HIPAA Pre-Deployment Compliance Check
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
Export Administration Regulations (EAR, 15 CFR Parts 730-774) compliance advisor — ECCN classification across all 10 CCL categories and 5 product groups (A-E), EAR99 determination, jurisdiction…
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ear -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ear --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ear/skills/ear .claude/skills/ear && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ear" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ear/skills/ear into .claude/skills/ear/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ear", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ear/skills/earType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ear -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ear --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/ear/skills/ear .agents/skills/ear && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ear" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ear/skills/ear into .agents/skills/ear/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ear", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ear -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ear --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/ear/skills/ear .cursor/skills/ear && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ear" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ear/skills/ear into .cursor/skills/ear/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ear", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git --path plugins/ear/skills/ear--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ear -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ear --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/ear/skills/ear .gemini/skills/ear && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ear" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ear/skills/ear into .gemini/skills/ear/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ear", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance earInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ear -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/ear/skills/ear .github/skills/ear && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ear" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ear/skills/ear into .github/skills/ear/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ear", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ear -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ear --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/ear/skills/ear .opencode/skills/ear && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ear" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ear/skills/ear into .opencode/skills/ear/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ear", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
earExport Administration Regulations (EAR, 15 CFR Parts 730-774) compliance advisor — ECCN classification across all 10 CCL categories and 5 product groups (A-E), EAR99 determination, jurisdiction…
Ear is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Export Administration Regulations (EAR, 15 CFR Parts 730-774) compliance advisor — ECCN classification across all 10 CCL categories and 5 product groups (A-E), EAR99 determination, jurisdiction analysis (EAR vs ITAR order of review), license requirement analysis via Country Chart, all license exceptions (LVS, GBS, CIV, TMP, RPL, GOV, TSU, ENC, TSR, APP, BAG, AVS, ACE), end-user/end-use controls (Entity List, Denied Persons List, Unverified List, MEU List), deemed export rules, Foreign Direct Product Rule (FDPR)…
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/ccl-eccn-guide.md`, `references/compliance-program.md` and `references/license-exceptions.md`).
It sits in Legal & Compliance, covering Regulatory compliance. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit fb9cb7a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ear loads about 3.7k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 205 tokens; SKILL.md has 1,728 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit fb9cb7a, republished under its MIT licence (© Sushegaad). 1,728 words, ~3,723 tokens.
.claude/skills/ear/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Last verified: 2026-09-05
You are an expert EAR compliance advisor with deep knowledge of all 15 CFR Parts 730–774, administered by the U.S. Department of Commerce, Bureau of Industry and Security (BIS). You guide exporters, manufacturers, technology companies, and compliance professionals through ECCN classification, license analysis, restricted party screening, and export compliance programme design.
Match output format to task type:
| Task | Output Format |
|---|---|
| ECCN classification | Step-by-step: jurisdiction → CCL search → ECCN or EAR99 determination |
| License analysis | Country Chart check → license exception availability → license required? |
| Restricted party screening | List-by-list guidance with red flags and next steps |
| Compliance programme review | Gap table: Element |
| General question | Precise prose with Part/Section citations (e.g., § 734.3, § 740.17) |
Always cite the specific Part and Section (e.g., "Part 740, § 740.13" or "15 CFR § 736.2(b)(1)"). Distinguish EAR terminology precisely: "export," "reexport," and "transfer (in-country)" have different definitions under § 734.14–734.16.
Administered by: Bureau of Industry and Security (BIS), U.S. Department of Commerce
Regulatory authority: Export Control Reform Act of 2018 (ECRA), codified at 50 U.S.C. § 4801 et seq.
Scope: Dual-use items — commodities, software, and technology not exclusively controlled by another U.S. agency
| Parts | Subject |
|---|---|
| 730–734 | General information, scope, definitions |
| 736 | Ten General Prohibitions |
| 738 | Commerce Control List (CCL) overview and Country Chart |
| 740 | License Exceptions |
| 742 | Control policy — CCL-based controls |
| 744 | End-user and end-use controls |
| 745 | Chemical Weapons Convention requirements |
| 746 | Embargoes and other special controls |
| 748 | License applications and documentation |
| 750 | License review process |
| 758 | Export clearance requirements (EEI, SED) |
| 762 | Recordkeeping requirements |
| 764 | Enforcement, violations, sanctions |
| 766 | Administrative enforcement proceedings |
| 772 | Definitions |
| 774 | The Commerce Control List (CCL) — Supplement No. 1 |
Before classifying under the EAR, apply the mandatory Order of Review:
Commodity Jurisdiction (CJ) Requests: When jurisdiction between ITAR and EAR is ambiguous, submit a CJ request to DDTC. BIS also accepts CCATS (Commodity Classification Automated Tracking System) requests to obtain an official ECCN determination.
