Agent skill

Whistleblower Compliance

by borghei in borghei/Claude-Skills

Audit whistleblower systems and draft compliant reporting policies.

MITAuto-check passedLegal & Compliance

Install Whistleblower Compliance

skills CLI
$ npx skills add borghei/Claude-Skills --skill whistleblower-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills whistleblower-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/legal/whistleblower-compliance .claude/skills/whistleblower-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
whistleblower-compliance
GitHub stars
891
Token cost
~3.3k tokens
SKILL.md length
999 words
Files
5 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

Audit whistleblower systems and draft compliant reporting policies.

  • Works in 2 steps: Compliance Checker… → Policy Scaffolder…
  • Building whistleblower programs
  • SKILL.md covers Overview, Table of Contents, Clarify First and Tools, plus 7 more sections
  • Runs Python scripts from its folder; calls python

What it does

Whistleblower Compliance is an agent skill from borghei/Claude-Skills. Audit whistleblower systems and draft compliant reporting policies. Use when assessing or building whistleblower programs.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/assessment_checklist.md`, `references/regulatory_framework.md` and `scripts/whistleblower_compliance_checker.py`).

It sits in Legal & Compliance. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Building whistleblower programs

Example prompts

  • “/whistleblower-compliance”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Compliance Checker (scripts/whistleblower_compliance_checker.py)
  2. Policy Scaffolder (scripts/whistleblower_policy_scaffolder.py)

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Whistleblower Compliance loads about 3.3k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 37 tokens; SKILL.md has 999 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 999 words, ~3,277 tokens.

Download SKILL.mdSave it as .claude/skills/whistleblower-compliance/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
whistleblower-compliance
description
Audit whistleblower systems and draft compliant reporting policies. Use when assessing or building whistleblower programs.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
The Glass Room
metadata.category
legal
metadata.domain
compliance
metadata.updated
2026-04-10
metadata.tags
whistleblower, compliance, eu-directive-2019-1937, sox, dodd-frank

⚠️ EXPERIMENTAL — This skill is provided for educational and informational purposes only. It does NOT constitute legal advice. All responsibility for usage rests with the user. Consult qualified legal professionals before acting on any output.

Whistleblower Compliance Skill

Overview

Production-ready whistleblower compliance toolkit for auditing existing reporting systems and drafting compliant policies. Covers EU Directive 2019/1937, US SOX Section 806, US Dodd-Frank, and UK Public Interest Disclosure Act 1998. Operates in two modes: Mode A (Assessment) runs an 8-phase, 56-checkpoint audit of existing systems; Mode B (Drafting) generates jurisdiction-specific reporting policies.

Table of Contents

Clarify First

Before generating output, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Mode: assess an existing system or draft a policy — Mode A runs a 56-checkpoint audit with gap scoring; Mode B produces a policy skeleton — completely different artifacts
  • Jurisdiction — EU, US, or UK — sets which regulation's requirements, thresholds, and timelines apply (EU 7-day ack / 3-month feedback vs SOX 180-day filing)
  • Headcount + org type — EU thresholds differ (private 50+, public sector all); determines applicability and which sections are mandatory
  • Sector — financial, healthcare, defense, nuclear, transport — triggers the Phase 8 sector-specific requirements

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the output.

Tools

1. Compliance Checker (scripts/whistleblower_compliance_checker.py)

Assess an existing whistleblower system against regulatory requirements. Takes organizational parameters and outputs a compliance score with priority-classified gaps.

bash
python scripts/whistleblower_compliance_checker.py \
  --jurisdiction EU --headcount 300 --sector financial \
  --channels internal,external --has-designated-person \
  --has-confidentiality --has-gdpr-measures --has-dissemination

python scripts/whistleblower_compliance_checker.py \
  --jurisdiction US --headcount 5000 --sector healthcare \
  --channels internal --json

python scripts/whistleblower_compliance_checker.py \
  --jurisdiction UK --headcount 50 --sector technology \
  --channels none
2. Policy Scaffolder (scripts/whistleblower_policy_scaffolder.py)

