Compliance Os
alirezarezvani/claude-skills
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…
Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…
$ npx skills add petrkindlmann/qa-skills --skill compliance-testing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install petrkindlmann/qa-skills compliance-testing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/compliance-testing .claude/skills/compliance-testing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "compliance-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/compliance-testing into .claude/skills/compliance-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-testing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/petrkindlmann/qa-skills/tree/main/skills/compliance-testingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add petrkindlmann/qa-skills --skill compliance-testing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install petrkindlmann/qa-skills compliance-testing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/compliance-testing .agents/skills/compliance-testing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "compliance-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/compliance-testing into .agents/skills/compliance-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-testing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add petrkindlmann/qa-skills --skill compliance-testing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install petrkindlmann/qa-skills compliance-testing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/compliance-testing .cursor/skills/compliance-testing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "compliance-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/compliance-testing into .cursor/skills/compliance-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-testing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/petrkindlmann/qa-skills.git --path skills/compliance-testing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add petrkindlmann/qa-skills --skill compliance-testing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install petrkindlmann/qa-skills compliance-testing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/compliance-testing .gemini/skills/compliance-testing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "compliance-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/compliance-testing into .gemini/skills/compliance-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-testing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install petrkindlmann/qa-skills compliance-testingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add petrkindlmann/qa-skills --skill compliance-testing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/compliance-testing .github/skills/compliance-testing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "compliance-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/compliance-testing into .github/skills/compliance-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-testing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add petrkindlmann/qa-skills --skill compliance-testing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install petrkindlmann/qa-skills compliance-testing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/compliance-testing .opencode/skills/compliance-testing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "compliance-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/compliance-testing into .opencode/skills/compliance-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "compliance-testing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
compliance-testingTest for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…
Compliance Testing is an agent skill from petrkindlmann/qa-skills. Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards, and cookie-inventory auditing. Covers automated consent-flow testing, third-party script blocking before consent, and cookie drift detection. Use when: "GDPR test," "compliance," "CMP test," "cookie consent," "consent mode," "CCPA," "GPC," "AI Act," "Better Ads," "privacy banner." Not for: WCAG/axe-core test authoring —…
Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/better-ads-tests.md`, `references/ci-automation.md` and `references/cookie-compliance.md`).
It sits in Legal & Compliance, covering Privacy and GDPR, Accessibility and AI governance. The repository describes itself as: 50 QA and test-automation skills for Claude Code, Codex, Cursor, and any Agent Skills Standard runtime. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b3bb61b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Compliance Testing loads about 4.6k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 197 tokens; SKILL.md has 2,306 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from petrkindlmann/qa-skills at commit b3bb61b, republished under its MIT licence (© petrkindlmann). 2,306 words, ~4,587 tokens.
.claude/skills/compliance-testing/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.<objective>
Compliance is binary: a single analytics cookie that fires before consent, or a "Reject all" rendered as a tiny grey link, is a violation no matter how polished the rest of the flow looks. Manual quarterly audits miss the regression a developer shipped on a Tuesday. This skill automates the technical checks — consent state, script blocking, cookie attributes, GPC, Consent Mode v2, AI Act disclosure — so configuration drift fails CI instead of a regulator's inbox.
</objective>
First, check for .agents/qa-project-context.md in the project root — it carries applicable regulations, CMP details, ad networks, and geographic scope. Skip any question already answered there. If it is missing, suggest creating one with the qa-project-context skill.
Sec-GPC: 1).__tcfapi), a custom data layer, or direct CMP API?accessibility-testing — this skill only maps the legal landscape, see below.There is no "mostly compliant." A cookie that fires before consent is a violation. A banner you cannot dismiss without accepting is a violation. Test for exact compliance, not "good enough."
Automate: cookies before consent, scripts loading without consent, banner functionality, cookie attributes, consent persistence, GPC, Consent Mode signals. A human still audits privacy-policy language and cross-border transfer documentation. Don't pretend a test settles a legal-language question.
The compliance boundary lives in the "no interaction," "rejected," and "withdrawn" states — that is where violations hide. The "all accepted" state is the least interesting one to test.
