Agent skill

Whistleblower Policy Malik Taiar

by lawve-ai in lawve-ai/awesome-legal-skills

Guide for (a) auditing an existing whistleblower system or (b) drafting a compliant reporting policy from a provided template.

AGPL-3.0Auto-check passedLegal & Compliance

Install Whistleblower Policy Malik Taiar

skills CLI
$ npx skills add lawve-ai/awesome-legal-skills --skill whistleblower-policy-malik-taiar -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install lawve-ai/awesome-legal-skills whistleblower-policy-malik-taiar --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/whistleblower-policy-advisor-malik-taiar .claude/skills/whistleblower-policy-malik-taiar && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
whistleblower-policy-malik-taiar
GitHub stars
847
Token cost
~6.2k tokens
SKILL.md length
2,068 words
Files
9 (incl. references)
Skills in repo
154
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Guide for (a) auditing an existing whistleblower system or (b) drafting a compliant reporting policy from a provided template.

  • Works in 12 steps: Verify Applicability → Assess Compliance (use references) → Draft the Report → …
  • Legal & Compliance work in your project
  • SKILL.md covers Overview, Legal Framework Covered, Contents and DISCLAIMER, plus 5 more sections
  • Reaches legifrance.gouv.fr

What it does

Whistleblower Policy Malik Taiar is an agent skill from lawve-ai/awesome-legal-skills. Guide for (a) auditing an existing whistleblower system or (b) drafting a compliant reporting policy from a provided template. Covers EU Directive 2019/1937, the amended Sapin II law (Waserman 2022), Decree 2022-1284, CNIL guidelines, public sector requirements, and duty of vigilance.

Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `README.md`, `SKILL.fr.md` and `references/DECRET_PROCEDURE.md`).

It sits in Legal & Compliance. The repository describes itself as: A curated list of awesome Agent Skills for automating legal work. The licence is AGPL-3.0.

When your agent uses it

  • Legal & Compliance work in your project

Example prompts

  • “/whistleblower-policy-malik-taiar”

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Verify Applicability
  2. Assess Compliance (use references)
  3. Draft the Report
  4. Prioritize Recommendations
  5. Applicability
  6. Reception Channel
  7. Designated Persons
  8. Verification and Processing
  9. Confidentiality
  10. Dissemination and Information
  11. GDPR Compliance (CNIL Framework 06/07/2023)
  12. Sector-Specific Requirements

What it can do on your machine

Read from SKILL.md and the folder at commit 045f738. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • legifrance.gouv.fr

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Whistleblower Policy Malik Taiar loads about 6.2k tokens when it runs, and up to ~30k if it reads all its reference files. Until then it costs about 80 tokens; SKILL.md has 2,068 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~6.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~30k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from lawve-ai/awesome-legal-skills at commit 045f738, republished under its AGPL-3.0 licence (© lawve-ai). 2,068 words, ~6,221 tokens.

Download SKILL.mdSave it as .claude/skills/whistleblower-policy-malik-taiar/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
whistleblower-policy-malik-taiar
description
Guide for (a) auditing an existing whistleblower system or (b) drafting a compliant reporting policy from a provided template. Covers EU Directive 2019/1937, the amended Sapin II law (Waserman 2022), Decree 2022-1284, CNIL guidelines, public sector requirements, and duty of vigilance.
metadata.author
Malik Taiar
metadata.license
agpl-3.0
metadata.version
2026-04-26

Whistleblower Systems - Assessment & Drafting

Overview

This Guide can help you (a) assess the compliance of an existing whistleblower system or (b) draft a reporting policy based on a provided template.

