Agent skill

Ca Policy Investigation

by SCStelz in SCStelz/security-investigator

A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy…

MITAuto-check passedLegal & Compliance

Install Ca Policy Investigation

skills CLI
$ npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SCStelz/security-investigator ca-policy-investigation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/ca-policy-investigation .claude/skills/ca-policy-investigation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ca-policy-investigation
GitHub stars
249
Token cost
~3.8k tokens
SKILL.md length
1,407 words
Files
1
Skills in repo
22
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy…

  • Works in 5 steps: Identify Sign-In Failures → Query ALL CA Policy Changes in Timeframe → Parse Policy State Changes → …
  • Asked to investigate Conditional Access policy changes
  • SKILL.md covers Purpose, 📑 TABLE OF CONTENTS, Critical Investigation Rules and Common Error Codes, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ca Policy Investigation is an agent skill from SCStelz/security-investigator. Use this skill when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy bypass/manipulation. Triggers on keywords like "Conditional Access", "CA policy", "device compliance", "policy bypass", "53000", "50074", or when investigating why a user was blocked then suddenly unblocked. This skill provides forensic analysis of CA policy modifications correlated with sign-in failures.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Regulatory compliance and Digital forensics. The repository describes itself as: Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions. The licence is MIT.

When your agent uses it

  • Asked to investigate Conditional Access policy changes
  • Sign-in failures related to CA policies (error codes 53000
  • Suspected policy bypass/manipulation
  • Keywords like Conditional Access

Example prompts

  • “Conditional Access”
  • “CA policy”
  • “device compliance”
  • “/ca-policy-investigation”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify Sign-In Failures
  2. Query ALL CA Policy Changes in Timeframe
  3. Parse Policy State Changes
  4. Extract Policy State from JSON
  5. Security Assessment

What it can do on your machine

Read from SKILL.md and the folder at commit 51e1385. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are kql and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ca Policy Investigation loads about 3.8k tokens when it runs. Until then it costs about 126 tokens; SKILL.md has 1,407 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~126
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SCStelz/security-investigator at commit 51e1385, republished under its MIT licence (© SCStelz). 1,407 words, ~3,752 tokens.

Download SKILL.mdSave it as .claude/skills/ca-policy-investigation/SKILL.md (or your agent's skills folder).
name
ca-policy-investigation
description
Use this skill when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy bypass/manipulation. Triggers on keywords like "Conditional Access", "CA policy", "device compliance", "policy bypass", "53000", "50074", or when investigating why a user was blocked then suddenly unblocked. This skill provides forensic analysis of CA policy modifications correlated with sign-in failures.
threat_pulse_domains
identity
drill_down_prompt
Investigate Conditional Access policy changes — sign-in correlation, bypass detection

Conditional Access Policy Investigation - Instructions

Purpose

This skill investigates Conditional Access (CA) policy changes in correlation with sign-in failures to detect:

  • Legitimate troubleshooting (authorized policy changes to resolve access issues)
  • Security control bypass (unauthorized policy modifications to circumvent blocks)
  • Privilege abuse (users with admin rights weakening security controls)

The key distinction is whether policy changes were authorized and necessary vs self-service bypass of security controls.


📑 TABLE OF CONTENTS

  1. Critical Investigation Rules - Mandatory workflow steps
  2. Common Error Codes - Sign-in failure reference
  3. CA Policy States - Understanding policy modes
  4. 5-Step Investigation Workflow - KQL queries and analysis
  5. Real-World Example - Complete walkthrough
  6. Critical Mistakes - What NOT to do
  7. Security Recommendations - Remediation guidance

Critical Investigation Rules

When investigating sign-in failures (error codes 53000, 50074) with CA policy correlation:

⚠️ MANDATORY STEPS - DO NOT SKIP:

  1. Query ALL CA policy changes in chronological order (±2 days from failure time)
  2. Parse policy state transitions from the JSON (enabled → disabled → report-only)
  3. Compare failure timeline with policy change timeline
  4. Verify logical consistency: Ask "does this make sense?"

