ISO Standards Readiness Evidence
K-Dense-AI/scientific-agent-skills
Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.
Checks that plugins, collected findings and history exist before a GRC /report command runs, and walks the user through setup instead of producing an empty report.
$ npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install GRCEngClub/claude-grc-engineering context-bootstrap --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/GRCEngClub/claude-grc-engineering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/grc-reporter/skills/context-bootstrap .claude/skills/context-bootstrap && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "context-bootstrap" agent skill from https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/grc-reporter/skills/context-bootstrap into .claude/skills/context-bootstrap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-bootstrap", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/grc-reporter/skills/context-bootstrapType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install GRCEngClub/claude-grc-engineering context-bootstrap --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/GRCEngClub/claude-grc-engineering.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/grc-reporter/skills/context-bootstrap .agents/skills/context-bootstrap && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "context-bootstrap" agent skill from https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/grc-reporter/skills/context-bootstrap into .agents/skills/context-bootstrap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-bootstrap", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install GRCEngClub/claude-grc-engineering context-bootstrap --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/GRCEngClub/claude-grc-engineering.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/grc-reporter/skills/context-bootstrap .cursor/skills/context-bootstrap && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "context-bootstrap" agent skill from https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/grc-reporter/skills/context-bootstrap into .cursor/skills/context-bootstrap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-bootstrap", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/GRCEngClub/claude-grc-engineering.git --path plugins/grc-reporter/skills/context-bootstrap--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install GRCEngClub/claude-grc-engineering context-bootstrap --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/GRCEngClub/claude-grc-engineering.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/grc-reporter/skills/context-bootstrap .gemini/skills/context-bootstrap && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "context-bootstrap" agent skill from https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/grc-reporter/skills/context-bootstrap into .gemini/skills/context-bootstrap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-bootstrap", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install GRCEngClub/claude-grc-engineering context-bootstrapInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/GRCEngClub/claude-grc-engineering.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/grc-reporter/skills/context-bootstrap .github/skills/context-bootstrap && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "context-bootstrap" agent skill from https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/grc-reporter/skills/context-bootstrap into .github/skills/context-bootstrap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-bootstrap", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install GRCEngClub/claude-grc-engineering context-bootstrap --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/GRCEngClub/claude-grc-engineering.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/grc-reporter/skills/context-bootstrap .opencode/skills/context-bootstrap && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "context-bootstrap" agent skill from https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/grc-reporter/skills/context-bootstrap into .opencode/skills/context-bootstrap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-bootstrap", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
context-bootstrapChecks that plugins, collected findings and history exist before a GRC /report command runs, and walks the user through setup instead of producing an empty report.
Meant to run ahead of any /report command in the GRC Engineering Club toolkit, this skill makes the agent confirm that the inputs exist rather than invent a report from nothing. It checks that the grc-engineer hub plugin, at least one connector (such as github-inspector, aws-inspector or okta-inspector) and at least one framework plugin (such as soc2, fedramp-rev5 or iso27001) are installed.
It then looks for collected findings under ~/.cache/claude-grc/findings with recent timestamps, a framework_metadata block in each framework plugin's plugin.json, metric snapshots in ./grc-data/metrics taken at least 7 days apart for week-over-week reports, and optional risk, metrics and incident files under ./grc-data.
Each command has its own minimum. The exec-summary report needs one connector, one framework and recent findings, while program-health needs two framework plugins and a gap-assessment run for each. When context is complete the agent finds it automatically and asks only a couple of questions; when it is partial, the agent names what is missing and offers an interview mode to fill the gaps.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 784fd9a. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGlobBashFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
GRC Report Context Bootstrap loads about 1.4k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 644 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Glob, BashAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 644 words (~1,423 tokens).
“Hollow reports are worse than no reports. When a user runs /report:exec-summary with an empty findings cache, the right move is to teach them the setup, not to make up a report.”
Just SKILL.md in plugins/grc-reporter/skills/context-bootstrap of GRCEngClub/claude-grc-engineering.
Open the folder on GitHubat commit 784fd9a
GRC Report Context Bootstrap next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| GRC Report Context Bootstrap this skillGRCEngClub/claude-grc-engineering | 419 | — | ~1.4k | Automated safety check: Notes | Custom licence | |
| ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~4.6k | Automated safety check: Notes | MIT | |
| Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance | 942 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| PCI DSS Compliancewshobson/agents | 40k | 11 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Quality Manager Qms Iso13485alirezarezvani/claude-skills | 28k | 1 repos | ~4.4k | Automated safety check: Pass | MIT | |
| Implementing Complianceancoleman/ai-design-components | 526 | — | ~4k | Automated safety check: Pass | MIT |
K-Dense-AI/scientific-agent-skills
Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
wshobson/agents
Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.
alirezarezvani/claude-skills
ISO 13485 Quality Management System implementation and maintenance for medical device organizations.
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
cbrock84/headcount
Owns legal, contracts, intellectual property, regulatory compliance, privacy, security governance, enterprise risk, and audit readiness.
GRCEngClub/claude-grc-engineering
Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.
GRCEngClub/claude-grc-engineering
Generates draw.io diagrams as native .drawio files, including GRC workflows and control maps, with optional PNG, SVG or PDF export that stays editable.
GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication.
GRCEngClub/claude-grc-engineering
Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export.
GRCEngClub/claude-grc-engineering
Reviews pull requests for compliance regressions. An agent skill from GRCEngClub/claude-grc-engineering.
GRCEngClub/claude-grc-engineering
Composes week-over-week automation coverage narratives. An agent skill from GRCEngClub/claude-grc-engineering.
Categories
Checks that plugins, collected findings and history exist before a GRC /report command runs, and walks the user through setup instead of producing an empty report. Meant to run ahead of any /report command in the GRC Engineering Club toolkit, this skill makes the agent confirm that the inputs exist rather than invent a report from nothing. It checks that the grc-engineer hub plugin, at least one connector (such as github-inspector, aws-inspector or okta-inspector) and at least one framework plugin (such as soc2, fedramp-rev5 or iso27001) are installed.
GRC Report Context Bootstrap fits situations like: A /report command finds an empty findings cache or no framework plugin installed; preparing a board brief and needing to know what history and risk data it requires; setting up the GRC toolkit for the first time and deciding what to install; checking whether enough metric snapshots exist for an automation coverage report.
Run `npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a claude-code`. Or copy the skill folder (plugins/grc-reporter/skills/context-bootstrap in GRCEngClub/claude-grc-engineering) into .claude/skills/context-bootstrap in your project. Claude Code loads it when a task matches its description.
Run `npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a codex`. Or copy the skill folder (plugins/grc-reporter/skills/context-bootstrap in GRCEngClub/claude-grc-engineering) into .agents/skills/context-bootstrap in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/context-bootstrap, .gemini/skills/context-bootstrap, .github/skills/context-bootstrap and .opencode/skills/context-bootstrap in your project.
Going by SKILL.md and its folder, GRC Report Context Bootstrap needs the command-line tools its instructions call (gh). Our summary lists: The grc-engineer plugin plus one connector and one framework plugin; Bash and file read access to the findings cache and the grc-data folder. Its frontmatter pre-approves these tools: Read, Glob, Bash.
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
GRC Report Context Bootstrap has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.
About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with GRC Report Context Bootstrap: ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars), Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars), PCI DSS Compliance (wshobson/agents, 40k stars) and Quality Manager Qms Iso13485 (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
GRCEngClub (a GitHub organization) maintains it in GRCEngClub/claude-grc-engineering, which has 419 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 4, 2026.
Source: GRCEngClub/claude-grc-engineering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.