Agent skill

Nis2 Navigator

by lawve-ai in lawve-ai/awesome-legal-skills

NIS2 Compliance Navigator — scope classification, Art. An agent skill from lawve-ai/awesome-legal-skills.

AGPL-3.0Auto-check passedSecurity

Install Nis2 Navigator

skills CLI
$ npx skills add lawve-ai/awesome-legal-skills --skill nis2-navigator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install lawve-ai/awesome-legal-skills nis2-navigator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/nis2-navigator-oliver-schmidt-prietz .claude/skills/nis2-navigator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nis2-navigator
GitHub stars
847
Token cost
~3.6k tokens
SKILL.md length
1,574 words
Files
10 (incl. references)
Skills in repo
154
Repo updated
First seen
Licence
AGPL-3.0

At a glance

NIS2 Compliance Navigator — scope classification, Art. An agent skill from lawve-ai/awesome-legal-skills.

  • Works in 3 steps: Display Disclaimer (show at session… → Web Search on Activation → Determine Jurisdiction Focus
  • User mentions NIS2
  • SKILL.md covers Session Initialization, Phase 1: Scope &…, Phase 2: Art. 21 Gap Analysis… and Phase 3: Compliance Roadmap, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nis2 Navigator is an agent skill from lawve-ai/awesome-legal-skills. NIS2 Compliance Navigator — scope classification, Art. 21 gap analysis (0-4 maturity scoring), and compliance roadmap under EU Directive 2022/2555 with deep German BSIG-neu coverage and profiles for Italy, France, Netherlands, Austria, Spain. Use when: (1) User mentions "NIS2", "NIS-2", "BSIG", "BSIG-neu", "NIS2UmsuCG", "Cyberbeveiligingswet", "Loi Résilience", "NISG", "decreto legislativo 138", (2) User asks if their organization falls under NIS2 or needs a cybersecurity compliance assessment, (3) User mentions…

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `README.md`, `evals.json` and `references/art21-measures.md`).

It sits in Security, covering Supply chain security and Audit readiness. The repository describes itself as: A curated list of awesome Agent Skills for automating legal work. The licence is AGPL-3.0.

When your agent uses it

  • User mentions NIS2
  • Cyberbeveiligingswet
  • Decreto legislativo 138
  • User asks if their organization falls under NIS2

Example prompts

  • “BSIG-neu”
  • “NIS2UmsuCG”
  • “Cyberbeveiligingswet”
  • “/nis2-navigator”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Display Disclaimer (show at session start, do not block)
  2. Web Search on Activation
  3. Determine Jurisdiction Focus

What it can do on your machine

Read from SKILL.md and the folder at commit 045f738. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • onezero.legal

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nis2 Navigator loads about 3.6k tokens when it runs, and up to ~18k if it reads all its reference files. Until then it costs about 217 tokens; SKILL.md has 1,574 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~217
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~18k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from lawve-ai/awesome-legal-skills at commit 045f738, republished under its AGPL-3.0 licence (© lawve-ai). 1,574 words, ~3,583 tokens.

Download SKILL.mdSave it as .claude/skills/nis2-navigator/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
nis2-navigator
description
NIS2 Compliance Navigator — scope classification, Art. 21 gap analysis (0-4 maturity scoring), and compliance roadmap under EU Directive 2022/2555 with deep German BSIG-neu coverage and profiles for Italy, France, Netherlands, Austria, Spain. Use when: (1) User mentions "NIS2", "NIS-2", "BSIG", "BSIG-neu", "NIS2UmsuCG", "Cyberbeveiligingswet", "Loi Résilience", "NISG", "decreto legislativo 138", (2) User asks if their organization falls under NIS2 or needs a cybersecurity compliance assessment, (3) User mentions essential/important entities, Annex I/II, BSI registration, § 30 BSIG, incident reporting, management body liability, supply chain security, (4) User wants a NIS2 gap analysis, readiness assessment, or compliance roadmap, (5) User asks about NIS2 fines, enforcement, or Nachweispflicht, (6) User asks about NIS2 in any EU Member State.
metadata.author
Oliver Schmidt-Prietz
metadata.license
agpl-3.0
metadata.version
2026-06-05

NIS2 Compliance Navigator

Guide users through a full NIS2 compliance assessment: scope determination, Art. 21 gap analysis across 10 risk management measures, and prioritized compliance roadmap. Covers EU Directive 2022/2555 with deep German national transposition (BSIG-neu) and high-level profiles for Italy, France, Netherlands, Austria, and Spain.

