Agent skill

Compliance

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or…

MITAuto-check passedLegal & Compliance

Install Compliance

skills CLI
$ npx skills add ericrisco/rsc-harness --skill compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/compliance .claude/skills/compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance
GitHub stars
167
Token cost
~2.4k tokens
SKILL.md length
1,237 words
Files
6 (incl. scripts, references)
Skills in repo
227
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or…

  • Works in 4 steps: Scope to the frameworks that actually bind → Build the control register → Stand up the operating rhythm → …
  • Scoping which regulatory frameworks bind a business — SOC 2
  • SKILL.md covers Step 1 — Scope to the…, Step 2 — Build the control…, Step 3 — Stand up the… and Step 4 — Evidence discipline, plus 2 more sections
  • Runs Shell scripts from its folder

What it does

Compliance is an agent skill from ericrisco/rsc-harness. Use when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or standing up the cadence that keeps it audit-ready. NOT drafting privacy-policy/ROPA/DPA or ToS text (that is gdpr-privacy, terms-conditions), NOT hardening code (that is secure-coding).

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/frameworks.md`).

It sits in Legal & Compliance, covering Privacy and GDPR, SOC 2 and security compliance and Healthcare and finance regulation. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Scoping which regulatory frameworks bind a business — SOC 2
  • NIS2 — building a control register with owners and evidence
  • Standing up the cadence that keeps it audit-ready

Example prompts

  • “/compliance”

Requirements

  • A Bash shell

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Scope to the frameworks that actually bind
  2. Build the control register
  3. Stand up the operating rhythm
  4. Evidence discipline

What it can do on your machine

Read from SKILL.md and the folder at commit e3d5b33. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance loads about 2.4k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 1,237 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit e3d5b33, republished under its MIT licence (© ericrisco). 1,237 words, ~2,419 tokens.

Download SKILL.mdSave it as .claude/skills/compliance/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
compliance
description
Use when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or standing up the cadence that keeps it audit-ready. NOT drafting privacy-policy/ROPA/DPA or ToS text (that is gdpr-privacy, terms-conditions), NOT hardening code (that is secure-coding).
tags
compliance, soc2, iso27001, audit-readiness, controls, governance
recommends
gdpr-privacy, terms-conditions, data-policy, contracts, secure-coding
origin
risco

Compliance — scope the frameworks, build the register, run the rhythm

You turn a vague "we need to be compliant" into artifacts that survive an audit: a scoped framework list with current deadlines, a control register (one row per control, tagged to every framework it satisfies, each with an owner and an evidence source), a cadence calendar of the recurring work that keeps the program true between audits instead of scrambling once a year, and an evidence-source catalog.

Your job is scoping and orchestration, not legal opinion. You map the business to the frameworks, build the register, assign owners and cadences, and stand up the rhythm. You do not give legal advice; flag where a licensed specialist or auditor must sign off.

Route out — these are owned by siblings, not by you. You reference the resulting documents as evidence sources in the register; you do not write them here.

  • Privacy notice, ROPA, DSAR flow, consent banner → ../gdpr-privacy/SKILL.md.
  • Terms of Service, EULA, acceptable-use → ../terms-conditions/SKILL.md.
  • Internal retention/classification policy text → ../data-policy/SKILL.md.
  • Commercial contract / MSA / DPA clause drafting → ../contracts/SKILL.md.
  • Hardening the code (authn, secrets, injection, headers) → ../secure-coding/SKILL.md.

Step 1 — Scope to the frameworks that actually bind

Do not copy a framework because a competitor has it. Map business attributes to obligations. Ask the operator the attribute questions, then apply this table.

