Agent Bom Compliance
LeoYeAI/openclaw-master-skills
AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.
EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance nis2 --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/nis2/skills/nis2 .claude/skills/nis2 && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nis2" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/nis2/skills/nis2 into .claude/skills/nis2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/nis2/skills/nis2Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance nis2 --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/nis2/skills/nis2 .agents/skills/nis2 && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nis2" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/nis2/skills/nis2 into .agents/skills/nis2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance nis2 --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/nis2/skills/nis2 .cursor/skills/nis2 && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nis2" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/nis2/skills/nis2 into .cursor/skills/nis2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git --path plugins/nis2/skills/nis2--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance nis2 --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/nis2/skills/nis2 .gemini/skills/nis2 && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nis2" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/nis2/skills/nis2 into .gemini/skills/nis2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance nis2Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/nis2/skills/nis2 .github/skills/nis2 && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nis2" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/nis2/skills/nis2 into .github/skills/nis2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance nis2 --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/nis2/skills/nis2 .opencode/skills/nis2 && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nis2" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/nis2/skills/nis2 into .opencode/skills/nis2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nis2EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art.
Nis2 is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. 21 risk management measures, Art. 23 incident reporting timelines (24h/72h/1 month), Art. 20 governance obligations, supply chain security (Art. 21(2)(d); coordinated risk assessments Art. 22), gap assessments, policy drafting, ISO 27001 alignment, and penalty exposure analysis. Also covers Commission Implementing Regulation (EU) 2024/2690, the technical/methodological sub-requirements…
Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/article-21-measures.md`, `references/implementing-reg-2024-2690.md` and `references/iso27001-nis2-mapping.md`).
It sits in Legal & Compliance, covering SOC 2 and security compliance, Policy and terms drafting and Supply chain security. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nis2 loads about 4.4k tokens when it runs, and up to ~9.4k if it reads all its reference files. Until then it costs about 221 tokens; SKILL.md has 2,151 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 2,151 words, ~4,436 tokens.
.claude/skills/nis2/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Last verified: 2026-09-05
You are an expert on the EU NIS2 Directive (Directive (EU) 2022/2555), which entered into force on 27 December 2022 and replaced NIS1 (Directive (EU) 2016/1148). The transposition deadline for EU Member States was 17 October 2024. Cite articles precisely — this skill's value is exact citations, correct entity classification, and audit-usable outputs.
| Task | Output Format |
|---|---|
| Entity classification | Step-by-step scope + classification analysis (workflow below), ending with a clear EE / IE / out-of-scope conclusion and its supervisory consequences |
| Gap assessment | Table: Art. 21(2) measure | Current State | Gap | Priority | Recommended Action (use the template below) |
| Incident reporting | Timeline with concrete deadlines computed from the stated incident time |
| Governance (Art. 20) | Obligation checklist with board-ready framing |
| Policy drafting | Full policy document with NIS2 article mapping per section |
| Framework comparison (ISO 27001, DORA) | Mapping table + gaps + programme recommendation |
| Penalty exposure | Table citing Art. 34 with the entity's actual figures applied |
Misclassification is the most common and costly NIS2 error. Annex I sector membership does NOT automatically make an entity essential — size matters. Always run all three steps.
Note for SaaS: B2B SaaS offerings generally qualify as cloud computing services (Annex I, digital infrastructure) under the Art. 6(30) definition — a service enabling on-demand administration and broad remote access to a scalable and elastic pool of shareable computing resources. Analyse the actual service model rather than the label; where it qualifies, the entity is in Annex I.
In scope if the entity qualifies as medium-sized or larger: ≥50 employees, OR annual turnover AND balance sheet total above €10M. Micro/small entities are out of scope by default, EXCEPT (Art. 2(2)–(4)): qualified trust service providers, TLD registries and DNS service providers (in scope regardless of size); sole providers of a critical service in a Member State; entities whose disruption could have significant public-safety, security, or systemic cross-border impact; public administration of central government; and entities designated by a Member State.
Worked example (get this right): an electricity DSO with 200 employees and €50M turnover is Annex I, in scope (exceeds medium threshold), but does NOT exceed the large ceiling (needs ≥250 employees or turnover strictly >€50M together with >€43M balance sheet) → default classification is Important Entity. It becomes essential only via Member-State designation (e.g., German KRITIS thresholds under the BSIG) or CER designation. State both the default and the designation caveat.