Session Initialization

1. Display Disclaimer (show at session start, do not block)

Important: This skill provides structured NIS2 compliance guidance based on EU Directive 2022/2555 and national transposition laws. It is not legal advice. Final compliance decisions should involve your organisation's CISO / Information Security Officer and qualified legal counsel experienced in cybersecurity regulation.

2. Web Search on Activation

Search for current regulatory developments before starting — NIS2 transposition is still evolving in many Member States, and enforcement practice is developing rapidly:

NIS2 enforcement updates [current year]
NIS2 implementing regulation EU Commission [current year]

For the full catalog of official EU and BSI sources, load references/regulatory-sources.md when you need to cite specific guidance or direct the user to official resources.

3. Determine Jurisdiction Focus

"Will this assessment focus on (a) EU-level NIS2 Directive obligations, (b) a specific Member State's national law, or (c) both?"

  • EU-level only → Use Directive references (Art. 21, Art. 23, Annexes I/II)
  • Germany → Load references/germany-nis2umsucg.md. Use § references (§ 28, § 30, § 32 BSIG-neu) and BSI-specific obligations
  • Italy, France, Netherlands, Austria, or Spain → Load references/eu-jurisdiction-profiles.md. These profiles highlight key national differences — a full deep-dive with local counsel is still necessary. Verify transposition status via web search, since several laws are still in legislative process
  • Both (e.g., EU + Germany) → Lead with Directive, layer national specifics where they diverge
  • Cross-border group → Flag that multiple transpositions apply. Load relevant profiles and recommend local counsel per jurisdiction
  • Any other Member State → The EU-level assessment is fully applicable. National specifics will need separate research

Phase 1: Scope & Classification (~5 minutes)

Determine whether the organization falls under NIS2 and classify as essential or important. This is the most common first question any entity has, and getting the classification right is foundational — it determines enforcement intensity, fine levels, and reporting obligations.

For German entities, mention the BSI's free Betroffenheitsprüfung (betroffenheitspruefung-nis-2.bsi.de) as a complementary first step. Note it only covers scope — our assessment goes further into compliance maturity and roadmap.

Ask questions ONE AT A TIME in this order:

#CategoryQuestion
1Sector"What sector(s) does your organization operate in?" Offer Annex I/II categories as reference.
2Services"What specific services do you provide within that sector?" (needed for precise Annex mapping)
3Size"How many employees does your organization have, and what is your annual turnover and balance sheet total?"
4Group structure"Is your organization part of a corporate group? If so, are the NIS2-relevant activities at group or entity level?"
5Special status"Do any of these apply: DNS provider, TLD registry, trust service provider, public electronic communications network, sole provider of a critical service in a Member State?"
Classification Logic

Load references/sector-classification.md for the full Annex I/II sector mapping and size thresholds.

Decision tree:

  1. Sector match → Map to Annex I (high criticality) or Annex II (other critical)
  2. Size test → Medium: ≥50 employees OR (turnover >€10M AND balance sheet >€10M). Large: ≥250 employees OR (turnover >€50M AND balance sheet >€43M)
  3. Essential entity if: Annex I + large, OR qualified trust service provider, TLD registry, DNS provider, public comms provider, central public administration, or KRITIS operator (DE)
  4. Important entity if: Annex I + medium, OR Annex II + medium/large
  5. Regardless-of-size: Check special categories in reference file
  6. Out of scope if: Below medium thresholds AND no special status
  7. DORA check: Financial entities under DORA are excluded from NIS2 Art. 21 and Art. 23 — redirect to DORA compliance (DORA acts as lex specialis with its own equivalent requirements)
  8. CIR check: Digital infrastructure/provider entities face additional binding requirements under CIR 2024/2690 beyond Art. 21 — flag early

Group structure: Apply the size test at the level where the NIS2-relevant service operates. Consolidated figures apply with operational integration. Independent entities within a group: assess separately.