Key Questions to Answer:

  • Was the user blocked BEFORE the policy change?
  • Did the policy change resolve the block?
  • Who initiated the policy change? (same user = suspicious)
  • What was the business justification?

Common Error Codes

Error CodeDescriptionTypical Cause
53000Device not compliantDevice not enrolled in Intune or failing compliance checks
50074Strong authentication requiredMFA not satisfied
50074User must enroll in MFAMFA not configured for user
530032Blocked by CA policyGeneric CA policy block
65001User consent requiredApplication consent needed
53003Access blocked by CA policyExplicit block condition met
70044Session expiredUser needs to re-authenticate
Error Code Investigation Priority
PriorityError CodesInvestigation Focus
HIGH53000, 530032, 53003Device compliance, CA policy blocks - check for policy manipulation
MEDIUM50074MFA requirements - check if MFA was bypassed
LOW65001, 70044Consent/session issues - usually not security-related

CA Policy State Meanings

StateWhat It MeansSecurity Impact
enabledPolicy actively enforcingBlocks non-compliant access (intended behavior)
disabledPolicy not enforcingSecurity control bypassed - all access allowed
enabledForReportingButNotEnforcedReport-only modeLogs violations but doesn't block - defeats purpose
State Transition Risk Assessment
TransitionRisk LevelInterpretation
enabled → disabledHIGHComplete security bypass
enabled → enabledForReportingButNotEnforcedMEDIUM-HIGHPartial bypass (monitoring only)
disabled → enabledLOWSecurity restored (good)
enabledForReportingButNotEnforced → enabledLOWSecurity strengthened (good)

Investigation Workflow Pattern

Step 1: Identify Sign-In Failures

Query sign-in failures with CA context:

kql
// Get failures with CA context
union isfuzzy=true SigninLogs, AADNonInteractiveUserSignInLogs
| where TimeGenerated between (datetime(<START>) .. datetime(<END>))
| where UserPrincipalName =~ '<UPN>'
| where ResultType != '0'
| where AppDisplayName has '<APPLICATION>'  // e.g., "Visual Studio Code"
| project TimeGenerated, IPAddress, Location, ResultType, ResultDescription, 
    ConditionalAccessStatus, UserAgent
| order by TimeGenerated asc

What to Look For:

  • ResultType values: 53000, 50074, 530032, 53003
  • ConditionalAccessStatus: "failure", "notApplied"
  • Pattern of repeated failures followed by success

Step 2: Query ALL CA Policy Changes in Timeframe

CRITICAL: Query ±2 days from the first failure time

kql
let failure_time = datetime(<FIRST_FAILURE_TIME>);
let start = failure_time - 2d;
let end = failure_time + 2d;
AuditLogs
| where TimeGenerated between (start .. end)
| where OperationName has_any ("Conditional Access", "policy")
| where Identity =~ '<UPN>' or tostring(InitiatedBy) has '<UPN>'
| extend InitiatorUPN = tostring(parse_json(InitiatedBy).user.userPrincipalName)
| extend InitiatorIPAddress = tostring(parse_json(InitiatedBy).user.ipAddress)
| extend TargetName = tostring(parse_json(TargetResources)[0].displayName)
| project TimeGenerated, OperationName, Result, InitiatorUPN, InitiatorIPAddress, 
    TargetName, CorrelationId
| order by TimeGenerated asc  // CRITICAL: Chronological order

Critical Analysis Points:

  • InitiatorUPN: Who made the change? Same user as blocked = suspicious
  • TargetName: Which policy was modified?
  • TimeGenerated: Did change occur AFTER sign-in failures?
  • Order: Always chronological (oldest first) to see cause/effect

Step 3: Parse Policy State Changes

For each CorrelationId from Step 2, get detailed changes:

kql
// Get detailed property changes for a specific policy modification
AuditLogs
| where CorrelationId == "<CORRELATION_ID>"
| extend ModifiedProperties = parse_json(TargetResources)[0].modifiedProperties
| mv-expand ModifiedProperties
| extend PropertyName = tostring(ModifiedProperties.displayName)
| extend OldValue = tostring(ModifiedProperties.oldValue)
| extend NewValue = tostring(ModifiedProperties.newValue)
| project TimeGenerated, PropertyName, OldValue, NewValue

