or scripting the tools.
Show full SKILL.md (318 more words)Show less

Scope & Limitations

In Scope:

  • Readiness assessment against all 5 DORA pillars with per-pillar scoring
  • ICT incident classification per Article 18 criteria with major incident determination
  • Reporting deadline calculation (4-hour initial, 72-hour intermediate, 1-month final)
  • Incident notification template generation for competent authority submissions
  • Third-party risk management guidance including register template and contractual requirements
  • Resilience testing program design covering basic and advanced (TLPT) testing
  • Gap analysis with prioritized remediation recommendations

Out of Scope:

  • Actual penetration testing execution or vulnerability scanning -- this skill provides planning and assessment frameworks, not testing tools
  • Direct interaction with competent authorities or ESAs (EBA, ESMA, EIOPA)
  • Legal determination of entity scope (whether your organization falls under DORA's 20 entity types) -- consult regulatory counsel
  • CTPP (Critical Third-Party Provider) oversight framework compliance -- applicable only to ESA-designated providers
  • Real-time ICT monitoring or SIEM implementation -- use infrastructure-compliance-auditor for technical security controls

Important Notes:

  • DORA became applicable January 17, 2025; regulators are treating 2025 as a transition year but enforcement is expected to intensify in 2026
  • Non-compliance penalties can reach up to 2% of total annual worldwide turnover or 1% of average daily global turnover for up to 6 months (for CTPPs)

Integration Points

SkillIntegrationWhen to Use
information-security-manager-iso27001ISO 27001 controls map directly to DORA Pillar 1 requirements; ISO 27001 certification supports DORA compliance evidenceWhen building ICT risk management framework aligned with both ISO 27001 and DORA
nis2-directive-specialistDORA is lex specialis for financial sector; NIS2 applies residually; coordinate incident reporting timelinesWhen financial entity also falls under NIS2 scope for non-financial ICT services
infrastructure-compliance-auditorTechnical infrastructure checks validate DORA Pillar 1 (protection, detection) and Pillar 3 (resilience testing) controlsWhen assessing actual infrastructure security posture against DORA requirements
nist-csf-specialistNIST CSF 2.0 functions map to DORA pillars; useful for organizations with US operationsWhen building a unified resilience framework across US and EU requirements

Last Updated: June 2026 Regulation Reference: EU 2022/2554 Applicable From: January 17, 2025

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references) in ra-qm-team/dora-compliance-expert of borghei/Claude-Skills.

  • SKILL.md
  • references/dora-five-pillars-guide.md
  • references/dora-third-party-management.md
  • references/five-pillars-detail.md
  • references/framework-overview.md
  • references/implementation-and-infrastructure.md
  • references/tools-and-cli.md
  • scripts/dora_incident_classifier.py
  • scripts/dora_readiness_checker.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Dora Compliance Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dora Compliance Expert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dora Compliance Expert this skillborghei/Claude-Skills886—~1.9kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.7kAutomated safety check: PassMIT
Fleet Triagegoogle-labs-code/jules-sdk137—~1.2kAutomated safety check: PassApache-2.0
PCI DSS Compliancewshobson/agents40k11 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    943 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Fleet Triage

    google-labs-code/jules-sdk

    Official

    Cognitive triage of fleet audit findings. An agent skill from google-labs-code/jules-sdk.

    137 GitHub stars~1.2k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • PCI DSS Compliance

    wshobson/agents

    Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

    40k GitHub starsUsed in 11 repos~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    420 GitHub stars~2.6k tokensUpdated 5 days ago
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    886 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    886 GitHub stars~4.2k tokensUpdated 2 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    886 GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    886 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Dora Compliance Expert

What does Dora Compliance Expert do?

DORA (EU 2022/2554) digital operational resilience compliance for financial entities, covering all 5 pillars. Dora Compliance Expert is an agent skill from borghei/Claude-Skills. DORA (EU 2022/2554) digital operational resilience compliance for financial entities, covering all 5 pillars.

When should I use Dora Compliance Expert?

Dora Compliance Expert fits situations like: DORA readiness assessments; ICT risk management; incident classification; third-party ICT oversight.

How do I install Dora Compliance Expert in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill dora-compliance-expert -a claude-code`. Or copy the skill folder (ra-qm-team/dora-compliance-expert in borghei/Claude-Skills) into .claude/skills/dora-compliance-expert in your project. Claude Code loads it when a task matches its description.

How do I install Dora Compliance Expert in Codex?

Run `npx skills add borghei/Claude-Skills --skill dora-compliance-expert -a codex`. Or copy the skill folder (ra-qm-team/dora-compliance-expert in borghei/Claude-Skills) into .agents/skills/dora-compliance-expert in your project. Codex loads it when a task matches its description.

Can I use Dora Compliance Expert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill dora-compliance-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dora-compliance-expert, .gemini/skills/dora-compliance-expert, .github/skills/dora-compliance-expert and .opencode/skills/dora-compliance-expert in your project.

What does Dora Compliance Expert need to run?

Going by SKILL.md and its folder, Dora Compliance Expert needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Dora Compliance Expert access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dora Compliance Expert safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dora Compliance Expert use?

Dora Compliance Expert is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dora Compliance Expert use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 18k tokens, read only when the agent opens those files.

What are the alternatives to Dora Compliance Expert?

Skills that share tags, products or a category with Dora Compliance Expert: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars), Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars) and Fleet Triage (google-labs-code/jules-sdk, 137 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dora Compliance Expert?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 886 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.