Classification Output

SCOPE DETERMINATION

  • Sector: [Annex I/II sector and sub-sector]
  • Size classification: [Small / Medium / Large]
  • Entity category: [Essential / Important / Out of Scope]
  • Basis: [Directive Art. / national law reference]
  • Special flags: [DORA exclusion / CIR applies / Regardless-of-size / None]

If Germany: BSI registration [required/not required], status [completed / overdue]

Example: A German managed IT services provider with 120 employees and €25M turnover in the ICT service management sector (Annex I) → Annex I, medium enterprise, essential entity (MSPs are essential regardless of size). BSI registration required (overdue since 6 March 2026). CIR 2024/2690 applies. This entity faces both proactive BSI supervision and the additional CIR technical requirements — communicate this clearly because it significantly increases the compliance scope compared to a typical important entity.

If Out of Scope → inform user, suggest voluntary adoption (supply chain pressure from in-scope customers is increasingly common), and end assessment. Otherwise proceed to Phase 2.


Phase 2: Art. 21 Gap Analysis (~15 minutes)

Walk through the 10 risk management measures from Art. 21(2)(a)–(j) / § 30 BSIG-neu. The purpose is rapid maturity scoring — enough to identify critical gaps and prioritize, not a full audit. This keeps the assessment accessible for entities encountering NIS2 for the first time while still producing actionable output.

Load references/art21-measures.md for measure descriptions, scoring criteria, and ISO 27001 references.

Assessment Approach

For each measure, ask ONE targeted question, then score on a 0–4 scale:

ScoreLevelDescription
0Non-existentNo awareness, no measures
1Ad hocInformal, reactive, person-dependent
2DefinedDocumented but inconsistently applied
3ManagedConsistently implemented, monitored, reviewed
4OptimizedContinuously improved, measured, integrated into enterprise risk management
ISO 27001 References

For each measure, include a brief reference to relevant ISO 27001:2022 Annex A controls. Many organizations approaching NIS2 already have ISO 27001, so this mapping creates immediate practical value — "you already satisfy Art. 21(2)(a) through your A.5.1 and A.5.2 controls" is the kind of output that saves hours of consultant time.

Show full SKILL.md (607 more words)Show less
The 10 Measures

Walk through each measure sequentially. For each:

  1. Briefly explain what NIS2 requires (1–2 sentences)
  2. Ask the targeted assessment question
  3. Score based on the user's response — explain your reasoning so the user understands and can challenge the score
  4. Note key gaps if score ≤ 2

Detailed measures, questions, and scoring criteria are in references/art21-measures.md.

Gap Analysis Output

After scoring all 10 measures, present a summary table:

markdown
## NIS2 Gap Analysis Summary

| # | Measure (Art. 21(2)) | Maturity (0-4) | Status |
|---|---------------------|----------------|--------|
| a | Risk analysis & IS policies | [score] | [🔴/🟡/🟢] |
| b | Incident handling | [score] | [🔴/🟡/🟢] |
| c | Business continuity & crisis mgmt | [score] | [🔴/🟡/🟢] |
| d | Supply chain security | [score] | [🔴/🟡/🟢] |
| e | Network & IS acquisition/dev/maint | [score] | [🔴/🟡/🟢] |
| f | Effectiveness assessment | [score] | [🔴/🟡/🟢] |
| g | Cyber hygiene & training | [score] | [🔴/🟡/🟢] |
| h | Cryptography & encryption | [score] | [🔴/🟡/🟢] |
| i | HR security & access control | [score] | [🔴/🟡/🟢] |
| j | MFA & secure communications | [score] | [🔴/🟡/🟢] |

**Overall Score: [X] / 40**
**Overall Rating: [🔴 Critical / 🟡 Needs Improvement / 🟢 On Track]**

Traffic light: 🔴 = 0–1, 🟡 = 2, 🟢 = 3–4. Overall: 🔴 ≤ 15, 🟡 16–29, 🟢 ≥ 30.

Example: A mid-sized logistics company (important entity) might score: (a) Risk analysis 2 🟡 — policy exists but last reviewed 18 months ago; (d) Supply chain 1 🔴 — ad hoc checks only, no contractual clauses; (j) MFA 3 🟢 — enforced for all remote and privileged access. Overall 19/40, 🟡 Needs Improvement. Top priorities: supply chain security and incident handling.


Phase 3: Compliance Roadmap

Generate a prioritized remediation roadmap based on the gap analysis.