Key Properties to Extract:

  • Look for "state" property in the JSON
  • Parse OldValue and NewValue for state transitions
  • Document: enabled → disabled → enabledForReportingButNotEnforced

Step 4: Extract Policy State from JSON

Manual JSON Parsing:

The OldValue and NewValue fields contain JSON. Look for the "state" field:

json
{
  "state": "enabled",
  "conditions": { ... },
  "grantControls": { ... }
}

Build the Timeline:

  1. Extract "state" from each OldValue and NewValue
  2. Create chronological list: enabled → disabled → enabledForReportingButNotEnforced
  3. Correlate with sign-in failure timeline

Step 5: Security Assessment

Compare timelines and assess intent:

PatternInterpretationRisk Level
Failures → Policy DisabledUser bypassed security control to unblock selfHIGH - Privilege abuse
Failures → Policy Changed to Report-OnlyUser weakened security controlMEDIUM-HIGH - Partial bypass
Policy Disabled → Failures ContinueCached tokens (5-15 min propagation delay)INFO - Expected behavior
Policy Changed → No More FailuresPolicy change resolved issueContext-dependent - May be legitimate troubleshooting
Different user made changeAdmin assisted with access issueLOW - Likely legitimate (verify authorization)

Risk Escalation Criteria:

CriteriaRisk Level
Same user blocked AND made policy changeHIGH
Policy disabled within 30 minutes of first failureHIGH
Multiple policies modifiedHIGH
Change made outside business hoursMEDIUM-HIGH
No change request ticket/approvalMEDIUM-HIGH
Admin made change for blocked user (with ticket)LOW

Real-World Example Analysis

Scenario: User blocked by device compliance policy, then modifies policy

Timeline
TimeEventDetails
19:05Sign-in failureError 53000: device not compliant
19:06Sign-in failureError 53000: device not compliant
19:07Sign-in failureError 53000: device not compliant
19:09Policy changeenabled → disabled
19:09Policy changedisabled → enabledForReportingButNotEnforced
19:12Sign-in failureError 53000 (cached token)
19:14Sign-in successAccess granted
Analysis
  1. ✅ Policy was correctly blocking non-compliant device

    • Device compliance policy was enforcing as intended
    • User's device failed compliance checks (not enrolled or failing policy)
  2. 🚨 User disabled security control to bypass block

    • Same user who was blocked made the policy change
    • Change occurred within 4 minutes of repeated failures
    • No approval or change request documented
  3. ⚠️ User partially reversed by enabling report-only

    • Shows some awareness that disabling was too aggressive
    • But report-only still defeats the purpose (doesn't block)
  4. ❌ Report-only mode is NOT a valid security posture

    • Logs violations but allows non-compliant access
    • Creates false sense of security (policy "exists" but doesn't protect)
Show full SKILL.md (555 more words)Show less
Assessment
FieldValue
Risk LevelMEDIUM-HIGH
FindingSelf-service security bypass using privileged role
Root CauseUser's device is non-compliant (not enrolled/failing compliance)
Policy ImpactDevice compliance checks now ineffective for all users
Recommendations
  1. Immediate Actions:

    • Restore policy to enabled state
    • Verify user's device compliance status
    • Document incident for security review
  2. User-Specific:

    • Enroll user's device in Intune
    • Verify device meets compliance requirements
    • Review if user needs Security Administrator role
  3. Process Improvements:

    • Implement approval workflow for CA policy changes
    • Create alert for policy state changes (enabled → disabled/report-only)
    • Review all users with permission to modify CA policies
    • Consider PIM for Security Administrator role