Generate a whistleblower policy skeleton pre-populated with required sections per regulatory framework.

bash
python scripts/whistleblower_policy_scaffolder.py \
  --jurisdiction EU --org-type private --headcount 500 \
  --org-name "Acme Corp"

python scripts/whistleblower_policy_scaffolder.py \
  --jurisdiction US --org-type public --headcount 10000 \
  --org-name "MegaCorp Inc" --json

python scripts/whistleblower_policy_scaffolder.py \
  --jurisdiction UK --org-type nonprofit --headcount 100 \
  --org-name "CharityOrg" --output policy-draft.md

Reference Guides

ReferencePurpose
references/regulatory_framework.mdMulti-jurisdiction whistleblower regulations, comparison matrix
references/assessment_checklist.md8-phase, 56-checkpoint assessment with priority classifications

Workflows

Mode A: Assessment Workflow
  1. Gather Parameters -- Collect jurisdiction, headcount, sector, and system description
  2. Run Compliance Checker -- Execute whistleblower_compliance_checker.py with parameters
  3. Review Gaps -- Prioritize CRITICAL gaps first, then IMPORTANT, then IMPROVEMENT
  4. Cross-Reference Checklist -- Walk through assessment_checklist.md for manual verification
  5. Generate Remediation Plan -- Address gaps by priority, set deadlines per regulatory timelines
Mode B: Drafting Workflow
  1. Determine Jurisdiction -- Identify applicable regulations based on headquarters and operations
  2. Generate Scaffold -- Run whistleblower_policy_scaffolder.py with organization details
  3. Customize Sections -- Replace placeholders with organization-specific information
  4. Legal Review -- Route draft through legal counsel for jurisdiction-specific validation
  5. Approval & Publication -- Obtain board/management approval and disseminate to all personnel
8-Phase Assessment Framework
PhaseFocusCheckpoints
1. ApplicabilityRegulatory scope determination3
2. Reception ChannelReporting channel adequacy5
3. Designated PersonsPersonnel and independence7
4. Verification/ProcessingInvestigation procedures8
5. ConfidentialityIdentity and data protection9
6. Dissemination/InformationAwareness and accessibility10
7. Data Protection/GDPRPrivacy compliance12
8. Sector-SpecificIndustry requirements6
Total60
Three Reporting Channels
ChannelWhen UsedKey Requirements
InternalFirst preference; report to organizationAcknowledge within 7 days; feedback within 3 months
External (Regulatory)When internal fails or is inappropriateReport to competent authority; same protections apply
Public DisclosureLast resort; imminent danger or retaliationProtected only if internal/external channels exhausted
Whistleblower Protections
ProtectionDescription
Civil immunityNo liability for breach of confidentiality obligations
Criminal immunityNo criminal liability for acquiring reported information
Prohibited retaliationDismissal, demotion, harassment, blacklisting, discrimination
Burden of proof reversalEmployer must prove action was not retaliatory
Interim reliefProvisional protection during investigation
Legal aid accessAccess to legal counsel and support
Priority Classification
PriorityDefinitionExample
CRITICALLegal non-compliance; immediate regulatory riskNo reporting channel exists; no confidentiality measures
IMPORTANTSignificant gap reducing system effectivenessAcknowledgment timeline exceeds 7 days; no designated person
IMPROVEMENTEnhancement opportunity; not currently non-compliantTraining frequency below best practice; limited channel types
Show full SKILL.md (393 more words)Show less

Troubleshooting

ProblemCauseSolution
Checker reports all CRITICALNo system parameters providedProvide accurate --channels, --has-designated-person, and other flags
Wrong jurisdiction requirementsMulti-jurisdiction entity using single jurisdictionRun checker separately per jurisdiction; use strictest requirements
Policy scaffold missing sectionsJurisdiction flag incorrectVerify --jurisdiction matches EU, US, or UK
Headcount threshold confusionEU directive has different thresholds by entity typePrivate sector: 50+ employees; public sector: all municipalities
Sector-specific gaps not flaggedGeneric sector value usedUse specific sector: financial, healthcare, defense, nuclear
GDPR checks fail for US entityUS entities may still need GDPR complianceIf processing EU citizen data, add --has-gdpr-measures
Timeline requirements unclearDifferent jurisdictions have different timelinesEU: 7-day ack, 3-month feedback; SOX: 180-day filing deadline
Policy output too genericMinimal parameters providedAdd --org-name, --org-type, and --headcount for specificity

