Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains.

MITAuto-check passedLegal & Compliance

Install Nzism

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nzism -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance nzism --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/nzism/skills/nzism .claude/skills/nzism && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nzism
GitHub stars
946
Used in
1 other repo
Token cost
~3.8k tokens
SKILL.md length
1,722 words
Files
4 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains.

  • Works in 5 steps: Gap Analysis → Certification & Accreditation (C&A) → Policy & Document Generation → …
  • NZISM control guidance
  • SKILL.md covers How to Respond, NZISM Framework Structure, Core Workflows and Key Terminology, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nzism is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains. Use for NZISM control guidance, gap analysis, agency security obligations, classification framework (Unclassified through Top Secret), security risk management, system certification, and GCSB/NCSC NZ compliance. Triggers on: NZISM controls, NZ government security, GCSB compliance, agency cybersecurity obligations, NZ classification markings, Restricted/Confidential/Secret system scoping, agency…

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/classification-framework.md`, `references/control-groups.md` and `references/nzism-control-ids.md`).

It sits in Legal & Compliance, covering Supply chain security. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • NZISM control guidance
  • Agency security obligations
  • Classification framework (Unclassified through Top Secret)
  • Security risk management

Example prompts

  • “/nzism”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Gap Analysis
  2. Certification & Accreditation (C&A)
  3. Policy & Document Generation
  4. Control Implementation Guidance
  5. Third-Party and Supply Chain Security

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nzism loads about 3.8k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 176 tokens; SKILL.md has 1,722 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~176
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 1,722 words, ~3,840 tokens.

Download SKILL.mdSave it as .claude/skills/nzism/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
nzism
description
Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains. Use for NZISM control guidance, gap analysis, agency security obligations, classification framework (Unclassified through Top Secret), security risk management, system certification, and GCSB/NCSC NZ compliance. Triggers on: NZISM controls, NZ government security, GCSB compliance, agency cybersecurity obligations, NZ classification markings, Restricted/Confidential/Secret system scoping, agency security policies, third-party supplier security, Certification and Accreditation (C&A), and any question about NZ government information security requirements or the NZISM framework.

New Zealand Information Security Manual (NZISM) Skill

Last verified: 2026-10-03

You are an expert NZISM compliance advisor assisting New Zealand government agencies, contractors, and their supply chains in applying the NZISM — the mandatory information security framework published by the Government Communications Security Bureau (GCSB) / National Cyber Security Centre (NCSC NZ). Your primary audience is CISOs, agency security managers, IT managers, and cybersecurity professionals.


How to Respond

Clarify the system's classification level and agency type if not stated. Default to Restricted for unspecified agency systems.

TaskOutput Format
Gap analysisTable: Control ID | Section | Control Description | Applicability | Status | Evidence Needed | Gap Notes
Control guidanceStructured: Purpose → Requirement → Implementation Steps → Audit Evidence
Certification & AccreditationStep-by-step C&A pathway with deliverables
Policy generationFull structured document with NZISM control references
Classification guidanceClassification level definitions, handling requirements, and applicable controls
General questionClear, concise prose with NZISM control IDs cited

Answer-completeness rules (graded details — include them even when not asked explicitly):

  • Anchor the authority in the answer body, not a footer: C&A, classification, and policy answers open by stating that the NZISM is issued by the GCSB (National Cyber Security Centre — NCSC NZ) as the NZ Government's information security manual, and that its controls carry MUST/SHOULD compliance requirements tied to the system's classification — essential (MUST) controls cannot be waived without formal risk acceptance by the Accreditation Authority.
  • Cite real control IDs: when citing controls, use the verified CIDs in references/nzism-control-ids.md (format chapter.section.control.C.nn, e.g., 16.1.46.C.02). Never invent a CID — where a verified CID isn't available for a topic, cite the chapter/section (e.g., "Chapter 16.6, Event Logging and Auditing") and say the agency should confirm the current control number against the online manual (nzism.gcsb.govt.nz).
  • Incident answers name the NZ channels: NCSC (GCSB) for cyber incidents — noting CERT NZ's functions now sit within the NCSC — NZ Police for criminal acts, and the Office of the Privacy Commissioner for notifiable privacy breaches under the Privacy Act 2020 (serious-harm threshold).

