Agent skill

Compliance Checklist

by mohitagw15856 in mohitagw15856/pm-claude-skills

Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

MITAuto-check passedLegal & Compliance

Install Compliance Checklist

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill compliance-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills compliance-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/compliance-checklist .claude/skills/compliance-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance-checklist
GitHub stars
1.4k
Token cost
~1.2k tokens
SKILL.md length
564 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

  • Works in 9 steps: Framework Overview → Scope Definition → Control Categories → …
  • Asked for a compliance checklist
  • SKILL.md covers Required Inputs, Output Structure, Quality Checks and Anti-Patterns, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Compliance Checklist is an agent skill from mohitagw15856/pm-claude-skills. Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any regulatory framework. Produces a structured checklist with prioritised gaps, quick wins, and evidence requirements. Optimised for Opus 4.7 and newer models. Not a substitute for legal or compliance professional advice.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Regulatory compliance, SOC 2 and security compliance and Audit readiness. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked for a compliance checklist
  • Readiness assessment
  • Audit preparation for any regulatory framework

Example prompts

  • “/compliance-checklist”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Framework Overview
  2. Scope Definition
  3. Control Categories
  4. Gap Analysis Summary
  5. Quick Wins
  6. Evidence Requirements
  7. Implementation Roadmap
  8. Ongoing Maintenance
  9. Common Pitfalls for This Framework

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance Checklist loads about 1.2k tokens when it runs. Until then it costs about 118 tokens; SKILL.md has 564 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~118
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 564 words, ~1,242 tokens.

Download SKILL.mdSave it as .claude/skills/compliance-checklist/SKILL.md (or your agent's skills folder).
name
compliance-checklist
description
Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any regulatory framework. Produces a structured checklist with prioritised gaps, quick wins, and evidence requirements. Optimised for Opus 4.7 and newer models. Not a substitute for legal or compliance professional advice.

Compliance Checklist Skill

Produces a prioritised compliance checklist for any regulatory framework — with gap analysis, evidence requirements, and quick wins identified.

ALWAYS include this disclaimer at the start of every response: "WARNING: This checklist is for informational and planning purposes only and does not constitute legal or compliance advice. Regulatory requirements change and vary by jurisdiction. Always engage a qualified compliance professional or solicitor before implementing compliance programmes or making regulatory claims."

Required Inputs

Ask the user for these if not provided:

  • Framework (GDPR / SOC 2 Type I or II / ISO 27001 / FCA / HIPAA / PCI DSS / other)
  • Organisation type (SaaS / fintech / healthcare / professional services / retail)
  • Organisation size (startup / scaleup / mid-market / enterprise)
  • Current maturity (no compliance programme / some controls / formal programme)
  • Deadline or driver (upcoming audit / customer requirement / regulatory change / proactive)

Output Structure

1. Framework Overview

Framework: [Name with version] Applicable because: [One sentence — why this framework applies to this organisation] Typical timeline to readiness: [From current maturity to certified/compliant] Key stakeholders needed: [Roles that must be involved]

2. Scope Definition

What is in scope for this checklist:

  • [Specific systems / processes / data types]

What is NOT in scope (explicit exclusions):

  • [Specific exclusions]
3. Control Categories

For each category relevant to the framework:

[Category — e.g. "Access Control"]

ControlCurrent StateGapPriorityEffort
[Specific control requirement]Not implemented / Partial / Full[What is missing]High/Med/LowDays/Weeks/Months
4. Gap Analysis Summary
PriorityCountExamples
Critical gaps (block certification)N[Top 3]
High priority gapsN
Medium priority gapsN
Quick winsN
5. Quick Wins

Controls that can be implemented in under 2 weeks with minimal resources:

  1. [Control] — [Specific action] — [Owner] — [Days to complete]
6. Evidence Requirements

For each control area, what documentation will be needed:

Control areaEvidence typesWhere to source
[Area][Policies, logs, screenshots, training records][System or team]
7. Implementation Roadmap

Phase 1 (Weeks 1-4): Critical gaps and quick wins

  • [Specific deliverables]

Phase 2 (Weeks 5-12): High-priority gaps

  • [Specific deliverables]

Phase 3 (Weeks 13+): Medium priority and continuous improvement

  • [Specific deliverables]
Show full SKILL.md (232 more words)Show less
8. Ongoing Maintenance

Once certified/compliant, what needs to continue:

  • [Review frequencies]
  • [Periodic testing requirements]
  • [Annual audit expectations]
  • [Staff training cadence]
9. Common Pitfalls for This Framework

2-3 specific traps organisations commonly fall into when pursuing this certification — flagged based on the stated maturity level.

