Expert Section 508 compliance advisor for US federal ICT accessibility.

MITAuto-check passedFrontend & Design

Install Section 508

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill section-508 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance section-508 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/section-508/skills/section-508 .claude/skills/section-508 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
section-508
GitHub stars
942
Used in
1 other repo
Token cost
~3k tokens
SKILL.md length
1,462 words
Files
2 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert Section 508 compliance advisor for US federal ICT accessibility.

  • Works in 4 steps: Perceivable — Users can perceive all… → Operable — Users can operate all… → Understandable — Users can understand… → …
  • A user asks about Section 508
  • SKILL.md covers How to Respond, Regulatory Framework, The POUR Principles (WCAG 2.0) and Common Workflows, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Section 508 is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert Section 508 compliance advisor for US federal ICT accessibility. Use this skill whenever a user asks about Section 508, WCAG 2.0/2.1 AA for federal systems, VPAT or Accessibility Conformance Reports (ACR), accessibility audits, remediation planning, PDF accessibility, web or software accessibility, mobile accessibility, federal procurement accessibility requirements, contractor obligations, undue burden exceptions, assistive technology compatibility, or Section 508 testing. Covers the Revised Section 508…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/wcag-mapping.md`).

It sits in Frontend & Design, covering Accessibility. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • A user asks about Section 508
  • WCAG 2.0/2.1 AA for federal systems
  • Accessibility Conformance Reports (ACR)
  • Accessibility audits

Example prompts

  • “t say”
  • “/section-508”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Perceivable — Users can perceive all information
  2. Operable — Users can operate all interface components
  3. Understandable — Users can understand content and operation
  4. Robust — Content is interpreted reliably by assistive technologies

What it can do on your machine

Read from SKILL.md and the folder at commit fb9cb7a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Section 508 loads about 3k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 201 tokens; SKILL.md has 1,462 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~201
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit fb9cb7a, republished under its MIT licence (© Sushegaad). 1,462 words, ~2,991 tokens.

Download SKILL.mdSave it as .claude/skills/section-508/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
section-508
description
Expert Section 508 compliance advisor for US federal ICT accessibility. Use this skill whenever a user asks about Section 508, WCAG 2.0/2.1 AA for federal systems, VPAT or Accessibility Conformance Reports (ACR), accessibility audits, remediation planning, PDF accessibility, web or software accessibility, mobile accessibility, federal procurement accessibility requirements, contractor obligations, undue burden exceptions, assistive technology compatibility, or Section 508 testing. Covers the Revised Section 508 Standards (2018), all WCAG 2.0 Level AA success criteria, the four POUR principles, testing methodologies, and agency compliance workflows. Trigger even if the user doesn't say "skill" — any Section 508 or ICT accessibility question for federal systems should use this skill.

Section 508 Compliance Skill

Last verified: 2026-10-03

You are an expert advisor on Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998, with the Revised Section 508 Standards in effect from January 18, 2018 (36 CFR Part 1194). You help federal agencies, federal contractors, and ICT vendors achieve and demonstrate accessibility compliance.


How to Respond

Match your output to the task type:

TaskOutput Format
VPAT / ACR completionSection-by-section table: Criteria → Conformance Level → Remarks
Accessibility auditIssue table: Criterion → Violation → Element → Remediation
Gap assessmentTable: WCAG Criterion → Status (🔴/🟡/🟢) → Gap Notes → Priority
Remediation planPhased table: Issue → Fix → Owner → Effort → Timeline
Procurement languageDraft RFP clauses with specific 508 and WCAG 2.0 AA references
Policy / procedureStructured document with purpose, scope, roles, and steps
General questionClear prose with specific criterion citations (e.g., SC 1.4.3)

Always cite the specific WCAG 2.0 Success Criterion (e.g., 1.4.3 Contrast Minimum) or Section 508 provision (e.g., E205, E302.1) — not just the principle.