Business attributeFramework that bindsCurrent deadline / status (as of 2026-06-02)
Sells SaaS to enterprise / asked for a security reportSOC 2 (Security TSC mandatory)Type II window 3–12 months; pick scope before you start
Wants an internationally recognized ISMS certificateISO/IEC 27001:202293 Annex A controls, 4 themes; 2013→2022 transition deadline passed 31 Oct 2025, all live certs are 2022
Stores / processes / transmits cardholder dataPCI DSS v4.0.1Fully mandatory since 31 Mar 2025 — ~50 former "best practice" items (MFA on all CDE accounts, automated log review, internal vuln scans, periodic account reviews, asset inventory) are now hard requirements
Touches US protected health information (PHI/ePHI)HIPAA Security RuleIn force today. A 2024 NPRM is NOT yet finalized (mid-2026) — flag forthcoming, but note OCR is already citing the proposed standard in enforcement
Handles personal data of EU/EEA usersGDPR (as a control source)In force; feeds controls (access, breach notice, vendor DPAs). Document text → ../gdpr-privacy/SKILL.md
Builds or deploys an AI system, esp. high-risk useEU AI ActPhased — see below; 2 Aug 2026 is the active legal date for Annex III high-risk
Is an EU financial entity (or critical ICT vendor to one)DORAIn force since Jan 2025 — ICT risk mgmt, incident reporting, resilience testing, third-party risk
Operates essential/important services in the EUNIS2Transposed in 21/27 member states by Mar 2026; many set a first audit deadline of 30 Jun 2026

EU AI Act — get the dates exactly right (high audit risk):

  • Prohibited practices + AI-literacy: 2 Feb 2025.
  • GPAI-model obligations + governance + penalties: 2 Aug 2025.
  • Annex III (use-based) high-risk obligations: 2 Aug 2026.
  • Annex I (product-regulated, incl. medical devices): 2 Aug 2027.
  • The Digital Omnibus on AI (provisional trilogue agreement 7 May 2026) proposes deferring Annex III to 2 Dec 2027 and Annex I to 2 Aug 2028 — but this is NOT yet adopted. Until the amendment is published in the Official Journal, 2 Aug 2026 remains binding. Plan to the original date; flag the deferral as forthcoming-not-final.
  • Fines: up to EUR 35M or 7% of global turnover (prohibited use), up to EUR 15M or 3% (high-risk non-compliance).

Rule: treat a not-yet-adopted amendment or an NPRM as forthcoming, never as law. Why: scoping to a draft that slips leaves you out of compliance on the date that is actually still in force. See references/frameworks.md for the per-framework control summaries.

Step 2 — Build the control register

One row per control. The register is the source of truth; everything else (checklists, audit responses, the cadence calendar) is generated from it.

ColumnWhat goes in it
control-idStable internal id, e.g. AC-02
frameworkEvery framework this control satisfies (multi-tag)
ownerA named person/role accountable — never "the team"
evidenceThe exact artifact that proves it, and where it lives
cadenceHow often it is reviewed, sized by risk
last-verifiedTimestamp of the last attestation
statusmet / gap / in-progress

Bad → Good control:

text
Bad:  "We do access control."        (no owner, no proof, not testable)
Good: AC-02 | ISO A.5.18 + SOC2 CC6.2 + PCI 7.2 | owner: Head of IT |
      evidence: quarterly IdP access-export reviewed & signed |
      cadence: quarterly | last-verified: 2026-05-30 | status: met

The Good row is auditable: an auditor can ask the owner for the dated export and verify the claim in minutes.

Exploit the overlap — one control, many frameworks. SOC 2 and ISO 27001 overlap ~60–70% (risk assessment, access management, incident response, logging, change management, vendor management all count toward both). So:

  • Bad: maintain a separate register per framework → the same control gets re-documented 3 times and drifts out of sync.
  • Good: one register, each control tagged to all frameworks it satisfies. Generate the per-framework checklist as a filtered view.
Show full SKILL.md (452 more words)Show less

Step 3 — Stand up the operating rhythm

Audit-readiness is a continuous state, not an annual project. Emit a cadence calendar and put the recurring work on real dates with owners.

CadenceRecurring compliance work
DailyAutomated control monitoring / alerting (failed logins, drift)
WeeklyControl-health review — the heartbeat: walk open gaps, stale evidence, overdue owners
MonthlyEvidence refresh for high-risk controls; vulnerability-scan review
QuarterlyAccess recertification; vendor/third-party risk reassessment
AnnualFull risk assessment; policy review; penetration test; audit prep

The weekly control-health review is the single habit that kills the annual scramble. Why: a gap caught weekly is a five-minute fix; a gap discovered during the audit window is a finding. The full calendar, register schema, and audit-prep runbook live in references/operating-rhythm.md.

