Install the "classification-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/classification-policy into .claude/skills/classification-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "classification-policy", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add Hack23/cia --skill classification-policy -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "classification-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/classification-policy into .agents/skills/classification-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "classification-policy", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Hack23/cia --skill classification-policy -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "classification-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/classification-policy into .cursor/skills/classification-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "classification-policy", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add Hack23/cia --skill classification-policy -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "classification-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/classification-policy into .gemini/skills/classification-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "classification-policy", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add Hack23/cia --skill classification-policy -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "classification-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/classification-policy into .github/skills/classification-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "classification-policy", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Hack23/cia --skill classification-policy -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "classification-policy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/classification-policy into .opencode/skills/classification-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "classification-policy", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
classification-policy
GitHub stars
239
Token cost
~7.4k tokens
SKILL.md length
1,449 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0
At a glance
Risk-based data and asset classification framework: PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED aligned with ISO 27001 A.5.12 and CIA triad
Tasks that involve SOC 2 and security compliance
SKILL.md covers Purpose, When to Use This Skill, 4-Tier Classification Model and Classification Decision Tree, plus 7 more sections
Calls psql; reaches github.com
What it does
Classification Policy is an agent skill from Hack23/cia. Risk-based data and asset classification framework: PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED aligned with ISO 27001 A.5.12 and CIA triad
Its SKILL.md is about 7.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering SOC 2 and security compliance. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.
When your agent uses it
Tasks that involve SOC 2 and security compliance
Example prompts
“/classification-policy”
What it can do on your machine
Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
psql
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
github.com
Also links to:
img.shields.io
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Classification Policy loads about 7.4k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 1,449 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~40
When it runs· the whole SKILL.md, loaded when a task matches
~7.4k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/classification-policy/SKILL.md (or your agent's skills folder).
name
classification-policy
description
Risk-based data and asset classification framework: PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED aligned with ISO 27001 A.5.12 and CIA triad
license
Apache-2.0
Data Classification Policy Skill
Purpose
This skill provides systematic guidance for implementing risk-based data and asset classification within the CIA platform, ensuring proper protection controls align with information sensitivity, business impact, and regulatory requirements per ISO 27001 A.5.12, A.5.13, and A.8.10.
When to Use This Skill
Apply this skill when:
✅ Designing data models with sensitive information (personal data, political records)
✅ Implementing access controls for classified information
✅ Defining encryption requirements for data at rest and in transit
✅ Creating data handling procedures (storage, transmission, disposal)
Integrity: Image: Moderate - Modification affects business operations
Availability: Image: Moderate - Business operations continue with delays
Examples in CIA Platform:
Internal project planning documents
System performance metrics and analytics
Employee directory and contact information
Internal training materials
Aggregated usage statistics (anonymized)
Security Controls:
Control Type
Requirement
Implementation
Encryption at Rest
Recommended for sensitive subsets
Database encryption optional
Encryption in Transit
TLS 1.2 for external access
HTTPS for web interfaces
Access Control
Authentication required
Standard user accounts
Audit Logging
Significant events logged
Basic application logs
Labeling
Classification marking optional
File metadata preferred
Retention
Standard business retention
3 years typical
Java Implementation Example:
java
/**
* CLASSIFICATION: INTERNAL
* System performance metrics for internal monitoring
*
* Access requires authentication
*/
@Entity
@Table(name = "system_metrics")
public class SystemMetrics {
@Id
@GeneratedValue(strategy = GenerationType.IDENTITY)
private Long id;
@Column(name = "metric_name")
private String metricName;
@Column(name = "metric_value")
private Double metricValue;
@Column(name = "timestamp")
private LocalDateTime timestamp;
@Column(name = "server_id")
private String serverId;
}
@RestController
@RequestMapping("/api/internal/metrics")
public class MetricsController {
// INTERNAL: Requires authenticated user
@GetMapping
@PreAuthorize("isAuthenticated()")
public ResponseEntity<List<SystemMetrics>> getMetrics(
@RequestParam LocalDateTime startTime,
@RequestParam LocalDateTime endTime) {
List<SystemMetrics> metrics = metricsService.findByTimeRange(startTime, endTime);
return ResponseEntity.ok(metrics);
}
}
Handling Requirements:
❌ NEVER publish to public websites or repositories
❌ NEVER share with external parties without approval
✅ Share with authenticated internal users
✅ Use standard email for internal distribution
✅ Standard backup and retention procedures
✅ Dispose using normal deletion procedures
🟢 PUBLIC - No Confidentiality
Definition: Information approved for public disclosure with no confidentiality requirements.
