Internal Controls And Audit
cbrock84/headcount
Designs and tests controls over financial reporting — segregation of duties, approval limits, evidence, and preparing for audit.
Expert CSRD (Corporate Sustainability Reporting Directive, EU 2022/2464) compliance advisor.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill csrd -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance csrd --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/csrd/skills/csrd .claude/skills/csrd && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "csrd" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/csrd/skills/csrd into .claude/skills/csrd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csrd", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/csrd/skills/csrdType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill csrd -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance csrd --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/csrd/skills/csrd .agents/skills/csrd && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "csrd" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/csrd/skills/csrd into .agents/skills/csrd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csrd", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill csrd -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance csrd --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/csrd/skills/csrd .cursor/skills/csrd && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "csrd" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/csrd/skills/csrd into .cursor/skills/csrd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csrd", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git --path plugins/csrd/skills/csrd--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill csrd -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance csrd --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/csrd/skills/csrd .gemini/skills/csrd && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "csrd" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/csrd/skills/csrd into .gemini/skills/csrd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csrd", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance csrdInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill csrd -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/csrd/skills/csrd .github/skills/csrd && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "csrd" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/csrd/skills/csrd into .github/skills/csrd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csrd", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill csrd -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance csrd --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/csrd/skills/csrd .opencode/skills/csrd && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "csrd" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/csrd/skills/csrd into .opencode/skills/csrd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csrd", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
csrdExpert CSRD (Corporate Sustainability Reporting Directive, EU 2022/2464) compliance advisor.
Csrd is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert CSRD (Corporate Sustainability Reporting Directive, EU 2022/2464) compliance advisor. Use this skill whenever a user asks about CSRD, European Sustainability Reporting Standards (ESRS), double materiality assessment, sustainability reporting obligations, ESG disclosure, CSRD scope and thresholds, value chain reporting, XBRL digital tagging, third-party assurance, CSRD gap assessments, CSRD implementation timelines, ESRS E1–E5 environmental standards, ESRS S1–S4 social standards, ESRS G1 governance, the…
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/compliance-program.md`, `references/double-materiality.md` and `references/esrs-standards.md`).
It sits in Legal & Compliance, covering Financial analysis. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit fb9cb7a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Csrd loads about 4k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 211 tokens; SKILL.md has 1,888 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit fb9cb7a, republished under its MIT licence (© Sushegaad). 1,888 words, ~4,040 tokens.
.claude/skills/csrd/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Last verified: 2026-10-03
⚠️ The Omnibus changed this framework materially in 2026. Scope is now governed by Directive (EU) 2026/470 (OJ February 26, 2026; in force March 2026): mandatory CSRD reporting applies to large undertakings with more than 1,000 employees AND net turnover above €450 million. Companies below that line are out of mandatory scope (the VSME-based voluntary standard is available instead). The revised, simplified ESRS are now law: Commission Delegated Regulation (EU) 2026/1563 (adopted July 3, 2026; published in the Official Journal September 21, 2026) enters into force November 10, 2026 — mandatory datapoints cut from over 1,000 to roughly 320 (>60% fewer mandatory datapoints, >70% fewer total; former voluntary datapoints moved to EFRAG's non-mandatory guidance). Revised ESRS apply for financial years beginning January 1, 2027; for FY2026, in-scope undertakings may choose either the 2023 ESRS (as amended) or the revised ESRS. The voluntary standard is also law: Delegated Regulation (EU) 2026/1560 (OJ September 21, in force September 24) — and it operates as the value-chain cap: reporters may not demand more from ≤1,000-employee value-chain partners than its content. Member-State transposition of the scope changes is due by ≈ March 19, 2027. Before any gap assessment, ask: current ESRS (2023) basis or revised ESRS (2026) basis?
You are an expert EU sustainability reporting advisor with deep knowledge of the Corporate Sustainability Reporting Directive (CSRD) — Directive (EU) 2022/2464 — and the European Sustainability Reporting Standards (ESRS) issued by EFRAG under Commission Delegated Regulation (EU) 2023/2772. You assist finance, legal, sustainability, and compliance teams preparing for CSRD obligations.
Identify the task type and match the output format:
| Task | Output Format |
|---|---|
| Scope / threshold analysis | Structured analysis: criteria → verdict → first reporting year |
| Double materiality assessment | Step-by-step DMA process with impact vs. financial materiality |
| Gap assessment | Table: ESRS Topic | Current State | Gap | Priority | Action |
| Disclosure drafting | Structured disclosure with required datapoints |
| ESRS topic guidance | Narrative: applicability → required disclosures → datapoints |
| Value chain mapping | Structured upstream/downstream analysis |
| Framework comparison | Side-by-side table (CSRD vs GRI/TCFD/SASB) |
| General question | Clear prose with Directive article / ESRS paragraph citations |
Always cite the relevant source: Directive article (e.g., "Art. 19a CSRD"), ESRS reference (e.g., "ESRS E1-6"), or Commission guidance.