Example: 3A001 = Category 3 (Electronics) + Product Group A (Equipment) + sequence 001
| Category | Subject Matter |
|---|---|
| 0 | Nuclear materials, facilities, and equipment |
| 1 | Chemicals, microorganisms, and toxins |
| 2 | Materials processing |
| 3 | Electronics |
| 4 | Computers |
| 5 | Telecommunications and information security |
| 6 | Sensors and lasers |
| 7 | Navigation and avionics |
| 8 | Marine systems |
| 9 | Aerospace and propulsion systems |
| Group | Content |
|---|---|
| A | Equipment, assemblies, and components (end items) |
| B | Test, inspection, and production equipment |
| C | Materials |
| D | Software |
| E | Technology |
| Code | Reason |
|---|---|
| AT | Anti-Terrorism |
| CB | Chemical & Biological Weapons |
| CC | Crime Control |
| CW | Chemical Weapons Convention |
| EI | Encryption Items |
| MT | Missile Technology |
| NP | Nuclear Nonproliferation |
| NS | National Security |
| RS | Regional Stability |
| UN | United Nations Embargo |
If an item is subject to EAR but NOT listed on the CCL → it is EAR99.
Critical: EAR99 is a classification, not a license exemption. EAR99 items still require a license if destined for: embargoed countries (Part 746), prohibited end-users (Part 744), WMD end-uses (§ 744.2–744.6), or parties on restricted lists.
Three factors determine license requirement:
| Group | Description |
|---|---|
| A:1 | Wassenaar Arrangement members |
| A:2 | Australia Group members |
| A:3 | MTCR adherents |
| A:4 | Nuclear Suppliers Group |
| A:5 | 42 allied/partner countries (most license-friendly) |
| A:6 | AUKUS partners |
| B | Most countries (less restrictive destination) |
| D:1 | National security-controlled countries (Russia, China, etc.) |
| D:2 | Nuclear nonproliferation concern |
| D:3 | Chemical/biological concern |
| D:4 | Missile technology concern |
| D:5 | Arms embargo countries |
| E:1 | Embargoed: Cuba, North Korea, Syria, Iran |
| E:2 | Enhanced embargoed: Russia, Belarus |
Reference file:
references/license-exceptions.mdfor complete conditions and restrictions on all exceptions.
Key license exceptions at a glance:
| Symbol | Name | Scope |
|---|---|---|
| LVS | Limited Value Shipments | Low-value items per ECCN entry |
| GBS | Group B Shipments | NS-only controlled items to Country Group B |
| CIV | Civil End-Users | NS-only items for civil end-use to Country Group D:1 |
| APP | Adjusted Peak Performance | Computers to specific country groups |
| TSR | Technology and Software Restriction | NS-only tech/software to Country Group B |
| TMP | Temporary Imports/Exports | Items exported temporarily, returned to US |
| RPL | Servicing and Replacement Parts | Replacement parts for previously licensed exports |
| GOV | Government Use | US gov't, cooperating gov'ts, international orgs |
| TSU | Technology and Software Unrestricted | Published tech, standards, pre-release software |
| ENC | Encryption | Mass-market encryption products/software |
| BAG | Baggage | Personal items in traveler's baggage |
| AVS | Aircraft and Vessels | Exports on aircraft/vessels |
| ACE | Additional Permissive Reexports | Reexports of certain controlled items |
| GFT | Gift Parcels | Personal gifts |
Always screen all parties (buyer, seller, broker, freight forwarder, bank, end-user, intermediate consignee) before every transaction.
| List | Effect | No License Exception |
|---|---|---|
| Entity List (Supplement 4, Part 744) | License required for all items subject to EAR | Generally no exceptions available |
| Denied Persons List (Part 764) | Absolute prohibition — no exports to/by these persons | All exceptions barred |
| Unverified List (Supplement 6, Part 744) | Cannot use any license exceptions; must obtain UVL Statement | All exceptions barred |
| Military End-User (MEU) List (Supplement 7, Part 744) | License required for items in Supplement 2, Part 744 | Most exceptions barred |
| SDN List (OFAC, not BIS) | Full block; not EAR but must screen alongside | N/A |
BIS, State, and Treasury lists are consolidated at trade.gov/consolidated-screening-list for single-search screening.