  • EU Directive 2019/1937
  • Amended Sapin II Law (Waserman Law 2022)
  • Decree No. 2022-1284
  • CNIL Professional Alerts Framework
Two Modes of Use
ModeDescriptionOutput
A. Compliance AssessmentAudit an existing systemAssessment report + action plan
B. Policy DraftingCreate a system based on referenced sourcesPolicy based on template
What This Skill Does / Does Not Do
What this skill doesWhat it does not do
Assesses compliance of an existing systemProvide definitive legal conclusions
Drafts a reporting policy based on the provided templateGuarantee enforceability

Scope: Internal reporting systems subject to the amended Sapin II Law and Decree No. 2022-1284.

Variation Callouts:

  • Public Sector: Coordination with Art. 40 CPP
  • Duty of Vigilance: Companies with ≥ 5,000 / 10,000 employees

Contents

/
├── SKILL.md
├── LICENSE.txt
├── README.md
├── assets/
    ├── Template_Politique_Lanceur_Alerte.docx ← Template for Mode B
    ├── [PDF sources]
└── references/
    ├── TEXTES_LEGAUX.md      ← Verbatim legal article citations
    ├── DECRET_PROCEDURE.md   ← Mandatory elements (Decree 2022-1284)
    ├── RGPD_CNIL.md          ← GDPR compliance and CNIL framework
    ├── FONCTION_PUBLIQUE.md  ← Public sector specifics + Art. 40 CPP
    └── VIGILANCE.md          ← Duty of vigilance coordination

DISCLAIMER

THIS IS NOT LEGAL ADVICE. This skill is provided for informational and educational purposes only. Laws vary by jurisdiction and individual circumstances, and only a qualified lawyer can provide advice tailored to your specific situation. This does not constitute legal advice or opinion—it is a Claude skill intended for legal professionals. All outputs from this skill must be reviewed by a qualified legal professional before any legal use.

Choosing the Mode of Use

Mode A: Compliance Assessment

When to use: The client already has a system and wants to verify its compliance.

→ Go to Section 3 (Inputs) then Section 5 (Assessment Workflow)

Mode B: Policy Drafting

When to use: The client does not have a system or wants to create a new one.

→ Go to Section 3 (Inputs) then Section 13 (Policy Drafting)

TemplateFormatUsage
Template_Politique_Lanceur_Alerte.docxWordInternal reporting policy template

IMPORTANT: The template must be used EXACTLY as provided. Only variable elements should be adapted.

Inputs to Collect (request before assessing)

A. Organizational Context (mandatory)
  • Legal form and headcount (threshold ≥ 50 employees/agents?)
  • Business sector and status (private/public/mixed)
  • Group structure (pooling possible?)
  • Existing system: implementation date, post-Waserman update?
B. Documentation to Request
  • Internal reporting procedure
  • Employee communication materials
  • Templates used (acknowledgment, feedback, closure)
  • Job description / designated officer appointment
  • GDPR register / DPIA if existing
  • Pooling with other entities considered?
  • Outsourcing of reception channel?
  • Coordination with other systems (duty of vigilance)?

Deliverables - Mode A: Assessment

Quick Start (default output)

ALWAYS produce:

  1. Executive Summary (1 page)
  2. Phase-by-Phase Assessment Table (8 phases)
  3. Recommended Action Plan
A. Executive Summary
  • Overall compliance: Compliant / Partially Compliant / Non-Compliant
  • Top 5 gaps identified (ranked by priority)
  • Recommendation: "Compliant" / "Correct before deployment" / "Escalate"
B. Detailed Assessment Table
PhaseCheckpointCompliantGap IdentifiedPriorityRecommendation
1. Applicability
1.1Headcount threshold met (≥ 50)
1.2Entity type identified (private/public/mixed)
1.3Pooling compliant if applicable (< 250, concurrent decision)
2. Reception Channel
2.1Written OR oral channel provided (entity's choice)
2.2If oral provided: telephone or voicemail mentioned
2.3If oral provided: video/in-person meeting on request (20 business days)
2.4Ability to transmit any type of document
2.5Written acknowledgment within 7 business days
3. Designated Persons
3.1Formal designation for receipt
3.2Formal designation for processing
3.3Sufficient competence
3.4Sufficient authority
3.5Sufficient resources
3.6Impartiality safeguards in place
3.7If outsourced: third-party obligations compliant
4. Verification / Processing
4.1Admissibility criteria defined (Art. 6 + Art. 8 I.A.)
4.2Reporter informed if inadmissible
4.3Follow-up for non-compliant reports specified
4.4Follow-up for anonymous reports specified
4.5Written feedback within 3 months
4.6Feedback content compliant (measures + reasons)
4.7Reasoned closure provided
4.8Written closure notification to reporter
5. Confidentiality
5.1Information integrity guaranteed
5.2Reporter identity confidentiality
5.3Persons concerned confidentiality
5.4Third parties mentioned confidentiality
5.5Access restricted to authorized persons
5.6Prompt transmission to designated persons
5.7If oral: recording procedures defined
5.8Reporter's right to verify/approve
5.9Retention period limited
6. Dissemination / Information
6.1Procedure disseminated with sufficient publicity
6.2Permanently accessible to eligible persons
6.3Whistleblower status conditions
6.4Categories of eligible persons
6.5Reporting procedures (form, channels)
6.6Processing timelines (7-day acknowledgment, 3-month feedback)
6.7Confidentiality guarantees
6.8Protections granted
6.9Information on external channels
6.10GDPR information
7. GDPR Compliance (CNIL Ref. 06/07/2023)
7.1Legal basis identified (legal obligation or legitimate interest)
7.2Purposes defined with no incompatible reuse
7.3Data minimization respected (by phase: collection, investigation, post-decision)
7.4Anonymous reports possible, no re-identification
7.5Authorized users documented, access logged
7.6Disclosure rules followed (reporter: consent / subject: after substantiation)
7.7Retention periods defined by phase and communicated
7.8Data subject notification compliant (reporter at acknowledgment, subject within 1 month)
7.9Data subject rights guaranteed (access, objection, rectification, restriction)
7.10Security measures compliant (17 CNIL categories)
7.11Processing register updated
7.12DPIA completed (recommended)
8. Sector-Specific Requirements
8.1Public sector: Art. 40 CPP coordination documented
8.2Public sector: Designated officer informed of Art. 40 obligations
8.3Vigilance: Consultation with representative unions
8.4Vigilance: Extended scope (subsidiaries, subcontractors)
8.5Vigilance: External stakeholders eligible
8.6Regulated sectors: Sector-specific obligations coordinated

Assessment Workflow (Mode A)

Step 1 — Verify Applicability

IS THE ORGANIZATION SUBJECT TO THE OBLIGATION?

  • Private legal entity ≥ 50 employees → YES
  • Public legal entity ≥ 50 agents → YES
  • Municipality ≥ 10,000 inhabitants → YES
  • State administration → YES
  • Other → CHECK sector-specific regulations

Pooling possible (< 250 employees/agents): See Art. 8 I. B. and C. of the amended Sapin II Law + Art. 7 II of the Decree

Step 2 — Assess Compliance (use references)

IMPORTANT - MANDATORY READING: Before any assessment, read IN FULL the file assets/Decret_2022_1284.pdf (Articles 1 to 8 + annex). Do not rely solely on summaries—the exact decree text is authoritative.

Assess the system systematically using the references:

ReferenceWhat it covers
assets/Decret_2022_1284.pdfALWAYS READ FIRST - Full decree text
DECRET_PROCEDURE.mdSummary of mandatory elements (Art. 4-8 decree)
RGPD_CNIL.mdGDPR compliance and CNIL framework
FONCTION_PUBLIQUE.mdPublic sector specifics + Art. 40 CPP
VIGILANCE.mdDuty of vigilance coordination (if applicable)
TEXTES_LEGAUX.mdVerbatim citations for verification

Assessment method:

  1. Read Decree 2022-1284 in full before starting the assessment
  2. Verify that all mandatory elements are present (completeness)
  3. Verify that each clause is compliant with the legal and regulatory framework (no contradictions)
  4. Use the Section 6 checklist to structure the assessment by phase
  5. When in doubt, always return to the exact text of the decree
Step 3 — Draft the Report
REPORT STRUCTURE:
1. Executive summary (overall compliance, strengths, priority areas)
2. Context and scope (organization, regulatory framework, documents analyzed)
3. Detailed results (cover all 8 checklist phases)
4. Gap summary table
5. Recommended action plan
6. Annexes (completed checklist, applicable texts)
Step 4 — Prioritize Recommendations
PriorityCriterionExample
CRITICALAbsence of system, non-compliance with legal deadlines, confidentiality failureNo acknowledgment of receipt
IMPORTANTInsufficient information, unidentified designated officer, GDPR non-complianceImpartiality risk with processing officer
IMPROVEMENTProcedure needs refinement, incomplete documentation, training to strengthenCommunication materials to complete

Assessment Checklist (8 phases)

Phase 1: Applicability

See Art. 8 I. B. amended Sapin II Law + Art. 1 and 2 of the Decree

  • Organization subject to obligation (threshold met)
  • Entity type identified (private/public/mixed)
  • Pooling compliant if applicable (< 250, concurrent decision)
Phase 2: Reception Channel

→ Detailed reference: DECRET_PROCEDURE.md - Section 1

  • Written OR oral channel provided (entity's choice - Art. 4 I decree)
  • If oral provided: telephone or voicemail mentioned
  • If oral provided: video/in-person meeting on request (20 business days)
  • Ability to transmit any type of document
  • Written acknowledgment within 7 business days provided
Phase 3: Designated Persons

→ Detailed reference: DECRET_PROCEDURE.md - Section 3

  • Formal designation in procedure (receipt AND processing)
  • Sufficient competence, authority, and resources
  • Impartiality safeguards in place
  • If pooling (< 250 employees): Art. 7 II conditions met
  • If outsourced: third-party obligations compliant with Art. 7 I
Show full SKILL.md (845 more words)Show less
Phase 4: Verification and Processing

→ Detailed reference: DECRET_PROCEDURE.md - Section 2

VERIFICATION:

  • Admissibility criteria defined (Art. 6 and Art. 8 I.A.)
  • Reporter notification in case of inadmissibility provided
  • Follow-up for non-compliant reports specified
  • Follow-up for anonymous reports specified

PROCESSING:

  • Written feedback within 3 months maximum provided
  • Feedback content compliant (measures considered/taken + reasons)
  • Reasoned closure provided (unfounded or moot allegations)
  • Written closure notification to reporter provided
Phase 5: Confidentiality

→ Detailed reference: DECRET_PROCEDURE.md - Section 4

  • Information integrity and confidentiality guaranteed
  • Identity protection: reporter, persons concerned, third parties mentioned
  • Access prohibited to unauthorized persons
  • Prompt transmission to designated persons provided
  • If oral: recording procedures defined
  • Retention period limited to strict necessity
Phase 6: Dissemination and Information

→ Detailed reference: DECRET_PROCEDURE.md - Section 6

  • Procedure disseminated with sufficient publicity
  • Permanently accessible to eligible persons
  • Complete information content (see Section 7 of decree)
  • Information on external channels available
Phase 7: GDPR Compliance (CNIL Framework 06/07/2023)

→ Detailed reference: RGPD_CNIL.md

  • Legal basis identified (legal obligation or legitimate interest)
  • Purposes defined, no incompatible reuse
  • Data minimization by phase (collection, investigation, post-decision)
  • Anonymous reports possible, no re-identification
  • Authorized users documented, access logged
  • Disclosure rules followed (reporter: consent / subject: after substantiation)
  • Retention periods defined by phase and communicated
  • Data subject notification compliant (reporter at acknowledgment, subject within 1 month)
  • Data subject rights guaranteed (access, objection, rectification, restriction)
  • Security measures compliant (17 CNIL categories)
  • Processing register updated
  • DPIA completed (recommended)
Phase 8: Sector-Specific Requirements