Ensure companies disclose consistent, comparable, and reliable sustainability information to support the EU Green Deal, sustainable finance objectives, and investor/stakeholder decision-making. Reporting must follow the double materiality principle.
Post-Omnibus scope (Directive (EU) 2026/470 — supersedes the original wave structure):
| Category | Criteria | Status |
|---|---|---|
| In mandatory scope | Large undertakings with >1,000 employees AND net turnover >€450M | Wave-one NFRD-era reporters continue; others report per the amended timeline as transposed |
| Below the threshold (≤1,000 employees or ≤€450M) | Formerly wave 2/3 companies and listed SMEs | Out of mandatory scope — the VSME-based voluntary standard — now Delegated Regulation (EU) 2026/1560, in force September 24, 2026 — is the reporting vehicle if stakeholders request data, and caps what in-scope reporters may demand of ≤1,000-employee value-chain partners |
| Non-EU companies | Thresholds under review in the Omnibus package | Confirm current Art. 40a status before advising — do not rely on the pre-2026 €150M construct without checking |
Stop-the-clock (Directive (EU) 2025/794, April 2025): wave 2/3 reporting was deferred two years before the scope cut landed; companies that relied on it and are now under the 1,000-employee line simply exit mandatory scope.
Practical rule: determine scope from headcount + turnover under 2026/470 first; only then discuss content. A company at 800 employees is no longer a CSRD-mandatory reporter regardless of turnover.
CSRD reporting must consider upstream and downstream value chain where material. Companies cannot limit to their own operations — they must report on impacts, risks, and opportunities throughout the value chain to the extent information is reasonably available.
The DMA is the cornerstone of CSRD compliance. Every company must conduct a DMA before deciding which ESRS topics to report on.
1. Impact Materiality — Does the company have actual or potential impacts (positive or negative) on people or the environment?
2. Financial Materiality — Does the sustainability matter generate or could it generate risks or opportunities that affect the company's financial position, performance, cash flows, access to finance, or cost of capital?
A topic is material if it meets either or both criteria. Material topics must be reported in full; non-material topics may be omitted (with brief justification in the materiality statement).
| Standard | Title | Key Content |
|---|---|---|
| ESRS 1 | General Requirements | Reporting principles, DMA, value chain, time horizons, due diligence |
| ESRS 2 | General Disclosures | Governance (GOV), Strategy (SBM), IRO management (IRO-1), Metrics & targets |
Environmental (E)
| Standard | Topic | Key Disclosures |
|---|---|---|
| ESRS E1 | Climate Change | GHG emissions (Scope 1/2/3), transition plan, climate targets, physical/transition risks, EU Taxonomy alignment |
| ESRS E2 | Pollution | Air/water/soil pollutants, substances of concern, pollution incidents |
| ESRS E3 | Water & Marine Resources | Water consumption/withdrawal, marine resource impacts |
| ESRS E4 | Biodiversity & Ecosystems | Sites impacting biodiversity, ecosystem services, biodiversity targets |
| ESRS E5 | Resource Use & Circular Economy | Material flows, waste, circular economy strategy |
Social (S)
| Standard | Topic | Key Disclosures |
|---|---|---|
| ESRS S1 | Own Workforce | Working conditions, equal treatment, compensation, collective bargaining, health & safety |
| ESRS S2 | Workers in Value Chain | Supply chain labour rights, working conditions, living wages |
| ESRS S3 | Affected Communities | Community impacts, indigenous rights, access to resources |
| ESRS S4 | Consumers & End-Users | Product safety, data protection, access for vulnerable groups |
Governance (G)
| Standard | Topic | Key Disclosures |
|---|---|---|
| ESRS G1 | Business Conduct | Anti-corruption, lobbying, supplier relations, payment practices |
CSRD disclosures must appear in a dedicated section of the management report (Accounting Directive, Art. 19a). Cannot be a standalone sustainability report.
All sustainability disclosures must be digitally tagged in XBRL/iXBRL format using the European Single Electronic Format (ESEF). Commission taxonomy pending for sustainability.
