Agent skill

Compliance Checklist

by Hack23 in Hack23/cia

Unified compliance verification across ISO 27001, NIST CSF, CIS Controls, NIS2, EU CRA, GDPR, SOC 2, PCI DSS, and HIPAA for cybersecurity consulting

Apache-2.0Auto-check passedLegal & Compliance

Install Compliance Checklist

skills CLI
$ npx skills add Hack23/cia --skill compliance-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia compliance-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/compliance-checklist .claude/skills/compliance-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance-checklist
GitHub stars
239
Token cost
~994 tokens
SKILL.md length
220 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Unified compliance verification across ISO 27001, NIST CSF, CIS Controls, NIS2, EU CRA, GDPR, SOC 2, PCI DSS, and HIPAA for cybersecurity consulting

  • Tasks that involve SOC 2 and security compliance
  • SKILL.md covers Purpose, When to Use This Skill, Multi-Framework Alignment… and ISO 27001:2022 Control…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Regulatory compliance

What it does

Compliance Checklist is an agent skill from Hack23/cia. Unified compliance verification across ISO 27001, NIST CSF, CIS Controls, NIS2, EU CRA, GDPR, SOC 2, PCI DSS, and HIPAA for cybersecurity consulting

Its SKILL.md is about 990 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering SOC 2 and security compliance, Regulatory compliance and Healthcare and finance regulation. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve SOC 2 and security compliance
  • Tasks that involve Regulatory compliance
  • Tasks that involve Healthcare and finance regulation

Example prompts

  • “/compliance-checklist”

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are mermaid).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance Checklist loads about 994 tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 220 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~994

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 220 words, ~994 tokens.

Download SKILL.mdSave it as .claude/skills/compliance-checklist/SKILL.md (or your agent's skills folder).
name
compliance-checklist
description
Unified compliance verification across ISO 27001, NIST CSF, CIS Controls, NIS2, EU CRA, GDPR, SOC 2, PCI DSS, and HIPAA for cybersecurity consulting
license
Apache-2.0

Compliance Checklist Skill

Purpose

This skill provides comprehensive multi-framework compliance verification aligned with Hack23 AB's ISMS architecture. It enables systematic assessment of security controls across eight major frameworks simultaneously, demonstrating that robust ISMS design becomes a competitive advantage for cybersecurity consulting services.

When to Use This Skill

Apply this skill when:

  • ✅ Conducting quarterly ISMS compliance reviews
  • ✅ Preparing for ISO 27001 certification audits
  • ✅ Responding to client due diligence requests
  • ✅ Validating control implementation status
  • ✅ Creating compliance evidence packages
  • ✅ Mapping new controls to multiple frameworks
  • ✅ Updating Statement of Applicability (SOA)
  • ✅ Assessing regulatory readiness (NIS2, CRA, GDPR)

Do NOT use for:

  • ❌ Specific technical vulnerability assessments (use vulnerability-management skill)
  • ❌ Code security reviews (use secure-code-review skill)
  • ❌ Incident response procedures (use incident-response skill)

Multi-Framework Alignment Architecture

mermaid
mindmap
  root(("✅ ISMS Compliance"))
    ISO_27001_2022(("🔵 ISO 27001:2022"))
      A5_Organizational(("🟢 A.5 Organizational"))
      A6_People(("🟡 A.6 People"))
      A7_Physical(("🟢 A.7 Physical"))
      A8_Technological(("🟢 A.8 Technological"))
    NIST_CSF_2_0(("🔵 NIST CSF 2.0"))
      NIST_Govern(("🟢 Govern"))
      NIST_Protect(("🟢 Protect"))
      NIST_Detect(("🟢 Detect"))
      NIST_Respond(("🟢 Respond"))
    CIS_Controls_v8_1(("🔵 CIS Controls v8.1"))
      CIS_IG1(("🟢 IG1 Basic"))
      CIS_IG2(("🟢 IG2 Advanced"))
    NIS2(("🔵 NIS2 Directive"))
      NIS2_Art20(("🟢 Governance"))
      NIS2_Art21(("🟢 Risk Mgmt"))
    EU_CRA(("🔵 EU CRA"))
      CRA_Annex1(("🟢 Essential Reqs"))
    GDPR(("🔵 GDPR"))
      GDPR_Core(("🟢 Core Articles"))

