Agent skill

AI Governance

by magnus919 in magnus919/agent-skills

Design and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS…

MITAuto-check passedLegal & Compliance

Install AI Governance

skills CLI
$ npx skills add magnus919/agent-skills --skill ai-governance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills ai-governance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance .claude/skills/ai-governance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-governance
GitHub stars
115
Token cost
~3.6k tokens
SKILL.md length
1,296 words
Files
37 (incl. scripts, references)
Skills in repo
131
Repo updated
First seen
Licence
MIT

At a glance

Design and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS…

  • Retire Agent Skills
  • SKILL.md covers Scope: What This Skill Owns, When To Use, Capability admission and… and Reference Files (load on…, plus 5 more sections
  • MCP servers and A2A capabilities
  • Approve an agent for production actions

What it does

AI Governance is an agent skill from magnus919/agent-skills. Design and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS, API, self-hosted and agentic systems. Use to admit, update or retire Agent Skills, MCP servers and A2A capabilities; approve an agent for production actions; or decide earned-autonomy promotion, reduction or revocation. Cover GxP, ALCOA+, data integrity, electronic records, assurance and QMS interfaces for life…

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 38 other files, including scripts and reference files (for example `README.md`, `evals/evals.json` and `references/ai-lifecycle-governance.md`). Compatibility notes: Agent-agnostic methodology; no external services, APIs, or runtime dependencies. The two scripts are Python 3 standard-library only.

It sits in Legal & Compliance, covering AI governance, Data pipelines and ETL and SOC 2 and security compliance. It works with Model Context Protocol. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • Retire Agent Skills
  • MCP servers and A2A capabilities
  • Approve an agent for production actions
  • Decide earned-autonomy promotion

Example prompts

  • “/ai-governance”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Agent-agnostic methodology; no external services, APIs, or runtime dependencies. The two scripts are Python 3 standard-library only.

What it can do on your machine

Read from SKILL.md and the folder at commit 22b4723. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Agent-agnostic methodology; no external services, APIs, or runtime dependencies. The two scripts are Python 3 standard-library only.

    From compatibility in the SKILL.md frontmatter.

Context cost

AI Governance loads about 3.6k tokens when it runs, and up to ~69k if it reads all its reference files. Until then it costs about 201 tokens; SKILL.md has 1,296 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~201
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~69k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit 22b4723, republished under its MIT licence (© magnus919). 1,296 words, ~3,587 tokens.

Download SKILL.mdSave it as .claude/skills/ai-governance/SKILL.md (or your agent's skills folder). This skill also uses 36 other files; get the full folder from GitHub.
name
ai-governance
description
Design and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS, API, self-hosted and agentic systems. Use to admit, update or retire Agent Skills, MCP servers and A2A capabilities; approve an agent for production actions; or decide earned-autonomy promotion, reduction or revocation. Cover GxP, ALCOA+, data integrity, electronic records, assurance and QMS interfaces for life sciences. Do not use for legal interpretation (legal-strategy), data-platform mechanics (data-architect/data-engineering), security implementation (secure-software-engineering), skill package inspection (agent-skills), or executing runtime changes (agent-production-operations).
compatibility
Agent-agnostic methodology; no external services, APIs, or runtime dependencies. The two scripts are Python 3 standard-library only.
license
MIT
metadata.tags
ai-governance, responsible-ai, model-risk, ai-risk-management, governance-operating-model, ai-governance-principles, lifecycle-gates, fairness, transparency…

AI Governance

AI governance is the system an organization uses to decide, before a model is built and while it runs, who is accountable for an AI system, what risk it is allowed to carry, what evidence must gate each lifecycle stage, and how the organization reports and audits that posture. This skill teaches an agent to reason about and operate that system: it is a methodology skill, not a tool manual and not legal or security advice.