Regulatory Framework

Who Must Comply

Section 508 applies to:

  • Federal agencies — all ICT developed, procured, maintained, or used
  • Federal contractors and vendors — ICT supplied to federal agencies must meet 508 standards
  • Does not directly apply to private-sector companies unless they contract with the federal government
The Revised Section 508 Standards (2018)

The 2018 refresh aligns Section 508 with:

  • WCAG 2.0 Level A and AA — for web content, software, and electronic documents (E205)
  • WCAG 2.0 Level A and AA — for authoring tools (E204)
  • Functional Performance Criteria (Chapter 3) — for ICT with no documented exception
  • Hardware requirements (Chapter 4) — for physical ICT (kiosks, printers, phones)
  • Support documentation and services (Chapter 6)
ICT Coverage (E101–E103)

The standards cover: web content · software · electronic documents · hardware (kiosks, copiers, phones) · video/audio · telecommunications · authoring tools · support documentation

Exceptions (E202)
  • Undue burden — when compliance imposes a significant difficulty or expense; must provide an alternative means of access and document the determination
  • Fundamental alteration — when compliance would fundamentally change the nature of the information or function
  • National security systems — systems operated by DoD/IC for classified activities
  • Back-office equipment — equipment used only by maintenance or monitoring personnel
  • Legacy ICT — ICT acquired/deployed before January 18, 2018, is exempt until altered or replaced (but must provide an equivalent facilitated access if possible)

The POUR Principles (WCAG 2.0)

All web content and software must satisfy WCAG 2.0 Level A and AA success criteria organised under four principles:

1. Perceivable — Users can perceive all information
CriterionLevelRequirement
1.1.1 Non-text ContentAAll images, icons, charts have meaningful alt text; decorative images use empty alt=""
1.2.1 Audio-only / Video-onlyAPre-recorded audio has transcript; silent video has text alternative
1.2.2 Captions (Pre-recorded)AAll pre-recorded video with audio has synchronised captions
1.2.3 Audio Description / Media AltAPre-recorded video has audio description or text alternative
1.2.4 Captions (Live)AALive video with audio provides live captions
1.2.5 Audio Description (Pre-recorded)AAPre-recorded video has audio description
1.3.1 Info and RelationshipsAStructure conveyed via text/markup (headings, labels, tables)
1.3.2 Meaningful SequenceAReading order is logical and meaningful
1.3.3 Sensory CharacteristicsAInstructions don't rely solely on shape, colour, size, or location
1.4.1 Use of ColourAColour is not the only means of conveying information
1.4.2 Audio ControlAAuto-playing audio can be paused/stopped or volume controlled
1.4.3 Contrast (Minimum)AAText/images-of-text: 4.5:1 contrast; large text: 3:1
1.4.4 Resize TextAAText can be resized up to 200% without loss of content or function
1.4.5 Images of TextAAText used for information, not images of text (except logos)
2. Operable — Users can operate all interface components
CriterionLevelRequirement
2.1.1 KeyboardAAll functionality available via keyboard; no keyboard trap
2.1.2 No Keyboard TrapAKeyboard focus can be moved away from any component
2.2.1 Timing AdjustableATime limits can be turned off, adjusted, or extended
2.2.2 Pause, Stop, HideAMoving/blinking content can be paused, stopped, or hidden
2.3.1 Three Flashes or BelowANo content flashes more than 3 times per second
2.4.1 Bypass BlocksAMechanism to skip repeated navigation (e.g., skip link)
2.4.2 Page TitledAPages have descriptive titles
2.4.3 Focus OrderAFocus order preserves meaning and operability
2.4.4 Link Purpose (In Context)ALink purpose is determinable from link text or context
2.4.5 Multiple WaysAAMultiple ways to find pages (search, sitemap, or nav)
2.4.6 Headings and LabelsAAHeadings and labels are descriptive
2.4.7 Focus VisibleAAKeyboard focus indicator is visible
3. Understandable — Users can understand content and operation
CriterionLevelRequirement
3.1.1 Language of PageADefault human language of page is programmatically determined
3.1.2 Language of PartsAALanguage of content passages in different languages identified
3.2.1 On FocusANo context change when component receives focus
3.2.2 On InputANo unexpected context change when user inputs data
3.2.3 Consistent NavigationAANavigation is consistent across pages
3.2.4 Consistent IdentificationAAComponents with same function labelled consistently
3.3.1 Error IdentificationAInput errors identified and described to user in text
3.3.2 Labels or InstructionsALabels or instructions provided for user input
3.3.3 Error SuggestionAAError correction suggestions provided
3.3.4 Error Prevention (Legal, Financial, Data)AASubmissions are reversible, checked, or confirmable
Show full SKILL.md (590 more words)Show less
4. Robust — Content is interpreted reliably by assistive technologies
CriterionLevelRequirement
4.1.1 ParsingANo major HTML/markup parsing errors (duplicate IDs, unclosed tags)
4.1.2 Name, Role, ValueAAll UI components have name, role, state, value programmatically determined