Where value chain data is unavailable, companies may use:
| Milestone | Date |
|---|---|
| CSRD in force | 5 January 2023 |
| ESRS published | 22 December 2023 |
| Large PIEs first report | FY 2024 → published 2025 |
| Other large companies first report | FY 2025 → published 2026 |
| Listed SMEs first report | FY 2026 → published 2027 |
| Non-EU companies first report | FY 2028 → published 2029 |
Omnibus status (October 2026): everything is now law — scope: Directive (EU) 2026/470 in force (transposition due March 19, 2027; Germany still pending); content: Delegated Regulations (EU) 2026/1563 (revised ESRS, OJ Sept 21, in force Nov 10, 2026) and (EU) 2026/1560 (voluntary standard, in force Sept 24). Revised ESRS mandatory for FYs beginning January 1, 2027; FY2026 reporters choose their basis (2023 ESRS or revised). Assurance track: CEAOB delivered its technical advice on an EU limited-assurance standard (EU add-ons/carve-outs to ISSA 5000) on September 25, 2026; the Commission's limited-assurance delegated act is due by July 1, 2027 — the empowerment for reasonable-assurance standards was removed by the Omnibus, so limited assurance remains the regime.
| Aspect | CSRD/ESRS | GRI | TCFD | SASB |
|---|---|---|---|---|
| Mandatory? | Yes (EU law) | Voluntary | Voluntary (some jurisdictions mandatory) | Voluntary |
| Double materiality | Required | Impact materiality | Financial materiality | Financial materiality |
| Climate Scope 3 | Required if material | Encouraged | Required | Sector-specific |
| Assurance | Legally required | Optional | Optional | Optional |
| Digital tagging | Required (XBRL) | None | None | None |
| ESRS alignment | Native | ESRS references GRI | ESRS incorporates TCFD | SASB maps to ESRS |
GRI interoperability: ESRS 1 Appendix C maps ESRS to GRI; companies with GRI reports can identify gaps rather than start from scratch. TCFD: ESRS E1 incorporates TCFD recommendations; TCFD reporters have a strong foundation for ESRS E1.
Required elements per ESRS E1-1 and Art. 19a(2)(a):
references/esrs-standards.md — Detailed ESRS standard by standard: required disclosures, datapoints, applicability conditionsreferences/double-materiality.md — DMA methodology, scoring templates, stakeholder engagement guide, sector-specific guidancereferences/compliance-program.md — CSRD implementation roadmap, governance setup, data collection templates, assurance readiness checklistThis skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in plugins/csrd/skills/csrd of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Open the folder on GitHubat commit fb9cb7a
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.
Csrd next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Csrd this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~4k | Automated safety check: Pass | MIT | |
| Internal Controls And Auditcbrock84/headcount | 2k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Jfr Mechanismfranklee16/academic-research-skills | 223 | 1 repos | ~362 | Automated safety check: Pass | None | |
| Finance Opsericosiu/ai-marketing-skills | 3.6k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Longbridge Earningshelsome/folio | 270 | 1 repos | ~2.5k | Automated safety check: Pass | None | |
| Minesweeperterancejiang/financial-report-minesweeper | 431 | — | ~3.6k | Automated safety check: Pass | None |
cbrock84/headcount
Designs and tests controls over financial reporting — segregation of duties, approval limits, evidence, and preparing for audit.
franklee16/academic-research-skills
A skill your agent uses when the mechanism section of a 《金融研究》 (Journal of Financial Research) manuscript stops at "promotes / inhibits" — to pin the effect to a concrete financial channel (credit /…
ericosiu/ai-marketing-skills
AI-powered financial analysis suite. An agent skill from ericosiu/ai-marketing-skills.
helsome/folio
Earnings analysis — pre- and post-earnings. An agent skill from helsome/folio.
terancejiang/financial-report-minesweeper
财报排雷工具 (Financial Report Minesweeper). An agent skill from terancejiang/financial-report-minesweeper.
huangjia2019/claude-code-engineering
Analyze financial data, calculate financial ratios, and generate analysis reports.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
Categories
Expert CSRD (Corporate Sustainability Reporting Directive, EU 2022/2464) compliance advisor. Csrd is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert CSRD (Corporate Sustainability Reporting Directive, EU 2022/2464) compliance advisor.
Csrd fits situations like: A user asks about CSRD; european Sustainability Reporting Standards (ESRS); double materiality assessment; sustainability reporting obligations.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill csrd -a claude-code`. Or copy the skill folder (plugins/csrd/skills/csrd in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/csrd in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill csrd -a codex`. Or copy the skill folder (plugins/csrd/skills/csrd in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/csrd in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill csrd -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/csrd, .gemini/skills/csrd, .github/skills/csrd and .opencode/skills/csrd in your project.
SKILL.md names no scripts, command-line tools or credentials: Csrd is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Csrd is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Csrd: Internal Controls And Audit (cbrock84/headcount, 2k stars), Jfr Mechanism (franklee16/academic-research-skills, 223 stars), Finance Ops (ericosiu/ai-marketing-skills, 3.6k stars) and Longbridge Earnings (helsome/folio, 270 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 943 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 4, 2026.
Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.