Critical Mistakes to Avoid

❌ DON'T:
MistakeWhy It's Wrong
Query only ONE policy change eventYou'll miss the sequence of changes
Read policy changes in reverse chronological orderConfuses cause/effect relationship
Assume policy was already disabledMust check starting state from OldValue
Skip verifying "does this make logical sense?"Disabled policies can't block users
Ignore the initiator identitySame user = suspicious, different admin = verify authorization
Focus only on final stateThe transition sequence reveals intent
✅ DO:
Best PracticeWhy It Matters
Query ALL policy changes in the timeframeComplete picture of modifications
Order chronologically (oldest first)See cause/effect sequence
Parse the full JSON for state transitionsExtract exact policy states
Cross-check: blocked user → policy must be enabledLogical consistency verification
Ask: "Why would user disable this policy?"Usually to bypass a legitimate block
Check if initiator had authorizationTicket, approval, documented reason

Security Recommendations

When CA Policy Changes Are Detected
1. Determine Legitimacy
  • Was the policy change authorized?
  • Was there a valid business reason?
  • Did the user have approval to make this change?
  • Is there a change request ticket?
2. Assess Impact
  • How many users affected by policy change?
  • What applications/resources are now unprotected?
  • How long was the policy disabled/weakened?
  • Are there compliance implications (regulatory requirements)?
3. Remediation Actions
ActionPriority
Restore policy to enabled state if unauthorizedIMMEDIATE
Investigate root cause (why was user blocked?)HIGH
Fix underlying issue (device compliance, MFA enrollment)HIGH
Review who has permission to modify CA policiesMEDIUM
Implement approval workflows for policy changesMEDIUM
Create alerts for future CA policy modificationsMEDIUM
4. Long-Term Improvements
ImprovementBenefit
Use PIM for Security Administrator roleRequires approval for elevated access
Implement CA policy change alertsReal-time notification of modifications
Require multi-admin approval for state changesPrevents single-person bypass
Document approved proceduresClear guidance for legitimate troubleshooting
Regular access reviewsEnsure only necessary users have CA admin rights

Prerequisites

Required MCP Servers

This skill requires:

  1. Microsoft Sentinel MCP - For KQL queries against SigninLogs and AuditLogs
    • mcp_sentinel-data_query_lake: Execute KQL queries
    • mcp_sentinel-data_search_tables: Discover table schemas
Required Data Sources
  • SigninLogs - Interactive sign-in events with CA status
  • AADNonInteractiveUserSignInLogs - Non-interactive sign-in events
  • AuditLogs - CA policy modification events
Required Permissions

To view CA policy changes in AuditLogs, ensure:

  • Sentinel workspace has AuditLogs ingestion enabled
  • User has appropriate RBAC to query the workspace

Integration with Other Skills

CA Policy Investigation often follows a user-investigation:

  1. Run user-investigation skill → Identifies sign-in failures
  2. Notice CA-related error codes → 53000, 50074, 530032
  3. Run ca-policy-investigation skill → Correlate failures with policy changes
  4. Document findings → Security assessment with remediation recommendations

Key Integration Points:

  • Sign-in failure data comes from user investigation
  • CA policy changes are NEW queries specific to this skill
  • Assessment combines timeline correlation with policy state analysis

© SCStelz, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/ca-policy-investigation of SCStelz/security-investigator.

Open the folder on GitHubat commit 51e1385

Compare with similar skills

Ca Policy Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ca Policy Investigation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ca Policy Investigation this skillSCStelz/security-investigator249—~3.8kAutomated safety check: PassMIT
Implementing Complianceancoleman/ai-design-components525—~4kAutomated safety check: PassMIT
PCI DSS Compliancewshobson/agents40k11 repos~1.9kAutomated safety check: PassMIT
Oss Reviewanthropics/claude-for-legal9.6k3 repos~5kAutomated safety check: PassApache-2.0
Security Automationsickn33/agentic-awesome-skills47k2 repos~1kAutomated safety check: PassMIT
Dependency Auditoralirezarezvani/claude-skills28k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • PCI DSS Compliance

    wshobson/agents

    Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

    40k GitHub starsUsed in 11 repos~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Oss Review

    anthropics/claude-for-legal

    Official

    Open source license compliance check for a dependency list, a single library, or outbound code.

