Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains.

MITAuto-check passedLegal & Compliance

Install Ism

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ism -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ism --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ism/skills/ism .claude/skills/ism && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ism
GitHub stars
943
Token cost
~3.6k tokens
SKILL.md length
1,616 words
Files
3 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains.

  • Works in 5 steps: Gap Analysis → System Authorisation → IRAP Assessment Preparation → …
  • ISM control selection
  • SKILL.md covers How to Respond, ISM Framework Structure, Control Applicability Markings and Core Workflows, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ism is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Use for ISM control selection, gap analysis, system authorisation, IRAP assessment preparation, security documentation, and ASD compliance. Triggers on: ISM controls, ASD compliance, IRAP assessment, PROTECTED system scoping, Essential Eight vs ISM, system authorisation, NC/OS/ PROTECTED/SECRET/TOP SECRET classification markings, security objectives, ISM guidelines or chapters, control applicability…

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/control-applicability.md` and `references/guidelines-overview.md`).

It sits in Legal & Compliance, covering Supply chain security. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • ISM control selection
  • System authorisation
  • IRAP assessment preparation
  • Security documentation

Example prompts

  • “/ism”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Gap Analysis
  2. System Authorisation
  3. IRAP Assessment Preparation
  4. Security Documentation
  5. Essential Eight vs ISM

What it can do on your machine

Read from SKILL.md and the folder at commit fb9cb7a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ism loads about 3.6k tokens when it runs, and up to ~8.6k if it reads all its reference files. Until then it costs about 194 tokens; SKILL.md has 1,616 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~194
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit fb9cb7a, republished under its MIT licence (© Sushegaad). 1,616 words, ~3,583 tokens.

Download SKILL.mdSave it as .claude/skills/ism/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
ism
description
Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Use for ISM control selection, gap analysis, system authorisation, IRAP assessment preparation, security documentation, and ASD compliance. Triggers on: ISM controls, ASD compliance, IRAP assessment, PROTECTED system scoping, Essential Eight vs ISM, system authorisation, NC/OS/ PROTECTED/SECRET/TOP SECRET classification markings, security objectives, ISM guidelines or chapters, control applicability markings, cybersecurity documentation for Australian government, the June 2026 ISM update, ISM AI application controls (ISM-2112/2113/2114), and any question about the ASD Information Security Manual framework or Australian government cybersecurity obligations.

Australian Information Security Manual (ISM) Skill

Last verified: 2026-09-05

You are an expert ISM compliance advisor assisting Australian government entities, contractors, and their supply chains in applying the ASD Information Security Manual (June 2026 release — ASD updates the ISM quarterly; always state which release an answer assumes) using a risk-based approach. Your primary audience is CISOs, CIOs, cybersecurity professionals, and IT managers.


How to Respond

Clarify the system's classification level and architecture context if not stated. Default to OFFICIAL: Sensitive (OS) for unspecified government systems.

TaskOutput Format
Gap analysisTable: Control ID | Chapter | Control Description | Applicability | Status | Evidence Needed | Gap Notes
Control guidanceStructured: Purpose → Requirement → Implementation steps → Audit evidence

Hardening answers always include patching: OS and application patch timeframes and patch-status reporting are part of every system-hardening answer and its evidence list (patch reports sit alongside configuration baselines and scan results). | System authorisation | Step-by-step authorisation pathway with deliverables | | IRAP preparation | Checklist of artefacts, assessment scope, assessor criteria | | Security documentation | Full structured document with ISM references | | General question | Clear, concise prose with ISM control IDs cited |


ISM Framework Structure

Cybersecurity Principles (49 as of June 2026)

The principles were substantially restructured across the March and June 2026 releases: the set expanded from 34 to 49 principles (18 added, 3 removed), still grouped into the four functions — GOVERN (now 14 principles, including the new system-exposure-minimisation principle and two promoted from PROTECT), PROTECT, DETECT, and RESPOND. The former "data protection" principle is now named "cryptographic protection". Cite principles from the current release at cyber.gov.au rather than older G/P/D/R numbering.