→ Public sector → FONCTION_PUBLIQUE.md

  • Coordination with Art. 40 CPP documented
  • Designated officer informed of Art. 40 obligations

→ Duty of vigilance → VIGILANCE.md

  • Mechanism established in consultation with representative unions
  • Extended scope (subsidiaries, subcontractors, suppliers)
  • External stakeholders eligible

→ Regulated sectors (financial, healthcare, etc.)

  • Coordination with sector-specific obligations documented

The Three Reporting Channels (Art. 8 Sapin II Law)

┌──────────────────────────────────────────────────────────────────────────────┐
│  CHANNEL 1: INTERNAL REPORTING (Art. 8 I)                                    │
│  ────────────────────────────────────────                                    │
│  WHEN: Can be used directly, without prior condition                         │
│                                                                              │
│  ELIGIBLE PERSONS (Art. 8 I.A. 1° to 5°):                                    │
│  → Staff members (current or former)                                         │
│  → Job applicants                                                            │
│  → Shareholders, partners, voting rights holders                             │
│  → Members of administrative, management, supervisory bodies                 │
│  → External and occasional collaborators                                     │
│  → Contractors, subcontractors and their bodies/staff                        │
├──────────────────────────────────────────────────────────────────────────────┤
│  CHANNEL 2: EXTERNAL REPORTING (Art. 8 II)                                   │
│  ─────────────────────────────────────────                                   │
│  WHEN: Can be used in two ways                                               │
│    ✓ EITHER after making an internal report                                  │
│    ✓ OR directly (without going through internal)                            │
│                                                                              │
│  POSSIBLE RECIPIENTS:                                                        │
│  1° Competent authority (list in annex to Decree No. 2022-1284)              │
│  2° Defender of Rights                                                       │
│  3° Judicial authority (Public Prosecutor)                                   │
│  4° Competent EU institution, body or agency                                 │
├──────────────────────────────────────────────────────────────────────────────┤
│  CHANNEL 3: PUBLIC DISCLOSURE (Art. 8 III)                                   │
│  ─────────────────────────────────────────                                   │
│  WHEN: Protection granted only in the following cases                        │
│                                                                              │
│  CASE 1 (Art. 8 III 1°) - Ineffective reports:                               │
│    → After external report (preceded or not by internal)                     │
│    → AND no appropriate measure taken at deadline expiry                     │
│                                                                              │
│  CASE 2 (Art. 8 III 2°) - Serious and imminent danger                        │
│                                                                              │
│  CASE 3 (Art. 8 III 3°) - Risks related to external reporting:               │
│    → Risk of retaliation                                                     │
│    → OR impossibility of effective remedy                                    │
│                                                                              │
│  DEROGATORY CASE (Art. 8 III penultimate paragraph):                         │
│    → IMMINENT or MANIFEST danger to the public interest                      │
│                                                                              │
│  ⚠️ EXCLUSION: Cases 2°, 3° and derogatory do NOT apply if                   │
│     disclosure harms national defense/security                               │
└──────────────────────────────────────────────────────────────────────────────┘

NOTE: Since the Waserman Law (2022), whistleblowers can freely choose between internal and external channels. They are no longer required to go through internal channels first.

Whistleblower Definition (Art. 6 Sapin II Law)

WHISTLEBLOWER = Natural person who:

  • Reports or discloses WITHOUT DIRECT FINANCIAL CONSIDERATION
  • In GOOD FAITH
  • Information concerning:
    • A crime or offense
    • A threat or harm to the public interest
    • A violation OR an attempt to conceal a violation of:
      • an international commitment
      • European Union law
      • a law or regulation

Exclusions (Art. 6 II): National defense secrets, medical confidentiality, judicial deliberation secrecy, investigation/inquiry secrecy, attorney-client privilege.

