Audit Report
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
Design and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS…
$ npx skills add magnus919/agent-skills --skill ai-governance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install magnus919/agent-skills ai-governance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance .claude/skills/ai-governance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ai-governance" agent skill from https://github.com/magnus919/agent-skills/tree/main/ai-governance into .claude/skills/ai-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-governance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/magnus919/agent-skills/tree/main/ai-governanceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add magnus919/agent-skills --skill ai-governance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install magnus919/agent-skills ai-governance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ai-governance .agents/skills/ai-governance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ai-governance" agent skill from https://github.com/magnus919/agent-skills/tree/main/ai-governance into .agents/skills/ai-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-governance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add magnus919/agent-skills --skill ai-governance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install magnus919/agent-skills ai-governance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ai-governance .cursor/skills/ai-governance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ai-governance" agent skill from https://github.com/magnus919/agent-skills/tree/main/ai-governance into .cursor/skills/ai-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-governance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/magnus919/agent-skills.git --path ai-governance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add magnus919/agent-skills --skill ai-governance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install magnus919/agent-skills ai-governance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ai-governance .gemini/skills/ai-governance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ai-governance" agent skill from https://github.com/magnus919/agent-skills/tree/main/ai-governance into .gemini/skills/ai-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-governance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install magnus919/agent-skills ai-governanceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add magnus919/agent-skills --skill ai-governance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/ai-governance .github/skills/ai-governance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ai-governance" agent skill from https://github.com/magnus919/agent-skills/tree/main/ai-governance into .github/skills/ai-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-governance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add magnus919/agent-skills --skill ai-governance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install magnus919/agent-skills ai-governance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ai-governance .opencode/skills/ai-governance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ai-governance" agent skill from https://github.com/magnus919/agent-skills/tree/main/ai-governance into .opencode/skills/ai-governance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ai-governance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ai-governanceDesign and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS…
AI Governance is an agent skill from magnus919/agent-skills. Design and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS, API, self-hosted and agentic systems. Use to admit, update or retire Agent Skills, MCP servers and A2A capabilities; approve an agent for production actions; or decide earned-autonomy promotion, reduction or revocation. Cover GxP, ALCOA+, data integrity, electronic records, assurance and QMS interfaces for life…
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 38 other files, including scripts and reference files (for example `README.md`, `evals/evals.json` and `references/ai-lifecycle-governance.md`). Compatibility notes: Agent-agnostic methodology; no external services, APIs, or runtime dependencies. The two scripts are Python 3 standard-library only.
It sits in Legal & Compliance, covering AI governance, Data pipelines and ETL and SOC 2 and security compliance. It works with Model Context Protocol. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.
Read from SKILL.md and the folder at commit 22b4723. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Agent-agnostic methodology; no external services, APIs, or runtime dependencies. The two scripts are Python 3 standard-library only.
From compatibility in the SKILL.md frontmatter.
AI Governance loads about 3.6k tokens when it runs, and up to ~69k if it reads all its reference files. Until then it costs about 201 tokens; SKILL.md has 1,296 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from magnus919/agent-skills at commit 22b4723, republished under its MIT licence (© magnus919). 1,296 words, ~3,587 tokens.
.claude/skills/ai-governance/SKILL.md (or your agent's skills folder). This skill also uses 36 other files; get the full folder from GitHub.AI governance is the system an organization uses to decide, before a model is built and while it runs, who is accountable for an AI system, what risk it is allowed to carry, what evidence must gate each lifecycle stage, and how the organization reports and audits that posture. This skill teaches an agent to reason about and operate that system: it is a methodology skill, not a tool manual and not legal or security advice.
| You own | You don't own |
|---|---|
| Governance principles and how they translate into policy and controls | Drafting or opining on legal interpretation of a regulation |
| The governance operating model: councils, stewards, decision rights, RACI, federated vs. centralized | Data-platform mechanics, pipelines, and lineage tooling internals |
| Risk frameworks: NIST AI RMF, ISO/IEC 42001 & 23894, model-risk tiering, risk registers | Implementing authentication, authorization, or vulnerability fixes |
| Lifecycle stage gates across ideation, build, evaluate, deploy, monitor, retire | CI/CD pipeline and deployment-gate configuration |
| Cross-cutting 6L-G governance loop: strategy, impact, implementation, acceptance, operations, learning | Treating an author-developed framework as a regulatory or standards requirement |
| Fairness, bias, transparency, explainability, and accountability controls | Product portfolio/roadmap governance cadences |
| Privacy and data governance for training and operational data | Capital allocation, org structure, or M&A governance |
| GxP AI governance overlay: ALCOA+, data integrity, electronic records, risk-based assurance, QMS interfaces | Legal applicability determinations, validation protocols, SOPs, or quality-system operation |
| LLM/agent safety: prompt injection, exposure ladders, tool authorization, memory, egress, red-teaming, supply chain | Host-level or application-level security scanning |
| Regulatory landscape and compliance mapping (as guidance, not advice) | Legal drafting, regulatory filings, or attorney-client work product |
| Third-party and model due diligence, board reporting, audit | Any authoritative statement of "your system is compliant" |
This is a prevention-and-operations methodology: it gives the agent frameworks, decision models, and controls to design and run governance, not a claim that a system is compliant or safe. For every engagement, record the operating model, the risk tier, the evidence that gated each stage, and the accountable owner of each accepted exception.