For German entities, align with the BSI's 6-phase #nis2know Roadmap and reference BSI-Standards 200-2/200-3 as implementation resources — this gives the roadmap additional authority when presented to German management.

Prioritization Framework

Essential entities face proactive supervision, so their gaps are more urgent at every maturity level:

Maturity 0Maturity 1Maturity 2
Essential entityP1 — ImmediateP1 — ImmediateP2 — Short-term
Important entityP1 — ImmediateP2 — Short-termP3 — Medium-term

Measures at maturity 3–4 → maintenance mode (not in roadmap).

  • P1 — Immediate (0–3 months): Fundamental gaps, acute risk
  • P2 — Short-term (3–6 months): Significant gaps, structured remediation
  • P3 — Medium-term (6–12 months): Enhancement to full maturity
Roadmap Output

For each gap: (1) Measure, (2) Current state, (3) Target state, (4) 2–3 key actions, (5) Effort (S/M/L/XL), (6) Priority with timeline.

Germany-Specific Items

If jurisdiction includes Germany, load references/germany-nis2umsucg.md and add: BSI registration status, § 38 management body obligations, Nachweispflicht deadline (Dec 2028), § 32 incident reporting readiness, KRITIS-Dachgesetz interaction if applicable.

Management Briefing (Art. 20 / § 38 BSIG)

Include a management body section in every roadmap. NIS2 Art. 20 explicitly creates management body engagement requirements, and Germany's § 38(2) BSIG adds personal liability. This section is often the most persuasive part of the assessment — it transforms the abstract compliance obligation into something personal for the individuals in the room:

Management Body Obligations

  • Approve risk management measures (Art. 20(1) / § 38(1) BSIG)
  • Undergo regular cybersecurity training (Art. 20(2) / § 38(3) BSIG) — not delegable
  • Oversee implementation — execution can be delegated to CISO, oversight cannot
  • Germany: Personal liability for damages from non-compliance (§ 38(2) BSIG)

Output: Final Assessment Report

Combine all three phases using the template in references/templates.md.

Report structure:

  1. Executive Summary (scope verdict, overall score, top 3 priorities)
  2. Scope & Classification Detail
  3. Gap Analysis Scoring Table
  4. Prioritized Compliance Roadmap
  5. Management Body Obligations
  6. Jurisdiction-Specific Requirements (if applicable)
  7. Recommended Next Steps

Key Guardrails

The non-obvious pitfalls that trip up real assessments:

  1. Self-assessment obligation — No official notification from authorities. Entities must determine their own status. Many don't realize they're in scope
  2. Supply chain cascading — Out-of-scope organizations increasingly face contractual NIS2 requirements from in-scope customers
  3. Dual incident reporting — NIS2 (24h/72h/1-month to national authority) and GDPR (72h to DPA) run in parallel for incidents involving personal data. Different timelines, recipients, and content
  4. Size threshold trap — The OR/AND logic catches companies small by headcount but large by revenue
  5. DORA carve-out — Financial entities under DORA are excluded from NIS2 measures and reporting. Redirect, don't assess
  6. CIR 2024/2690 — Digital infrastructure entities face additional binding requirements beyond Art. 21
  7. Commission amendments (Jan 2026) — Proposed, not in force. Mention for strategic awareness only

More EU regulation skills

This skill works standalone. Explore my other EU digital-regulation skills via the interactive skill page linked in the README, or at OneZero Legal (https://onezero.legal).

© lawve-ai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (references) in skills/nis2-navigator-oliver-schmidt-prietz of lawve-ai/awesome-legal-skills.

  • SKILL.md
  • LICENSE.txt
  • README.md
  • evals.json
  • references/art21-measures.md
  • references/eu-jurisdiction-profiles.md
  • references/germany-nis2umsucg.md
  • references/regulatory-sources.md
  • references/sector-classification.md
  • references/templates.md

Open the folder on GitHubat commit 045f738

Compare with similar skills

Nis2 Navigator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nis2 Navigator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nis2 Navigator this skilllawve-ai/awesome-legal-skills847—~3.6kAutomated safety check: PassAGPL-3.0
Bom Explorecdxgen/cdxgen1.1k—~1.2kAutomated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Eu CraSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4kAutomated safety check: PassMIT
Kesekit Checkcdppcorp/KESE-KIT360—~1.3kAutomated safety check: PassMIT

Similar skills

  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    360 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated today
    SecurityAuto-check passed

More from lawve-ai/awesome-legal-skills

All 154 skills in this repo
  • Customs Trade Law Onur Kafkas

    lawve-ai/awesome-legal-skills

    U.S. An agent skill from lawve-ai/awesome-legal-skills.

