HIPAA Pre-Deployment Compliance Check
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
Regulatory text mining, compliance research, and policy analysis tools
$ npx skills add wentorai/research-plugins --skill regulatory-compliance-guide -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install wentorai/research-plugins regulatory-compliance-guide --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/wentorai/research-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/domains/law/regulatory-compliance-guide .claude/skills/regulatory-compliance-guide && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "regulatory-compliance-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/domains/law/regulatory-compliance-guide into .claude/skills/regulatory-compliance-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-compliance-guide", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/wentorai/research-plugins/tree/main/skills/domains/law/regulatory-compliance-guideType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add wentorai/research-plugins --skill regulatory-compliance-guide -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install wentorai/research-plugins regulatory-compliance-guide --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wentorai/research-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/domains/law/regulatory-compliance-guide .agents/skills/regulatory-compliance-guide && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "regulatory-compliance-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/domains/law/regulatory-compliance-guide into .agents/skills/regulatory-compliance-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-compliance-guide", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wentorai/research-plugins --skill regulatory-compliance-guide -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install wentorai/research-plugins regulatory-compliance-guide --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wentorai/research-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/domains/law/regulatory-compliance-guide .cursor/skills/regulatory-compliance-guide && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "regulatory-compliance-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/domains/law/regulatory-compliance-guide into .cursor/skills/regulatory-compliance-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-compliance-guide", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/wentorai/research-plugins.git --path skills/domains/law/regulatory-compliance-guide--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add wentorai/research-plugins --skill regulatory-compliance-guide -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install wentorai/research-plugins regulatory-compliance-guide --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wentorai/research-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/domains/law/regulatory-compliance-guide .gemini/skills/regulatory-compliance-guide && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "regulatory-compliance-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/domains/law/regulatory-compliance-guide into .gemini/skills/regulatory-compliance-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-compliance-guide", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install wentorai/research-plugins regulatory-compliance-guideInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add wentorai/research-plugins --skill regulatory-compliance-guide -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/wentorai/research-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/domains/law/regulatory-compliance-guide .github/skills/regulatory-compliance-guide && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "regulatory-compliance-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/domains/law/regulatory-compliance-guide into .github/skills/regulatory-compliance-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-compliance-guide", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wentorai/research-plugins --skill regulatory-compliance-guide -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install wentorai/research-plugins regulatory-compliance-guide --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wentorai/research-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/domains/law/regulatory-compliance-guide .opencode/skills/regulatory-compliance-guide && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "regulatory-compliance-guide" agent skill from https://github.com/wentorai/research-plugins/tree/main/skills/domains/law/regulatory-compliance-guide into .opencode/skills/regulatory-compliance-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-compliance-guide", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
regulatory-compliance-guideRegulatory text mining, compliance research, and policy analysis tools
Regulatory Compliance Guide is an agent skill from wentorai/research-plugins. Regulatory text mining, compliance research, and policy analysis tools
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering Regulatory compliance and Natural language processing. The repository describes itself as: 350+ academic research skills, MCP configs, and plugins for Research-Claw and AI agents. The licence is MIT.
Read from SKILL.md and the folder at commit bf44b3c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
federalregister.govFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Regulatory Compliance Guide loads about 2.3k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 236 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from wentorai/research-plugins at commit bf44b3c, republished under its MIT licence (© wentorai). 236 words, ~2,341 tokens.
.claude/skills/regulatory-compliance-guide/SKILL.md (or your agent's skills folder).A skill for mining regulatory texts, tracking regulatory changes, and conducting compliance research. Covers accessing regulatory databases, parsing regulatory language, change detection in regulations, compliance gap analysis, and computational policy analysis.
| Source | Content | Format | Access |
|---|---|---|---|
| Federal Register API | Proposed and final rules | JSON API | Free (federalregister.gov) |
| eCFR (Electronic CFR) | Current Code of Federal Regulations | XML + API | Free (ecfr.gov) |
| Regulations.gov | Public comments on rulemakings | JSON API | Free |
| Congress.gov | Bills and legislative history | API + bulk | Free |
| SEC EDGAR | Securities filings and no-action letters | Full-text search + API | Free |
import requests
from datetime import date, timedelta
class FederalRegisterClient:
"""Client for the Federal Register API."""
BASE_URL = "https://www.federalregister.gov/api/v1"
def search_rules(self, query: str, agency: str = None,
date_from: str = None, per_page: int = 20) -> dict:
"""
Search for rules and proposed rules in the Federal Register.
