Cometchat Compliance
cometchat/cometchat-skills
Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery…
A skill your agent uses when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art.
$ npx skills add ericrisco/rsc-harness --skill data-policy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness data-policy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/data-policy .claude/skills/data-policy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "data-policy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/data-policy into .claude/skills/data-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-policy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/data-policyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill data-policy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness data-policy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/data-policy .agents/skills/data-policy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "data-policy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/data-policy into .agents/skills/data-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-policy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill data-policy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness data-policy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/data-policy .cursor/skills/data-policy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "data-policy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/data-policy into .cursor/skills/data-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-policy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/data-policy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill data-policy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness data-policy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/data-policy .gemini/skills/data-policy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "data-policy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/data-policy into .gemini/skills/data-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-policy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness data-policyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill data-policy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/data-policy .github/skills/data-policy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "data-policy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/data-policy into .github/skills/data-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-policy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill data-policy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness data-policy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/data-policy .opencode/skills/data-policy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "data-policy" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/data-policy into .opencode/skills/data-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "data-policy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
data-policyA skill your agent uses when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art.
Data Policy is an agent skill from ericrisco/rsc-harness. Use when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art. 6 lawful-basis register, an Art. 30 ROPA, or a consent capture/withdrawal model. NOT the public privacy notice or DSAR handling (that is gdpr-privacy), NOT SOC 2 posture (that is compliance).
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/consent-and-ropa.md`).
It sits in Legal & Compliance, covering Privacy and GDPR, SOC 2 and security compliance and Data governance. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Data Policy loads about 3.1k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,463 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,463 words, ~3,132 tokens.
.claude/skills/data-policy/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.You produce the structured governance artifacts engineering and ops implement — a retention schedule, a lawful-basis register, a Record of Processing Activities (ROPA), a consent model — not the public-facing notice users read (that is ../gdpr-privacy/SKILL.md). You are not a DPO and you never claim to be one.
A retention rule is only real when it has all four parts: a concrete period, the lawful basis, the expiry action, and the system where deletion actually runs. A policy that names a period but never deletes anything is a paper policy — and a paper policy is precisely what regulators fine. Cumulative GDPR fines hit ~EUR 5.65B across ~2,245 actions by March 2025, and the two failures that recur are no systematic data classification and no automated deletion capability (Secure Privacy / CMS Enforcement Tracker, 2025). Every schedule you emit ends with the DPO/counsel sign-off boundary below.
Map the request to one artifact before writing anything. Each routes to a section.
| Operator says | Artifact | Go to |
|---|---|---|
| "How long do we keep X / write our retention policy" | Retention schedule | Build the retention schedule |
| "Is our basis consent or legitimate interest?" | Lawful-basis register | Pick the lawful basis |
| "Set up a ROPA / Article 30 record" | ROPA row | The ROPA |
| "Design consent capture / withdrawal" | Consent matrix | Consent model |
| "Auto-delete but keep legal holds / backups still have data" | Deletion workflow | Make it real in systems |
If they want the public privacy notice, DPA clauses, or SOC 2 readiness instead, stop and route them — see the boundary below.
This is the core artifact. For every category of personal data, walk five columns in order: data category -> purpose -> lawful basis -> retention period -> expiry action -> system of record. GDPR's storage-limitation principle (Art. 5(1)(e)) requires data be held in identifiable form no longer than necessary for the purpose it was collected for; GDPR sets no fixed periods — duration is driven by purpose plus sector law (gdpr-info.eu Art. 5; Usercentrics, 2026).
The expiry action is one of three, and you must pick one explicitly:
Worked example. The Bad version is what gets fined; the Good version is enforceable.
Bad: Customer data — kept as long as necessary.