Scope: What This Skill Owns

You ownYou don't own
Governance principles and how they translate into policy and controlsDrafting or opining on legal interpretation of a regulation
The governance operating model: councils, stewards, decision rights, RACI, federated vs. centralizedData-platform mechanics, pipelines, and lineage tooling internals
Risk frameworks: NIST AI RMF, ISO/IEC 42001 & 23894, model-risk tiering, risk registersImplementing authentication, authorization, or vulnerability fixes
Lifecycle stage gates across ideation, build, evaluate, deploy, monitor, retireCI/CD pipeline and deployment-gate configuration
Cross-cutting 6L-G governance loop: strategy, impact, implementation, acceptance, operations, learningTreating an author-developed framework as a regulatory or standards requirement
Fairness, bias, transparency, explainability, and accountability controlsProduct portfolio/roadmap governance cadences
Privacy and data governance for training and operational dataCapital allocation, org structure, or M&A governance
GxP AI governance overlay: ALCOA+, data integrity, electronic records, risk-based assurance, QMS interfacesLegal applicability determinations, validation protocols, SOPs, or quality-system operation
LLM/agent safety: prompt injection, exposure ladders, tool authorization, memory, egress, red-teaming, supply chainHost-level or application-level security scanning
Regulatory landscape and compliance mapping (as guidance, not advice)Legal drafting, regulatory filings, or attorney-client work product
Third-party and model due diligence, board reporting, auditAny authoritative statement of "your system is compliant"

This is a prevention-and-operations methodology: it gives the agent frameworks, decision models, and controls to design and run governance, not a claim that a system is compliant or safe. For every engagement, record the operating model, the risk tier, the evidence that gated each stage, and the accountable owner of each accepted exception.

When To Use

Load this skill to answer "how should we govern this AI system?" — standing up or maturing a governance program, tiering use-case risk, designing the operating model and decision rights, reviewing an LLM/agent system for governance and safety gaps, mapping a regulation to a compliance/control plan, scoring governance maturity, or preparing board-level reporting.

Capability admission and authority decisions

For “may this capability enter or remain in our environment?”, read references/capability-admission-and-update.md and use templates/capability-admission-record.md. For “may this agent act?”, use the earned-autonomy path below. Admission approves a component at a recorded revision and configuration; it does not issue a runtime grant. Link the two records in one review when both decisions are needed. Reuse current evidence and existing authorized scope; request a new decision only for a material change or an unmet approval condition.

Earned autonomy

When setting agent promotion/demotion thresholds or reviewing earned autonomy, read references/earned-autonomy.md and use templates/earned-autonomy-decision.md. Support accountable humans making capability/environment/action-class decisions; the agent cannot grant itself authority. site-reliability-engineering supplies operational evidence and agent-production-operations implements the approved control plan. This five-level autonomy ladder is separate from the Six-Level Governance framework.

Reference Files (load on demand, one per task)

Progressive disclosure: load only the reference relevant to the current question.

Load whenReference
Framing what AI governance is and its principles; governance vs. compliance vs. riskreferences/foundations-and-principles.md
Designing the operating model, councils, stewards, decision rights, RACI, maturity, culturereferences/governance-operating-model.md
Applying NIST AI RMF, ISO/IEC 42001 & 23894, model-risk tiering, inherent vs. residual riskreferences/risk-management-and-frameworks.md
Placing stage gates across ideation, data, build, evaluate, deploy, monitor, retirereferences/ai-lifecycle-governance.md
Applying the Six-Level Governance framework, evidence loop, maturity, and posture overlayreferences/six-level-governance-framework.md
Fairness metrics and their limits, bias sources, trade-offs, algorithmic justicereferences/fairness-bias-accountability.md
Explainability (XAI) methods, when explanation is required, disclosure, auditabilityreferences/transparency-and-explainability.md
Training/operational data governance, ownership, lineage, quality, consent, PETs, agentic memory, and purpose-aware egressreferences/privacy-and-data-governance.md
AI used in GLP, GCP, GMP, GDP, or pharmacovigilance contexts; ALCOA+, data integrity, electronic records, audit trails, validation/assurance, and QMS interfacesreferences/gxp-and-data-integrity.md
Trust boundaries, prompt injection, exposure ladders, excessive agency, tool authorization, containment, supply chain, red-teamingreferences/llm-and-agent-security.md
Current law by jurisdiction, compliance mapping, enforcement, horizon scanningreferences/regulatory-landscape.md
Vendor/model due diligence, supply chain, board reporting, metrics, auditreferences/procurement-third-party-and-board-oversight.md
Admitting, updating, disabling or retiring Skills, MCP servers or A2A capabilitiesreferences/capability-admission-and-update.md
Granting, promoting, reducing, suspending or revoking scoped agent authorityreferences/earned-autonomy.md
Tracing any idea to its informing books and research notes; bibliographyreferences/source-index.md

Templates (fillable)

Use these to turn the methodology into working artifacts.