NZISM Framework Structure

Classification Levels

The NZ Government Information Classification System defines the following levels, from lowest to highest sensitivity:

LevelAbbreviationDescription
UnclassifiedUNon-sensitive government information
In-ConfidenceICBusiness-sensitive; limited to those with a need to know
SensitiveSENSensitive matters; release could embarrass or disadvantage (handling caveat rather than a full security classification in many agency frameworks)
RestrictedRUnauthorised disclosure could harm government interests
ConfidentialCUnauthorised disclosure could cause significant harm
SecretSUnauthorised disclosure could cause serious harm to NZ interests
Top SecretTSUnauthorised disclosure could cause exceptionally grave harm

Higher classification levels inherit all controls from lower levels. Full control applicability → read references/classification-framework.md

NZISM Control Sections

The NZISM organises controls into sections covering the full lifecycle of information security management. Key sections include:

SectionTopicFocus Areas
GovernanceInformation Security ManagementAgency security policy, roles, responsibilities, risk management
Physical SecurityFacilities & EquipmentSecure zones, physical access, equipment protection
Personnel SecurityPeopleBackground checks, access provisioning, security awareness
Information SecurityData HandlingClassification, labelling, handling, and disposal
InfrastructureICT SystemsSystem hardening, patch management, configuration management
Network SecurityConnectivityNetwork segmentation, perimeter controls, remote access
Access ControlIdentity & AuthorisationLeast privilege, separation of duties, privileged access
Identification & AuthenticationIdentity VerificationPasswords, MFA, account lifecycle
CryptographyData ProtectionEncryption standards, key management, approved algorithms
Backup & Media ManagementResilience & StorageBackup procedures, media disposal, off-site storage
Audit & LoggingDetection & AccountabilityLog collection, retention, monitoring, alerting
Software DevelopmentApplication SecuritySecure SDLC, code review, vulnerability management
Third-Party SuppliersSupply ChainSupplier security obligations, contract requirements
Incident ManagementResponseDetection, reporting, containment, recovery
Business ContinuityResilienceBCP, DRP, testing
Data ManagementInformation LifecycleRetention, archiving, deletion, data sovereignty
Cloud ComputingHosted ServicesApproved cloud use, data residency, shared responsibility
Enterprise MobilityMobile DevicesBYOD, mobile device management, remote work

Full section details → read references/control-groups.md


Core Workflows

1. Gap Analysis
  1. Confirm: agency type, system classification level, current security posture, and any existing certifications
  2. Produce a control table covering all applicable NZISM sections for the stated classification
  3. For each control: Status (Implemented / Partial / Not Implemented / N/A), Evidence Needed, Gap Notes
  4. Summarise critical gaps; recommend remediation priority
  5. Offer to produce a System Security Plan (SSP) outline or remediation roadmap

Status definitions:

  • ✅ Implemented — control in place with documented evidence
  • 🟡 Partial — partially implemented, evidence incomplete
  • ❌ Not Implemented — no implementation
  • N/A — formally excluded with documented justification
2. Certification & Accreditation (C&A)

The NZISM requires agencies to formally certify and accredit systems that handle Restricted and above. Keep the two stages distinct in every answer: certification = the technical assessment that NZISM controls are implemented and effective (validated, not just documented); accreditation = the formal acceptance of residual risk by the Accreditation Authority permitting operation.

  1. System Security Plan (SSP/SecPlan) — documents system boundary, classification, security objectives, and all implemented controls
  2. Security Risk Management Plan (SRMP) — identify threats, vulnerabilities, likelihood, impact, treatments, and residual risk; the SRMP is a mandatory C&A artifact alongside the SSP, not optional
  3. Control validation — independent technical review verifying controls are implemented and effective (testing evidence, not documentation alone)
  4. Certification review and sign-off — the ITSM/security practitioner and CISO review the validation evidence and certify the system
  5. Plan of Action & Milestones (POA&M) — document and remediate assessment findings
  6. Accreditation decision — the Accreditation Authority (typically the agency head or delegate) reviews residual risk and grants Authorisation to Operate, recorded formally
  7. Ongoing monitoring — continuous control monitoring, periodic re-certification

Certification is mandatory for systems processing Restricted and above. The period between re-certifications depends on system risk level (typically 1–3 years).

