Ak Dev New Messaging Integration
yaalalabs/agent-kernel
Step-by-step guide for adding a new messaging platform integration to Agent Kernel.
Guide the design and maintenance of recordkeeping programs under SEC Rules 17a-3, 17a-4, and 204-2.
$ npx skills add JoelLewis/finance_skills --skill books-and-records -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install JoelLewis/finance_skills books-and-records --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/JoelLewis/finance_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/compliance/skills/books-and-records .claude/skills/books-and-records && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "books-and-records" agent skill from https://github.com/JoelLewis/finance_skills/tree/main/plugins/compliance/skills/books-and-records into .claude/skills/books-and-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "books-and-records", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/JoelLewis/finance_skills/tree/main/plugins/compliance/skills/books-and-recordsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add JoelLewis/finance_skills --skill books-and-records -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install JoelLewis/finance_skills books-and-records --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/JoelLewis/finance_skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/compliance/skills/books-and-records .agents/skills/books-and-records && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "books-and-records" agent skill from https://github.com/JoelLewis/finance_skills/tree/main/plugins/compliance/skills/books-and-records into .agents/skills/books-and-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "books-and-records", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add JoelLewis/finance_skills --skill books-and-records -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install JoelLewis/finance_skills books-and-records --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/JoelLewis/finance_skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/compliance/skills/books-and-records .cursor/skills/books-and-records && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "books-and-records" agent skill from https://github.com/JoelLewis/finance_skills/tree/main/plugins/compliance/skills/books-and-records into .cursor/skills/books-and-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "books-and-records", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/JoelLewis/finance_skills.git --path plugins/compliance/skills/books-and-records--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add JoelLewis/finance_skills --skill books-and-records -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install JoelLewis/finance_skills books-and-records --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/JoelLewis/finance_skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/compliance/skills/books-and-records .gemini/skills/books-and-records && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "books-and-records" agent skill from https://github.com/JoelLewis/finance_skills/tree/main/plugins/compliance/skills/books-and-records into .gemini/skills/books-and-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "books-and-records", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install JoelLewis/finance_skills books-and-recordsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add JoelLewis/finance_skills --skill books-and-records -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/JoelLewis/finance_skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/compliance/skills/books-and-records .github/skills/books-and-records && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "books-and-records" agent skill from https://github.com/JoelLewis/finance_skills/tree/main/plugins/compliance/skills/books-and-records into .github/skills/books-and-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "books-and-records", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add JoelLewis/finance_skills --skill books-and-records -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install JoelLewis/finance_skills books-and-records --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/JoelLewis/finance_skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/compliance/skills/books-and-records .opencode/skills/books-and-records && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "books-and-records" agent skill from https://github.com/JoelLewis/finance_skills/tree/main/plugins/compliance/skills/books-and-records into .opencode/skills/books-and-records/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "books-and-records", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
books-and-recordsGuide the design and maintenance of recordkeeping programs under SEC Rules 17a-3, 17a-4, and 204-2.
Books And Records is an agent skill from JoelLewis/finance_skills. Guide the design and maintenance of recordkeeping programs under SEC Rules 17a-3, 17a-4, and 204-2. Use when the user asks about document retention schedules, how long to keep trade records or customer complaints, WORM storage requirements, email or text message archiving, social media capture, BYOD compliance policies, or electronic storage audit trails. Also trigger when users mention 'we got an exam request for records', 'migrating to a new archiving vendor', 'blotter retention', 'order ticket requirements'…
Its SKILL.md is about 11k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/retention-schedule.md`).
It sits in Productivity & Automation, covering Messaging and chat bots and Regulatory compliance. It works with WhatsApp. The repository describes itself as: Claude Code skill plugins for financial services — 81 skills across 7 domain plugins covering investment management, compliance, advisory practice, trading, and operations. The licence is MIT.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 5c498ea. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Books And Records loads about 11k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 158 tokens; SKILL.md has 5,637 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from JoelLewis/finance_skills at commit 5c498ea, republished under its MIT licence (© JoelLewis). 5,637 words, ~10,531 tokens.