ISO 27001:2022 Control Verification

A.5 Organizational Controls Priority Matrix
ControlHack23 Policy/EvidenceStatusNIST CSFCIS v8.1
A.5.1 Policies for information securityInformation Security Policy✅ ImplementedGV.PO-0114.1
A.5.2 Roles & responsibilitiesInformation Security Policy § Roles✅ ImplementedGV.RR-0214.3
A.5.3 Segregation of dutiesSegregation of Duties Policy✅ ImplementedPR.AC-036.1
A.5.7 Threat intelligenceRisk Register • Threat Modeling✅ ImplementedID.RA-047.1
A.5.8 Security in project mgmtSecure Development Policy • Change Management✅ ImplementedPR.IP-0116.1

Hack23 ISMS Policy References

Comprehensive Compliance Documentation:

All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/compliance-checklist of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Compliance Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compliance Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compliance Checklist this skillHack23/cia239—~994Automated safety check: PassApache-2.0
Policy OpaAgentSecOps/SecOpsAgentKit2191 repos~3.5kAutomated safety check: PassCustom licence
Implementing Complianceancoleman/ai-design-components526—~4kAutomated safety check: PassMIT
Security Compliance Compliance Checkaiskillstore/marketplace4307 repos~600Automated safety check: PassNone
Compliance Testingproffesor-for-testing/agentic-qe494—~1.8kAutomated safety check: PassMIT
Cometchat Compliancecometchat/cometchat-skills129—~1.7kAutomated safety check: PassMIT

Similar skills

  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    219 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    526 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Security Compliance Compliance Check

    aiskillstore/marketplace

    You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards.

    430 GitHub starsUsed in 7 repos~600 tokens
    Legal & ComplianceAuto-check passed
  • Compliance Testing

    proffesor-for-testing/agentic-qe

    Regulatory compliance testing for GDPR, CCPA, HIPAA, SOC2, PCI-DSS and industry-specific regulations.

    494 GitHub stars~1.8k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Cometchat Compliance

    cometchat/cometchat-skills

    Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery…

    129 GitHub stars~1.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Compliance Checklist

    mohitagw15856/pm-claude-skills

    Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Questions about Compliance Checklist

What does Compliance Checklist do?

Unified compliance verification across ISO 27001, NIST CSF, CIS Controls, NIS2, EU CRA, GDPR, SOC 2, PCI DSS, and HIPAA for cybersecurity consulting. Compliance Checklist is an agent skill from Hack23/cia.

When should I use Compliance Checklist?

Compliance Checklist fits situations like: tasks that involve SOC 2 and security compliance; tasks that involve Regulatory compliance; tasks that involve Healthcare and finance regulation.

How do I install Compliance Checklist in Claude Code?

Run `npx skills add Hack23/cia --skill compliance-checklist -a claude-code`. Or copy the skill folder (.github/skills/compliance-checklist in Hack23/cia) into .claude/skills/compliance-checklist in your project. Claude Code loads it when a task matches its description.

How do I install Compliance Checklist in Codex?

Run `npx skills add Hack23/cia --skill compliance-checklist -a codex`. Or copy the skill folder (.github/skills/compliance-checklist in Hack23/cia) into .agents/skills/compliance-checklist in your project. Codex loads it when a task matches its description.

Can I use Compliance Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill compliance-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-checklist, .gemini/skills/compliance-checklist, .github/skills/compliance-checklist and .opencode/skills/compliance-checklist in your project.

What does Compliance Checklist need to run?

SKILL.md names no scripts, command-line tools or credentials: Compliance Checklist is instructions for the agent only.

Does Compliance Checklist access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Compliance Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Compliance Checklist use?

Compliance Checklist is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compliance Checklist use?

About 994 tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Compliance Checklist?

Skills that share tags, products or a category with Compliance Checklist: Policy Opa (AgentSecOps/SecOpsAgentKit, 219 stars), Implementing Compliance (ancoleman/ai-design-components, 526 stars), Security Compliance Compliance Check (aiskillstore/marketplace, 430 stars) and Compliance Testing (proffesor-for-testing/agentic-qe, 494 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compliance Checklist?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.