Trust Center Builder
GRCEngClub/claude-grc-engineering
Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.
ISMS auditing for ISO 27001 compliance, control assessment, and certification support.
$ npx skills add borghei/Claude-Skills --skill isms-audit-expert -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install borghei/Claude-Skills isms-audit-expert --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/isms-audit-expert .claude/skills/isms-audit-expert && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "isms-audit-expert" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/isms-audit-expert into .claude/skills/isms-audit-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "isms-audit-expert", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/isms-audit-expertType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add borghei/Claude-Skills --skill isms-audit-expert -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install borghei/Claude-Skills isms-audit-expert --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ra-qm-team/isms-audit-expert .agents/skills/isms-audit-expert && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "isms-audit-expert" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/isms-audit-expert into .agents/skills/isms-audit-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "isms-audit-expert", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add borghei/Claude-Skills --skill isms-audit-expert -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install borghei/Claude-Skills isms-audit-expert --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ra-qm-team/isms-audit-expert .cursor/skills/isms-audit-expert && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "isms-audit-expert" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/isms-audit-expert into .cursor/skills/isms-audit-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "isms-audit-expert", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/borghei/Claude-Skills.git --path ra-qm-team/isms-audit-expert--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add borghei/Claude-Skills --skill isms-audit-expert -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install borghei/Claude-Skills isms-audit-expert --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ra-qm-team/isms-audit-expert .gemini/skills/isms-audit-expert && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "isms-audit-expert" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/isms-audit-expert into .gemini/skills/isms-audit-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "isms-audit-expert", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install borghei/Claude-Skills isms-audit-expertInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add borghei/Claude-Skills --skill isms-audit-expert -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/ra-qm-team/isms-audit-expert .github/skills/isms-audit-expert && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "isms-audit-expert" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/isms-audit-expert into .github/skills/isms-audit-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "isms-audit-expert", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add borghei/Claude-Skills --skill isms-audit-expert -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install borghei/Claude-Skills isms-audit-expert --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ra-qm-team/isms-audit-expert .opencode/skills/isms-audit-expert && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "isms-audit-expert" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/isms-audit-expert into .opencode/skills/isms-audit-expert/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "isms-audit-expert", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
isms-audit-expertISMS auditing for ISO 27001 compliance, control assessment, and certification support.
Isms Audit Expert is an agent skill from borghei/Claude-Skills. ISMS auditing for ISO 27001 compliance, control assessment, and certification support. Use for ISMS audit programs, internal/external ISO 27001 audits, ISO 27002 Annex A control testing, and Stage 1/Stage 2 certification audits.
Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/cloud-security-audit.md`, `references/iso27001-audit-methodology.md` and `references/security-control-testing.md`).
It sits in Legal & Compliance, covering Audit readiness and SOC 2 and security compliance. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Isms Audit Expert loads about 4.9k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 1,915 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 1,915 words, ~4,907 tokens.
.claude/skills/isms-audit-expert/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.
Before planning or executing the audit, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the audit plan.
| Risk Level | Audit Frequency | Examples |
|---|---|---|
| Critical | Quarterly | Privileged access, vulnerability management, logging |
| High | Semi-annual | Access control, incident response, encryption |
| Medium | Annual | Policies, awareness training, physical security |
| Low | Annual | Documentation, asset inventory |
ISMS AUDIT PLAN 2026
Prepared by: Information Security Manager
Approved by: CISO
Date: 2026-01-15
Q1 2026 (January-March)
Scope: Privileged access (A.8.2, A.8.18), Logging (A.8.15, A.8.16)
Auditor: External consultant (independence required)
Risk level: Critical
Q2 2026 (April-June)
Scope: Access control (A.8.3-A.8.5), Incident response (A.5.24-A.5.28)
Auditor: Internal audit team
Risk level: High
Q3 2026 (July-September)
Scope: Physical security (A.7.1-A.7.14), HR security (A.6.1-A.6.8)
Auditor: Internal audit team
Risk level: Medium
Q4 2026 (October-December)
Scope: Policies (A.5.1-A.5.8), Asset management (A.5.9-A.5.14)
Auditor: Internal audit team
Risk level: Medium-Low
Coverage: 93/93 Annex A controls scheduled across 4 quarters| Method | Use Case | Example |
|---|---|---|
| Inquiry | Process understanding | Interview Security Manager about incident response |
| Observation | Operational verification | Watch visitor sign-in process at reception |
| Inspection | Documentation review | Check access approval records for last quarter |
| Re-performance | Control testing | Attempt login with weak password to verify policy enforcement |
Organizational Controls (A.5): Information security policies, roles and responsibilities, segregation of duties, contact with authorities, threat intelligence, information security in projects.
People Controls (A.6): Screening and background checks, employment terms, security awareness and training, disciplinary process, remote working security.
Physical Controls (A.7): Physical security perimeters, entry controls, securing offices and facilities, physical security monitoring, equipment protection.
Technological Controls (A.8): User endpoint devices, privileged access rights, access restriction, secure authentication, malware protection, vulnerability management, backup and recovery, logging and monitoring, network security, cryptography.