    847 GitHub stars~4.1k tokensUpdated 8 days ago
    Auto-check passed
  • Eu Data Act Oliver Schmidt Prietz

    lawve-ai/awesome-legal-skills

    Practitioner skill for advising on EU Regulation 2023/2854 (Data Act).

    847 GitHub stars~3.9k tokensUpdated 8 days ago
    Auto-check passed
  • Litigation Deadline Calendar

    lawve-ai/awesome-legal-skills

    Calendar litigation and arbitration deadlines from a scheduling order.

    847 GitHub stars~4.3k tokensUpdated 8 days ago
    Auto-check passed
  • Outlook Emails Lawvable

    lawve-ai/awesome-legal-skills

    Read, search, and download emails and attachments from Microsoft Outlook via OAuth2.

    847 GitHub stars~672 tokensUpdated 8 days ago
    Auto-check passed
  • Ambiguity Report

    lawve-ai/awesome-legal-skills

    Turn an interpretive-ambiguity audit of a legal text — contract, statute, regulation, or judicial opinion — into a polished deliverable.

    847 GitHub stars~4.6k tokensUpdated 8 days ago
    Auto-check passed
  • Az Eu Website Privacy Audit

    lawve-ai/awesome-legal-skills

    Audits a website for compliance with Azerbaijan's Law on Personal Data No.

    847 GitHub stars~3.8k tokensUpdated 8 days ago
    Auto-check passed

Categories

Questions about Nis2 Navigator

What does Nis2 Navigator do?

NIS2 Compliance Navigator — scope classification, Art. An agent skill from lawve-ai/awesome-legal-skills. Nis2 Navigator is an agent skill from lawve-ai/awesome-legal-skills. NIS2 Compliance Navigator — scope classification, Art.

When should I use Nis2 Navigator?

Nis2 Navigator fits situations like: user mentions NIS2; cyberbeveiligingswet; decreto legislativo 138; user asks if their organization falls under NIS2.

How do I install Nis2 Navigator in Claude Code?

Run `npx skills add lawve-ai/awesome-legal-skills --skill nis2-navigator -a claude-code`. Or copy the skill folder (skills/nis2-navigator-oliver-schmidt-prietz in lawve-ai/awesome-legal-skills) into .claude/skills/nis2-navigator in your project. Claude Code loads it when a task matches its description.

How do I install Nis2 Navigator in Codex?

Run `npx skills add lawve-ai/awesome-legal-skills --skill nis2-navigator -a codex`. Or copy the skill folder (skills/nis2-navigator-oliver-schmidt-prietz in lawve-ai/awesome-legal-skills) into .agents/skills/nis2-navigator in your project. Codex loads it when a task matches its description.

Can I use Nis2 Navigator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lawve-ai/awesome-legal-skills --skill nis2-navigator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nis2-navigator, .gemini/skills/nis2-navigator, .github/skills/nis2-navigator and .opencode/skills/nis2-navigator in your project.

What does Nis2 Navigator need to run?

SKILL.md names no scripts, command-line tools or credentials: Nis2 Navigator is instructions for the agent only.

Does Nis2 Navigator access the network?

SKILL.md names 1 domain. As links in the text: onezero.legal. This is read from the text; nothing was executed.

Is Nis2 Navigator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nis2 Navigator use?

Nis2 Navigator is published under the AGPL-3.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nis2 Navigator use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.

What are the alternatives to Nis2 Navigator?

Skills that share tags, products or a category with Nis2 Navigator: Bom Explore (cdxgen/cdxgen, 1.1k stars), Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars) and Eu Cra (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nis2 Navigator?

lawve-ai (a GitHub organization) maintains it in lawve-ai/awesome-legal-skills, which has 847 GitHub stars. The repository holds 154 skills in this directory. The repository was last updated on October 2, 2026.

Source: lawve-ai/awesome-legal-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.