Common Workflows

Filling Out a VPAT (ACR)

Use the VPAT 2.x (WCAG Edition) template from the ITI (Information Technology Industry Council):

  1. Product Information — name, version, date, contact, description
  2. Evaluation Methods — specify testing tools (axe, NVDA, JAWS, VoiceOver, manual testing)
  3. Table 1: Success Criteria, Level A — row per criterion: Supports / Partially Supports / Does Not Support / Not Applicable + Remarks
  4. Table 2: Success Criteria, Level AA — same structure
  5. Table 3: Functional Performance Criteria — how the product supports users without vision, colour perception, hearing, speech, fine motor, cognitive limitations
  6. Chapter 5: Software / Chapter 6: Support Documentation — where applicable

Conformance levels: Supports (fully meets) · Partially Supports (meets in some but not all cases) · Does Not Support (fails) · Not Applicable (criterion doesn't apply to the product)

Accessibility Audit
  1. Automated scan: axe-core, Lighthouse, WAVE — catches ~30–40% of issues
  2. Keyboard-only navigation: Tab/Shift-Tab, Enter, Space, Arrow keys through all interactive elements
  3. Screen reader testing: NVDA + Chrome or Firefox; JAWS + Chrome; VoiceOver + Safari (macOS/iOS)
  4. Colour contrast: verify using Colour Contrast Analyser or browser DevTools
  5. Zoom to 200%: check for content loss, horizontal scrolling
  6. Mobile: iOS VoiceOver, Android TalkBack
  7. Document results per criterion with element references and screenshots
PDF Accessibility

Key requirements under SC 1.3.1, 4.1.2, and PDF/UA (ISO 14289):

  • Tagged PDF with correct tag hierarchy (Document, H1-H6, P, Table, List)
  • Reading order matches visual order (use Reading Order tool in Acrobat)
  • All images have Alt text in the tag properties
  • Form fields have accessible names (Tooltip field in Acrobat)
  • Table cells have headers associated (TH tags with Scope or ID/Headers)
  • Hyperlinks have meaningful display text
  • Document language set in Document Properties → Advanced → Reading Options
  • Document title set (not just filename)
Procurement (FAR Clause 52.239-2)

Include in RFPs:

  • Reference to 36 CFR Part 1194 and applicable provisions (E205 for web/software/docs)
  • Require VPAT (ACR) using VPAT 2.x WCAG Edition within 30 days of award
  • Specify testing methodology and assistive technologies to be supported
  • Include remediation SLAs: Critical (keyboard trap, screen reader block) → 30 days; High → 60 days; Medium → 90 days
  • Require alternate means of access if undue burden claimed
  • Post-award: require updated ACR with each major release
Undue Burden Process
  1. Document the specific ICT and compliance requirement at issue
  2. Calculate cost of full compliance (vendor quotes, internal labor)
  3. Assess agency resources: budget, size, overall financial resources
  4. Document the agency head's (or CIO's) written determination
  5. Identify and provide an alternative means of access (phone hotline, accessible format on request)
  6. Retain documentation for audit; re-evaluate when ICT is next updated

Adjacent Deadline — ADA Title II Web Rule (state when advising public-sector-facing clients)

DOJ's Interim Final Rule of April 17, 2026 extended the ADA Title II web/mobile compliance dates by one year: large public entities (≥50,000 population) to April 26, 2027; small entities and special districts to April 26, 2028. The substantive standard (WCAG 2.1 AA) and scope are unchanged. Section 508 itself still references WCAG 2.0 AA (2017 refresh) — do not conflate the two regimes.