Load this skill to answer "how should we govern this AI system?" — standing up or maturing a governance program, tiering use-case risk, designing the operating model and decision rights, reviewing an LLM/agent system for governance and safety gaps, mapping a regulation to a compliance/control plan, scoring governance maturity, or preparing board-level reporting.
For “may this capability enter or remain in our environment?”, read
references/capability-admission-and-update.md and use
templates/capability-admission-record.md. For “may this agent act?”, use the earned-autonomy
path below. Admission approves a component at a recorded revision and configuration; it does
not issue a runtime grant. Link the two records in one review when both decisions are needed.
Reuse current evidence and existing authorized scope; request a new decision only for a material
change or an unmet approval condition.
When setting agent promotion/demotion thresholds or reviewing earned autonomy, read references/earned-autonomy.md and use templates/earned-autonomy-decision.md. Support accountable humans making capability/environment/action-class decisions; the agent cannot grant itself authority. site-reliability-engineering supplies operational evidence and agent-production-operations implements the approved control plan. This five-level autonomy ladder is separate from the Six-Level Governance framework.
Progressive disclosure: load only the reference relevant to the current question.
| Load when | Reference |
|---|---|
| Framing what AI governance is and its principles; governance vs. compliance vs. risk | references/foundations-and-principles.md |
| Designing the operating model, councils, stewards, decision rights, RACI, maturity, culture | references/governance-operating-model.md |
| Applying NIST AI RMF, ISO/IEC 42001 & 23894, model-risk tiering, inherent vs. residual risk | references/risk-management-and-frameworks.md |
| Placing stage gates across ideation, data, build, evaluate, deploy, monitor, retire | references/ai-lifecycle-governance.md |
| Applying the Six-Level Governance framework, evidence loop, maturity, and posture overlay | references/six-level-governance-framework.md |
| Fairness metrics and their limits, bias sources, trade-offs, algorithmic justice | references/fairness-bias-accountability.md |
| Explainability (XAI) methods, when explanation is required, disclosure, auditability | references/transparency-and-explainability.md |
| Training/operational data governance, ownership, lineage, quality, consent, PETs, agentic memory, and purpose-aware egress | references/privacy-and-data-governance.md |
| AI used in GLP, GCP, GMP, GDP, or pharmacovigilance contexts; ALCOA+, data integrity, electronic records, audit trails, validation/assurance, and QMS interfaces | references/gxp-and-data-integrity.md |
| Trust boundaries, prompt injection, exposure ladders, excessive agency, tool authorization, containment, supply chain, red-teaming | references/llm-and-agent-security.md |
| Current law by jurisdiction, compliance mapping, enforcement, horizon scanning | references/regulatory-landscape.md |
| Vendor/model due diligence, supply chain, board reporting, metrics, audit | references/procurement-third-party-and-board-oversight.md |
| Admitting, updating, disabling or retiring Skills, MCP servers or A2A capabilities | references/capability-admission-and-update.md |
| Granting, promoting, reducing, suspending or revoking scoped agent authority | references/earned-autonomy.md |
| Tracing any idea to its informing books and research notes; bibliography | references/source-index.md |
Use these to turn the methodology into working artifacts.
| Use when | Template |
|---|---|
| Recording capability admission, configuration changes, overlap and exit | templates/capability-admission-record.md |
| Recording scoped authority, evidence, counterevidence and independent approval | templates/earned-autonomy-decision.md |
| Standing up the governance council and its terms of reference | templates/governance-charter.md |
| Registering a use case and classifying it at intake | templates/use-case-intake-form.md |
| Running a NIST-aligned risk assessment and tiering worksheet | templates/model-risk-assessment.md |
| Documenting a released model: intended use, data, performance, fairness, limitations | templates/model-card.md |
| Conducting vendor/model supply-chain due diligence | templates/third-party-due-diligence.md |
| Preparing executive/board AI-governance reporting | templates/board-ai-governance-report.md |
| Reviewing SaaS/API/self-hosted boundaries and agentic tools, actions, egress, memory, and evidence | templates/agentic-governance-review.md |
Executable, flag-driven, stdlib-only Python CLIs with tests. Both accept a JSON input path and emit
deterministic output; --json prints one JSON object on stdout; --dry-run previews without
changing anything. Exit 0 on success; the maturity scorer also exits 1 on a critical posture, and both scripts exit 1 on input errors.