Facilitators (Art. 6-1): Natural or legal person under private non-profit law who assists the whistleblower.

Whistleblower Protections

→ Detailed reference: TEXTES_LEGAUX.md - Article 10-1

Civil and criminal immunity (Art. 10-1 I) if reasonable grounds to believe the report was necessary.

Prohibited retaliation measures (Art. 10-1 II): suspension, dismissal, demotion, transfer of duties, discrimination, harassment, blacklisting, etc.

Reversal of burden of proof (Art. 10-1 III): the employer must prove their decision was justified.

Automatic nullity of any act taken in breach of these protections.

Common Errors

ErrorRiskCorrection
System not updated since 2022Waserman non-complianceComplete revision
Requiring internal channel firstContrary to free channel choiceRemove this requirement
No automatic acknowledgment of receiptNon-compliance with 7-day deadlineAutomate sending
Confidentiality not technically guaranteedCompromise riskEncryption, partitioning
Designated officer = member of senior managementPotential conflict of interestAppoint independent officer
No information on external channelsLegal obligationComplete the information
Unlimited data retentionGDPR non-complianceApply CNIL retention periods
No oral reporting optionDecree 2022-1284 requirementProvide oral channel

Penalties and Risks

OffensePenaltyLegal Basis
Obstructing reporting1 year prison + €15,000 fineArt. 13 Sapin II Law
Retaliation3 years prison + €45,000 fineArt. 225-1 and 225-2 Criminal Code
Disclosing whistleblower identity2 years prison + €30,000 fineArt. 9 Sapin II Law
Abusive reporting5 years prison + €45,000 fineArt. 226-10 Criminal Code

Reference Texts

TextDateFile
EU Directive 2019/193710/23/2019assets/Directive_2019_1937.pdf
Law No. 2016-1691 (Sapin II)12/09/2016assets/Loi_Sapin_II_consolidee.pdf
Law No. 2022-401 (Waserman)03/21/2022assets/Loi_Waserman_2022.pdf
Decree No. 2022-128410/03/2022assets/Decret_2022_1284.pdf
CNIL Framework07/24/2023assets/Referentiel_CNIL_alertes_professionnelles.pdf
Public Sector Circular06/26/2024assets/Circulaire_26_juin_2024.pdf
DREETS Summary02/17/2025assets/DREETS_synthese_2025.pdf
Law No. 2017-399 (Vigilance)03/27/2017assets/L225-102-1.pdf and assets/L225-102-2.pdf
EU Directive 2024/1760 (CS3D)06/13/2024assets/Directive_CS3D_2024_1760.pdf

Policy Drafting (Mode B)

Provided Template
TemplateFormatUsage
Template_Politique_Lanceur_Alerte.docxWordInternal reporting policy template

IMPORTANT: The template must be used EXACTLY as provided. Only variable elements should be adapted to the client's situation. Do not rephrase, delete, or reorganize template clauses.

Drafting Workflow

STEP 1 — Collect Client Information

  • Legal form and headcount
  • Channels chosen (written, oral, both)
  • Identity of designated officer(s)
  • Reporting channel contact details
  • Scope of eligible persons
  • Coordination with other systems (duty of vigilance)

STEP 2 — Adapt the Template

  • Open Template_Politique_Lanceur_Alerte.docx
  • Complete ONLY the variable elements
  • Do NOT rephrase existing clauses
  • Do NOT delete sections
  • Add the mandatory clause on external channels

Example wording to insert in the policy:

Independently of this system, any person may submit an external report
directly to the Defender of Rights, the judicial authority, or the
competent authority according to the relevant domain. The list of
external authorities is set by the annex to Decree No. 2022-1284 of
October 3, 2022, available at:
https://www.legifrance.gouv.fr/loda/id/JORFTEXT000046357368

