Agent skill

AI Governance

by Hack23 in Hack23/cia

AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

Apache-2.0Auto-check passedLegal & Compliance

Install AI Governance

skills CLI
$ npx skills add Hack23/cia --skill ai-governance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia ai-governance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/ai-governance .claude/skills/ai-governance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-governance
GitHub stars
239
Token cost
~1.4k tokens
SKILL.md length
419 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

  • Tasks that involve AI governance
  • SKILL.md covers Purpose, When to Use This Skill, EU AI Act Classification and OWASP LLM Top 10 for CIA…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve LLM guardrails

What it does

AI Governance is an agent skill from Hack23/cia. AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering AI governance, LLM guardrails and Prompt injection and agent security. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve AI governance
  • Tasks that involve LLM guardrails
  • Tasks that involve Prompt injection and agent security

Example prompts

  • “/ai-governance”

What it can do on your machine

Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml and java).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • artificialintelligenceact.eu
    • owasp.org
    • github.com
    • resources.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Governance loads about 1.4k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 419 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 419 words, ~1,433 tokens.

Download SKILL.mdSave it as .claude/skills/ai-governance/SKILL.md (or your agent's skills folder).
name
ai-governance
description
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
license
Apache-2.0

AI Governance Skill

Purpose

This skill provides governance guidelines for AI usage in the CIA platform, including GitHub Copilot agent security, EU AI Act compliance, and responsible AI practices. It ensures AI-assisted development follows Hack23 ISMS policies and regulatory requirements.

When to Use This Skill

Apply this skill when:

  • ✅ Configuring or updating GitHub Copilot agent workflows
  • ✅ Integrating AI/ML models for political data analysis
  • ✅ Reviewing AI-generated code before merge
  • ✅ Assessing AI risk classification under EU AI Act
  • ✅ Implementing prompt engineering for data analysis
  • ✅ Auditing AI agent outputs for bias or accuracy

Do NOT use for:

  • ❌ Standard code reviews without AI involvement
  • ❌ Manual data analysis without AI components
  • ❌ Infrastructure changes unrelated to AI services

EU AI Act Classification

Risk Assessment for CIA Platform
CIA Platform AI Usage Assessment
│
├─→ Political Data Analysis (NLP, trend detection)
│   ├─ Risk Level: LIMITED RISK (Article 52)
│   ├─ Requirement: Transparency obligations
│   └─ Action: Disclose AI-generated analysis to users
│
├─→ GitHub Copilot Code Generation
│   ├─ Risk Level: MINIMAL RISK
│   ├─ Requirement: Voluntary codes of conduct
│   └─ Action: Code review before merge, security scanning
│
├─→ Political Risk Scoring
│   ├─ Risk Level: HIGH RISK (Annex III, Category 8)
│   ├─ Requirement: Conformity assessment, human oversight
│   └─ Action: Human review of all risk scores, audit trail
│
└─→ Voter Behavior Prediction
    ├─ Risk Level: HIGH RISK
    ├─ Requirement: Transparency, fairness, accountability
    └─ Action: Bias testing, explainability, regular audits
Compliance Checklist
  • ✅ Document AI system purpose and intended use
  • ✅ Classify AI risk level per EU AI Act categories
  • ✅ Implement human oversight for high-risk AI outputs
  • ✅ Maintain audit trail of AI-generated decisions
  • ✅ Conduct bias and fairness assessments
  • ✅ Provide transparency notices for AI-generated content
  • ✅ Implement data governance for training datasets

OWASP LLM Top 10 for CIA Platform

LLM01: Prompt Injection

Risk: Malicious input manipulating Copilot agent behavior.

Mitigation:

yaml
# .github/copilot-instructions.md safeguards
- Validate all agent outputs before committing
- Never allow agents to modify security configurations
- Restrict agent file access to source code only
- Review agent-generated code with CodeQL scanning
LLM02: Insecure Output Handling

Risk: AI-generated code containing vulnerabilities.

Mitigation:

  • Run CodeQL on all AI-generated code changes
  • Apply OWASP secure code review checklist
  • Validate AI outputs against coding standards
  • Never trust AI-generated SQL or security logic without review
LLM06: Sensitive Information Disclosure

Risk: AI agents leaking secrets or sensitive political data.

Mitigation:

java
// Never pass sensitive data to AI prompts
// ✅ SECURE: Generic analysis request
String prompt = "Analyze voting patterns for committee " + committeeId;

// ❌ INSECURE: Including PII in prompts
String prompt = "Analyze voting for " + politicianName + " SSN: " + ssn;
Show full SKILL.md (180 more words)Show less
LLM09: Overreliance

Risk: Blindly trusting AI-generated political analysis.