    9.6k GitHub starsUsed in 3 repos~5k tokens
    Legal & ComplianceAuto-check passed
  • Security Automation

    sickn33/agentic-awesome-skills

    Automate security workflows and remediation. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~1k tokens
    Legal & ComplianceAuto-check passed
  • Dependency Auditor

    alirezarezvani/claude-skills

    Audit and manage dependencies across multi-language projects.

    28k GitHub stars~1.1k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Memstack Business Licensing

    cwinvestments/memstack

    A skill your agent uses when the user says 'licensing', 'license audit', 'can I use this commercially', 'OSS license check', 'license compatibility', 'GPL', 'MIT', 'AGPL', 'copyleft'.

    423 GitHub stars~3.5k tokensUpdated 14 days ago
    Legal & ComplianceAuto-check passed

More from SCStelz/security-investigator

All 22 skills in this repo
  • Context Memory Review

    SCStelz/security-investigator

    Weekly review of an investigation tenant-context memory file against the most recent SOC scan reports (e.g.

    249 GitHub stars~3.7k tokensUpdated 2 days ago
    Auto-check passed
  • Heatmap Visualization

    SCStelz/security-investigator

    A skill your agent uses when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format.

    249 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • AI Agent Activity

    SCStelz/security-investigator

    Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield…

    249 GitHub stars~17k tokensUpdated 2 days ago
    Auto-check passed
  • AI Agent Posture

    SCStelz/security-investigator

    Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents.

    249 GitHub stars~21k tokensUpdated 2 days ago
    Auto-check passed
  • App Registration Posture

    SCStelz/security-investigator

    Audit Entra ID app registration and service principal security posture.

    249 GitHub stars~21k tokensUpdated 2 days ago
    Auto-check passed
  • Authentication Tracing

    SCStelz/security-investigator

    A skill your agent uses when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins.

    249 GitHub stars~8.6k tokensUpdated 2 days ago
    Auto-check passed

Questions about Ca Policy Investigation

What does Ca Policy Investigation do?

A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy…. Ca Policy Investigation is an agent skill from SCStelz/security-investigator. Use this skill when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy bypass/manipulation.

When should I use Ca Policy Investigation?

Ca Policy Investigation fits situations like: asked to investigate Conditional Access policy changes; sign-in failures related to CA policies (error codes 53000; suspected policy bypass/manipulation; keywords like Conditional Access.

How do I install Ca Policy Investigation in Claude Code?

Run `npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a claude-code`. Or copy the skill folder (.github/skills/ca-policy-investigation in SCStelz/security-investigator) into .claude/skills/ca-policy-investigation in your project. Claude Code loads it when a task matches its description.

How do I install Ca Policy Investigation in Codex?

Run `npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a codex`. Or copy the skill folder (.github/skills/ca-policy-investigation in SCStelz/security-investigator) into .agents/skills/ca-policy-investigation in your project. Codex loads it when a task matches its description.

Can I use Ca Policy Investigation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ca-policy-investigation, .gemini/skills/ca-policy-investigation, .github/skills/ca-policy-investigation and .opencode/skills/ca-policy-investigation in your project.

What does Ca Policy Investigation need to run?

SKILL.md names no scripts, command-line tools or credentials: Ca Policy Investigation is instructions for the agent only.

Does Ca Policy Investigation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ca Policy Investigation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ca Policy Investigation use?

Ca Policy Investigation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ca Policy Investigation use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ca Policy Investigation?

Skills that share tags, products or a category with Ca Policy Investigation: Implementing Compliance (ancoleman/ai-design-components, 525 stars), PCI DSS Compliance (wshobson/agents, 40k stars), Oss Review (anthropics/claude-for-legal, 9.6k stars) and Security Automation (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ca Policy Investigation?

SCStelz (a GitHub user) maintains it in SCStelz/security-investigator, which has 249 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 8, 2026.

Source: SCStelz/security-investigator on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.