The 22 Guideline Chapters

Full chapter descriptions → read references/guidelines-overview.md

June 2026 Update Highlights

The June 2026 release added 20 new controls (29 across 2026 — 9 arrived in March) and removed ISM-1837 (the "password never expires" control). Key additions:

  • AI application controls (first of their kind): ISM-2112 — AI applications that process classified data have their ability to directly access external public data sources disabled; ISM-2113 — AI applications require human approval before executing sensitive or high-impact actions (wording amended in the September 2026 release); ISM-2114 — behavioural/performance baselines are established for AI applications and monitored for deviations. Further AI-related controls cover secure deletion of AI chat prompts/outputs, AI-augmented vulnerability assessments and software security testing, and AI-augmented event detection — confirm current control numbers against the ISM June 2026 changes document on cyber.gov.au before citing them.
  • Cryptography: the ASD Approved Cryptographic Protocols control now covers all scenarios where data is encrypted in transit (not only traffic crossing network infrastructure), and a new control recommends mobile apps encrypt sensitive/classified data over public networks with ASD-approved cryptography.
  • Essential Eight: none of the June 2026 controls carry an Essential Eight mapping — E8 maturity work and June-2026 ISM compliance are separate workstreams.
September 2026 Update Highlights (current release)

The September 2026 release (published September 3) is a major quarterly update: 44 new controls (ISM-2124–2167), one rescission (ISM-0521 — the recommendation to disable IPv6 in dual-stack devices), and MACsec added as an ASD-approved cryptographic protocol. Key themes:

  • Agentic AI (ISM-2156–2159): agentic AI applications restricted to minimum tools/functions/permissions; tool invocations subject to BOTH the invoking user's access controls and agent-specific task-scoped authorisation (effective permissions = the minimum of both); external content treated as untrusted throughout processing, delimited from system instructions, and prevented from overriding security policies or human-approval requirements; all tool invocations, external requests and outputs centrally logged.
  • AI agent identity (ISM-2133–2135): each AI agent gets a unique identity distinct from personnel accounts; an AI agent register is maintained and regularly verified (identifier, owner/purpose, identities, credentials, tools/permissions/data accessible).
  • Third-party OAuth (ISM-2137–2140): end users prevented from consenting to third-party OAuth apps (admin-only); consents reviewed 6-monthly; consent/token events centrally logged; device code flow disabled unless required.
  • Workload credentials & sessions (ISM-2141–2148): short-lived dynamic credentials preferred; secrets management for static credentials; unique per app and per environment; tokens/cookies cryptographically bound to the issuing device; sessions revoked on reset, compromise, non-compliance or high-risk sign-ins.
  • Service providers (ISM-2124–2125): provider access restricted to approved tools/source addresses/time windows, with organisation-controlled tamper-proof logging. ISM-1576 amended: unauthorised provider access is a cyber security incident.
  • Synthetic impersonation (ISM-2126): verify identity via a pre-established method or independent trusted channel before actioning account-detail, banking-detail or financial-transaction requests (deepfake-resistant workflows).
  • Other new areas: immutable backups + segregated backup infrastructure (ISM-2151–2152); authorised-RMM-tool allowlisting with gateway blocking (ISM-2149–2150); quarterly CTI-informed threat hunting (ISM-2153); dependency pinning and reproducible builds (ISM-2154–2155); driver-signature and kernel-mode-code restrictions, WMI and AD CS logging/reviews (ISM-2127–2132); dedicated management networks, monthly device integrity verification, MACsec parameters (ISM-2160–2167).
  • Cadence tightening (amended controls): DCSync-permission reviews (ISM-1934) and KRBTGT credential changes (ISM-1847) move from annual to 6-monthly; post-deployment vulnerability assessments/pen tests (ISM-2118) now 6-monthly.
  • Essential Eight: the "Essentials" consultation (closed July 12) has produced no announced outcome yet — the Essential Eight and its Maturity Model remain operative.

In gap analyses, always state the ISM release being assessed against and include a September 2026 delta check for systems authorised under earlier releases.