Mitigation:

  • All AI analysis must include confidence scores
  • Human analyst review required for published insights
  • Cross-validate AI outputs with official data sources
  • Label AI-generated content clearly in the UI

GitHub Copilot Agent Security

Agent Configuration Best Practices
yaml
# Secure agent workflow permissions
permissions:
  contents: read      # Read-only by default
  pull-requests: write # Only for PR creation
  issues: write       # Only for issue management
  actions: read       # Read workflow status

# Never grant:
# - admin permissions
# - security_events write
# - secrets access
Agent Output Validation
Agent Output Validation Pipeline
│
├─ Step 1: Syntax validation (compile check)
├─ Step 2: Security scan (CodeQL, OWASP)
├─ Step 3: Test execution (unit + integration)
├─ Step 4: Code review (human or Copilot review)
└─ Step 5: Merge approval (maintainer sign-off)

Responsible AI Practices

Bias Prevention in Political Analysis
  • Test analysis algorithms across all 8 Swedish parties equally
  • Validate data representation for minority viewpoints
  • Audit sentiment analysis for political neutrality
  • Document model limitations and known biases
Transparency Requirements
  • Label all AI-generated content in the CIA platform UI
  • Provide methodology documentation for AI analysis
  • Enable users to access raw data behind AI insights
  • Maintain changelog of AI model updates

ISMS Alignment

ControlRequirementImplementation
ISO 27001 A.5.1Information security policiesAI governance policy
ISO 27001 A.8.1Asset managementAI model inventory
NIST CSF GV.OCOrganizational contextAI risk assessment
CIS Control 16Application securityAI code review gates
GDPR Art. 22Automated decision-makingHuman oversight for scoring

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/ai-governance of Hack23/cia.

Open the folder on GitHubat commit bbed538

Compare with similar skills

AI Governance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Governance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Governance this skillHack23/cia239—~1.4kAutomated safety check: PassApache-2.0
China AI Compliance AuditjnMetaCode/shellward140—~1.1kAutomated safety check: PassApache-2.0
Sailpillar-labs/sail-skill113—~5.1kAutomated safety check: PassCustom licence
Writing Eval Scenariosopen-bias/open-bias143—~1.5kAutomated safety check: PassApache-2.0
Defending Applicationstelagod/code-abyss243—~777Automated safety check: PassMIT
Moai Ref LLM Securitymodu-ai/moai-adk1.2k—~4.5kAutomated safety check: PassApache-2.0

Similar skills

  • China AI Compliance Audit

    jnMetaCode/shellward

    按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's…

    140 GitHub stars~1.1k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Sail

    pillar-labs/sail-skill

    Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.

    113 GitHub stars~5.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Writing Eval Scenarios

    open-bias/open-bias

    Guide for writing eval conversation JSONs and running them through policy engines

    143 GitHub stars~1.5k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Defending Applications

    telagod/code-abyss

    Application security defense knowledge for builders. An agent skill from telagod/code-abyss.

    243 GitHub stars~777 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Moai Ref LLM Security

    modu-ai/moai-adk

    AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and…

    1.2k GitHub stars~4.5k tokensUpdated today
    SecurityAuto-check passed
  • Red Teaming LLMs With Garak

    mukul975/Anthropic-Cybersecurity-Skills

    Runs NVIDIA garak probe suites (jailbreak, prompt injection, data leakage, toxicity, and more) against an LLM endpoint - Hugging Face models, OpenAI-compatible APIs, or Bedrock - then interprets the…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Business continuity and disaster recovery: 30-day retention, quarterly restore tests, RTO/RPO targets per ISO 27001 A.17

    239 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed

Questions about AI Governance

What does AI Governance do?

AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents. AI Governance is an agent skill from Hack23/cia.

When should I use AI Governance?

AI Governance fits situations like: tasks that involve AI governance; tasks that involve LLM guardrails; tasks that involve Prompt injection and agent security.

How do I install AI Governance in Claude Code?

Run `npx skills add Hack23/cia --skill ai-governance -a claude-code`. Or copy the skill folder (.github/skills/ai-governance in Hack23/cia) into .claude/skills/ai-governance in your project. Claude Code loads it when a task matches its description.

How do I install AI Governance in Codex?

Run `npx skills add Hack23/cia --skill ai-governance -a codex`. Or copy the skill folder (.github/skills/ai-governance in Hack23/cia) into .agents/skills/ai-governance in your project. Codex loads it when a task matches its description.

Can I use AI Governance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill ai-governance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-governance, .gemini/skills/ai-governance, .github/skills/ai-governance and .opencode/skills/ai-governance in your project.

What does AI Governance need to run?

SKILL.md names no scripts, command-line tools or credentials: AI Governance is instructions for the agent only.

Does AI Governance access the network?

SKILL.md names 4 domains. As links in the text: artificialintelligenceact.eu, owasp.org, github.com and resources.github.com. This is read from the text; nothing was executed.

Is AI Governance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AI Governance use?

AI Governance is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Governance use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AI Governance?

Skills that share tags, products or a category with AI Governance: China AI Compliance Audit (jnMetaCode/shellward, 140 stars), Sail (pillar-labs/sail-skill, 113 stars), Writing Eval Scenarios (open-bias/open-bias, 143 stars) and Defending Applications (telagod/code-abyss, 243 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Governance?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.