Good: | Category | Purpose | Lawful basis | Period | Expiry | System of record |
| Customer orders | fulfil + tax | Art. 6(1)(b) +(c) | 36 mo after last order | anonymize| Postgres `orders` + DWH|Working default periods — starting points, never asserted as universally lawful; validate against local + sector law (Usercentrics; Secure Privacy, 2026):
| Category | Common default | Basis it usually rides on |
|---|---|---|
| Accounting / tax records | ~10 years (statutory in most EU states) | Art. 6(1)(c) legal obligation |
| HR records (post-employment) | ~3–6 years | Art. 6(1)(b)/(c) |
| Customer / CRM | ~3 years after last interaction | Art. 6(1)(b)/(f) |
| Marketing consent records | life of consent + proof | Art. 6(1)(a) consent |
| Support tickets | 1–3 years | Art. 6(1)(b)/(f) |
| Server / access logs | short (30–180 days typical) | Art. 6(1)(f) legitimate interest |
Every processing activity in the ROPA should appear as a row here. The full fillable template with the delete-vs-anonymize-vs-archive note and the validation checklist lives in references/retention-schedule.md.
Art. 6 gives six lawful bases, and you must identify one before processing starts: consent, contract, legal obligation, vital interests, public task, legitimate interests (gdpr-info.eu Art. 6; IAPP). Consent is one of six and is often the weakest choice for operational data.
The trap: defaulting everything to consent. Consent is revocable at any time, so building contract-essential processing on it means a withdrawal can leave you unable to deliver the service. Use contract (Art. 6(1)(b)) for what the service requires, legal obligation (Art. 6(1)(c)) for statutory keep-periods, and legitimate interest (Art. 6(1)(f)) for fraud prevention, security logging, and most analytics. Reserve consent (Art. 6(1)(a)) for marketing and non-essential cookies/trackers.
When you lean on legitimate interest, run the three-part balancing test and write it down:
Anchor this to the EDPB Guidelines 1/2024 on legitimate interest (Oct 2024). The worksheet is in references/consent-and-ropa.md.
A ROPA (Art. 30) is the central inventory: one row per processing activity. Minimum columns: activity, purpose, data categories + data subjects, recipients, transfers, retention period, security measures. Art. 30 does not strictly require logging the Art. 6 basis — but record it per row anyway; it speeds audits, DPIAs, and notice updates (TermsFeed; Legiscope, 2026).
Activity: Customer support ticketing
Purpose: resolve and track support requests
Data cats: name, email, account ID, message content | Subjects: customers
Recipients: internal support team; Zendesk (processor)
Transfers: US (SCCs in place) — point to gdpr-privacy for the mechanism
Retention: 2 years after ticket closed, then delete
Security: RBAC, encryption at rest, access logging
Lawful basis: Art. 6(1)(b) contract ← log it even though Art. 30 doesn't demand itThe full ROPA template with a second worked row — plus the consent-matrix template and the withdrawal/refresh workflow — is in references/consent-and-ropa.md.
Where consent is the basis, it must be valid under Art. 4(11) / Art. 7: freely given, specific, informed, and unambiguous — a positive opt-in act (EDPB).
| Purpose | Basis | Capture point | Proof fields stored | Withdrawal |
| Marketing email | Art. 6(1)(a) | signup checkbox | ts, text v2.1, scope, method | one-click unsub |
| Product analytics| Art. 6(1)(a) | cookie banner | ts, banner vN, categories, method| banner re-open |One note so you don't over-promise on cookies: the ePrivacy Regulation was formally withdrawn by the European Commission in February 2025, so the ePrivacy Directive (and its national implementations) still governs cookies and trackers (Hunton; Clym, 2026). Don't cite a Regulation that does not exist.
The policy is worthless until deletion runs in the systems that actually hold the data — including backups and archives, which is exactly where regulators find data that should be gone.
Checklist:
Bad: A nightly cron deletes expired rows from the prod database.
Good: The deletion job covers prod + the data warehouse + backup snapshots;
it skips any row flagged under legal hold; and it writes a deletion
audit record (category, count, timestamp, job id) for every run.The deletion mechanics — TTL columns, partition drops, soft-delete schema — belong to ../db-migrations/SKILL.md and ../postgresdb/SKILL.md. You write the policy that those mechanics must satisfy.
State explicitly in the policy whether production data may be reused for AI/model training. GDPR purpose limitation (Art. 5(1)(b)) restricts reusing data collected for one purpose to train a model — that is a new purpose needing its own basis. The EU AI Act adds documentation and logging-retention duties, with high-risk obligations applying from 2 Aug 2026; the Commission's Digital Omnibus proposal would let AI providers lean on legitimate interest for development with enhanced safeguards and an unconditional opt-out (TechGDPR; IAPP, 2026). Practical rule: the retention policy must say whether AI reuse is allowed, on what basis, and how a subject opts out.