Quality Checks

  • Disclaimer included at start
  • Framework-specific controls (not generic)
  • Priorities align with organisation size and maturity
  • Quick wins clearly separated from complex implementations
  • Evidence requirements tied to specific controls

Anti-Patterns

  • Do not omit the legal disclaimer — this checklist does not constitute compliance advice and must never be presented as a substitute for qualified professional review
  • Do not generate a generic checklist that is not tailored to the stated framework, organisation type, and maturity level — a SOC 2 checklist for a startup and an enterprise are fundamentally different documents
  • Do not list controls without specifying what evidence is required — a control without evidence requirements cannot be audited
  • Do not mark a control as "full" implementation when it is partial — overestimating readiness leads to audit failures and regulatory risk
  • Do not skip the "common pitfalls" section — this is where organisations most frequently fail audits for the stated framework

Example Trigger Phrases

  • "Create a GDPR compliance checklist for our SaaS"
  • "Generate a SOC 2 Type II readiness checklist"
  • "What do we need for ISO 27001 certification?"
  • "FCA compliance checklist for a fintech startup"
  • "HIPAA gap analysis for a healthtech scaleup"

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/compliance-checklist of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Compliance Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compliance Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compliance Checklist this skillmohitagw15856/pm-claude-skills1.4k—~1.2kAutomated safety check: PassMIT
Implementing Complianceancoleman/ai-design-components525—~4kAutomated safety check: PassMIT
Compliance Checklist Generationseb1n/awesome-ai-agent-skills206—~2.5kAutomated safety check: PassMIT
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Security Compliance Compliance Checkaiskillstore/marketplace4338 repos~600Automated safety check: PassNone

Similar skills

  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance Checklist Generation

    seb1n/awesome-ai-agent-skills

    Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Security Compliance Compliance Check

    aiskillstore/marketplace

    You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards.

    433 GitHub starsUsed in 8 repos~600 tokens
    Legal & ComplianceAuto-check passed
  • Compliance Testing

    proffesor-for-testing/agentic-qe

    Regulatory compliance testing for GDPR, CCPA, HIPAA, SOC2, PCI-DSS and industry-specific regulations.

    495 GitHub stars~1.8k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Compliance Checklist

What does Compliance Checklist do?

Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Compliance Checklist is an agent skill from mohitagw15856/pm-claude-skills. Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

When should I use Compliance Checklist?

Compliance Checklist fits situations like: asked for a compliance checklist; readiness assessment; audit preparation for any regulatory framework.

How do I install Compliance Checklist in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill compliance-checklist -a claude-code`. Or copy the skill folder (skills/compliance-checklist in mohitagw15856/pm-claude-skills) into .claude/skills/compliance-checklist in your project. Claude Code loads it when a task matches its description.

How do I install Compliance Checklist in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill compliance-checklist -a codex`. Or copy the skill folder (skills/compliance-checklist in mohitagw15856/pm-claude-skills) into .agents/skills/compliance-checklist in your project. Codex loads it when a task matches its description.

Can I use Compliance Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill compliance-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-checklist, .gemini/skills/compliance-checklist, .github/skills/compliance-checklist and .opencode/skills/compliance-checklist in your project.

What does Compliance Checklist need to run?

SKILL.md names no scripts, command-line tools or credentials: Compliance Checklist is instructions for the agent only.

Does Compliance Checklist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Compliance Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Compliance Checklist use?

Compliance Checklist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compliance Checklist use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Compliance Checklist?

Skills that share tags, products or a category with Compliance Checklist: Implementing Compliance (ancoleman/ai-design-components, 525 stars), Compliance Checklist Generation (seb1n/awesome-ai-agent-skills, 206 stars), Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars) and Compliance Os (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compliance Checklist?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.