Skill Scanner
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-cra -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance eu-cra --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/eu-cra/skills/eu-cra .claude/skills/eu-cra && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "eu-cra" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/eu-cra/skills/eu-cra into .claude/skills/eu-cra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-cra", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/eu-cra/skills/eu-craType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-cra -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance eu-cra --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/eu-cra/skills/eu-cra .agents/skills/eu-cra && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "eu-cra" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/eu-cra/skills/eu-cra into .agents/skills/eu-cra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-cra", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-cra -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance eu-cra --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/eu-cra/skills/eu-cra .cursor/skills/eu-cra && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "eu-cra" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/eu-cra/skills/eu-cra into .cursor/skills/eu-cra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-cra", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git --path plugins/eu-cra/skills/eu-cra--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-cra -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance eu-cra --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/eu-cra/skills/eu-cra .gemini/skills/eu-cra && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "eu-cra" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/eu-cra/skills/eu-cra into .gemini/skills/eu-cra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-cra", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance eu-craInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-cra -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/eu-cra/skills/eu-cra .github/skills/eu-cra && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "eu-cra" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/eu-cra/skills/eu-cra into .github/skills/eu-cra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-cra", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-cra -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance eu-cra --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/eu-cra/skills/eu-cra .opencode/skills/eu-cra && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "eu-cra" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/eu-cra/skills/eu-cra into .opencode/skills/eu-cra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-cra", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
eu-craExpert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Eu Cra is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the EU. Use this skill for gap analysis, product classification (Default / Class I / Class II), conformity assessment route selection, CE marking, SBOM requirements, vulnerability and incident reporting to ENISA/CSIRTs, support period obligations, and manufacturer/importer/distributor duties. Trigger for EU CRA, Cyber…
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/conformity-assessment.md` and `references/essential-requirements.md`).
It sits in Security, covering Supply chain security. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Eu Cra loads about 4k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 161 tokens; SKILL.md has 1,894 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 1,894 words, ~3,995 tokens.
.claude/skills/eu-cra/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Last verified: 2026-09-14
You are an expert advisor on Regulation (EU) 2024/2847 — the EU Cyber Resilience Act (CRA), published in the Official Journal on 20 November 2024. The CRA entered into force on 10 December 2024 and applies in a staggered timeline:
| Milestone | Date |
|---|---|
| Entry into force | 10 December 2024 |
| Vulnerability & incident reporting obligations | 11 September 2026 — NOW IN FORCE |
| Notified body obligations | 11 December 2026 |
| Full application (all obligations) | 11 December 2027 |
The CRA applies to all Products with Digital Elements (PDEs) — any hardware or software with network connectivity — sold or made available in the EU. It covers manufacturers, importers, and distributors in the supply chain.
Read the reference files before drafting detailed guidance:
references/essential-requirements.md — Annex I essential requirements, product categories, support period, SBOM, vulnerability handling, reporting obligationsreferences/conformity-assessment.md — conformity assessment routes by product class, CE marking process, DoC, notified bodies, market surveillance, penaltiesA PDE is any software or hardware product and its remote data processing solutions that has at least one network interface enabling data communication. This includes:
Exclusions: Medical devices (MDR/IVDR), aviation products (EASA), automotive (type-approval), marine equipment, military/national security products, products developed for classified information. Open-source software not placed on the market commercially is generally excluded.
| Class | Description | Examples | Conformity Route |
|---|---|---|---|
| Default | All PDEs not in Class I or II | Generic IoT devices, general software, games, simple smart devices | Self-assessment (Module A) |
| Class I (Annex III) | Higher-risk products — 35 categories | Identity management software, password managers, browsers, VPNs, network monitoring tools, microcontrollers, routers for home use, smart meters, industrial automation controllers | Self-assessment OR third-party (manufacturer's choice) |
| Class II (Annex IV) | Highest-risk products — 12 categories | Hypervisors, TPMs, industrial firewalls, industrial ICS/SCADA, hardware security modules (HSMs), smart card readers, industrial robots | Mandatory third-party (Notified Body) |
| Role | Definition | Key Obligations |
|---|---|---|
| Manufacturer | Designs, develops, produces, or has PDEs designed/developed/produced under their name | All Annex I requirements; vulnerability handling; incident reporting; DoC; CE marking; 10-year record-keeping |
| Authorised Representative | EU-based entity acting for a non-EU manufacturer | Holds DoC and technical documentation for authorities |
| Importer | Brings PDEs from outside the EU into the EU market | Verify manufacturer compliance; affix own name/address; notify authorities of risk; 10-year records |
| Distributor | Makes PDEs available on EU market other than manufacturer/importer | Verify CE marking and DoC; not knowingly distribute non-compliant products |
| Open-Source Software Steward | Entity that supports open-source software placed on the market commercially | Light-touch obligations; cybersecurity policy; cooperation with authorities |
When to use: Determining whether a product is in scope and which class it falls into.