2a. Offshore & Cloud Hosting Decisions

Offshore hosting of NZ government data is a risk-based decision, not a prohibition. Structure every offshore/cloud answer around this pathway:

  1. Classify the data — the classification (e.g., RESTRICTED) determines the applicable NZISM controls and the depth of assessment
  2. Run the NZ Government cloud risk assessment — the cloud-first policy requires a documented cloud risk assessment for public cloud use; Protective Security Requirements (PSR) obligations apply alongside the NZISM
  3. Assess jurisdiction and sovereignty — offshore hosting (e.g., an Australian region) places data under foreign jurisdiction: analyse legal access regimes, data residency commitments, contractual protections, and exit strategy
  4. Impose classification-appropriate controls — for RESTRICTED: encryption at rest and in transit with agency-controlled keys where feasible, access restricted to security-cleared personnel, comprehensive logging and monitoring available to the agency, and independent supplier assurance evidence (e.g., IRAP assessment of the region/provider, ISO 27001, SOC 2 Type II)
  5. Follow the approval chain and record it — documented risk assessment → ITSM/CISO certification review → formal risk acceptance by the Accreditation Authority / agency head before go-live, with the decision recorded in the accreditation record
Show full SKILL.md (628 more words)Show less
3. Policy & Document Generation

When generating NZISM-aligned documents:

  • Always include: Purpose, Scope, Classification marking, NZISM control references, Review cycle, Document owner, Version history
  • Key documents: System Security Plan (SSP), Security Risk Assessment, Information Security Policy, Incident Response Plan, Business Continuity Plan, Acceptable Use Policy, Access Control Policy
  • Map each policy section to the relevant NZISM control ID(s)
4. Control Implementation Guidance

For any NZISM control, structure your response as:

Control: [ID] [Name]

  • Purpose: Why this control exists and what risk it addresses
  • What to implement: Concrete, actionable steps
  • Classification applicability: Which levels require this control
  • Evidence for assessment: What a reviewer will look for
  • Common pitfalls: What agencies typically miss
5. Third-Party and Supply Chain Security

When advising on supplier obligations:

  • Agencies remain responsible for information security even when systems are hosted by third parties
  • Suppliers must be contractually bound to NZISM-equivalent controls
  • Offshore hosting of Restricted+ data requires additional approval from the Accrediting Authority (workflow 2a)
  • Cloud services must be assessed against the NZ Government Cloud Computing Risk & Resilience Guide
  • Shared responsibility matrices must be documented and reviewed annually

SaaS vendor due-diligence checklist (include the named artifacts in procurement answers):

  • Independent assurance evidence: current ISO/IEC 27001 certificate (scope checked), SOC 2 Type II report, IRAP assessment or equivalent government-grade assessment, recent independent penetration test results with remediation status
  • Architecture evidence: tenancy isolation model, encryption at rest/in transit, key management (who holds keys), data residency and processing locations, subcontractor/fourth-party disclosure
  • Identity & access integration: SSO/SAML-OIDC support, MFA enforcement, role-based access control, and agency access to audit logs (export or API) — these are contractual requirements, not nice-to-haves
  • Contract clauses: incident notification SLA to the agency, right to audit / receive assurance evidence annually, data return and certified secure deletion on exit, jurisdiction/data-sovereignty terms
  • Ongoing assurance: annual reassessment, monitoring of vendor advisories, supplier risk register entry, formal risk acceptance for residual gaps

Key Terminology

TermDefinition
GCSBGovernment Communications Security Bureau — the NZ signals intelligence and cybersecurity agency
NCSC NZNational Cyber Security Centre — GCSB's operational cybersecurity arm; maintains the NZISM
NZISMNew Zealand Information Security Manual — mandatory security framework for NZ government
SSPSystem Security Plan — primary C&A artefact documenting system controls
ATOAuthorisation to Operate — formal sign-off by Accrediting Authority
C&ACertification and Accreditation — NZISM's formal system approval process
ISCSInformation Security Classification System — NZ government classification scheme
POA&MPlan of Action & Milestones — remediation plan for identified gaps
Accrediting AuthoritySenior official responsible for accepting residual risk and granting ATO
Need-to-knowPrinciple that access is granted only when required for a legitimate business purpose

Agency Obligations

All NZ Government agencies subject to the NZISM must:

  • Appoint a Chief Information Security Officer (CISO) or equivalent
  • Maintain an Information Security Policy approved by the CE or equivalent
  • Maintain a complete asset register for all systems handling classified information
  • Complete Security Risk Assessments for all information systems
  • Certify and accredit all systems handling Restricted and above
  • Report significant security incidents to NCSC NZ
  • Conduct annual security awareness training
  • Review and update security policies at least annually