CMPs have bugs. Don't trust the CMP UI as proof. Assert the actual outcome: were cookies set, did scripts load, was the GPC opt-out registered. The CMP is an implementation detail; compliance is measured by behavior.
Verify at multiple layers — CMP config, network requests, cookie state, client signals. Drive tests from a typed inventory and a tracking-domain list so adding a category or threshold is a data edit, not a suite rewrite. Regulations change; the suite must be cheap to update.
Consent-flow compliance breaks into distinct, independently failing checks. Full runnable code for each is in references/gdpr-cmp-tests.md.
isStrictlyNecessary / isAnalyticsCookie classifiers against your inventory.google-analytics.com, googletagmanager.com, facebook.net, analytics.tiktok.com, bat.bing.com, …) must not load before consent and should load after acceptance. This is the most critical check — monitor with page.on('request').Sec-GPC: 1) — a required honored signal under CCPA/CPRA and most active US state laws. With the header set, assert navigator.globalPrivacyControl === true (the real browser signal) and that marketing cookies are absent. Do not assert an invented window.__cmp.gpcStatus global — it does not exist; TCF v1's __cmp is legacy and TCF v2 uses __tcfapi.window.__tcfapi('getTCData', 2, cb). Read purpose/vendor consent through it directly instead of guessing at CMP-private globals; the same call exposes tcfPolicyVersion, which doubles as a TCF-v2.3 freshness guard.denied for ad_storage / analytics_storage / ad_user_data / ad_personalization; an update signal must fire granted after acceptance. The interception assumes the gtag arguments-array shape — note the object-form fallback in the reference.The Act applies in phases, and the timeline shifted in 2026. Note: the Digital Omnibus (Nov 2025 proposal; 7 May 2026 provisional agreement) postponed the high-risk obligations — do not test against the old 2 Aug 2026 high-risk date.
| Obligation | Applies | What to test |
|---|---|---|
| Prohibitions + AI literacy | 2 Feb 2025 (live) | No Article 5 prohibited practices (social scoring, real-time public biometric ID, manipulative AI). Document AI features in scope; gate prohibited libraries. |
| GPAI obligations + penalties | 2 Aug 2025 (live) | Model cards, training-data summaries, copyright-policy and disclosure pages exist. |
| Article 50 transparency | 2 Aug 2026 | AI-generated content marked; deepfake disclosure; user told they are interacting with AI. Test the disclosure label/watermark. Still live on this date. |
| Machine-readable marking grace | 2 Dec 2026 | Systems already on the market before 2 Aug 2026 get until here to add the watermark/marking (Omnibus compressed six months to three). |
| High-risk (Annex III, use-case) | 2 Dec 2027 | Risk management, data governance, human oversight, transparency UI. Postponed from 2 Aug 2026 by the Omnibus. |
| High-risk (Annex I, product-regulated) | 2 Aug 2028 | As above, embedded in regulated products. Postponed from 2 Aug 2027. |
Write the Article 50 disclosure test now; defer the high-risk UI tests until the Annex III obligations land. See references/eu-ai-act-tests.md for the Article 50 transparency-disclosure test and the Article 5 prohibited-practice (biometric library) gate. For LLM-specific evaluation (hallucination, jailbreak resistance, prompt-injection), use the ai-system-testing skill.
The Coalition for Better Ads defines ad formats that trigger browser-level ad filtering (Chrome filters ads on non-compliant sites).
| Format | Desktop | Mobile | Test approach |
|---|---|---|---|
| Pop-up ads | Yes | Yes | Check for modal/overlay within 5s of load without user action |
| Auto-playing video with sound | Yes | Yes | Read the live video.autoplay / video.muted properties (not the HTML attributes) |
| Prestitial countdown ads | Yes | Yes | Check for a countdown timer blocking content |
| Large sticky ads (>30% viewport) | Yes | Yes | Measure sticky element dimensions vs viewport |
| Ad density >30% | No | Yes | Calculate total ad area vs content area |
| Flashing animated ads | No | Yes | Monitor animation frame rate (>3 flashes/second) |
The muted-video check must read the live DOM property (el.muted), not getAttribute('muted') — player scripts set video.muted = true in JS without ever adding the content attribute, so an attribute-only check reports muted ads as having sound and misses muted-then-unmuted ads.