For cross-border transfers, name the mechanism in the ROPA row (e.g. SCCs) and point to ../gdpr-privacy/SKILL.md for the SCC/notice depth — that is its territory, not yours.
Retention periods are jurisdiction- and sector-specific, so a period you assert as final is legal advice you are not qualified to give — that is why this line has no exceptions. You produce governance drafts, not legal sign-off. Every policy you emit ends with a statement that a qualified DPO or privacy counsel must validate the schedule and lawful-basis register before adoption, and that this is not legal advice. You never assert a period is universally lawful.
Hand off the edges: public-facing privacy notice + data-subject access/erasure (DSAR) handling -> ../gdpr-privacy/SKILL.md; audit posture, SOC 2 / ISO 27001, control mapping -> ../compliance/SKILL.md; a negotiated DPA's contractual clauses or a two-party data contract -> ../contracts/SKILL.md; encryption, access hardening, threat controls on the systems -> ../secure-coding/SKILL.md; the actual deletion mechanics in the database -> ../db-migrations/SKILL.md / ../postgresdb/SKILL.md.
| Anti-pattern | Why it bites | Do instead |
|---|---|---|
| Consent as the default basis for everything | Consent is revocable; a withdrawal breaks contract-essential processing | Use contract / legal obligation / legitimate interest for operational data; reserve consent for marketing |
| "As long as necessary" / "indefinitely" as the only period | No concrete clock means nothing ever deletes — the classic paper policy | Give months/years or named criteria per category, validated against local law |
| Delete from prod but leave backups/archives untouched | The data regulators find is the copy you forgot | Deletion job must cover prod + warehouse + backups |
| No legal-hold exception in the auto-deletion job | The job destroys data under litigation hold — spoliation | Flag held rows; skip them; document the hold basis |
| Copy a generic retention template unchanged | Periods are jurisdiction/sector-specific; a copied period can be unlawful | Tag every period "validate vs local + sector law"; adjust |
| Emit the policy as final / "compliant" | Crosses into legal advice you can't give | End with DPO/counsel sign-off + not-legal-advice line |
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in skills/data-policy of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
Data Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Data Policy this skillericrisco/rsc-harness | 156 | — | ~3.1k | Automated safety check: Pass | MIT | |
| Cometchat Compliancecometchat/cometchat-skills | 129 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Nw Security And GovernancenWave-ai/nWave | 617 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance | 939 | 1 repos | ~3.3k | Automated safety check: Pass | MIT | |
| Audit Reportharness/harness-skills | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 939 | 1 repos | ~4.2k | Automated safety check: Pass | MIT |
cometchat/cometchat-skills
Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery…
nWave-ai/nWave
Database security (encryption, access control, injection prevention), data governance (lineage, quality, MDM), and compliance frameworks (GDPR, CCPA, HIPAA)
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…
sangrokjung/claude-forge
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Categories
A skill your agent uses when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art. Data Policy is an agent skill from ericrisco/rsc-harness. Use when building internal data-governance machinery: a retention schedule (period, lawful basis, expiry action, system where deletion runs), an Art.
Data Policy fits situations like: building internal data-governance machinery: a retention schedule (period; system where deletion runs).
Run `npx skills add ericrisco/rsc-harness --skill data-policy -a claude-code`. Or copy the skill folder (skills/data-policy in ericrisco/rsc-harness) into .claude/skills/data-policy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill data-policy -a codex`. Or copy the skill folder (skills/data-policy in ericrisco/rsc-harness) into .agents/skills/data-policy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill data-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/data-policy, .gemini/skills/data-policy, .github/skills/data-policy and .opencode/skills/data-policy in your project.
Going by SKILL.md and its folder, Data Policy needs a shell for the scripts in its folder. Our summary lists: A Bash shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Data Policy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Data Policy: Cometchat Compliance (cometchat/cometchat-skills, 129 stars), Nw Security And Governance (nWave-ai/nWave, 617 stars), Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars) and Audit Report (harness/harness-skills, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.