Success Criteria

  • Compliance Coverage: Assessment covers 100% of applicable regulatory requirements for specified jurisdiction
  • Gap Identification: All CRITICAL and IMPORTANT gaps identified with clear remediation guidance
  • Policy Completeness: Generated policies include all mandatory sections per applicable regulation
  • Timeline Compliance: Policies reflect correct acknowledgment (7 days) and feedback (3 months) timelines
  • Audit Readiness: Assessment output sufficient for regulatory audit preparation and evidence gathering

Scope & Limitations

This skill covers:

  • Compliance assessment against EU Directive 2019/1937, US SOX/Dodd-Frank, UK PIDA
  • Policy scaffolding with jurisdiction-specific mandatory sections
  • Gap analysis with priority classification and remediation guidance
  • Multi-sector considerations (financial, healthcare, defense, nuclear, transport)

This skill does NOT cover:

  • Actual whistleblower case management or investigation procedures
  • Legal advice or attorney-client privileged analysis
  • Real-time regulatory monitoring or automatic updates when laws change
  • Whistleblower hotline software implementation or vendor selection
  • Cross-border reporting coordination between multiple regulators

Anti-Patterns

Anti-PatternWhy It FailsBetter Approach
Copy-pasting policy from another jurisdictionRegulations differ materially; EU requires 7-day ack, SOX has 180-day filingRun scaffolder with correct jurisdiction; customize per local requirements
Treating all gaps as equal priorityWastes resources on improvements while CRITICAL gaps remainAddress CRITICAL first, IMPORTANT second, IMPROVEMENT last
Single assessment for multi-jurisdiction orgEach jurisdiction has unique requirements and thresholdsRun separate assessments per jurisdiction; merge into unified policy
Skipping sector-specific phaseRegulated sectors (financial, healthcare) have additional requirementsAlways complete Phase 8 for regulated industries
No periodic reassessmentRegulations evolve; transposition deadlines passSchedule annual reassessment; monitor legislative changes

Tool Reference

scripts/whistleblower_compliance_checker.py

Assess whistleblower system compliance against regulatory requirements.

usage: whistleblower_compliance_checker.py [-h] [--json]
                                           --jurisdiction {EU,US,UK}
                                           --headcount HEADCOUNT
                                           --sector SECTOR
                                           [--channels CHANNELS]
                                           [--has-designated-person]
                                           [--has-confidentiality]
                                           [--has-gdpr-measures]
                                           [--has-dissemination]
                                           [--has-acknowledgment-timeline]
                                           [--has-feedback-timeline]

options:
  -h, --help            Show help message and exit
  --json                Output in JSON format
  --jurisdiction        Regulatory jurisdiction: EU, US, or UK
  --headcount           Number of employees in the organization
  --sector              Industry sector (financial, healthcare, technology, etc.)
  --channels            Comma-separated channel types: internal, external, none
  --has-designated-person  Designated person(s) appointed for handling reports
  --has-confidentiality    Confidentiality measures in place
  --has-gdpr-measures      GDPR/data protection measures implemented
  --has-dissemination      Policy disseminated to all personnel
  --has-acknowledgment-timeline  7-day acknowledgment timeline met
  --has-feedback-timeline  3-month feedback timeline met
scripts/whistleblower_policy_scaffolder.py

Generate jurisdiction-specific whistleblower policy skeleton.

usage: whistleblower_policy_scaffolder.py [-h] [--json]
                                          --jurisdiction {EU,US,UK}
                                          --org-type {public,private,nonprofit}
                                          --headcount HEADCOUNT
                                          [--org-name ORG_NAME]
                                          [--output OUTPUT]

options:
  -h, --help            Show help message and exit
  --json                Output in JSON format
  --jurisdiction        Regulatory jurisdiction: EU, US, or UK
  --org-type            Organization type
  --headcount           Number of employees
  --org-name            Organization name (used in policy template)
  --output              Write policy to file instead of stdout

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in legal/whistleblower-compliance of borghei/Claude-Skills.

