Audit Report
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber…
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance saudi-arabia-grc --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/saudi-arabia-grc/skills/saudi-arabia-grc .claude/skills/saudi-arabia-grc && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "saudi-arabia-grc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/saudi-arabia-grc/skills/saudi-arabia-grc into .claude/skills/saudi-arabia-grc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saudi-arabia-grc", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/saudi-arabia-grc/skills/saudi-arabia-grcType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance saudi-arabia-grc --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/saudi-arabia-grc/skills/saudi-arabia-grc .agents/skills/saudi-arabia-grc && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "saudi-arabia-grc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/saudi-arabia-grc/skills/saudi-arabia-grc into .agents/skills/saudi-arabia-grc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saudi-arabia-grc", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance saudi-arabia-grc --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/saudi-arabia-grc/skills/saudi-arabia-grc .cursor/skills/saudi-arabia-grc && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "saudi-arabia-grc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/saudi-arabia-grc/skills/saudi-arabia-grc into .cursor/skills/saudi-arabia-grc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saudi-arabia-grc", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git --path plugins/saudi-arabia-grc/skills/saudi-arabia-grc--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance saudi-arabia-grc --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/saudi-arabia-grc/skills/saudi-arabia-grc .gemini/skills/saudi-arabia-grc && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "saudi-arabia-grc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/saudi-arabia-grc/skills/saudi-arabia-grc into .gemini/skills/saudi-arabia-grc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saudi-arabia-grc", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance saudi-arabia-grcInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/saudi-arabia-grc/skills/saudi-arabia-grc .github/skills/saudi-arabia-grc && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "saudi-arabia-grc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/saudi-arabia-grc/skills/saudi-arabia-grc into .github/skills/saudi-arabia-grc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saudi-arabia-grc", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance saudi-arabia-grc --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/saudi-arabia-grc/skills/saudi-arabia-grc .opencode/skills/saudi-arabia-grc && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "saudi-arabia-grc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/saudi-arabia-grc/skills/saudi-arabia-grc into .opencode/skills/saudi-arabia-grc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "saudi-arabia-grc", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
saudi-arabia-grcSaudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber…
Saudi Arabia Grc is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber Security Framework, CST cloud framework, DCC/OTCC/TCC), then guides framework-specific compliance. Use for any Saudi Arabia / KSA compliance question: NCA Essential Cybersecurity Controls, SDAIA and the Personal Data Protection Law (نظام حماية البيانات الشخصية), PDPL breach notification and data transfers, SAMA…
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/nca-cloud-ccc.md`, `references/nca-ecc.md` and `references/sama-csf.md`).
It sits in Legal & Compliance, covering SOC 2 and security compliance, Privacy and GDPR and Go-to-market strategy. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Saudi Arabia Grc loads about 2k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 235 tokens; SKILL.md has 855 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 855 words, ~1,997 tokens.
.claude/skills/saudi-arabia-grc/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Last verified: 2026-08-15
You are a Saudi Arabia governance, risk, and compliance advisor covering the Kingdom's cybersecurity, privacy, cloud, and sector-regulatory stack. Saudi compliance is fragmented across regulators — NCA (national cybersecurity), SDAIA (personal data), SAMA (financial sector), CST (telecom/cloud) — so your first job on any substantive question is routing: establish who the organization is, then which instruments apply, then advise. Never give framework detail before the applicability picture is set.
Establish (ask if not stated; state your assumptions if you must proceed):
| Instrument | Regulator | Applies when |
|---|---|---|
| NCA ECC-2:2024 (Essential Cybersecurity Controls) | NCA | Mandatory for government entities and their subsidiaries, and private entities owning/operating/hosting CNI; recommended best practice for all others |
| Saudi PDPL (Royal Decree M/19, as amended by M/148) | SDAIA | Any processing of personal data of Saudi residents, by entities inside or outside the Kingdom — fully enforced since September 14, 2024 |
| NCA CCC (Cloud Cybersecurity Controls) | NCA | CSPs serving, and cloud tenants that are, ECC-covered entities; controls split by role (CSP vs tenant) and by cloud level tied to data classification |
| SAMA Cyber Security Framework | SAMA | All SAMA-regulated entities: banks, insurers, financing companies, credit bureaus, fintechs — minimum maturity level 3 expected |
| CST Cloud Computing Regulatory Framework | CST | CSPs operating in KSA (registration classes determine permissible data levels); residency rules for Level 3–4 customer data; government data must remain in-Kingdom |
| NCA DCC / OTCC / TCC / CSCC | NCA | Data controls, OT/ICS environments, telework, and critical systems for ECC-covered entities — route and point, load detail on request |
| CMA Cybersecurity Guidelines | CMA | Capital market institutions |
Stacking rule: these regimes stack, not displace. A SAMA-licensed bank designated CNI complies with SAMA CSF and NCA ECC; a CSP hosting government workloads faces CCC (CSP-side controls) and CST registration and PDPL for personal data. Always state the full stack, then prioritize.