| Use when | Script |
|---|---|
| Scoring an organization's governance maturity from dimension scores (1-5); emits maturity level + gaps | scripts/governance-maturity.py |
| Classifying an AI use case into a risk tier and its required controls | scripts/use-case-risk-tier.py |
| Verifying the maturity scorer (unit + behavior tests) | scripts/test_governance_maturity.py |
| Verifying the risk-tier classifier (unit + behavior tests) | scripts/test_use_case_risk_tier.py |
Do not load this skill for work that belongs to a neighbor methodology or to execution:
legal-strategy work. This skill maps
obligations to controls and records a defensible governance posture; it does not opine on the
law. Prefer legal-strategy when the ask is legal interpretation, and return here to turn the
resulting obligations into a control plan.product-operations-and-governance, not to this skill. This skill governs the AI system's risk
and accountability, not the product portfolio cadence.data-architect / data-engineering work. This skill consumes data governance as
a control input but does not operate the data platform.secure-software-engineering work. This skill sets
the AI governance and safety controls and the risk tier; it does not implement the security
mechanisms.adr-authoring or product-methodology for general
architectural or product decisions. Individual AI capability admission and authority decisions
remain in this skill.| When you need... | Route to |
|---|---|
| Regulatory and board-legal strategy, legal interpretation | legal-strategy |
| Data-governance mechanics: catalogs, lineage, platform internals | data-architect or data-engineering |
| Implementing application and system security controls | secure-software-engineering |
| Recurring product decision cadences and evidence standards | product-operations-and-governance |
| A single durable architectural decision record | adr-authoring |
© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 36 other files (scripts, references) in ai-governance of magnus919/agent-skills.
Open the folder on GitHubat commit 22b4723
AI Governance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AI Governance this skillmagnus919/agent-skills | 115 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Audit Reportharness/harness-skills | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Compliance Osalirezarezvani/claude-skills | 28k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Ra Qm Skillsalirezarezvani/claude-skills | 28k | — | ~833 | Automated safety check: Pass | MIT | |
| Repo Prepglebis/claude-skills | 391 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Complianceericrisco/rsc-harness | 180 | — | ~2.4k | Automated safety check: Pass | MIT |
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
alirezarezvani/claude-skills
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…
alirezarezvani/claude-skills
Router/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document control, ISO…
glebis/claude-skills
Interactively prepare a code repository for publication — LICENSE, NOTICE, AUTHORSHIP, README sections, package metadata, .gitignore, community docs (CONTRIBUTING/CODEOFCONDUCT/SECURITY/CHANGELOG)…
ericrisco/rsc-harness
A skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or…
datadog-labs/agent-skills
Audit what the Bits AI assistant (MCP server) has done in your Datadog org — tool calls by user, resources accessed, and anomaly flags for AI governance.
magnus919/agent-skills
Organize durable agent research outputs as summaries, analysis, and evidence dossiers.
magnus919/agent-skills
Build portable, first-person colored ASCII city engines and small GIS-derived city packs.
magnus919/agent-skills
Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.
magnus919/agent-skills
A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…
magnus919/agent-skills
Use Docker Compose to define, run, debug, and harden multi-container applications.
magnus919/agent-skills
Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.
Works with
Categories
Design and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS…. AI Governance is an agent skill from magnus919/agent-skills. Design and operate AI governance: principles, decision rights, risk tiers, lifecycle gates, fairness, transparency, privacy, security, compliance mapping, maturity and board reporting across SaaS, API, self-hosted and agentic systems.
AI Governance fits situations like: retire Agent Skills; MCP servers and A2A capabilities; approve an agent for production actions; decide earned-autonomy promotion.
Run `npx skills add magnus919/agent-skills --skill ai-governance -a claude-code`. Or copy the skill folder (ai-governance in magnus919/agent-skills) into .claude/skills/ai-governance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add magnus919/agent-skills --skill ai-governance -a codex`. Or copy the skill folder (ai-governance in magnus919/agent-skills) into .agents/skills/ai-governance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill ai-governance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-governance, .gemini/skills/ai-governance, .github/skills/ai-governance and .opencode/skills/ai-governance in your project.
SKILL.md names no scripts, command-line tools or credentials: AI Governance is instructions for the agent only. Our summary lists: Python 3. Compatibility (from SKILL.md): Agent-agnostic methodology; no external services, APIs, or runtime dependencies. The two scripts are Python 3 standard-library only..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
AI Governance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 66k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with AI Governance: Audit Report (harness/harness-skills, 115 stars), Compliance Os (alirezarezvani/claude-skills, 28k stars), Ra Qm Skills (alirezarezvani/claude-skills, 28k stars) and Repo Prep (glebis/claude-skills, 391 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 115 GitHub stars. The repository holds 131 skills in this directory. The repository was last updated on October 10, 2026.
Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.