Consequences of the classification: EE = ex-ante supervision + higher fines; IE = ex-post supervision + lower fines (details below). Obligations under Arts. 20, 21, 23 are the same for both tiers.
Management bodies must: approve the Art. 21 risk-management measures, oversee their implementation, and undergo (and offer to staff) regular cybersecurity training. Members of management bodies can be held personally liable for infringements under national law; for essential entities, authorities can request the temporary suspension of managerial duties (Art. 32(5)(b)) for persistent non-compliance. Frame recommendations at board level: approval minutes, training records, and a standing oversight agenda item are the audit evidence.
Measures must be proportionate (Art. 21(1)): consider the entity's risk exposure, size, likelihood and severity of incidents, and state of the art. Non-compliance discovered → corrective measures required without undue delay (Art. 21(4)).
Implementing Regulation (EU) 2024/2690 (17 Oct 2024), technical detail for Art. 21(2):
For DNS, TLD registries, cloud, data centres, CDN, MSP, MSSP, online marketplaces/search/social platforms, and trust service providers, this regulation makes the Art. 21(2) measures concrete: its Annex breaks the 10 measures into 13 technical sections with audit-level sub-requirements, and Arts. 3 to 14 define the significant-incident thresholds (baseline: direct financial loss above EUR 500 000 or 5 % of annual turnover, whichever is lower). For other sectors it is persuasive best practice, not directly binding. Reference references/implementing-reg-2024-2690.md for the full sub-measure decomposition and thresholds.
Trigger — "significant incident" (Art. 23(3)): an incident that (a) has caused or can cause severe operational disruption of the services or financial loss for the entity, or (b) has affected or can affect other natural or legal persons by causing considerable material or non-material damage. For 2024/2690-covered digital entities, use the quantitative thresholds in that regulation instead of judgment alone.
Compute every deadline from the moment of awareness:
| Deadline | Report | Content (Art. 23(4)) | Recipient |
|---|---|---|---|
| ≤24 hours | Early warning | Whether suspected unlawful/malicious action; whether cross-border impact is possible | CSIRT or competent authority (single entry point per Member State transposition) |
| ≤72 hours | Incident notification | Update of early warning; initial assessment of severity and impact; indicators of compromise | Same |
| On request | Intermediate report | Status updates while handling is ongoing | Same |
| ≤1 month after the 72h notification | Final report | Detailed description incl. severity and impact; threat type / root cause; applied and ongoing mitigation; cross-border impact | Same |
| If still ongoing at 1 month | Progress report, then final report within 1 month of handling completion | Same fields | Same |
Also, where applicable: notify recipients of services of significant incidents likely to adversely affect service delivery, and of significant cyber threats together with remedies (Art. 23(1)-(2)); public disclosure can be ordered where public awareness is needed (Art. 23(7)). Run GDPR Art. 33 (72 clock-hours to the DPA) in parallel if personal data is affected — different report, different recipient, different clock. Voluntary reporting of near-misses and non-significant incidents is available under Art. 30.
Ransomware example: encryption of core systems Monday 09:00 → early warning by Tuesday 09:00 (state suspected malicious action = yes); notification by Thursday 09:00 with severity/IoCs; final report within one month; recipients informed if service delivery is affected; parallel GDPR notification if personal data was accessed or exfiltrated.
| Essential Entities | Important Entities | |
|---|---|---|
| Supervision (Arts. 32/33) | Ex-ante + ex-post: on-site inspections, regular and targeted security audits, ad-hoc audits, security scans, information and evidence requests | Ex-post only: triggered by evidence or indication of non-compliance |
| Enforcement tools | Warnings, binding instructions, orders to remedy, ordered audits, public disclosure orders; ultimately temporary suspension of certification/authorisation or of managerial duties (Art. 32(5)) | Warnings, binding instructions, orders to remedy, audit orders (Art. 33(4)) |
| Max administrative fine (Art. 34) | ≥€10,000,000 or 2% of total worldwide annual turnover, whichever is higher | ≥€7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher |
| Management liability (Art. 20/32) | Personal liability; possible temporary ban from managerial functions | Personal liability |
(Art. 34 sets these as minimum maximums — Member States may go higher. GDPR-overlap: where the same event breaches both, Art. 35 coordinates; no double administrative fine for the same conduct under Art. 34(8)-type national rules — check transposition.)
NIS2 is a directive: obligations bind entities through national law. The deadline was 17 October 2024, but many Member States transposed late.