Use whenTemplate
Recording capability admission, configuration changes, overlap and exittemplates/capability-admission-record.md
Recording scoped authority, evidence, counterevidence and independent approvaltemplates/earned-autonomy-decision.md
Standing up the governance council and its terms of referencetemplates/governance-charter.md
Registering a use case and classifying it at intaketemplates/use-case-intake-form.md
Running a NIST-aligned risk assessment and tiering worksheettemplates/model-risk-assessment.md
Documenting a released model: intended use, data, performance, fairness, limitationstemplates/model-card.md
Conducting vendor/model supply-chain due diligencetemplates/third-party-due-diligence.md
Preparing executive/board AI-governance reportingtemplates/board-ai-governance-report.md
Reviewing SaaS/API/self-hosted boundaries and agentic tools, actions, egress, memory, and evidencetemplates/agentic-governance-review.md
Show full SKILL.md (471 more words)Show less

Scripts

Executable, flag-driven, stdlib-only Python CLIs with tests. Both accept a JSON input path and emit deterministic output; --json prints one JSON object on stdout; --dry-run previews without changing anything. Exit 0 on success; the maturity scorer also exits 1 on a critical posture, and both scripts exit 1 on input errors.

Use whenScript
Scoring an organization's governance maturity from dimension scores (1-5); emits maturity level + gapsscripts/governance-maturity.py
Classifying an AI use case into a risk tier and its required controlsscripts/use-case-risk-tier.py
Verifying the maturity scorer (unit + behavior tests)scripts/test_governance_maturity.py
Verifying the risk-tier classifier (unit + behavior tests)scripts/test_use_case_risk_tier.py

Evaluation and Configuration

  • Eval manifest: evals/evals.json holds the output-quality cases (operating model design, use-case risk tiering, 6L-G and deployment-posture review, agentic security and privacy review, impact-assessment closure, LLM-app governance review, fairness/accountability review, regulatory compliance mapping, board governance reporting, and GxP/data-integrity governance) used to grade this skill.
  • Configuration: pytest.ini overrides the repository's root coverage settings so the subprocess-based skill tests run cleanly; do not add a second override.
  • Entry points: this SKILL.md is the router; README.md is the human-facing overview for people evaluating whether to install the skill.

When Not To Use

Do not load this skill for work that belongs to a neighbor methodology or to execution:

  • Regulatory/legal strategy. Interpreting what a law or regulation means, structuring compliance legal risk, or preparing legal positions is legal-strategy work. This skill maps obligations to controls and records a defensible governance posture; it does not opine on the law. Prefer legal-strategy when the ask is legal interpretation, and return here to turn the resulting obligations into a control plan.
  • Product operations and governance. Recurring product decision cadences (intake, portfolio, roadmap, experiment, launch, lifecycle reviews) with evidence standards belong to product-operations-and-governance, not to this skill. This skill governs the AI system's risk and accountability, not the product portfolio cadence.
  • Data-governance mechanics. Building data catalogs, lineage pipelines, or platform storage internals is data-architect / data-engineering work. This skill consumes data governance as a control input but does not operate the data platform.
  • Implementation-time security. Writing authentication, authorization, input validation, or dependency hardening for an application is secure-software-engineering work. This skill sets the AI governance and safety controls and the risk tier; it does not implement the security mechanisms.
  • Legal, financial, or security advice. Nothing in this skill is legal, financial, or security advice. Regulatory and standards material must be re-verified against primary sources at the time of use.
  • Other one-off decisions. Use adr-authoring or product-methodology for general architectural or product decisions. Individual AI capability admission and authority decisions remain in this skill.
When you need...Route to
Regulatory and board-legal strategy, legal interpretationlegal-strategy
Data-governance mechanics: catalogs, lineage, platform internalsdata-architect or data-engineering
Implementing application and system security controlssecure-software-engineering
Recurring product decision cadences and evidence standardsproduct-operations-and-governance
A single durable architectural decision recordadr-authoring

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 36 other files (scripts, references) in ai-governance of magnus919/agent-skills.