Note: the CBA added two desktop and two mobile ad experiences on 14 Jan 2025; Chrome assessment of those begins no earlier than 14 May 2026. Re-check newer combined formats against the current Better Ads Standards page before that date. See references/better-ads-tests.md for the auto-playing-video and mobile ad-density checks.
Maintain a typed cookie inventory as the source of truth, then assert that actual cookies match it on three axes:
CookieDefinition[] capturing name, category, purpose, max expiry, and the Secure / HttpOnly / SameSite attributes each cookie must carry.SameSite to None before comparing — Playwright omits or varies it when the server doesn't set it, so an un-normalized check fails spuriously or passes silently.throw, don't warn) when a cookie appears that is not in the inventory, forcing the inventory to stay current as scripts are added.See references/cookie-compliance.md for the typed inventory and both implementations.
Accessibility is a legal requirement in many jurisdictions, but author the actual tests in accessibility-testing (axe-core, keyboard, screen reader). This table is only the legal landscape so you know what the obligation is.
| Region | Law | Standard | Enforcement |
|---|---|---|---|
| EU | European Accessibility Act (EAA) | EN 301 549 / WCAG 2.1 AA | Applied 28 June 2025; member-state penalties active. WCAG 2.2 alignment expected in the next EN 301 549 revision. |
| USA | ADA | WCAG 2.1 AA (court precedent) | Private lawsuits |
| USA (federal) | Section 508 | WCAG 2.0 AA | Federal procurement requirement |
| Canada (Ontario) | AODA | WCAG 2.0 AA | Fines up to $100K/day |
| UK | Equality Act 2010 | WCAG 2.1 AA (guidance) | Lawsuits |
Run compliance tests weekly (not just on PR) to catch configuration drift, and retain results as long-lived CI artifacts for the audit trail. See references/ci-automation.md for the scheduled GitHub Actions workflow with 90-day artifact retention.
Running compliance tests only in the "all accepted" state. The compliance boundary is the "no interaction" and "rejected" states — that is where violations hide. Test every state: no interaction, accepted, rejected, partially accepted, withdrawn.
Checking window.__cmp.gpcStatus or similar fabricated globals to "prove" a GPC opt-out. That global does not exist. Assert navigator.globalPrivacyControl === true and verify marketing cookies are absent; read real consent state via __tcfapi.
Treating getAttribute('muted') === null as "has sound." The content attribute is frequently absent on programmatically-muted videos. Read el.muted / el.autoplay live properties instead.
A cookie inventory nobody updates. Use the drift-detection test that throws on any unknown cookie — reality and inventory stay in sync automatically.
Trusting the CMP and only exercising its UI. CMPs have bugs. Test the outcome: cookies set, scripts loaded, data transmitted.
Auditing by hand once a quarter. Between audits a developer adds an analytics script that fires before consent and nobody notices for three months. Automated tests catch it on the next CI run.
One global consent model. GDPR requires opt-in; CCPA allows opt-out via GPC. Serving both regions means testing both experiences.
Building the suite once and freezing it. Regulations evolve (ePrivacy Regulation, TCF version bumps, AI Act phases, updated CBA standards). Review quarterly.
Smallest check first — confirm the compliance suite runs and gates before trusting it:
npx playwright test --project=chromium --grep @complianceA correct run shows the unhappy-path tests as the gate: "no non-essential cookies before consent" and "no tracking scripts load before consent" must pass on a fresh context (storageState: undefined). To prove the suite actually catches violations, temporarily point it at a page that loads GA before consent — the script-blocking test must go red. A suite that stays green against a known-bad page is asserting nothing. Then confirm the GPC test sees navigator.globalPrivacyControl === true with the Sec-GPC: 1 header set, and that the Consent Mode default-state test reports denied for all four signals.
.agents/qa-project-context.md.Sec-GPC: 1, navigator.globalPrivacyControl === true and marketing cookies absent.denied for ad_storage / analytics_storage / ad_user_data / ad_personalization; update fires granted after accept (only required for sites serving Google ads in EEA/UK).references/)navigator.globalPrivacyControl), TCF v2 __tcfapi consent read + v2.3 version guard, and Google Consent Mode v2.© petrkindlmann, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in skills/compliance-testing of petrkindlmann/qa-skills.