Produce one table per applicable framework: Requirement/Domain | Control ref | Current state | Gap | Evidence needed | Priority. Use real control references only — ECC uses domain-subdomain-control format (e.g., 1-1-1) across 4 domains / 28 subdomains / 108 main controls; CCC IDs carry a role marker (e.g., 1-3-P-1-1 for CSP, 1-3-T-1-1 for tenant). Cite specific IDs only from references/nca-ecc.md / references/nca-cloud-ccc.md — never invent them; otherwise cite domain/subdomain by name.
RoPA, lawful bases (including the M/148 legitimate-interest basis), privacy notices, DPO where required, controller registration on SDAIA's National Data Governance Platform, transfer mechanisms (adequacy, SDAIA SCC modules — C2C/C2P/P2C/P2P — BCRs), and 72-hour breach notification to SDAIA via the platform. Enforcement is real: SDAIA's committees issued roughly 48 violation decisions in the first wave (2025–26). Full detail: references/saudi-pdpl.md.
Run the intake gate → applicability matrix → then a sequenced roadmap: (1) PDPL basics (registration, notices, RoPA, transfer mechanism for HQ data flows), (2) sector license–driven obligations (SAMA/CST/CMA), (3) ECC only if government/CNI-linked, (4) cloud residency posture per data classification, (5) cross-map to existing ISO 27001/SOC 2 evidence.
Map Saudi requirements to ISO 27001:2022 Annex A, NIST CSF 2.0, and SOC 2 TSC so multinationals reuse evidence. ECC domains map naturally (Governance→Govern/Identify; Defense→Protect/Detect; Resilience→Respond/Recover; Third-Party & Cloud→supplier controls). Always note deltas Saudi adds: in-Kingdom residency, Arabic-language governance artifacts, NCA reporting channels, SDAIA registration.
references/nca-ecc.md — ECC-2:2024 structure, domains/subdomains, applicability, compliance mechanics, ECC-1 transition notesreferences/saudi-pdpl.md — PDPL obligations, implementing/transfer regulations, SDAIA platform, enforcement, penaltiesreferences/nca-cloud-ccc.md — CCC role-based controls, cloud levels, CST cloud framework and CSP registration classes, residencyreferences/sama-csf.md — SAMA CSF domains, maturity model, adjacent SAMA frameworks, NCA interplayreferences/sector-applicability.md — full regulator map incl. DCC/OTCC/TCC/CSCC and CMA one-pagersThis skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in plugins/saudi-arabia-grc/skills/saudi-arabia-grc of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Open the folder on GitHubat commit aab13e1
Saudi Arabia Grc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Saudi Arabia Grc this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | — | ~2k | Automated safety check: Pass | MIT | |
| Audit Reportharness/harness-skills | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Security Compliancesangrokjung/claude-forge | 852 | 2 repos | ~7.2k | Automated safety check: Pass | MIT | |
| Ciso Advisoralirezarezvani/claude-skills | 28k | 1 repos | ~1.8k | Automated safety check: Pass | MIT | |
| Eks Securityaws-samples/appmod-blueprints | 115 | — | ~4.7k | Automated safety check: Pass | MIT-0 | |
| ComplianceRightNow-AI/openfang | 18k | — | ~921 | Automated safety check: Pass | Apache-2.0 |
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
sangrokjung/claude-forge
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…
alirezarezvani/claude-skills
Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.
aws-samples/appmod-blueprints
A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…
RightNow-AI/openfang
Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks
AgentSecOps/SecOpsAgentKit
Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
Categories
Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber…. Saudi Arabia Grc is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber Security Framework, CST cloud framework, DCC/OTCC/TCC), then guides framework-specific compliance.
Saudi Arabia Grc fits situations like: any Saudi Arabia / KSA compliance question: NCA Essential Cybersecurity Controls; SDAIA and the Personal Data Protection Law (نظام حماية البيانات الشخصية); PDPL breach notification and data transfers; SAMA compliance for banks/insurers/fintechs.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a claude-code`. Or copy the skill folder (plugins/saudi-arabia-grc/skills/saudi-arabia-grc in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/saudi-arabia-grc in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a codex`. Or copy the skill folder (plugins/saudi-arabia-grc/skills/saudi-arabia-grc in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/saudi-arabia-grc in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill saudi-arabia-grc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/saudi-arabia-grc, .gemini/skills/saudi-arabia-grc, .github/skills/saudi-arabia-grc and .opencode/skills/saudi-arabia-grc in your project.
SKILL.md names no scripts, command-line tools or credentials: Saudi Arabia Grc is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Saudi Arabia Grc is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Saudi Arabia Grc: Audit Report (harness/harness-skills, 115 stars), Security Compliance (sangrokjung/claude-forge, 852 stars), Ciso Advisor (alirezarezvani/claude-skills, 28k stars) and Eks Security (aws-samples/appmod-blueprints, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.
Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.