"""
params = {
"conditions[term]": query,
"conditions[type][]": ["RULE", "PRORULE"],
"per_page": per_page,
"order": "newest",
}
if agency:
params["conditions[agencies][]"] = agency
if date_from:
params["conditions[publication_date][gte]"] = date_from
resp = requests.get(f"{self.BASE_URL}/documents", params=params)
data = resp.json()
return {
"count": data.get("count", 0),
"results": [
{
"title": r["title"],
"document_number": r["document_number"],
"publication_date": r["publication_date"],
"agency_names": r.get("agency_names", []),
"type": r["type"],
"abstract": r.get("abstract", ""),
"html_url": r["html_url"],
}
for r in data.get("results", [])
],
}
def get_document(self, document_number: str) -> dict:
"""Retrieve full document details by document number."""
resp = requests.get(
f"{self.BASE_URL}/documents/{document_number}.json"
)
return resp.json()Regulatory language follows predictable patterns that indicate obligation strength:
import re
from enum import Enum
class ObligationLevel(Enum):
MANDATORY = "mandatory" # shall, must, required
PROHIBITIVE = "prohibitive" # shall not, must not, prohibited
PERMISSIVE = "permissive" # may, is permitted
RECOMMENDED = "recommended" # should, is recommended
INFORMATIVE = "informative" # for information, note
OBLIGATION_PATTERNS = {
ObligationLevel.MANDATORY: [
r"\bshall\b(?!\s+not)", r"\bmust\b(?!\s+not)",
r"\bis required to\b", r"\bare required to\b",
],
ObligationLevel.PROHIBITIVE: [
r"\bshall not\b", r"\bmust not\b",
r"\bis prohibited\b", r"\bmay not\b",
],
ObligationLevel.PERMISSIVE: [
r"\bmay\b(?!\s+not)", r"\bis permitted\b",
r"\bis authorized\b",
],
ObligationLevel.RECOMMENDED: [
r"\bshould\b(?!\s+not)", r"\bis recommended\b",
r"\bit is advisable\b",
],
}
def classify_obligations(text: str) -> list[dict]:
"""
Extract and classify regulatory obligations from text.
Returns sentences tagged with their obligation level.
"""
sentences = re.split(r'(?<=[.!?])\s+', text)
results = []
for sent in sentences:
level = ObligationLevel.INFORMATIVE
for obl_level, patterns in OBLIGATION_PATTERNS.items():
if any(re.search(p, sent, re.IGNORECASE) for p in patterns):
level = obl_level
break
results.append({"sentence": sent.strip(), "obligation": level.value})
return resultsdef parse_cfr_section(xml_text: str) -> dict:
"""
Parse an eCFR XML section into structured components.
Extracts the section number, heading, paragraphs, and cross-references.
"""
root = ET.fromstring(xml_text)
section = {
"number": root.findtext(".//SECTNO", ""),
"heading": root.findtext(".//SUBJECT", ""),
"paragraphs": [],
"cross_references": [],
}
for para in root.iter("P"):
text = "".join(para.itertext()).strip()
if text:
section["paragraphs"].append(text)
# Extract cross-references to other CFR sections
xrefs = re.findall(r"\d+\s+CFR\s+[\d.]+(?:\([a-z]\))?", text)
section["cross_references"].extend(xrefs)
return sectionfrom difflib import SequenceMatcher, unified_diff
def compare_regulation_versions(old_text: str, new_text: str,
section_id: str) -> dict:
"""
Compare two versions of a regulation section to identify changes.
Returns a structured diff with change classification.
"""
old_lines = old_text.splitlines(keepends=True)
new_lines = new_text.splitlines(keepends=True)
diff = list(unified_diff(old_lines, new_lines,
fromfile=f"{section_id} (old)",
tofile=f"{section_id} (new)"))
additions = sum(1 for l in diff if l.startswith("+") and not l.startswith("+++"))
deletions = sum(1 for l in diff if l.startswith("-") and not l.startswith("---"))
similarity = SequenceMatcher(None, old_text, new_text).ratio()
return {
"section": section_id,
"similarity": round(similarity, 4),
"lines_added": additions,
"lines_removed": deletions,
"change_magnitude": "major" if similarity < 0.8 else
"minor" if similarity < 0.95 else "trivial",
"diff": "".join(diff),
}def compliance_gap_analysis(requirements: list[dict],
controls: list[dict]) -> pd.DataFrame:
"""
Map regulatory requirements to organizational controls.