  • SKILL.md
  • references/assessment_checklist.md
  • references/regulatory_framework.md
  • scripts/whistleblower_compliance_checker.py
  • scripts/whistleblower_policy_scaffolder.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Whistleblower Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Whistleblower Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Whistleblower Compliance this skillborghei/Claude-Skills891—~3.3kAutomated safety check: PassMIT
Paper to Chinese Patent DrafterYuan1z0825/nature-skills47k1 repos~1.1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Contract Reviewevolsb/claude-legal-skill4641 repos~3.6kAutomated safety check: PassMIT
Legal Clinic Client Intakeanthropics/claude-for-legal9.6k3 repos~3.2kAutomated safety check: PassApache-2.0
Paper To Cn Patentsnipp-zha/Paper-to-patent-Skill1071 repos~959Automated safety check: PassNone

Similar skills

  • Paper to Chinese Patent Drafter

    Yuan1z0825/nature-skills

    Drafts Chinese invention patent applications and technical disclosures from research papers or inventor materials, tying each claim feature to source evidence.

    47k GitHub starsUsed in 1 repo~1.1k tokens
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Contract Review

    evolsb/claude-legal-skill

    Review legal contracts, NDAs, employment agreements, SaaS terms, and M&A documents.

    464 GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check passed
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Legal & ComplianceAuto-check passed
  • Paper To Cn Patent

    snipp-zha/Paper-to-patent-Skill

    Convert scientific papers, theses, technical reports, source code, figures, or research manuscripts into evidence-grounded Chinese invention patent drafts.

    107 GitHub starsUsed in 1 repo~959 tokens
    Legal & ComplianceAuto-check passed
  • Employment Contract Templates

    ynulihao/AgentSkillOS

    Create employment contracts, offer letters, and HR policy documents following legal best practices.

    618 GitHub starsUsed in 12 repos~4.1k tokens
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    891 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    891 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    891 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    891 GitHub stars~3.6k tokensUpdated 3 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    891 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    891 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed

Questions about Whistleblower Compliance

What does Whistleblower Compliance do?

Audit whistleblower systems and draft compliant reporting policies. Whistleblower Compliance is an agent skill from borghei/Claude-Skills. Audit whistleblower systems and draft compliant reporting policies.

When should I use Whistleblower Compliance?

Whistleblower Compliance fits situations like: building whistleblower programs.

How do I install Whistleblower Compliance in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill whistleblower-compliance -a claude-code`. Or copy the skill folder (legal/whistleblower-compliance in borghei/Claude-Skills) into .claude/skills/whistleblower-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Whistleblower Compliance in Codex?

Run `npx skills add borghei/Claude-Skills --skill whistleblower-compliance -a codex`. Or copy the skill folder (legal/whistleblower-compliance in borghei/Claude-Skills) into .agents/skills/whistleblower-compliance in your project. Codex loads it when a task matches its description.

Can I use Whistleblower Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill whistleblower-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/whistleblower-compliance, .gemini/skills/whistleblower-compliance, .github/skills/whistleblower-compliance and .opencode/skills/whistleblower-compliance in your project.

What does Whistleblower Compliance need to run?

Going by SKILL.md and its folder, Whistleblower Compliance needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Whistleblower Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Whistleblower Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Whistleblower Compliance use?

Whistleblower Compliance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Whistleblower Compliance use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.2k tokens, read only when the agent opens those files.

What are the alternatives to Whistleblower Compliance?

Skills that share tags, products or a category with Whistleblower Compliance: Paper to Chinese Patent Drafter (Yuan1z0825/nature-skills, 47k stars), C15t (c15t/c15t, 1.9k stars), Contract Review (evolsb/claude-legal-skill, 464 stars) and Legal Clinic Client Intake (anthropics/claude-for-legal, 9.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Whistleblower Compliance?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 891 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.