Security Compliance
sangrokjung/claude-forge
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…
A skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or…
$ npx skills add ericrisco/rsc-harness --skill compliance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness compliance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/compliance .claude/skills/compliance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "compliance" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/compliance into .claude/skills/compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/complianceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill compliance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness compliance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/compliance .agents/skills/compliance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "compliance" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/compliance into .agents/skills/compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill compliance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness compliance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/compliance .cursor/skills/compliance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "compliance" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/compliance into .cursor/skills/compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/compliance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill compliance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness compliance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/compliance .gemini/skills/compliance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "compliance" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/compliance into .gemini/skills/compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness complianceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill compliance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/compliance .github/skills/compliance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "compliance" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/compliance into .github/skills/compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill compliance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness compliance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/compliance .opencode/skills/compliance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "compliance" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/compliance into .opencode/skills/compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
complianceA skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or…
Compliance is an agent skill from ericrisco/rsc-harness. Use when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or standing up the cadence that keeps it audit-ready. NOT drafting privacy-policy/ROPA/DPA or ToS text (that is gdpr-privacy, terms-conditions), NOT hardening code (that is secure-coding).
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/frameworks.md`).
It sits in Legal & Compliance, covering Privacy and GDPR, SOC 2 and security compliance and Healthcare and finance regulation. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e3d5b33. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Compliance loads about 2.4k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 1,237 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit e3d5b33, republished under its MIT licence (© ericrisco). 1,237 words, ~2,419 tokens.
.claude/skills/compliance/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.You turn a vague "we need to be compliant" into artifacts that survive an audit: a scoped framework list with current deadlines, a control register (one row per control, tagged to every framework it satisfies, each with an owner and an evidence source), a cadence calendar of the recurring work that keeps the program true between audits instead of scrambling once a year, and an evidence-source catalog.
Your job is scoping and orchestration, not legal opinion. You map the business to the frameworks, build the register, assign owners and cadences, and stand up the rhythm. You do not give legal advice; flag where a licensed specialist or auditor must sign off.
Route out — these are owned by siblings, not by you. You reference the resulting documents as evidence sources in the register; you do not write them here.
../gdpr-privacy/SKILL.md.../terms-conditions/SKILL.md.../data-policy/SKILL.md.../contracts/SKILL.md.../secure-coding/SKILL.md.Do not copy a framework because a competitor has it. Map business attributes to obligations. Ask the operator the attribute questions, then apply this table.
| Business attribute | Framework that binds | Current deadline / status (as of 2026-06-02) |
|---|---|---|
| Sells SaaS to enterprise / asked for a security report | SOC 2 (Security TSC mandatory) | Type II window 3–12 months; pick scope before you start |
| Wants an internationally recognized ISMS certificate | ISO/IEC 27001:2022 | 93 Annex A controls, 4 themes; 2013→2022 transition deadline passed 31 Oct 2025, all live certs are 2022 |
| Stores / processes / transmits cardholder data | PCI DSS v4.0.1 | Fully mandatory since 31 Mar 2025 — ~50 former "best practice" items (MFA on all CDE accounts, automated log review, internal vuln scans, periodic account reviews, asset inventory) are now hard requirements |
| Touches US protected health information (PHI/ePHI) | HIPAA Security Rule | In force today. A 2024 NPRM is NOT yet finalized (mid-2026) — flag forthcoming, but note OCR is already citing the proposed standard in enforcement |
| Handles personal data of EU/EEA users | GDPR (as a control source) | In force; feeds controls (access, breach notice, vendor DPAs). Document text → ../gdpr-privacy/SKILL.md |
| Builds or deploys an AI system, esp. high-risk use | EU AI Act | Phased — see below; 2 Aug 2026 is the active legal date for Annex III high-risk |
| Is an EU financial entity (or critical ICT vendor to one) | DORA | In force since Jan 2025 — ICT risk mgmt, incident reporting, resilience testing, third-party risk |
| Operates essential/important services in the EU | NIS2 | Transposed in 21/27 member states by Mar 2026; many set a first audit deadline of 30 Jun 2026 |
EU AI Act — get the dates exactly right (high audit risk):
Rule: treat a not-yet-adopted amendment or an NPRM as forthcoming, never as
law. Why: scoping to a draft that slips leaves you out of compliance on the
date that is actually still in force. See references/frameworks.md for the
per-framework control summaries.
One row per control. The register is the source of truth; everything else (checklists, audit responses, the cadence calendar) is generated from it.
| Column | What goes in it |
|---|---|
control-id | Stable internal id, e.g. AC-02 |
framework | Every framework this control satisfies (multi-tag) |
owner | A named person/role accountable — never "the team" |
evidence | The exact artifact that proves it, and where it lives |
cadence | How often it is reviewed, sized by risk |
last-verified | Timestamp of the last attestation |
status | met / gap / in-progress |
Bad → Good control:
Bad: "We do access control." (no owner, no proof, not testable)
Good: AC-02 | ISO A.5.18 + SOC2 CC6.2 + PCI 7.2 | owner: Head of IT |
evidence: quarterly IdP access-export reviewed & signed |
cadence: quarterly | last-verified: 2026-05-30 | status: metThe Good row is auditable: an auditor can ask the owner for the dated export and verify the claim in minutes.
