Agent skill

AI Usage Policy

by mohitagw15856 in mohitagw15856/pm-claude-skills

Write an AI usage policy people can actually follow — approved tools, data rules, disclosure duties, and review obligations, in one page instead of legal fog.

MITAuto-check passedLegal & Compliance

Install AI Usage Policy

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill ai-usage-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills ai-usage-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ai-usage-policy .claude/skills/ai-usage-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-usage-policy
GitHub stars
1.4k
Token cost
~1.5k tokens
SKILL.md length
792 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Write an AI usage policy people can actually follow — approved tools, data rules, disclosure duties, and review obligations, in one page instead of legal fog.

  • Works in 6 steps: Legalise reality first. Shadow AI is the… → Rule on data, not tools. Tools churn… → Set the accountability rule once,… → …
  • Asked for a company AI policy
  • SKILL.md covers What This Skill Produces, Required Inputs, Policy Method and Output Format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

AI Usage Policy is an agent skill from mohitagw15856/pm-claude-skills. Write an AI usage policy people can actually follow — approved tools, data rules, disclosure duties, and review obligations, in one page instead of legal fog. Use when asked for a company AI policy, acceptable-use rules for ChatGPT/Claude/Copilot at work, guidance on what data may go into AI tools, or to fix a policy nobody reads. Produces a one-page usable policy plus the decision log behind it. Not a substitute for legal advice; pairs with compliance-checklist for regulatory mapping and ai-ethics-review for…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Regulatory compliance, Architecture decision records and AI governance. It works with OpenAI. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked for a company AI policy
  • Acceptable-use rules for ChatGPT/Claude/Copilot at work
  • Guidance on what data may go into AI tools
  • Fix a policy nobody reads

Example prompts

  • “/ai-usage-policy”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Legalise reality first. Shadow AI is the largest risk created by strict policies. Start from what people already use; the policy's first…
  2. Rule on data, not tools. Tools churn monthly; data classes don't. The core artifact is a traffic-light table people can apply in three…
  3. Set the accountability rule once, clearly. The human who ships it owns it — AI-assisted or not. From that root, the review duties follow…
  4. Decide disclosure deliberately. Internal: generally not required (it's a tool). External: disclose where the audience would feel deceived…
  5. Keep the enforcement honest. First violations of 🟡 rules are coaching moments; 🔴 violations follow the existing data-handling discipline…
  6. Log the reasoning separately. Every rule gets one line in the decision log: what we ruled, why, what we considered. Counsel reviews the…

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Usage Policy loads about 1.5k tokens when it runs. Until then it costs about 139 tokens; SKILL.md has 792 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~139
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 792 words, ~1,546 tokens.

Download SKILL.mdSave it as .claude/skills/ai-usage-policy/SKILL.md (or your agent's skills folder).
name
ai-usage-policy
description
Write an AI usage policy people can actually follow — approved tools, data rules, disclosure duties, and review obligations, in one page instead of legal fog. Use when asked for a company AI policy, acceptable-use rules for ChatGPT/Claude/Copilot at work, guidance on what data may go into AI tools, or to fix a policy nobody reads. Produces a one-page usable policy plus the decision log behind it. Not a substitute for legal advice; pairs with compliance-checklist for regulatory mapping and ai-ethics-review for system-level assessments.

AI Usage Policy Skill

Most corporate AI policies fail in one of two ways: a fearful ban everyone quietly ignores (shadow AI, zero visibility), or legal fog nobody can apply to the question they actually have — "can I paste this customer email into Claude?" This skill writes the policy as a decision aid: one page, answerable in the moment of use, with the reasoning logged separately for counsel.

What This Skill Produces

  • A one-page policy: approved tools, the data traffic-light, disclosure duties, review obligations, and how to get a tool approved
  • A decision log: the reasoning behind each rule, for legal/leadership review
  • A rollout note: how the policy lands without becoming shelfware

Required Inputs

Ask for (if not already provided):

  • The org: size, industry, regulatory exposure (health, finance, gov contracts change the answers)
  • Current reality: which AI tools are already in use — officially and (honestly) unofficially
  • Data landscape: what sensitive classes exist (customer PII, PHI, source code, financials, client-confidential)
  • Enterprise agreements in place: which tools have zero-retention/no-training terms signed vs consumer accounts
  • Risk appetite: enable-with-guardrails or restrict-hard? (Get the sponsor's one-word answer.)

Policy Method

  1. Legalise reality first. Shadow AI is the largest risk created by strict policies. Start from what people already use; the policy's first job is making the sanctioned path easier than the unsanctioned one — approved tools with enterprise terms, clearly listed, with a fast approval lane for new ones (named owner, ≤2-week SLA).
  2. Rule on data, not tools. Tools churn monthly; data classes don't. The core artifact is a traffic-light table people can apply in three seconds:
    • 🟢 Fine in approved tools — public info, your own drafts, non-confidential work product
    • 🟡 Approved tools with enterprise terms only — internal business data, code, unreleased plans
    • 🔴 Never in any AI tool (until a named exception is granted) — regulated data (PHI, card data), client-confidential under NDA, credentials, anything under legal hold Each row names examples from this org's actual work, not abstract categories.
  3. Set the accountability rule once, clearly. The human who ships it owns it — AI-assisted or not. From that root, the review duties follow: outputs going to customers/public/regulators get human review by someone competent to catch the errors; internal drafts don't need ceremony. State both halves; policies that demand review-everything get review-nothing.
  4. Decide disclosure deliberately. Internal: generally not required (it's a tool). External: disclose where the audience would feel deceived otherwise (bylined content, legal filings, anything presented as human judgment — expert reports, references) or where law/regulator requires it. Write the specific disclosure lines for this org's cases, not a principle.
  5. Keep the enforcement honest. First violations of 🟡 rules are coaching moments; 🔴 violations follow the existing data-handling discipline process (don't invent a parallel one). The policy names its owner, its review cadence (quarterly — the landscape moves), and where questions go today.
  6. Log the reasoning separately. Every rule gets one line in the decision log: what we ruled, why, what we considered. Counsel reviews the log; humans read the page.
Show full SKILL.md (299 more words)Show less