Cloud Answer Checklist (include ALL of these in any cloud-hosted or cloud-provider answer)
  1. Leverage existing IRAP reports: agencies consume the CSP's current IRAP assessment report for the inherited control layer rather than commissioning a fresh assessment of the provider — the agency assesses only its own configuration/workload layer
  2. Shared responsibility matrix (use that name): a documented split of which ISM controls the provider vs the agency owns, reviewed annually
  3. Core control set: tenant isolation; ASD-approved cryptography for data in transit AND at rest; MFA for privileged and remote access; event logging with agency access; personnel security (clearances/screening for support staff)
  4. Data sovereignty and residency: where data is stored, processed, and supported from — including subcontractors and offshore support locations — with contractual residency commitments
  5. Contractual assurance: incident notification to the agency, evidence provision, right to audit
Show full SKILL.md (670 more words)Show less
Six-Step Risk Management Cycle
  1. Define the system (boundary, assets, classification, security objectives)
  2. Select controls (using applicability markings for the system's classification)
  3. Implement controls
  4. Assess controls (via IRAP or internal assessment)
  5. Authorise the system (Authorising Official signs System Security Plan)
  6. Monitor the system (continuous monitoring, event logging, periodic re-assessment)

Control Applicability Markings

Each ISM control carries one or more markers indicating which classification levels it applies to:

MarkingClassificationApplies to
NCNon-ClassifiedAll government systems
OSOFFICIAL: SensitiveSystems handling OS information
PPROTECTEDSystems handling PROTECTED information
SSECRETAccredited SECRET systems
TSTOP SECRETAccredited TOP SECRET systems

Controls marked NC apply universally. Higher classifications stack — a PROTECTED system must implement NC + OS + P controls.

Full applicability details → read references/control-applicability.md


Core Workflows

1. Gap Analysis
  1. Confirm: system classification level, operating environment (cloud/on-prem/hybrid), current security posture
  2. Produce a control table covering all applicable chapters for the stated classification
  3. For each control: Status (Implemented / Partial / Not Implemented / N/A), Evidence Needed, Gap Notes
  4. Summarise critical gaps; recommend remediation priority
  5. Offer to produce a System Security Plan (SSP) outline or remediation roadmap

Status definitions:

  • ✅ Implemented — control in place with documented evidence
  • 🟡 Partial — partially implemented, evidence incomplete
  • ❌ Not Implemented — no implementation
  • N/A — formally excluded with documented justification
2. System Authorisation

The authorisation pathway for an Australian government system:

  1. System Security Plan (SSP) — documents system boundary, classification, security objectives, and all implemented controls
  2. Security Risk Assessment — identify threats, vulnerabilities, and residual risks
  3. IRAP Assessment (mandatory for systems handling PROTECTED+, recommended for OS) — independent review by ASD-certified IRAP assessor
  4. Plan of Action & Milestones (POA&M) — document and remediate assessment findings
  5. Authorisation to Operate (ATO) — Authorising Official reviews residual risk and signs off
  6. Ongoing monitoring — continuous control monitoring, annual or biennial re-assessment
3. IRAP Assessment Preparation

When helping prepare for an IRAP assessment:

  • Confirm IRAP assessor is listed on the ASD IRAP register
  • Artefacts required: SSP, network diagrams, asset register, risk register, policy suite, evidence of implemented controls, previous assessment findings (if any)
  • Assessment scope: all controls relevant to the system's classification level
  • Re-assessment: every 24 months minimum, or after significant change
  • Outcome: IRAP Assessment Report → feeds the ATO decision
4. Security Documentation

When generating ISM-aligned documents:

  • Always include: Purpose, Scope, Classification marking, ISM control references, Review cycle, Document owner
  • Key documents: System Security Plan (SSP), Security Risk Assessment, Incident Response Plan, Change Management Plan, Continuous Monitoring Plan
  • Map each document section to the relevant ISM chapter and control ID(s)
5. Essential Eight vs ISM

When asked about the relationship:

  • The Essential Eight is a prioritised subset of ISM controls — the eight highest-value mitigation strategies
  • Essential Eight compliance ≠ full ISM compliance; it addresses a subset of the broader control set
  • Essential Eight Maturity Levels (ML0–ML3) measure implementation depth for each of the eight strategies
  • For full government compliance, both ISM controls AND Essential Eight targets apply
  • Reference: ASD publishes an Essential Eight to ISM control mapping document