STEP 3 — Verify Compliance → Use DECRET_PROCEDURE.md and TEXTES_LEGAUX.md to verify mandatory elements → Use RGPD_CNIL.md to verify GDPR compliance

STEP 4 — Add External Channel Information (Legal obligation - Art. 8 para. 3 of Decree No. 2022-1284)

Finalization

STEP 5 — Validation

  • Have management review
  • Consult the works council if applicable (≥ 50 employees)
  • If duty of vigilance: consultation with representative unions

STEP 6 — Dissemination

  • Choose dissemination channels (see Section 6 - Phase 6)
  • Ensure permanent accessibility
  • Train designated officers

© lawve-ai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (references) in skills/whistleblower-policy-advisor-malik-taiar of lawve-ai/awesome-legal-skills.

  • SKILL.md
  • LICENSE.txt
  • README.md
  • SKILL.fr.md
  • references/DECRET_PROCEDURE.md
  • references/FONCTION_PUBLIQUE.md
  • references/RGPD_CNIL.md
  • references/TEXTES_LEGAUX.md
  • references/VIGILANCE.md

Open the folder on GitHubat commit 045f738

Compare with similar skills

Whistleblower Policy Malik Taiar next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Whistleblower Policy Malik Taiar compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Whistleblower Policy Malik Taiar this skilllawve-ai/awesome-legal-skills847—~6.2kAutomated safety check: PassAGPL-3.0
Paper to Chinese Patent DrafterYuan1z0825/nature-skills47k1 repos~1.1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Contract Reviewevolsb/claude-legal-skill4641 repos~3.6kAutomated safety check: PassMIT
Legal Clinic Client Intakeanthropics/claude-for-legal9.6k3 repos~3.2kAutomated safety check: PassApache-2.0
Paper To Cn Patentsnipp-zha/Paper-to-patent-Skill1071 repos~959Automated safety check: PassNone

Similar skills

  • Paper to Chinese Patent Drafter

    Yuan1z0825/nature-skills

    Drafts Chinese invention patent applications and technical disclosures from research papers or inventor materials, tying each claim feature to source evidence.

    47k GitHub starsUsed in 1 repo~1.1k tokens
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Contract Review

    evolsb/claude-legal-skill

    Review legal contracts, NDAs, employment agreements, SaaS terms, and M&A documents.

    464 GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check passed
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Legal & ComplianceAuto-check passed
  • Paper To Cn Patent

    snipp-zha/Paper-to-patent-Skill

    Convert scientific papers, theses, technical reports, source code, figures, or research manuscripts into evidence-grounded Chinese invention patent drafts.

    107 GitHub starsUsed in 1 repo~959 tokens
    Legal & ComplianceAuto-check passed
  • Employment Contract Templates

    ynulihao/AgentSkillOS

    Create employment contracts, offer letters, and HR policy documents following legal best practices.

    618 GitHub starsUsed in 12 repos~4.1k tokens
    Legal & ComplianceAuto-check passed

More from lawve-ai/awesome-legal-skills

All 154 skills in this repo
  • Customs Trade Law Onur Kafkas

    lawve-ai/awesome-legal-skills

    U.S. An agent skill from lawve-ai/awesome-legal-skills.

    847 GitHub stars~4.1k tokensUpdated 8 days ago
    Auto-check passed
  • Eu Data Act Oliver Schmidt Prietz

    lawve-ai/awesome-legal-skills

    Practitioner skill for advising on EU Regulation 2023/2854 (Data Act).

    847 GitHub stars~3.9k tokensUpdated 8 days ago
    Auto-check passed
  • Litigation Deadline Calendar

    lawve-ai/awesome-legal-skills

    Calendar litigation and arbitration deadlines from a scheduling order.