.claude/skills/books-and-records/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Regulatory status current as of June 2026 — verify effective dates, dollar thresholds, and pending rulemakings against current SEC/FINRA/FinCEN sources before advising.
SEC Rule 17a-3 (17 CFR 240.17a-3) specifies the books and records that every registered broker-dealer must create and maintain. These records form the foundation of regulatory oversight, enabling examiners to reconstruct transactions, verify compliance, and protect investors. The principal categories of required records are:
SEC Rule 17a-4 (17 CFR 240.17a-4) prescribes the retention periods for broker-dealer records. Records are categorized into three tiers based on their required retention period:
Six-year records (Rule 17a-4(a) and (b)):
Three-year records (Rule 17a-4(b) and (c)):
Lifetime-of-enterprise records (Rule 17a-4(d)):
First two years — easily accessible: For all records subject to three-year or six-year retention, the records must be maintained in an easily accessible place during the first two years of the applicable retention period (Rule 17a-4(a), (b)). "Easily accessible" means the firm must be able to produce the records promptly upon regulatory request — they cannot be stored in a manner that requires extensive effort or delay to retrieve during this initial period.
Electronic storage requirements (Rule 17a-4(f)): Rule 17a-4(f) governs the conditions under which broker-dealers may maintain required records in electronic format. Historically, this rule mandated that electronic records be preserved exclusively in non-rewriteable, non-erasable format — the WORM (Write Once, Read Many) standard. The 2022 SEC amendments to Rule 17a-4(f) (Exchange Act Release No. 34-96034, effective January 3, 2023) modernized these requirements by introducing an alternative to WORM storage. Under the amended rule, electronic records may now be maintained in either:
Regardless of which option is chosen, the following requirements apply:
SEC Rule 204-2 (17 CFR 275.204-2) under the Investment Advisers Act of 1940 specifies the books and records that SEC-registered investment advisers must make and keep. Investment adviser recordkeeping requirements differ from broker-dealer requirements in scope and emphasis, reflecting the advisory relationship and fiduciary obligations. Required records include:
Retention period: Most records required under Rule 204-2 must be retained for five years from the end of the fiscal year during which the last entry was made or the record was created. During the first two years of the five-year period, records must be kept in an easily accessible place (i.e., the adviser's principal office or another readily accessible location).
Custody-related records: Investment advisers that have custody of client assets must maintain additional records per Rule 206(4)-2 (the custody rule), including records of all client funds and securities over which the adviser has custody, a journal showing all purchases, sales, receipts, and deliveries of securities and funds for such accounts, and copies of all account statements delivered to clients.
FINRA member firms are subject to FINRA-specific recordkeeping obligations that supplement and reinforce the SEC requirements under Rules 17a-3 and 17a-4.
FINRA Rule 4511 (General Requirements): FINRA Rule 4511 requires each member firm to make and preserve books and records as required under the FINRA rules, the Securities Exchange Act of 1934, and the applicable SEC rules (i.e., Rules 17a-3 and 17a-4). Rule 4511 also requires that all books and records be maintained in a format and medium that comply with Rule 17a-4. This means FINRA firms must meet the electronic storage, index, and accessibility requirements of Rule 17a-4(f) for all records — including FINRA-specific records not explicitly addressed by the SEC rules.
FINRA Rule 3110 (Supervision) — Recordkeeping Implications: FINRA Rule 3110 generates significant recordkeeping obligations through its supervision requirements:
FINRA Rule 4513 (Records of Written Customer Complaints): Requires a separate file of all written customer complaints, indexed by complaint type and by associated person. The complaint record must include the complainant's name, date received, associated person identified, nature of the complaint, and disposition. These records are retained for at least four years.
SEC and FINRA rules require broker-dealers and investment advisers to capture, retain, and supervise all business-related electronic communications. The regulatory framework does not distinguish between communication platforms — the obligation applies uniformly regardless of the technology used.