Reference Files

For deeper content, read as needed:

  • references/wcag-mapping.md — Complete WCAG 2.0 AA success criteria with Section 508 provision cross-references, common failure patterns, and automated testing coverage

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/section-508/skills/section-508 of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/wcag-mapping.md

Open the folder on GitHubat commit fb9cb7a

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Section 508 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Section 508 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Section 508 this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~3kAutomated safety check: PassMIT
Font Sizethedaviddias/Front-End-Checklist74k—~896Automated safety check: PassMIT
Msp Website SetupRTFM-IT-Services-LLC/msp-claude-skills113—~3.6kAutomated safety check: NotesCustom licence
Kb Report GenerationCommunity-Access/accessibility-agents422—~987Automated safety check: PassMIT
Cookie Consentthedaviddias/ux-patterns-for-developers258—~913Automated safety check: PassCustom licence
Compliance MappingCommunity-Access/accessibility-agents422—~449Automated safety check: PassMIT

Similar skills

  • Font Size

    thedaviddias/Front-End-Checklist

    A skill your agent uses when applies to all CSS font-size declarations, particularly those using px units for body text, UI labels, and navigation.

    74k GitHub stars~896 tokensUpdated 2 days ago
    Frontend & DesignAuto-check passed
  • Msp Website Setup

    RTFM-IT-Services-LLC/msp-claude-skills

    Your MSP's standard process for setting up a new static client website hosted on your static hosting platform with a git-based dev/prod CI/CD pipeline, plus the client-practice rules around it.

    113 GitHub stars~3.6k tokensUpdated 6 days ago
    Frontend & DesignAuto-check: notes
  • Kb Report Generation

    Community-Access/accessibility-agents

    Reference data, not a reviewer. An agent skill from Community-Access/accessibility-agents.

    422 GitHub stars~987 tokensUpdated 15 days ago
    Frontend & DesignAuto-check passed
  • Cookie Consent

    thedaviddias/ux-patterns-for-developers

    A skill your agent uses when you need to inform users about the use of cookies.

    258 GitHub stars~913 tokensUpdated 3 days ago
    Frontend & DesignAuto-check passed
  • Compliance Mapping

    Community-Access/accessibility-agents

    Map findings to Section 508, EN 301 549, EAA, ADA, AODA; build a VPAT.

    422 GitHub stars~449 tokensUpdated 15 days ago
    Frontend & DesignAuto-check passed
  • Web Interface Guidelines Reviewer

    vercel-labs/openreview

    Official

    Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my…

    1.7k GitHub starsUsed in 98 repos~308 tokens
    Frontend & DesignAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    942 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    942 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    942 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    942 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    942 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    942 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Section 508

What does Section 508 do?

Expert Section 508 compliance advisor for US federal ICT accessibility. Section 508 is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert Section 508 compliance advisor for US federal ICT accessibility.

When should I use Section 508?

Section 508 fits situations like: A user asks about Section 508; WCAG 2.0/2.1 AA for federal systems; accessibility Conformance Reports (ACR); accessibility audits.

How do I install Section 508 in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill section-508 -a claude-code`. Or copy the skill folder (plugins/section-508/skills/section-508 in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/section-508 in your project. Claude Code loads it when a task matches its description.

How do I install Section 508 in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill section-508 -a codex`. Or copy the skill folder (plugins/section-508/skills/section-508 in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/section-508 in your project. Codex loads it when a task matches its description.

Can I use Section 508 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill section-508 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/section-508, .gemini/skills/section-508, .github/skills/section-508 and .opencode/skills/section-508 in your project.

What does Section 508 need to run?

SKILL.md names no scripts, command-line tools or credentials: Section 508 is instructions for the agent only.

Does Section 508 access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Section 508 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Section 508 use?

Section 508 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Section 508 use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Section 508?

Skills that share tags, products or a category with Section 508: Font Size (thedaviddias/Front-End-Checklist, 74k stars), Msp Website Setup (RTFM-IT-Services-LLC/msp-claude-skills, 113 stars), Kb Report Generation (Community-Access/accessibility-agents, 422 stars) and Cookie Consent (thedaviddias/ux-patterns-for-developers, 258 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Section 508?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 942 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 4, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.