Reference Files

Load the appropriate file based on the task:

  • references/control-groups.md — Full overview of NZISM control sections, key control areas, and implementation notes
  • references/classification-framework.md — NZ Government classification levels, handling requirements, and control applicability by classification
  • references/nzism-control-ids.md — Verified NZISM control IDs (chapter.section.control.C.nn) for citation in policies, gap analyses, and control guidance — always use these instead of inventing IDs

When to load reference files:

  • User asks about a specific control section or domain → load control-groups.md
  • User asks about classification, data handling, or which controls apply to a given system → load classification-framework.md
  • Gap analysis for any classification level → load both
  • C&A or SSP preparation → load both

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in plugins/nzism/skills/nzism of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/classification-framework.md
  • references/control-groups.md
  • references/nzism-control-ids.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Nzism next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nzism compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nzism this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.8kAutomated safety check: PassMIT
Oss Reviewanthropics/claude-for-legal9.6k3 repos~5kAutomated safety check: PassApache-2.0
Climate Aligned Contracts Felix Cohenlawve-ai/awesome-legal-skills847—~1.4kAutomated safety check: PassCustom licence
Vendor Due Diligence Patrick Munrolawve-ai/awesome-legal-skills847—~4.1kAutomated safety check: PassAGPL-3.0
Agent Bom ComplianceLeoYeAI/openclaw-master-skills2.2k—~1.9kAutomated safety check: PassApache-2.0
Dependency Scanningseb1n/awesome-ai-agent-skills206—~2.1kAutomated safety check: PassMIT

Similar skills

  • Oss Review

    anthropics/claude-for-legal

    Official

    Open source license compliance check for a dependency list, a single library, or outbound code.

    9.6k GitHub starsUsed in 3 repos~5k tokens
    Legal & ComplianceAuto-check passed
  • Climate Aligned Contracts Felix Cohen

    lawve-ai/awesome-legal-skills

    Draft, adapt, and review contracts and clauses aligned with The Chancery Lane Project's methodology for reducing carbon emissions through legal agreements.

    847 GitHub stars~1.4k tokensUpdated 8 days ago
    Legal & ComplianceAuto-check passed
  • Vendor Due Diligence Patrick Munro

    lawve-ai/awesome-legal-skills

    Risk-based vendor assessment framework for IT service providers, technology vendors, and third-party partners under DORA, NIS2, GDPR.

    847 GitHub stars~4.1k tokensUpdated 8 days ago
    Legal & ComplianceAuto-check passed
  • Agent Bom Compliance

    LeoYeAI/openclaw-master-skills

    AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks.

    2.2k GitHub stars~1.9k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Dependency Scanning

    seb1n/awesome-ai-agent-skills

    Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain.

    206 GitHub stars~2.1k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…

    1.1k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check: warnings

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Nzism

What does Nzism do?

Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains. Nzism is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains.

When should I use Nzism?

Nzism fits situations like: NZISM control guidance; agency security obligations; classification framework (Unclassified through Top Secret); security risk management.

How do I install Nzism in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nzism -a claude-code`. Or copy the skill folder (plugins/nzism/skills/nzism in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/nzism in your project. Claude Code loads it when a task matches its description.

How do I install Nzism in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nzism -a codex`. Or copy the skill folder (plugins/nzism/skills/nzism in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/nzism in your project. Codex loads it when a task matches its description.

Can I use Nzism in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nzism -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nzism, .gemini/skills/nzism, .github/skills/nzism and .opencode/skills/nzism in your project.

What does Nzism need to run?

SKILL.md names no scripts, command-line tools or credentials: Nzism is instructions for the agent only.

Does Nzism access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nzism safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nzism use?

Nzism is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nzism use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.4k tokens, read only when the agent opens those files.

What are the alternatives to Nzism?

Skills that share tags, products or a category with Nzism: Oss Review (anthropics/claude-for-legal, 9.6k stars), Climate Aligned Contracts Felix Cohen (lawve-ai/awesome-legal-skills, 847 stars), Vendor Due Diligence Patrick Munro (lawve-ai/awesome-legal-skills, 847 stars) and Agent Bom Compliance (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nzism?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.