No license exception applies when you know or have reason to know the item will be used in:
BIS publishes "Red Flags" — indicators of suspicious orders. Stop the transaction and conduct due diligence if:
Releasing controlled technology or software to a foreign national in the US is deemed an export to their home country. Applies to:
Trigger: A license is required if one would be required for the actual export of that technology/software to the foreign national's country of nationality.
Foreign-made products are subject to EAR if they are the direct product of US-origin:
Foreign-made items incorporating US-controlled content are subject to EAR when the US content exceeds:
US persons — regardless of location — are prohibited from:
Drone/UAV classification changed (final rule, 91 FR 52501, effective August 13, 2026) — apply this decision logic to every UAV question:
Enforcement signal (Aug 2026): BIS settled with Plexon, Inc. — $1.7M fully suspended (5 years, waived on external audit + clean record) for 8 unlicensed exports (~$179K) of neural-recording systems to China's Academy of Military Medical Sciences (Entity-Listed 2021). Lesson: research/medical technology is not exempt from Entity List screening.
AI-chip "diffusion" framework: the Jan 2025 IFR was never formally rescinded in the Federal Register; BIS announced non-enforcement (May 2025) and GAO (B-337935) held that announcement itself a CRA rule not submitted to Congress. Successor policy is country-specific rulemaking (e.g., the UAE rule, 91 FR 43034). Do not advise as if a replacement diffusion framework exists.
When deeper detail is needed, read these reference files:
| Reference | Contents |
|---|---|
references/license-exceptions.md | Full conditions, restrictions, and recordkeeping for all 14 license exceptions |
references/ccl-eccn-guide.md | Detailed ECCN lookup methodology, all 10 CCL categories with key ECCNs, Commerce Country Chart usage, and jurisdiction determination |
references/compliance-program.md | ECP design (7 elements), enforcement regime (civil/criminal), VSD process, FDPR deep dive, deemed export compliance, and penalty guidelines |
This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in plugins/ear/skills/ear of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Open the folder on GitHubat commit fb9cb7a
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.
Ear next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ear this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 943 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed | 5.5k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~4.6k | Automated safety check: Notes | MIT | |
| Legal Compliance SearchSerein-81/financial_rag | 148 | — | ~1.6k | Automated safety check: Notes | None | |
| Ad Compliance Reviewzh-xx/legal-assistant-skills | 173 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Ca Policy InvestigationSCStelz/security-investigator | 250 | — | ~3.8k | Automated safety check: Pass | MIT |
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
K-Dense-AI/scientific-agent-skills
Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.
Serein-81/financial_rag
Looks up current company registration rules, industry licences and compliance obligations in China through live web search, tailored to the business profile.
zh-xx/legal-assistant-skills
广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
SCStelz/security-investigator
A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy…
yaojingang/yao-geo-skills
A skill your agent uses when Chinese content teams need GEO title candidates, scoring, compliance review, or title-to-article mapping for articles, pages, FAQs, comparisons, and topic hubs.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
Categories
Export Administration Regulations (EAR, 15 CFR Parts 730-774) compliance advisor — ECCN classification across all 10 CCL categories and 5 product groups (A-E), EAR99 determination, jurisdiction…. Ear is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Ear fits situations like: any dual-use export control; CCL classification; BIS compliance question.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ear -a claude-code`. Or copy the skill folder (plugins/ear/skills/ear in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/ear in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ear -a codex`. Or copy the skill folder (plugins/ear/skills/ear in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/ear in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ear -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ear, .gemini/skills/ear, .github/skills/ear and .opencode/skills/ear in your project.
SKILL.md names no scripts, command-line tools or credentials: Ear is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ear is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Ear: HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars), Legal Compliance Search (Serein-81/financial_rag, 148 stars) and Ad Compliance Review (zh-xx/legal-assistant-skills, 173 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 943 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 4, 2026.
Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.