Scope of covered communications: The requirement extends to all written business communications, including email, instant messaging (Bloomberg chat, Reuters Eikon messaging, proprietary IM systems), text messages (SMS and messaging apps such as iMessage and WhatsApp), collaboration platforms (Microsoft Teams, Slack, Zoom chat), and any other electronic medium used to communicate about firm business.
Key regulatory guidance:
Retention requirements for electronic communications: Electronic communications related to the broker-dealer's business are treated as "correspondence" under Rule 17a-4(b)(4) and must be retained for a minimum of three years (the first two years in an easily accessible place). For investment advisers, written communications are retained for five years under Rule 204-2(a)(7).
Supervision requirements: Beyond mere retention, firms must supervise the content of electronic communications. FINRA Rule 3110 requires that firms establish procedures to review correspondence and internal communications. The review methodology may include automated keyword or lexicon surveillance, statistical sampling, targeted reviews of high-risk registered representatives or activity patterns, and escalation procedures for flagged communications. Supervisory reviews must be documented, and the firm must retain evidence of the review process.
BYOD (Bring Your Own Device) policies and challenges: Firms that permit employees and registered representatives to use personal devices for business communications face heightened compliance challenges. BYOD policies must address: mandatory installation of archiving applications on personal devices, prohibition of non-approved communication channels for business communications, technical controls to capture communications from personal devices, procedures for device collection or data preservation when an employee departs, and employee attestations acknowledging the firm's right to monitor and archive business communications on personal devices.
Rule 17a-4(f) has historically been the most technically prescriptive provision in the books-and-records framework. Understanding the WORM standard and the 2022 amendments is essential for designing compliant electronic recordkeeping systems.
WORM (Write Once, Read Many) standard: Under the original Rule 17a-4(f), electronic records had to be stored on non-rewriteable, non-erasable media — the WORM standard. The purpose of this requirement was to prevent firms from altering or destroying records to conceal violations. WORM-compliant storage options have historically included optical disks (CD-R, DVD-R), magnetic tape with write-protect mechanisms, and purpose-built WORM storage appliances. Cloud-based WORM storage solutions (such as those offered by Amazon S3 Object Lock, Azure Immutable Blob Storage, and similar services) are now available and widely used, provided they meet the non-rewriteability and non-erasability requirements.
Index and retrieval system: Regardless of storage format, the firm must maintain an index of all records stored electronically. The index must be organized to permit prompt identification and retrieval of any individual record. The index itself must be stored on a medium separate from the records and must be duplicated for disaster recovery purposes.
Audit trail: Under the 2022 amendments (Exchange Act Release No. 34-96034), firms that elect the audit-trail alternative (rather than WORM) must maintain an electronic recordkeeping system that creates a time-stamped, tamper-evident audit trail of every modification, deletion, or alteration of any record. The audit trail must preserve the original record and all subsequent versions, and it must be possible to reconstruct the complete history of any record from creation through its current state.
Third-party access agent: The broker-dealer must file with its designated examining authority (DEA) and the SEC the name, address, telephone number, and facsimile number of the designated third party who will provide access to electronic records in the event the broker-dealer ceases operations. The designated third party must file with the SEC an annual undertaking agreeing to provide such access. This requirement was designed to address the risk that electronic records could become inaccessible if the firm failed and its technology infrastructure was dismantled. The third-party access agent requirement remains in effect under the 2022 amendments for firms using either WORM or audit-trail storage.
Annual letter from the designated third party: The designated third party must file annually with the SEC a written statement affirming its agreement to provide the required access. Failure to maintain a current designated third party and annual undertaking is itself a books-and-records violation.
2022 SEC amendments (effective January 3, 2023): The amendments to Rule 17a-4 were designed to modernize the rule by: (1) offering the audit-trail alternative to WORM, (2) eliminating the requirement that firms notify the SEC before using electronic storage (firms previously had to file a notice 90 days before beginning to store records electronically), (3) permitting the use of any electronic recordkeeping system that meets the requirements, without specifying particular technologies, and (4) streamlining certain notification requirements. These amendments were adopted in recognition that WORM technology, while effective, imposed significant operational costs and that modern audit-trail technologies could achieve equivalent regulatory objectives.