CONTROL TEST WORKING PAPER
Control: A.8.2 - Privileged access rights
Objective: Privileged access is restricted and managed
Test date: 2026-03-10
Auditor: J. Smith
Test procedure:
1. Obtained list of privileged accounts from IAM system (42 accounts)
2. Selected sample of 10 accounts (25% sample rate)
3. For each account, verified:
- Documented business justification exists
- Manager approval on file
- Quarterly access review completed
- No dormant accounts (last login within 90 days)
Results:
- 8/10 accounts: All criteria met (PASS)
- 1/10: Missing quarterly review for Q4 2025 (MINOR NC)
- 1/10: No documented business justification (MINOR NC)
Conclusion: Control partially effective - minor nonconformity raised
Finding reference: ISMS-2026-007| Severity | Definition | Response Time |
|---|---|---|
| Major Nonconformity | Control failure creating significant risk | 30 days |
| Minor Nonconformity | Isolated deviation with limited impact | 90 days |
| Observation | Improvement opportunity | Next audit cycle |
Finding ID: ISMS-2026-007
Control Reference: A.8.2 - Privileged access rights
Severity: Minor Nonconformity
Evidence:
- 1 of 10 sampled privileged accounts missing Q4 2025 review
- 1 of 10 sampled accounts lacks documented business justification
- Screenshots of IAM records and review log exported 2026-03-10
Risk Impact:
- Unreviewed privileged access increases insider threat exposure
- Non-justified accounts may represent unnecessary attack surface
Root Cause:
- Access review process relies on manual tracking; no automated reminder
Recommendation:
- Implement automated quarterly review reminders via IAM platform
- Require business justification field as mandatory in provisioning workflow
- Backfill missing reviews within 14 days| Period | Focus |
|---|---|
| Year 1, Q2 | High-risk controls, Stage 2 findings follow-up |
| Year 1, Q4 | Continual improvement, control sample |
| Year 2, Q2 | Full surveillance |
| Year 2, Q4 | Re-certification preparation |
| Script | Purpose | Usage |
|---|---|---|
isms_audit_scheduler.py | Generate risk-based audit plans | python scripts/isms_audit_scheduler.py --year 2026 --format markdown |
# Generate annual audit plan
python scripts/isms_audit_scheduler.py --year 2026 --output audit_plan.json
# With custom control risk ratings
python scripts/isms_audit_scheduler.py --controls controls.csv --format markdown
# Generate plan for specific quarters only
python scripts/isms_audit_scheduler.py --year 2026 --quarters Q1 Q2 --format json| File | Content |
|---|---|
| iso27001-audit-methodology.md | Audit program structure, pre-audit phase, certification support |
| security-control-testing.md | Technical verification procedures for ISO 27002 controls |
| cloud-security-audit.md | Cloud provider assessment, configuration security, IAM review |
| KPI | Target | Measurement |
|---|---|---|
| Audit plan completion | 100% | Audits completed vs. planned |
| Finding closure rate | >90% within SLA | Closed on time vs. total |
| Major nonconformities | 0 at certification | Count per certification cycle |
| Audit effectiveness | Incidents prevented | Security improvements implemented |
| Framework | ISMS Audit Relevance |
|---|---|
| GDPR | A.5.34 Privacy, A.8.10 Information deletion |
| HIPAA | Access controls, audit logging, encryption |
| PCI DSS | Network security, access control, monitoring |
| SOC 2 | Trust Services Criteria mapped to ISO 27002 |
| Problem | Possible Cause | Resolution |
|---|---|---|
| Audit plan does not cover all 93 Annex A controls within the certification cycle | Controls not inventoried against the 2022 four-theme structure or risk-based scheduling gaps | Use isms_audit_scheduler.py with a complete controls CSV covering all 93 controls; ensure the 3-year cycle allocates quarterly audits for critical controls and annual coverage for all others |
| Major nonconformity found during certification audit | Systemic control failure or complete absence of a required ISMS element | Conduct immediate root cause analysis; develop corrective action plan with 30-day target; re-test the control with fresh evidence; schedule verification audit with certification body |
| Auditor independence challenged by certification body | Internal auditors assigned to areas they manage or operate | Establish clear auditor independence policy; never assign auditors to areas they are responsible for; consider external consultants for high-risk control areas; document independence verification for each audit |
| Evidence collection incomplete for technological controls (A.8) | Technical configurations not captured, logs not retained, or screenshots not timestamped | Prepare control-specific evidence checklists before audit; request system administrators to export configurations; ensure log retention covers the audit period; timestamp all evidence artifacts |
| Finding closure rate below 90% target | Corrective actions not prioritized, unclear ownership, or insufficient follow-up | Assign specific owners with due dates for every finding; implement automated tracking with escalation at 50% and 75% of SLA; conduct monthly corrective action reviews |
| Surveillance audit identifies regression in previously passed controls | Controls degraded after initial certification due to staff changes, system updates, or process drift | Implement continuous compliance monitoring (not just annual checks); schedule monthly control spot-checks for high-risk areas; include control effectiveness in management review |
| Sample-based testing misses systemic issues | Sample size too small or selection biased toward known-good records | Calculate sample size based on population and risk level (minimum 25 for quarterly reviews); use random selection methods; increase sample for areas with prior findings |
In Scope:
Out of Scope:
infrastructure-compliance-auditor for technical checksinformation-security-manager-iso27001 for implementation guidanceImportant Notes:
| Skill | Integration | When to Use |
|---|---|---|
information-security-manager-iso27001 | ISMS implementation provides the controls and documentation that audits assess | When audit findings require control improvements or ISMS enhancements |
infrastructure-compliance-auditor | Technical infrastructure checks provide audit evidence for Annex A technological controls | When audit requires evidence of A.8 technological control implementation |
soc2-compliance-expert | SOC 2 audit evidence and Trust Services Criteria overlap with ISO 27001 controls | When organization maintains both ISO 27001 and SOC 2 compliance programs |
capa-officer | Audit findings requiring formal corrective action feed into CAPA process | When major nonconformities require structured root cause analysis and corrective action |
Generates risk-based annual audit plans with quarterly scheduling based on control risk ratings.