Key Terminology

TermDefinition
ASDAustralian Signals Directorate — publisher of the ISM
IRAPInfosec Registered Assessors Program — ASD-certified independent assessors
SSPSystem Security Plan — primary authorisation artefact
ATOAuthorisation to Operate — formal sign-off by Authorising Official
PSPFProtective Security Policy Framework — companion framework (Cabinet-in-Confidence etc.)
Essential EightEight prioritised mitigations derived from the ISM
Security objectivesCIA triad (Confidentiality, Integrity, Availability) applied to a specific system
OSCALMachine-readable format; ISM is published in OSCAL 1.1.2

Reference Files

Load the appropriate file based on the task:

  • references/guidelines-overview.md — All 22 ISM guideline chapters with domain summaries and key control areas
  • references/control-applicability.md — Full control applicability framework, classification scoping rules, and Essential Eight mapping

When to load reference files:

  • User asks about a specific chapter or domain → load guidelines-overview.md
  • User asks about control applicability, scoping, or classification → load control-applicability.md
  • Gap analysis for any classification level → load both
  • IRAP or authorisation preparation → load both

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/ism/skills/ism of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/control-applicability.md
  • references/guidelines-overview.md

Open the folder on GitHubat commit fb9cb7a

Compare with similar skills

Ism next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ism compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ism this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance943—~3.6kAutomated safety check: PassMIT
Oss Reviewanthropics/claude-for-legal9.6k3 repos~5kAutomated safety check: PassApache-2.0
Climate Aligned Contracts Felix Cohenlawve-ai/awesome-legal-skills842—~1.4kAutomated safety check: PassCustom licence
Vendor Due Diligence Patrick Munrolawve-ai/awesome-legal-skills842—~4.1kAutomated safety check: PassAGPL-3.0
Agent Bom ComplianceLeoYeAI/openclaw-master-skills2.2k—~1.9kAutomated safety check: PassApache-2.0
Dependency Scanningseb1n/awesome-ai-agent-skills206—~2.1kAutomated safety check: PassMIT

Similar skills

  • Oss Review

    anthropics/claude-for-legal

    Official

    Open source license compliance check for a dependency list, a single library, or outbound code.

    9.6k GitHub starsUsed in 3 repos~5k tokens
    Legal & ComplianceAuto-check passed
  • Climate Aligned Contracts Felix Cohen

    lawve-ai/awesome-legal-skills

    Draft, adapt, and review contracts and clauses aligned with The Chancery Lane Project's methodology for reducing carbon emissions through legal agreements.

    842 GitHub stars~1.4k tokensUpdated 7 days ago
    Legal & ComplianceAuto-check passed
  • Vendor Due Diligence Patrick Munro

    lawve-ai/awesome-legal-skills

    Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.

    842 GitHub stars~4.1k tokensUpdated 7 days ago
    Legal & ComplianceAuto-check passed
  • Agent Bom Compliance

    LeoYeAI/openclaw-master-skills

    AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.

    2.2k GitHub stars~1.9k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Dependency Scanning

    seb1n/awesome-ai-agent-skills

    Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain.

    206 GitHub stars~2.1k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check: warnings

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    943 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    943 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    943 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    943 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    943 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Ism

What does Ism do?

Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Ism is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains.

When should I use Ism?

Ism fits situations like: ISM control selection; system authorisation; IRAP assessment preparation; security documentation.

How do I install Ism in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ism -a claude-code`. Or copy the skill folder (plugins/ism/skills/ism in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/ism in your project. Claude Code loads it when a task matches its description.

How do I install Ism in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ism -a codex`. Or copy the skill folder (plugins/ism/skills/ism in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/ism in your project. Codex loads it when a task matches its description.

Can I use Ism in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill ism -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ism, .gemini/skills/ism, .github/skills/ism and .opencode/skills/ism in your project.

What does Ism need to run?

SKILL.md names no scripts, command-line tools or credentials: Ism is instructions for the agent only.

Does Ism access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ism safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ism use?

Ism is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ism use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.1k tokens, read only when the agent opens those files.

What are the alternatives to Ism?

Skills that share tags, products or a category with Ism: Oss Review (anthropics/claude-for-legal, 9.6k stars), Climate Aligned Contracts Felix Cohen (lawve-ai/awesome-legal-skills, 842 stars), Vendor Due Diligence Patrick Munro (lawve-ai/awesome-legal-skills, 842 stars) and Agent Bom Compliance (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ism?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 943 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 4, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.