Output Format

AI Usage Policy: [org] — v1, [date] · owner: [role] · review: quarterly

Approved tools: [tool → account type (enterprise/consumer-banned) → what it's approved for] Getting a tool approved: [the lane: who, what they check, SLA]

The data rule (the table above, with org-specific examples per row)

Your accountability: [the ship-it-you-own-it rule + review duties by output destination]

Disclosure: [the org's specific cases with the exact lines to use]

If something goes wrong: [pasted the wrong thing / AI error shipped → who to tell, framed as no-fault-if-fast]


Decision log (separate artifact): [rule → reasoning → alternatives considered → open questions for counsel]

Rollout note: [announce with the enabling frame; 30-min manager briefing; the three examples everyone actually asks about, answered]

Quality Checks

  • A stressed employee can answer "can I paste X into Y?" from the page in under a minute
  • Every data-class row carries examples from this org's real work
  • The sanctioned path is genuinely easier than shadow use (tools listed, approval lane fast)
  • Disclosure rules are specific lines for specific cases, not a value statement
  • The policy names its owner, review cadence, and question channel
  • The decision log exists — counsel reviews reasoning, not just conclusions

Anti-Patterns

  • Do not ban broadly and enforce never — that policy trains people to hide usage you most need to see
  • Do not write rules per-tool as primary structure — tools churn; data classes are the stable spine
  • Do not require human review of everything — undifferentiated duty guarantees zero real review
  • Do not copy another company's policy without the data-class mapping — the table is the policy
  • Do not present this as legal advice — it's the draft counsel refines, and the page says so

Example Trigger Phrases

  • "Write a company AI policy."
  • "What are our rules for using ChatGPT and Claude at work?"
  • "Write acceptable-use rules for Copilot."
  • "Fix an AI policy nobody reads."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ai-usage-policy of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

AI Usage Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Usage Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Usage Policy this skillmohitagw15856/pm-claude-skills1.4k—~1.5kAutomated safety check: PassMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.7kAutomated safety check: PassMIT
EU AI Act System Inventoryanthropics/claude-for-legal9.6k3 repos~2.8kAutomated safety check: PassApache-2.0
Reg Gap Analysisanthropics/claude-for-legal9.6k3 repos~3.7kAutomated safety check: PassApache-2.0
Ra Qm Skillsalirezarezvani/claude-skills28k—~833Automated safety check: PassMIT
Eu AI Act Transparency Assessor Oliver Schmidt Prietzlawve-ai/awesome-legal-skills847—~5kAutomated safety check: PassAGPL-3.0

Similar skills

  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • EU AI Act System Inventory

    anthropics/claude-for-legal

    Official

    Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.

    9.6k GitHub starsUsed in 3 repos~2.8k tokens
    Legal & ComplianceAuto-check passed
  • Reg Gap Analysis

    anthropics/claude-for-legal

    Official

    Diff a new AI regulation or guidance against your current governance posture — surfaces gaps, priorities, and a remediation plan with owners and deadlines.

    9.6k GitHub starsUsed in 3 repos~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Ra Qm Skills

    alirezarezvani/claude-skills

    Router/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document control, ISO…

    28k GitHub stars~833 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • AI SAFE2 Secure Build Copilot

    CyberStrategyInstitute/ai-safe2-framework

    Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers.

    147 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about AI Usage Policy

What does AI Usage Policy do?

Write an AI usage policy people can actually follow — approved tools, data rules, disclosure duties, and review obligations, in one page instead of legal fog. AI Usage Policy is an agent skill from mohitagw15856/pm-claude-skills. Write an AI usage policy people can actually follow — approved tools, data rules, disclosure duties, and review obligations, in one page instead of legal fog.

When should I use AI Usage Policy?

AI Usage Policy fits situations like: asked for a company AI policy; acceptable-use rules for ChatGPT/Claude/Copilot at work; guidance on what data may go into AI tools; fix a policy nobody reads.

How do I install AI Usage Policy in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill ai-usage-policy -a claude-code`. Or copy the skill folder (skills/ai-usage-policy in mohitagw15856/pm-claude-skills) into .claude/skills/ai-usage-policy in your project. Claude Code loads it when a task matches its description.

How do I install AI Usage Policy in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill ai-usage-policy -a codex`. Or copy the skill folder (skills/ai-usage-policy in mohitagw15856/pm-claude-skills) into .agents/skills/ai-usage-policy in your project. Codex loads it when a task matches its description.

Can I use AI Usage Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill ai-usage-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-usage-policy, .gemini/skills/ai-usage-policy, .github/skills/ai-usage-policy and .opencode/skills/ai-usage-policy in your project.

What does AI Usage Policy need to run?

SKILL.md names no scripts, command-line tools or credentials: AI Usage Policy is instructions for the agent only.

Does AI Usage Policy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AI Usage Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AI Usage Policy use?

AI Usage Policy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Usage Policy use?

About 1.5k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AI Usage Policy?

Skills that share tags, products or a category with AI Usage Policy: Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), EU AI Act System Inventory (anthropics/claude-for-legal, 9.6k stars), Reg Gap Analysis (anthropics/claude-for-legal, 9.6k stars) and Ra Qm Skills (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Usage Policy?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.