Social media presents unique recordkeeping challenges that have been the subject of extensive regulatory guidance. The core principle remains unchanged: business-related communications on social media platforms must be captured, retained, and supervised just like any other written business communication.
Static vs. interactive content (FINRA Regulatory Notice 11-39):
Ephemeral content: Features such as Instagram/Facebook Stories, Snapchat, and disappearing messages on platforms like Telegram and WhatsApp present heightened compliance risk. If a registered representative uses an ephemeral messaging feature for business communication, the firm must capture and retain that content. Most regulatory enforcement actions involving off-channel communications have cited the failure to capture ephemeral or disappearing messages.
Personal device usage: Registered representatives who use personal social media accounts or personal devices for business-related communications create archiving gaps if the firm does not have technology in place to capture those communications. Firms should maintain policies that either (a) prohibit the use of personal social media accounts and unapproved platforms for business communications, or (b) deploy technology solutions to capture communications from approved personal accounts.
Third-party archiving vendors: The regulatory requirements have given rise to a market of specialized archiving vendors (such as Smarsh, Global Relay, Proofpoint, and others) that provide capture, retention, supervision, and retrieval capabilities across multiple communication platforms. When selecting a vendor, firms should evaluate whether the vendor's solution captures content from all platforms the firm uses, meets WORM or audit-trail requirements under Rule 17a-4(f), provides lexicon-based surveillance capabilities for supervisory review, supports search and retrieval for examination requests, and maintains its own disaster recovery and business continuity capabilities.
FINRA guidance on social media records: FINRA has emphasized that firms must: (1) inventory all social media platforms used by the firm and its associated persons for business purposes, (2) establish written policies identifying approved and prohibited platforms, (3) deploy archiving technology for all approved platforms, (4) train associated persons on social media policies and the consequences of using unapproved platforms, and (5) conduct periodic attestations from associated persons confirming compliance with the firm's social media policies.
For the full retention table mapping each document type to its required retention period and source rule (BD 3/4/6-year and lifetime tiers, IA 5-year records), load references/retention-schedule.md when answering "how long must we keep X" or building a retention policy. Universal rule of thumb: the first two years of any retention period must be in an easily accessible place.
Scenario: A mid-size broker-dealer migrates from an on-premises email system to a cloud-based platform. The migration takes place over a two-week period. Six months later, during preparation for a routine FINRA examination, the compliance department discovers that emails sent and received during the migration window were not captured by the firm's archiving vendor. The gap affects approximately 3,500 emails across 120 registered representatives over the two-week period. The firm cannot determine the content of the missing emails.
Compliance Issues:
Analysis: The firm should take the following remediation steps: (1) Conduct a forensic analysis to determine the exact scope of the gap — which users were affected, the precise dates, and whether any emails can be recovered from backup systems, individual mailboxes, or the cloud platform's own logs. (2) Engage the archiving vendor and the cloud platform provider to determine whether any copies of the missing emails exist in alternative storage. (3) Document the root cause of the gap — was it a failure in the migration plan, a vendor configuration error, or a lack of testing before cutover. (4) Self-report the deficiency to FINRA if the gap is material. FINRA considers self-reporting a mitigating factor in enforcement proceedings. (5) Implement preventive controls for future migrations, including parallel archiving during transition periods (running both old and new systems simultaneously), pre-migration testing of archiving capture, and post-migration validation audits. (6) Review the firm's vendor management procedures — the archiving vendor should have been involved in migration planning and should have validated capture continuity. The regulatory exposure depends on the scope of the gap and whether any of the missing communications related to customer complaints, order instructions, or other high-risk content. FINRA has brought enforcement actions for email archiving failures, with fines ranging from $10,000 to over $1 million depending on the scope and duration of the deficiency and the firm's remediation efforts.