Step 4 — Evidence discipline

Evidence is what an auditor tests. Every piece must be:

  • Timestamped — undated evidence proves nothing about when the control ran.
  • Mapped to the requirement — link the artifact back to the framework clause (e.g. this export proves ISO A.5.18 and SOC2 CC6.2).
  • Owner-attested — the named owner signs/confirms it, so accountability is traceable.
  • Refreshed on cadence — point-in-time evidence rots; a screenshot from last year does not prove a control operated over the audit window (Type II tests operating effectiveness across 3–12 months, not a single moment).

Store evidence where it is findable on demand, not assembled in a panic the week before the auditor arrives.

Anti-patterns

Anti-patternWhy it failsDo instead
Checklist with no owners"Everyone's job" means no one's job; the auditor asks who, and the room goes silentEvery control names one accountable owner
Copying a framework you don't fall underWastes months certifying SOC 2 when the binding obligation was PCI DSSScope from business attributes (Step 1) first
Treating an NPRM / not-yet-adopted amendment as lawThe draft slips; you're non-compliant on the date still legally in forcePlan to the active date; flag drafts as forthcoming
Point-in-time evidenceA single screenshot can't prove a control operated over the Type II windowTimestamped, periodic, owner-attested evidence
One register per frameworkSame control re-documented 3× and drifts; the 60–70% overlap is wastedOne register, each control multi-tagged
Annual evidence scrambleGaps surface as audit findings instead of weekly fixesWeekly control-health review + cadence calendar
Drafting the privacy policy / DPA hereThat's legal-document substance, a different skill's laneRoute to ../gdpr-privacy/SKILL.md / ../contracts/SKILL.md
Giving a legal opinionYou scope and orchestrate; you are not counselFlag where a licensed specialist or auditor must sign off

Verify

scripts/verify.sh <register> lints a control register (Markdown table or CSV): it checks the required columns exist and that no row is missing an owner, evidence, or cadence — the cardinal sin of checklist theater. Read-only, exits 0 on a clean or empty register.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/compliance of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/frameworks.md
  • references/operating-rhythm.md
  • scripts/verify.sh

Open the folder on GitHubat commit e3d5b33

Compare with similar skills

Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compliance this skillericrisco/rsc-harness167—~2.4kAutomated safety check: PassMIT
Security Compliancesangrokjung/claude-forge8502 repos~7.2kAutomated safety check: PassMIT
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT
ComplianceRightNow-AI/openfang18k—~921Automated safety check: PassApache-2.0

Similar skills

  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    850 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Compliance

    RightNow-AI/openfang

    Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

    18k GitHub stars~921 tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    113 GitHub stars~4.7k tokensUpdated today
    Legal & ComplianceAuto-check passed

More from ericrisco/rsc-harness

All 227 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    167 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    167 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    167 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    167 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    167 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    167 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Questions about Compliance

What does Compliance do?

A skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or…. Compliance is an agent skill from ericrisco/rsc-harness. Use when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or standing up the cadence that keeps it audit-ready.

When should I use Compliance?

Compliance fits situations like: scoping which regulatory frameworks bind a business — SOC 2; NIS2 — building a control register with owners and evidence; standing up the cadence that keeps it audit-ready.

How do I install Compliance in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill compliance -a claude-code`. Or copy the skill folder (skills/compliance in ericrisco/rsc-harness) into .claude/skills/compliance in your project. Claude Code loads it when a task matches its description.

How do I install Compliance in Codex?

Run `npx skills add ericrisco/rsc-harness --skill compliance -a codex`. Or copy the skill folder (skills/compliance in ericrisco/rsc-harness) into .agents/skills/compliance in your project. Codex loads it when a task matches its description.

Can I use Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance, .gemini/skills/compliance, .github/skills/compliance and .opencode/skills/compliance in your project.

What does Compliance need to run?

Going by SKILL.md and its folder, Compliance needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Compliance use?

Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compliance use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Compliance?

Skills that share tags, products or a category with Compliance: Security Compliance (sangrokjung/claude-forge, 850 stars), Compliance Os (alirezarezvani/claude-skills, 28k stars), Audit Report (harness/harness-skills, 115 stars) and Ciso Advisor (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compliance?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 167 GitHub stars. The repository holds 227 skills in this directory. The repository was last updated on October 7, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.