Open the folder on GitHubat commit b3bb61b
Compliance Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Compliance Testing this skillpetrkindlmann/qa-skills | 168 | — | ~4.6k | Automated safety check: Pass | MIT | |
| Compliance Osalirezarezvani/claude-skills | 28k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Ra Qm Skillsalirezarezvani/claude-skills | 28k | — | ~833 | Automated safety check: Pass | MIT | |
| AI Data Subject Rightsmukul975/Privacy-Data-Protection-Skills | 297 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Region Configindranilbanerjee/digital-marketing-pro | 859 | 1 repos | ~3.5k | Automated safety check: Pass | MIT | |
| AI Privacy Assessmentmukul975/Privacy-Data-Protection-Skills | 297 | — | ~4.3k | Automated safety check: Pass | Apache-2.0 |
alirezarezvani/claude-skills
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…
alirezarezvani/claude-skills
Router/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document control, ISO…
mukul975/Privacy-Data-Protection-Skills
Implements data subject rights mechanisms for AI systems including right to explanation of AI decisions, contestation procedures, human review, model output correction, and training data access.
indranilbanerjee/digital-marketing-pro
Configure a brand's regional settings — timezone, languages, currency, compliance regulations (GDPR, CCPA, APPI, LGPD, EU AI Act Article 50, and more), local platforms, business hours, holiday…
mukul975/Privacy-Data-Protection-Skills
Guides the combined DPIA and AI Act conformity assessment for AI systems processing personal data.
lawve-ai/awesome-legal-skills
Analyzes how multiple regulations interact for a specific product, service, or business model.
petrkindlmann/qa-skills
Test for WCAG 2.2 AA compliance with axe-core + Playwright, keyboard navigation audits, screen reader testing, ARIA pattern validation, and legal compliance mapping (ADA, EAA, Section 508).
petrkindlmann/qa-skills
Goal-driven E2E testing where a browser agent (Playwright MCP / computer-use) reads a natural-language goal and explores the app via the accessibility tree to assert outcomes — no pre-written script.
petrkindlmann/qa-skills
Use AI to write NEW test code from specs, PRDs, user stories, code diffs, bug reports, or OpenAPI specs.
petrkindlmann/qa-skills
Test REST and GraphQL APIs with Playwright APIRequestContext, Supertest, or standalone HTTP clients.
petrkindlmann/qa-skills
Design CI/CD pipelines that run test suites. An agent skill from petrkindlmann/qa-skills.
petrkindlmann/qa-skills
Implement consumer-driven contract testing with Pact-JS (v16).
Categories
Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…. Compliance Testing is an agent skill from petrkindlmann/qa-skills. Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards, and cookie-inventory auditing.
Compliance Testing fits situations like: privacy banner. Not for: WCAG/axe-core test authoring — use accessibility-testing; tasks that involve Privacy and GDPR; tasks that involve Accessibility.
Run `npx skills add petrkindlmann/qa-skills --skill compliance-testing -a claude-code`. Or copy the skill folder (skills/compliance-testing in petrkindlmann/qa-skills) into .claude/skills/compliance-testing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add petrkindlmann/qa-skills --skill compliance-testing -a codex`. Or copy the skill folder (skills/compliance-testing in petrkindlmann/qa-skills) into .agents/skills/compliance-testing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add petrkindlmann/qa-skills --skill compliance-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-testing, .gemini/skills/compliance-testing, .github/skills/compliance-testing and .opencode/skills/compliance-testing in your project.
Going by SKILL.md and its folder, Compliance Testing needs the command-line tools its instructions call (npx).
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Compliance Testing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Compliance Testing: Compliance Os (alirezarezvani/claude-skills, 28k stars), Ra Qm Skills (alirezarezvani/claude-skills, 28k stars), AI Data Subject Rights (mukul975/Privacy-Data-Protection-Skills, 297 stars) and Region Config (indranilbanerjee/digital-marketing-pro, 859 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
petrkindlmann (a GitHub user) maintains it in petrkindlmann/qa-skills, which has 168 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on June 10, 2026.
Source: petrkindlmann/qa-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.