Scenario: An SEC-registered investment adviser has been operating for five years, managing $400 million in assets across 200 client accounts. The firm has maintained basic financial records (journals and ledgers) and client agreements, but has never established a systematic recordkeeping process for investment recommendations. Investment recommendations are made verbally in client meetings and documented informally in advisors' personal notes, personal email accounts, and handwritten notebooks. The firm has no centralized repository for investment recommendations, no records of the research or analysis supporting recommendations, and no documentation of how investment opportunities were allocated among clients. The deficiency is discovered when the firm receives an SEC examination notification.
Compliance Issues:
Analysis: The firm faces a serious examination outcome. The remediation plan should include: (1) Immediately implement a centralized recordkeeping system for investment recommendations — this may include a CRM or portfolio management system that captures the recommendation, the date, the supporting rationale, the adviser who made it, and the client accounts that received it. (2) Collect and centralize whatever informal records exist — personal notes, emails, presentation materials — and incorporate them into the firm's official books and records going forward. Advisors should be directed to forward any business-related emails from personal accounts to the firm's archive. (3) Implement a written trade allocation policy and begin documenting how investment opportunities are allocated among clients. (4) Engage outside compliance counsel to prepare for the SEC examination. The firm should be prepared to explain the deficiency, present its remediation plan, and demonstrate that the new system satisfies Rule 204-2. (5) Consider whether a deficiency letter or self-disclosure to the SEC is appropriate before the examination begins. (6) Train all advisory personnel on recordkeeping obligations and implement attestation procedures. The SEC's examination staff will likely issue a deficiency letter at minimum. If the lack of records conceals substantive violations (unfair allocation, conflicted recommendations), the matter could escalate to an enforcement referral. The firm's prompt and comprehensive remediation will be a mitigating factor.
Scenario: A broker-dealer's compliance department learns that several registered representatives have been communicating with clients via personal cell phone text messages (iMessage and WhatsApp) for the past two years. The firm's policies prohibit the use of personal devices and unapproved platforms for business communications, but the prohibition has not been enforced. The firm has no archiving solution for text messages sent from personal devices. An estimated 15 registered representatives have exchanged thousands of text messages with clients discussing investment recommendations, trade instructions, account transfers, and complaints. The firm discovers the issue when a customer arbitration claimant produces text messages that the firm has no record of.
Compliance Issues:
Analysis: This scenario reflects a pattern that has been the subject of major SEC and FINRA enforcement actions. Beginning in 2021, the SEC and FINRA initiated a series of sweeping investigations into off-channel communications at broker-dealers and investment advisers. As of the 2021-2024 sweep (figures as of year-end 2024 — verify current totals), the SEC had imposed fines as high as $125 million on individual firms, with total industry penalties exceeding $2 billion; FINRA brought parallel actions with fines ranging from hundreds of thousands to tens of millions of dollars. The firm should take the following steps: (1) Immediately deploy a text message archiving solution for all registered representatives. Solutions include firm-issued devices with built-in archiving, mobile archiving applications installed on personal devices (with employee consent), or enterprise mobility management platforms that capture text messages from approved applications. (2) Collect and preserve all available text messages from the affected registered representatives' personal devices. This may require cooperation from the representatives and potentially forensic data collection. (3) Conduct a review of the collected text messages to identify any customer complaints, trade instructions, or other records that should have been maintained under Rules 17a-3 and 17a-4. (4) Self-report the deficiency to FINRA and the SEC. Given the current enforcement environment, self-reporting is strongly advisable — regulators have imposed significantly higher penalties on firms that failed to self-report or that were discovered through examination rather than voluntary disclosure. (5) Strengthen the firm's policies to include: a clear prohibition on unapproved communication channels, mandatory use of the firm's archiving solution for all business communications, annual (or more frequent) attestations from registered representatives confirming compliance, technical controls where feasible (e.g., monitoring for unapproved application usage on firm-issued devices), and disciplinary consequences for violations. (6) Retrain all registered representatives on the firm's communications policies, the regulatory basis for the requirements, and the personal liability exposure for off-channel communications. The regulatory exposure is significant. In the current enforcement climate, the SEC and FINRA have treated off-channel communications failures as serious violations warranting substantial monetary penalties, undertakings to engage independent compliance consultants, and requirements to implement enhanced supervisory systems.