| Flag | Required | Description |
|---|---|---|
--year <year> | No | Target year for audit plan (default: current year) |
--controls <file> | No | CSV file with custom control risk ratings (columns: control_id, name, risk); defaults to built-in risk ratings for 18 key controls |
--quarters <list> | No | Generate plan for specific quarters only (e.g., --quarters Q1 Q2) |
--format <fmt> | No | Output format: json (default) or markdown |
--output <file> | No | Export audit plan to specified file path |
Audit Frequency by Risk Level:
critical: Quarterly (4x per year) -- e.g., A.8.2 Privileged access, A.8.5 Authentication, A.8.8 Vulnerabilities, A.8.15 Logginghigh: Semi-annual (2x per year) -- e.g., A.5.15 Access control, A.5.24 Incident management, A.8.7 Malware protectionmedium: Annual (1x per year) -- e.g., A.5.1 Policies, A.6.3 Awareness training, A.7.1 Physical perimeterslow: Annual (1x per year) -- e.g., Documentation, asset inventoryOutput: Quarterly audit schedule with control assignments, auditor allocation guidance, risk-based prioritization, and coverage tracking ensuring all controls are scheduled within the certification cycle.
© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references) in ra-qm-team/isms-audit-expert of borghei/Claude-Skills.
Open the folder on GitHubat commit 4a698e8
Isms Audit Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Isms Audit Expert this skillborghei/Claude-Skills | 886 | — | ~4.9k | Automated safety check: Pass | MIT | |
| Trust Center BuilderGRCEngClub/claude-grc-engineering | 420 | — | ~2.6k | Automated safety check: Pass | Custom licence | |
| Isms Audit Expertalirezarezvani/claude-skills | 28k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Performing Soc2 Type2 Audit Preparationmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Compliance Osalirezarezvani/claude-skills | 28k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Implementing Complianceancoleman/ai-design-components | 526 | — | ~4k | Automated safety check: Pass | MIT |
GRCEngClub/claude-grc-engineering
Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.
alirezarezvani/claude-skills
Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support.
mukul975/Anthropic-Cybersecurity-Skills
Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing…
alirezarezvani/claude-skills
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
jeremylongshore/tons-of-skills-marketplace
Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification.
borghei/Claude-Skills
Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.
borghei/Claude-Skills
Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.
borghei/Claude-Skills
Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.
borghei/Claude-Skills
Idea to AI-generated prototype to customer validation to engineering handoff.
borghei/Claude-Skills
Analytics engineering across data modeling, dbt, transformation, and semantic layers.
borghei/Claude-Skills
Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.
Categories
ISMS auditing for ISO 27001 compliance, control assessment, and certification support. Isms Audit Expert is an agent skill from borghei/Claude-Skills. ISMS auditing for ISO 27001 compliance, control assessment, and certification support.
Isms Audit Expert fits situations like: ISMS audit programs; internal/external ISO 27001 audits; ISO 27002 Annex A control testing; stage 1/Stage 2 certification audits.
Run `npx skills add borghei/Claude-Skills --skill isms-audit-expert -a claude-code`. Or copy the skill folder (ra-qm-team/isms-audit-expert in borghei/Claude-Skills) into .claude/skills/isms-audit-expert in your project. Claude Code loads it when a task matches its description.
Run `npx skills add borghei/Claude-Skills --skill isms-audit-expert -a codex`. Or copy the skill folder (ra-qm-team/isms-audit-expert in borghei/Claude-Skills) into .agents/skills/isms-audit-expert in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill isms-audit-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/isms-audit-expert, .gemini/skills/isms-audit-expert, .github/skills/isms-audit-expert and .opencode/skills/isms-audit-expert in your project.
Going by SKILL.md and its folder, Isms Audit Expert needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Isms Audit Expert is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Isms Audit Expert: Trust Center Builder (GRCEngClub/claude-grc-engineering, 420 stars), Isms Audit Expert (alirezarezvani/claude-skills, 28k stars), Performing Soc2 Type2 Audit Preparation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Compliance Os (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 886 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.
Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.