CIA Triad Mapping:
Confidentiality: Image: Public - Intended for public consumption
Integrity: Image: Moderate - Accuracy important for reputation
Availability: Image: High - High availability expected by public
Examples in CIA Platform:
Public API documentation
Open-source code repositories (GitHub public repos)
Published voting records (already public from Riksdagen)
Press releases and marketing materials
Public data visualizations and dashboards
Security Controls:
Control Type
Requirement
Implementation
Encryption at Rest
Not required
Standard storage
Encryption in Transit
Recommended for integrity
HTTPS for web content
Access Control
None required
Public access allowed
Audit Logging
Optional
Basic web server logs
Labeling
Classification marking optional
Metadata optional
Retention
Indefinite or business need
Standard retention
Java Implementation Example:
java
/**
* CLASSIFICATION: PUBLIC
* Published voting records from Swedish Riksdagen
*
* Data already public via Riksdagen API
* No access restrictions required
*/
@Entity
@Table(name = "voting_record")
public class VotingRecord {
@Id
private String votingId;
@Column(name = "politician_id")
private String politicianId;
@Column(name = "vote")
@Enumerated(EnumType.STRING)
private VoteType voteType; // YES, NO, ABSTAIN, ABSENT
@Column(name = "voting_date")
private LocalDate votingDate;
@Column(name = "document_id")
private String documentId;
}
@RestController
@RequestMapping("/api/public/voting-records")
public class VotingRecordController {
// PUBLIC: No authentication required
@GetMapping
public ResponseEntity<List<VotingRecord>> getVotingRecords(
@RequestParam(required = false) String politicianId,
@RequestParam(required = false) LocalDate startDate,
@RequestParam(required = false) LocalDate endDate) {
List<VotingRecord> records = votingService.findPublicRecords(
politicianId, startDate, endDate
);
return ResponseEntity.ok(records);
}
}
Handling Requirements:
✅ Can be published to public websites
✅ Can be shared via any medium
✅ No special disposal requirements
⚠️ Verify data is truly public before classifying
⚠️ Ensure no embedded RESTRICTED/CONFIDENTIAL data
Classification Decision Tree
Use this decision tree to classify information:
mermaid
graph TD
START["🏷️ Start Classification"] --> Q1{"Contains credentials,<br/>encryption keys,<br/>or PII?"}
Q1 -->|Yes| RESTRICTED["🔴 RESTRICTED"]
Q1 -->|No| Q2{Business-sensitive or<br/>competitive advantage<br/>if disclosed?}
Q2 -->|Yes| Q3{Significant financial<br/>or legal impact<br/>if disclosed?}
Q2 -->|No| Q4{Already publicly<br/>available or<br/>approved for release?}
Q3 -->|Yes| CONFIDENTIAL["🟠 CONFIDENTIAL"]
Q3 -->|No| INTERNAL["🟡 INTERNAL"]
Q4 -->|Yes| PUBLIC["🟢 PUBLIC"]
Q4 -->|No| INTERNAL
RESTRICTED --> R_CONTROLS["🔐 Maximum Security:<br/>• AES-256 encryption<br/>• MFA required<br/>• Never log<br/>• Immediate disposal"]
CONFIDENTIAL --> C_CONTROLS["🛡️ High Security:<br/>• Encryption recommended<br/>• RBAC enforced<br/>• Access logging<br/>• Quarterly reviews"]
INTERNAL --> I_CONTROLS["🚪 Standard Security:<br/>• Authentication required<br/>• Internal use only<br/>• Standard retention<br/>• Basic logging"]
PUBLIC --> P_CONTROLS["🌐 Public Access:<br/>• No restrictions<br/>• Integrity focus<br/>• High availability<br/>• Public distribution OK"]
style RESTRICTED fill:#D32F2F
style CONFIDENTIAL fill:#FF9800
style INTERNAL fill:#FDD835
style PUBLIC fill:#4CAF50
style START fill:#1565C0
Labeling Requirements
Code-Level Labeling
JavaDoc Comments:
java
/**
* CLASSIFICATION: RESTRICTED
*
* Contains authentication tokens and encrypted credentials.