Exploit the overlap — one control, many frameworks. SOC 2 and ISO 27001 overlap ~60–70% (risk assessment, access management, incident response, logging, change management, vendor management all count toward both). So:
Audit-readiness is a continuous state, not an annual project. Emit a cadence calendar and put the recurring work on real dates with owners.
| Cadence | Recurring compliance work |
|---|---|
| Daily | Automated control monitoring / alerting (failed logins, drift) |
| Weekly | Control-health review — the heartbeat: walk open gaps, stale evidence, overdue owners |
| Monthly | Evidence refresh for high-risk controls; vulnerability-scan review |
| Quarterly | Access recertification; vendor/third-party risk reassessment |
| Annual | Full risk assessment; policy review; penetration test; audit prep |
The weekly control-health review is the single habit that kills the annual
scramble. Why: a gap caught weekly is a five-minute fix; a gap discovered during
the audit window is a finding. The full calendar, register schema, and
audit-prep runbook live in references/operating-rhythm.md.
Evidence is what an auditor tests. Every piece must be:
ISO A.5.18 and SOC2 CC6.2).Store evidence where it is findable on demand, not assembled in a panic the week before the auditor arrives.
| Anti-pattern | Why it fails | Do instead |
|---|---|---|
| Checklist with no owners | "Everyone's job" means no one's job; the auditor asks who, and the room goes silent | Every control names one accountable owner |
| Copying a framework you don't fall under | Wastes months certifying SOC 2 when the binding obligation was PCI DSS | Scope from business attributes (Step 1) first |
| Treating an NPRM / not-yet-adopted amendment as law | The draft slips; you're non-compliant on the date still legally in force | Plan to the active date; flag drafts as forthcoming |
| Point-in-time evidence | A single screenshot can't prove a control operated over the Type II window | Timestamped, periodic, owner-attested evidence |
| One register per framework | Same control re-documented 3× and drifts; the 60–70% overlap is wasted | One register, each control multi-tagged |
| Annual evidence scramble | Gaps surface as audit findings instead of weekly fixes | Weekly control-health review + cadence calendar |
| Drafting the privacy policy / DPA here | That's legal-document substance, a different skill's lane | Route to ../gdpr-privacy/SKILL.md / ../contracts/SKILL.md |
| Giving a legal opinion | You scope and orchestrate; you are not counsel | Flag where a licensed specialist or auditor must sign off |
scripts/verify.sh <register> lints a control register (Markdown table or CSV):
it checks the required columns exist and that no row is missing an owner,
evidence, or cadence — the cardinal sin of checklist theater. Read-only, exits 0
on a clean or empty register.
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in skills/compliance of ericrisco/rsc-harness.
Open the folder on GitHubat commit e3d5b33
Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Compliance this skillericrisco/rsc-harness | 167 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Security Compliancesangrokjung/claude-forge | 850 | 2 repos | ~7.2k | Automated safety check: Pass | MIT | |
| Compliance Osalirezarezvani/claude-skills | 28k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Audit Reportharness/harness-skills | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Ciso Advisoralirezarezvani/claude-skills | 28k | 1 repos | ~1.8k | Automated safety check: Pass | MIT | |
| ComplianceRightNow-AI/openfang | 18k | — | ~921 | Automated safety check: Pass | Apache-2.0 |
sangrokjung/claude-forge
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…
alirezarezvani/claude-skills
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
alirezarezvani/claude-skills
Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.
RightNow-AI/openfang
Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks
aws-samples/appmod-blueprints
A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Categories
A skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or…. Compliance is an agent skill from ericrisco/rsc-harness. Use when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or standing up the cadence that keeps it audit-ready.
Compliance fits situations like: scoping which regulatory frameworks bind a business — SOC 2; NIS2 — building a control register with owners and evidence; standing up the cadence that keeps it audit-ready.
Run `npx skills add ericrisco/rsc-harness --skill compliance -a claude-code`. Or copy the skill folder (skills/compliance in ericrisco/rsc-harness) into .claude/skills/compliance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill compliance -a codex`. Or copy the skill folder (skills/compliance in ericrisco/rsc-harness) into .agents/skills/compliance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance, .gemini/skills/compliance, .github/skills/compliance and .opencode/skills/compliance in your project.
Going by SKILL.md and its folder, Compliance needs a shell for the scripts in its folder. Our summary lists: A Bash shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Compliance: Security Compliance (sangrokjung/claude-forge, 850 stars), Compliance Os (alirezarezvani/claude-skills, 28k stars), Audit Report (harness/harness-skills, 115 stars) and Ciso Advisor (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 167 GitHub stars. The repository holds 227 skills in this directory. The repository was last updated on October 7, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.