© JoelLewis, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in plugins/compliance/skills/books-and-records of JoelLewis/finance_skills.
Open the folder on GitHubat commit 5c498ea
Books And Records next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Books And Records this skillJoelLewis/finance_skills | 206 | — | ~11k | Automated safety check: Pass | MIT | |
| Ak Dev New Messaging Integrationyaalalabs/agent-kernel | 192 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | |
| Whatsapp Automationdavepoon/buildwithclaude | 3.6k | 7 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Beepersteipete/agent-scripts | 7.3k | — | ~250 | Automated safety check: Pass | MIT | |
| C Messagingdaxaur/openpaw | 173 | — | ~568 | Automated safety check: Pass | MIT | |
| Ak Add Integrationyaalalabs/agent-kernel | 192 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 |
yaalalabs/agent-kernel
Step-by-step guide for adding a new messaging platform integration to Agent Kernel.
davepoon/buildwithclaude
Automate WhatsApp Business tasks via Rube MCP (Composio): send messages, manage templates, upload media, and handle contacts.
steipete/agent-scripts
Beeper cache: contact hints, room lookup, WhatsApp/iMessage traces, FTS.
daxaur/openpaw
Send and read messages via imsg (iMessage) and wacli (WhatsApp).
yaalalabs/agent-kernel
Add a messaging platform integration to an existing Agent Kernel project.
LeoYeAI/openclaw-master-skills
Chinese multi-platform content matrix generator — given a topic, auto-generate content adapted for Xiaohongshu, WeChat Official Account, Douyin, and Bilibili with true style transfer (not just…
JoelLewis/finance_skills
Determine how to distribute capital across asset classes using strategic and tactical allocation frameworks.
JoelLewis/finance_skills
Determine how much capital to allocate to individual positions within a portfolio.
JoelLewis/finance_skills
Analyze commodity markets including futures curve dynamics, roll yield, and supply/demand fundamentals.
JoelLewis/finance_skills
Analyze currency markets, exchange rate mechanics, and FX risk management for international portfolios.
JoelLewis/finance_skills
Provide frameworks for managing and paying off personal debt effectively.
JoelLewis/finance_skills
Build diversified portfolios using correlation analysis, efficient frontier construction, and factor-based diversification.
Works with
Guide the design and maintenance of recordkeeping programs under SEC Rules 17a-3, 17a-4, and 204-2. Books And Records is an agent skill from JoelLewis/finance_skills. Guide the design and maintenance of recordkeeping programs under SEC Rules 17a-3, 17a-4, and 204-2.
Books And Records fits situations like: the user asks about document retention schedules; how long to keep trade records; customer complaints; WORM storage requirements.
Run `npx skills add JoelLewis/finance_skills --skill books-and-records -a claude-code`. Or copy the skill folder (plugins/compliance/skills/books-and-records in JoelLewis/finance_skills) into .claude/skills/books-and-records in your project. Claude Code loads it when a task matches its description.
Run `npx skills add JoelLewis/finance_skills --skill books-and-records -a codex`. Or copy the skill folder (plugins/compliance/skills/books-and-records in JoelLewis/finance_skills) into .agents/skills/books-and-records in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add JoelLewis/finance_skills --skill books-and-records -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/books-and-records, .gemini/skills/books-and-records, .github/skills/books-and-records and .opencode/skills/books-and-records in your project.
SKILL.md names no scripts, command-line tools or credentials: Books And Records is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Books And Records is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 11k tokens (SKILL.md is roughly 42k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 596 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Books And Records: Ak Dev New Messaging Integration (yaalalabs/agent-kernel, 192 stars), Whatsapp Automation (davepoon/buildwithclaude, 3.6k stars), Beeper (steipete/agent-scripts, 7.3k stars) and C Messaging (daxaur/openpaw, 173 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
JoelLewis (a GitHub user) maintains it in JoelLewis/finance_skills, which has 206 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on July 18, 2026.
Source: JoelLewis/finance_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.