*
* Security Requirements:
* - Never log token values
* - Rotate tokens every 90 days
* - Immediate revocation on compromise
*
* @see <a href="https://github.com/Hack23/ISMS-PUBLIC/blob/main/CLASSIFICATION.md">Classification Policy</a>
* @see <a href="https://github.com/Hack23/ISMS-PUBLIC/blob/main/Secrets_Management_Policy.md">Secrets Management</a>
*/
public class AuthenticationToken {
// Implementation
}
SQL Table Comments:
sql
-- CLASSIFICATION: CONFIDENTIAL
-- Party financial data with business-sensitive budget details
-- Access requires PARTY_ANALYST role
COMMENT ON TABLE party_financial_record IS
'CLASSIFICATION: CONFIDENTIAL - Party financial data requiring access control';
COMMENT ON COLUMN party_financial_record.budget_json IS
'Detailed budget breakdown - business sensitive';
Document-Level Labeling
Markdown Header:
markdown
---
title: Security Vulnerability Assessment
classification: CONFIDENTIAL
date: 2025-02-10
author: Security Team
retention: 7 years
---
# CONFIDENTIAL: Security Vulnerability Assessment
**Classification**: CONFIDENTIAL
**Audience**: Internal Security Team Only
**Distribution**: Do not forward externally
Configuration Files:
yaml
# CLASSIFICATION: INTERNAL
# Application configuration - internal use only
spring:
application:
name: citizen-intelligence-agency
# ... configuration
GDPR and Privacy Classification
Show full SKILL.md (602 more words)Show less
Special Category Personal Data (Art. 9 GDPR)
Definition: Sensitive personal data requiring explicit consent and enhanced protection.
Examples:
Political opinions and party membership (Art. 9.1.a GDPR)
Enable audit logging for RESTRICTED/CONFIDENTIAL data
For Existing Systems
Inventory all data assets
Classify each asset using decision tree
Add classification labels to existing code
Verify current controls match classification requirements
Identify and remediate control gaps
Update documentation with classification markings
Conduct classification review (annual minimum)
Common Classification Mistakes
❌ Mistake 1: Over-Classification
Problem: Classifying all data as RESTRICTED/CONFIDENTIAL unnecessarily Impact: Excessive security overhead, reduced operational efficiency Solution: Use decision tree, classify based on actual business impact
❌ Mistake 2: Under-Classification
Problem: Classifying sensitive data as PUBLIC/INTERNAL Impact: Inadequate protection, compliance violations, data breaches Solution: When uncertain, classify higher and review with security team
❌ Mistake 3: No Classification
Problem: Leaving data unclassified Impact: No clear security controls, inconsistent protection Solution: Mandate classification for all new data models via PR reviews
❌ Mistake 4: Inconsistent Labeling
Problem: Same data classified differently across systems Impact: Confusion, control gaps, audit findings Solution: Centralized classification authority, regular reviews
Classification Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Classification Policy compared with similar skills
Risk-based data and asset classification framework: PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED aligned with ISO 27001 A.5.12 and CIA triad. Classification Policy is an agent skill from Hack23/cia.
When should I use Classification Policy?
Classification Policy fits situations like: tasks that involve SOC 2 and security compliance.
How do I install Classification Policy in Claude Code?
Run `npx skills add Hack23/cia --skill classification-policy -a claude-code`. Or copy the skill folder (.github/skills/classification-policy in Hack23/cia) into .claude/skills/classification-policy in your project. Claude Code loads it when a task matches its description.
How do I install Classification Policy in Codex?
Run `npx skills add Hack23/cia --skill classification-policy -a codex`. Or copy the skill folder (.github/skills/classification-policy in Hack23/cia) into .agents/skills/classification-policy in your project. Codex loads it when a task matches its description.
Can I use Classification Policy in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill classification-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/classification-policy, .gemini/skills/classification-policy, .github/skills/classification-policy and .opencode/skills/classification-policy in your project.
What does Classification Policy need to run?
Going by SKILL.md and its folder, Classification Policy needs the command-line tools its instructions call (psql).
Does Classification Policy access the network?
SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: img.shields.io. This is read from the text; nothing was executed.
Is Classification Policy safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Classification Policy use?
Classification Policy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Classification Policy use?
About 7.4k tokens (SKILL.md is roughly 30k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Classification Policy?
Skills that share tags, products or a category with Classification Policy: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars), Soc2 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars), Grc Knowledge (mlunato47/claude-grc-plugin, 183 stars) and Information Security Manager Iso27001 (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Classification Policy?
Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.
Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.