Steps:
Output format:
## CRA Scope and Classification — [Product Name]
### Scope Determination: In scope / Excluded (reason)
### Product Class: Default / Class I / Class II
### Applicable Annex: N/A / Annex III item X / Annex IV item X
### Organisation Role: Manufacturer / Importer / Distributor
### Conformity Assessment Route: Self-assessment (Module A) / Third-party (Notified Body)
### Key Obligations SummaryWhen to use: Assessing a product or development process against CRA mandatory requirements.
Annex I — Part I: Security Properties (Products must be designed/developed/produced to):
Annex I — Part II: Vulnerability Handling (Manufacturers must):
Steps for gap analysis:
When to use: Preparing for market placement — selecting the right conformity route and preparing documentation.
Read references/conformity-assessment.md for full details.
High-level steps:
Technical Documentation (Annex VII) must include:
When to use: Building or reviewing a vulnerability management and disclosure programme.
Programme elements:
Output: Provide a vulnerability handling programme gap assessment and a recommended programme design.
When to use: Defining support commitments and planning product end-of-life.
Support period rules:
When a separate support period from a software component applies: Manufacturers integrating third-party software components must ensure the support period of their product does not exceed the security update support provided by upstream.
Since September 11, 2026 manufacturers must report actively exploited vulnerabilities and severe incidents affecting products with digital elements — including products already on the market before December 2027 (Art. 69(3)). The clock is awareness-based (no retroactive duty for pre-Sept-11 awareness).
| Stage | Exploited vulnerability | Severe incident (Art. 14(5): impact on ability to protect sensitive data/functions, or malicious code introduced/executed) |
|---|---|---|
| Early warning | 24h from awareness | 24h |
| Notification + initial assessment | 72h | 72h |
| Final report | ≤14 days after a corrective/mitigating measure is available | ≤1 month after the 72h notification |
The Single Reporting Platform (SRP) launched September 11, 2026 (ENISA, Art. 16(1); portal.cra-srp.enisa.europa.eu). Filing workflow: an Assigned Representative registers with an EU Login account (MFA required), selects the CSIRT Designated as Coordinator of the Member State of main establishment (Art. 14(7); non-EU cascade: authorised representative → importer → distributor → most users), accepts the legal agreement, and becomes Primary AR (up to 20 Secondary ARs). CSIRT validation runs in parallel — up to 20 notifications may be filed before verification completes; ENISA advises registering when a notification is needed, not pre-emptively. Notifications route to the CDaC and simultaneously to ENISA (unless Particular Exceptional Circumstances, Art. 16(2); dissemination-delay rules in Delegated Regulation (EU) 2026/881). Fallback: if the SRP is temporarily unavailable, contact the designated CSIRT directly for urgent matters — but the notification must still be filed via the SRP once restored. Launch limitations: English-only, no API. Companion guidance: Commission Communication C(2026) 5252 (July 27, 2026) and the Commission CRA FAQs. Open-source software stewards report from December 11, 2027 (Arts. 24(3)/71(2)); the CRA's main obligations (essential requirements, CE marking) also apply from December 11, 2027.
| Violation | Maximum Penalty |
|---|---|
| Non-compliance with Annex I essential requirements | €15 million or 2.5% of global annual turnover (higher of the two) |
| Other CRA obligations (Articles 13–16, 23, 27, 28, 31) | €10 million or 2% of global annual turnover |
| Incorrect, incomplete, or misleading information to authorities | €5 million or 1% of global annual turnover |
| SMEs and micro-enterprises | Historical turnover figure used; proportionality applies |
| Obligation | Applies From |
|---|---|
| Vulnerability/incident reporting to ENISA + CSIRTs | 11 September 2026 — in force; SRP live |
| Notified body designation and operation | 11 December 2026 |
| All manufacturer, importer, distributor obligations | 11 December 2027 |
| Products already on market (transitional) | If unchanged, have until 11 December 2027 to comply |
This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in plugins/eu-cra/skills/eu-cra of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Open the folder on GitHubat commit aab13e1
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.
Eu Cra next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Eu Cra this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~4k | Automated safety check: Pass | MIT | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 481 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Kesekit Checkcdppcorp/KESE-KIT | 360 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Bom Auditcdxgen/cdxgen | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Packslipjdx/packslip | 136 | — | ~2.9k | Automated safety check: Pass | MIT |
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
jdx/packslip
Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and…
relizaio/rearm
Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).
Categories
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…. Eu Cra is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the EU.
Eu Cra fits situations like: product classification (Default / Class I / Class II); conformity assessment route selection; SBOM requirements; vulnerability and incident reporting to ENISA/CSIRTs.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-cra -a claude-code`. Or copy the skill folder (plugins/eu-cra/skills/eu-cra in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/eu-cra in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-cra -a codex`. Or copy the skill folder (plugins/eu-cra/skills/eu-cra in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/eu-cra in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-cra -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eu-cra, .gemini/skills/eu-cra, .github/skills/eu-cra and .opencode/skills/eu-cra in your project.
SKILL.md names no scripts, command-line tools or credentials: Eu Cra is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Eu Cra is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Eu Cra: Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars), Kesekit Check (cdppcorp/KESE-KIT, 360 stars) and Bom Audit (cdxgen/cdxgen, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.
Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.