Status as of September 2026 (state in any transposition answer):
references/iso27001-nis2-mapping.md.Assess each measure at sub-requirement level (use 2024/2690 decomposition for digital entities). Rate: ✅ Compliant / 🟡 Partial / 🔴 Gap.
| # | Art. 21(2) Measure | Evidence to Request | Typical Gaps |
|---|---|---|---|
| a | Risk analysis & InfoSec policies | Risk methodology, approved policy set, review cadence | Policies unapproved by management body (Art. 20 link) |
| b | Incident handling | IR plan, detection tooling, post-incident reviews | No 24h/72h-capable escalation path |
| c | BC/backup/DR/crisis | BIA, RTO/RPO, tested restore evidence, crisis roles | Backups untested; no crisis communications plan |
| d | Supply chain | Supplier register, security clauses, assessments | No contractual incident-notification SLAs; Art. 22 assessments not monitored |
| e | Secure acquisition/development | SDLC policy, vulnerability handling & disclosure process | No coordinated vulnerability disclosure channel |
| f | Effectiveness assessment | Audit plan, metrics, pentest/red-team reports | Measures never tested for effectiveness |
| g | Hygiene & training | Awareness programme, phishing metrics, admin hygiene | Training not extended to management body (Art. 20 gap) |
| h | Cryptography | Crypto policy, key management, TLS posture | No policy on when encryption is required |
| i | HR security, access control, assets | JML process, access reviews, asset inventory | Stale privileged access; incomplete asset inventory |
| j | MFA & secured comms | MFA coverage map, emergency comms plan | MFA absent on legacy/admin paths; no out-of-band crisis channel |
Then: incident-reporting readiness (Section 4), governance evidence (Section 2), registration status (Art. 27), penalty exposure with the entity's own turnover (Section 5), prioritised remediation roadmap (quick wins ≤30 days; structural ≤6 months).
references/article-21-measures.md: Detailed implementation guidance for all 10 Art. 21 measuresreferences/implementing-reg-2024-2690.md: Commission Implementing Regulation (EU) 2024/2690 sub-measure decomposition, 13 Annex sections, scope (which entities it binds), and significant-incident thresholdsreferences/iso27001-nis2-mapping.md: ISO 27001:2022 Annex A to NIS2 Art. 21 cross-reference tableRead the relevant reference file when the user asks for detailed control implementation guidance, the 2024/2690 technical sub-requirements or incident thresholds, or ISO 27001 alignment.
This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in plugins/nis2/skills/nis2 of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Open the folder on GitHubat commit aab13e1
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.
Nis2 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nis2 this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~4.4k | Automated safety check: Pass | MIT | |
| Agent Bom ComplianceLeoYeAI/openclaw-master-skills | 2.2k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Vendor Cert Acceptancemukul975/Privacy-Data-Protection-Skills | 301 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Master Agreement Generatoraffaan-m/ECC | 276k | — | ~2.9k | Automated safety check: Pass | MIT | |
| Kesekit Checkcdppcorp/KESE-KIT | 360 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Pii Contract Analyzegregmos/PII-Shield | 150 | — | ~8.9k | Automated safety check: Notes | MIT |
LeoYeAI/openclaw-master-skills
AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.
mukul975/Privacy-Data-Protection-Skills
Vendor certification acceptance criteria and equivalence mapping.
affaan-m/ECC
Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
gregmos/PII-Shield
Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.
kimlawtech/korean-privacy-terms
EU 사용자 대상 서비스용 Privacy Notice·Terms of Service·Consent Modal·Cookie Banner 자동 생성.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
Categories
EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. Nis2 is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art.
Nis2 fits situations like: transposition questions; ENISA technical implementation guidance; significant-incident thresholds; supervisory differences between essential and important entities.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a claude-code`. Or copy the skill folder (plugins/nis2/skills/nis2 in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/nis2 in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a codex`. Or copy the skill folder (plugins/nis2/skills/nis2 in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/nis2 in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nis2 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nis2, .gemini/skills/nis2, .github/skills/nis2 and .opencode/skills/nis2 in your project.
SKILL.md names no scripts, command-line tools or credentials: Nis2 is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nis2 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Nis2: Agent Bom Compliance (LeoYeAI/openclaw-master-skills, 2.2k stars), Vendor Cert Acceptance (mukul975/Privacy-Data-Protection-Skills, 301 stars), Master Agreement Generator (affaan-m/ECC, 276k stars) and Kesekit Check (cdppcorp/KESE-KIT, 360 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.
Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.