  • SKILL.md
  • README.md
  • evals/evals.json
  • pytest.ini
  • references/ai-lifecycle-governance.md
  • references/capability-admission-and-update.md
  • references/earned-autonomy.md
  • references/fairness-bias-accountability.md
  • references/foundations-and-principles.md
  • references/governance-operating-model.md
  • references/gxp-and-data-integrity.md
  • references/llm-and-agent-security.md
  • references/privacy-and-data-governance.md
  • references/procurement-third-party-and-board-oversight.md
  • references/regulatory-landscape.md
  • references/risk-management-and-frameworks.md
  • references/six-level-governance-framework.md
  • references/source-index.md
  • references/transparency-and-explainability.md
  • … and 18 more

Open the folder on GitHubat commit 22b4723

Compare with similar skills

AI Governance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Governance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Governance this skillmagnus919/agent-skills115—~3.6kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Ra Qm Skillsalirezarezvani/claude-skills28k—~833Automated safety check: PassMIT
Repo Prepglebis/claude-skills391—~1.6kAutomated safety check: PassMIT
Complianceericrisco/rsc-harness180—~2.4kAutomated safety check: PassMIT

Similar skills

  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Ra Qm Skills

    alirezarezvani/claude-skills

    Router/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document control, ISO…

    28k GitHub stars~833 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Repo Prep

    glebis/claude-skills

    Interactively prepare a code repository for publication — LICENSE, NOTICE, AUTHORSHIP, README sections, package metadata, .gitignore, community docs (CONTRIBUTING/CODEOFCONDUCT/SECURITY/CHANGELOG)…

    391 GitHub stars~1.6k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Compliance

    ericrisco/rsc-harness

    A skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or…

    180 GitHub stars~2.4k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Dd Audit AI Activity

    datadog-labs/agent-skills

    Audit what the Bits AI assistant (MCP server) has done in your Datadog org — tool calls by user, resources accessed, and anomaly flags for AI governance.

    177 GitHub stars~1.2k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed

More from magnus919/agent-skills

All 131 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    119 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    119 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    119 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    119 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    119 GitHub stars~2k tokensUpdated today
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    119 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Questions about AI Governance

What does AI Governance do?

Design and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS…. AI Governance is an agent skill from magnus919/agent-skills. Design and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS, API, self-hosted and agentic systems.

When should I use AI Governance?

AI Governance fits situations like: retire Agent Skills; MCP servers and A2A capabilities; approve an agent for production actions; decide earned-autonomy promotion.

How do I install AI Governance in Claude Code?

Run `npx skills add magnus919/agent-skills --skill ai-governance -a claude-code`. Or copy the skill folder (ai-governance in magnus919/agent-skills) into .claude/skills/ai-governance in your project. Claude Code loads it when a task matches its description.

How do I install AI Governance in Codex?

Run `npx skills add magnus919/agent-skills --skill ai-governance -a codex`. Or copy the skill folder (ai-governance in magnus919/agent-skills) into .agents/skills/ai-governance in your project. Codex loads it when a task matches its description.

Can I use AI Governance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill ai-governance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-governance, .gemini/skills/ai-governance, .github/skills/ai-governance and .opencode/skills/ai-governance in your project.

What does AI Governance need to run?

SKILL.md names no scripts, command-line tools or credentials: AI Governance is instructions for the agent only. Our summary lists: Python 3. Compatibility (from SKILL.md): Agent-agnostic methodology; no external services, APIs, or runtime dependencies. The two scripts are Python 3 standard-library only..

Does AI Governance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AI Governance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does AI Governance use?

AI Governance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Governance use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 66k tokens, read only when the agent opens those files.

What are the alternatives to AI Governance?

Skills that share tags, products or a category with AI Governance: Audit Report (harness/harness-skills, 115 stars), Compliance Os (alirezarezvani/claude-skills, 28k stars), Ra Qm Skills (alirezarezvani/claude-skills, 28k stars) and Repo Prep (glebis/claude-skills, 391 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Governance?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 115 GitHub stars. The repository holds 131 skills in this directory. The repository was last updated on October 10, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.