Identify gaps where requirements lack corresponding controls.
requirements: [{id, text, obligation_level, cfr_section}]
controls: [{id, description, implemented, evidence}]
"""
from sklearn.feature_extraction.text import TfidfVectorizer
from sklearn.metrics.pairwise import cosine_similarity
req_texts = [r["text"] for r in requirements]
ctrl_texts = [c["description"] for c in controls]
vectorizer = TfidfVectorizer(stop_words="english", max_features=5000)
all_texts = req_texts + ctrl_texts
tfidf = vectorizer.fit_transform(all_texts)
req_vecs = tfidf[:len(req_texts)]
ctrl_vecs = tfidf[len(req_texts):]
similarity_matrix = cosine_similarity(req_vecs, ctrl_vecs)
gaps = []
for i, req in enumerate(requirements):
best_match_idx = similarity_matrix[i].argmax()
best_score = similarity_matrix[i][best_match_idx]
matched_ctrl = controls[best_match_idx] if best_score > 0.3 else None
gaps.append({
"requirement_id": req["id"],
"cfr_section": req["cfr_section"],
"obligation": req["obligation_level"],
"matched_control": matched_ctrl["id"] if matched_ctrl else "NONE",
"match_score": round(best_score, 3),
"status": "covered" if matched_ctrl and matched_ctrl["implemented"]
else "gap" if not matched_ctrl
else "planned",
})
return pd.DataFrame(gaps)Key regulated sectors with their primary frameworks:
| Sector | Primary Regulator | Key Regulations |
|---|---|---|
| Financial services | SEC, CFTC, FINRA | Dodd-Frank, SOX, MiFID II |
| Healthcare | FDA, HHS | HIPAA, 21 CFR Parts 210-211 |
| Environment | EPA | Clean Air Act, RCRA, CERCLA |
| Data privacy | FTC, state AGs | CCPA, GDPR, COPPA |
| Telecommunications | FCC | Communications Act, net neutrality rules |
| Energy | FERC, NRC | Federal Power Act, 10 CFR 50 |
© wentorai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/domains/law/regulatory-compliance-guide of wentorai/research-plugins.
Open the folder on GitHubat commit bf44b3c
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in wentorai/research-plugins, which our catalogue first saw on October 7, 2026.
Regulatory Compliance Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Regulatory Compliance Guide this skillwentorai/research-plugins | 298 | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed | 5.5k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~4.6k | Automated safety check: Notes | MIT | |
| Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Legal Compliance SearchSerein-81/financial_rag | 148 | — | ~1.6k | Automated safety check: Notes | None |
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
K-Dense-AI/scientific-agent-skills
Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Serein-81/financial_rag
Looks up current company registration rules, industry licences and compliance obligations in China through live web search, tailored to the business profile.
zh-xx/legal-assistant-skills
广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
wentorai/research-plugins
Craft structured research abstracts that maximize clarity and journal acceptance
wentorai/research-plugins
Manage academic citations across BibTeX, APA, MLA, and Chicago formats
wentorai/research-plugins
Summarize academic papers with structured extraction of key elements
wentorai/research-plugins
Evidence-based study techniques for academic learning and retention
wentorai/research-plugins
Adjust writing tone and register for academic audiences and venues
wentorai/research-plugins
Academic translation, post-editing, and Chinglish correction guide
Categories
Regulatory text mining, compliance research, and policy analysis tools. Regulatory Compliance Guide is an agent skill from wentorai/research-plugins.
Regulatory Compliance Guide fits situations like: tasks that involve Regulatory compliance; tasks that involve Natural language processing.
Run `npx skills add wentorai/research-plugins --skill regulatory-compliance-guide -a claude-code`. Or copy the skill folder (skills/domains/law/regulatory-compliance-guide in wentorai/research-plugins) into .claude/skills/regulatory-compliance-guide in your project. Claude Code loads it when a task matches its description.
Run `npx skills add wentorai/research-plugins --skill regulatory-compliance-guide -a codex`. Or copy the skill folder (skills/domains/law/regulatory-compliance-guide in wentorai/research-plugins) into .agents/skills/regulatory-compliance-guide in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wentorai/research-plugins --skill regulatory-compliance-guide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/regulatory-compliance-guide, .gemini/skills/regulatory-compliance-guide, .github/skills/regulatory-compliance-guide and .opencode/skills/regulatory-compliance-guide in your project.
SKILL.md names no scripts, command-line tools or credentials: Regulatory Compliance Guide is instructions for the agent only. Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: federalregister.gov; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Regulatory Compliance Guide is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Regulatory Compliance Guide: HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars) and Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
wentorai (a GitHub user) maintains it in wentorai/research-plugins, which has 298 GitHub stars. The repository holds 405 skills in this directory. The repository was last updated on June 19, 2026.
Source: wentorai/research-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.