    847 GitHub stars~4.3k tokensUpdated 8 days ago
    Auto-check passed
  • Outlook Emails Lawvable

    lawve-ai/awesome-legal-skills

    Read, search, and download emails and attachments from Microsoft Outlook via OAuth2.

    847 GitHub stars~672 tokensUpdated 8 days ago
    Auto-check passed
  • Ambiguity Report

    lawve-ai/awesome-legal-skills

    Turn an interpretive-ambiguity audit of a legal text — contract, statute, regulation, or judicial opinion — into a polished deliverable.

    847 GitHub stars~4.6k tokensUpdated 8 days ago
    Auto-check passed
  • Az Eu Website Privacy Audit

    lawve-ai/awesome-legal-skills

    Audits a website for compliance with Azerbaijan's Law on Personal Data No.

    847 GitHub stars~3.8k tokensUpdated 8 days ago
    Auto-check passed

Questions about Whistleblower Policy Malik Taiar

What does Whistleblower Policy Malik Taiar do?

Guide for (a) auditing an existing whistleblower system or (b) drafting a compliant reporting policy from a provided template. Whistleblower Policy Malik Taiar is an agent skill from lawve-ai/awesome-legal-skills. Guide for (a) auditing an existing whistleblower system or (b) drafting a compliant reporting policy from a provided template.

When should I use Whistleblower Policy Malik Taiar?

Whistleblower Policy Malik Taiar fits situations like: legal & Compliance work in your project.

How do I install Whistleblower Policy Malik Taiar in Claude Code?

Run `npx skills add lawve-ai/awesome-legal-skills --skill whistleblower-policy-malik-taiar -a claude-code`. Or copy the skill folder (skills/whistleblower-policy-advisor-malik-taiar in lawve-ai/awesome-legal-skills) into .claude/skills/whistleblower-policy-malik-taiar in your project. Claude Code loads it when a task matches its description.

How do I install Whistleblower Policy Malik Taiar in Codex?

Run `npx skills add lawve-ai/awesome-legal-skills --skill whistleblower-policy-malik-taiar -a codex`. Or copy the skill folder (skills/whistleblower-policy-advisor-malik-taiar in lawve-ai/awesome-legal-skills) into .agents/skills/whistleblower-policy-malik-taiar in your project. Codex loads it when a task matches its description.

Can I use Whistleblower Policy Malik Taiar in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lawve-ai/awesome-legal-skills --skill whistleblower-policy-malik-taiar -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/whistleblower-policy-malik-taiar, .gemini/skills/whistleblower-policy-malik-taiar, .github/skills/whistleblower-policy-malik-taiar and .opencode/skills/whistleblower-policy-malik-taiar in your project.

What does Whistleblower Policy Malik Taiar need to run?

SKILL.md names no scripts, command-line tools or credentials: Whistleblower Policy Malik Taiar is instructions for the agent only.

Does Whistleblower Policy Malik Taiar access the network?

SKILL.md names 1 domain. In commands or code: legifrance.gouv.fr; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Whistleblower Policy Malik Taiar safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Whistleblower Policy Malik Taiar use?

Whistleblower Policy Malik Taiar is published under the AGPL-3.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Whistleblower Policy Malik Taiar use?

About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 24k tokens, read only when the agent opens those files.

What are the alternatives to Whistleblower Policy Malik Taiar?

Skills that share tags, products or a category with Whistleblower Policy Malik Taiar: Paper to Chinese Patent Drafter (Yuan1z0825/nature-skills, 47k stars), C15t (c15t/c15t, 1.9k stars), Contract Review (evolsb/claude-legal-skill, 464 stars) and Legal Clinic Client Intake (anthropics/claude-for-legal, 9.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Whistleblower Policy Malik Taiar?

lawve-ai (a GitHub organization) maintains it in lawve-ai/awesome-legal-skills, which has 847 GitHub stars. The repository holds 154 skills in this directory. The repository was last updated on October 2, 2026.

Source: lawve-ai/awesome-legal-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.