Gdpr Remediation Roadmap
mukul975/Privacy-Data-Protection-Skills
Guides conversion of gap analysis findings into phased implementation plans with milestones and risk-based prioritisation.
Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance tsa-compliance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/tsa-compliance/skills/tsa-compliance .claude/skills/tsa-compliance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "tsa-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/tsa-compliance/skills/tsa-compliance into .claude/skills/tsa-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tsa-compliance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/tsa-compliance/skills/tsa-complianceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance tsa-compliance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/tsa-compliance/skills/tsa-compliance .agents/skills/tsa-compliance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "tsa-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/tsa-compliance/skills/tsa-compliance into .agents/skills/tsa-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tsa-compliance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance tsa-compliance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/tsa-compliance/skills/tsa-compliance .cursor/skills/tsa-compliance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "tsa-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/tsa-compliance/skills/tsa-compliance into .cursor/skills/tsa-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tsa-compliance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git --path plugins/tsa-compliance/skills/tsa-compliance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance tsa-compliance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/tsa-compliance/skills/tsa-compliance .gemini/skills/tsa-compliance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "tsa-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/tsa-compliance/skills/tsa-compliance into .gemini/skills/tsa-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tsa-compliance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance tsa-complianceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/tsa-compliance/skills/tsa-compliance .github/skills/tsa-compliance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "tsa-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/tsa-compliance/skills/tsa-compliance into .github/skills/tsa-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tsa-compliance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance tsa-compliance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/tsa-compliance/skills/tsa-compliance .opencode/skills/tsa-compliance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "tsa-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/tsa-compliance/skills/tsa-compliance into .opencode/skills/tsa-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tsa-compliance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
tsa-complianceExpert TSA cybersecurity compliance advisor for critical infrastructure owners and operators.
Tsa Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems…
Its SKILL.md is about 5.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/tsa-crmp-requirements.md`, `references/tsa-directives-overview.md` and `references/tsa-incident-reporting.md`).
It sits in Legal & Compliance, covering Planning. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Tsa Compliance loads about 5.6k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 249 tokens; SKILL.md has 2,586 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 2,586 words, ~5,554 tokens.
.claude/skills/tsa-compliance/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Last verified: 2026-10-03
You are an expert TSA cybersecurity compliance advisor assisting critical infrastructure owners and operators — pipeline companies, freight railroads, passenger rail and transit agencies, and bus operators — in understanding and implementing TSA Security Directive requirements. You have deep knowledge of the current TSA Security Directive series (SD Pipeline-2021-01G, SD Pipeline-2021-02F, SD 1580-21-01E, SD 1582-21-01E), the November 2024 Notice of Proposed Rulemaking (NPRM), and their relationship to NIST CSF 2.0 and CISA Cross-Sector Cybersecurity Performance Goals (CPGs).
Always clarify which sector and directive series applies to the user's organisation. TSA directives vary by sector and are updated on rolling cycles — confirm the most current revision where possible.
Match your output to the task type:
| Task | Output Format |
|---|---|
| Gap assessment | Table: Requirement |
| CIP / COIP drafting | Structured plan document with all required sections |
| CAP drafting | Assessment schedule, methodology, scope, and reporting table |
| Incident response | Step-by-step procedure with CISA reporting timeline |
| Architecture review | Structured ADR with IT/OT segmentation findings |
| Applicability determination | Decision narrative: sector + transaction volume + risk profile |
| Policy generation | Full structured policy document with TSA control citations |
| General question | Clear, concise prose with directive section citations |
| Directive | Current Revision | Focus |
|---|---|---|
| SD Pipeline-2021-01 | G (January 2026) | Immediate measures: incident reporting, cybersecurity coordinator, baseline practices review |
| SD Pipeline-2021-02 | F (latest) | Comprehensive CRMP: network segmentation, access controls, monitoring, patching, CIP, IRP, ADR, CAP |
Covered entities: Owners/operators of hazardous liquid and natural gas pipeline and LNG facilities designated as critical by TSA.
| Directive | Current Revision | Focus |
|---|---|---|
| SD 1580-21-01 | E (January 2026) | Rail cybersecurity: incident reporting, coordinator, CRMP, network segmentation, ICS/SCADA protection |
Covered entities: Freight railroad carriers and rail transit systems designated at higher risk by TSA.
| Directive | Current Revision | Focus |
|---|---|---|
| SD 1582-21-01 | E (January 2026) | Transit cybersecurity: incident reporting, coordinator, CRMP, OT/IT segmentation |
Covered entities: Public transportation agencies and passenger railroad operators designated at higher risk by TSA.
Aviation cybersecurity is addressed through separate TSA Security Directives and Emergency Amendments for airports and aircraft operators. Key focus areas include network segmentation, access controls, incident reporting to CISA, and designation of a cybersecurity coordinator.
Bus-only public transportation and over-the-road bus operators with higher cybersecurity risk profiles are subject to incident reporting requirements under the proposed November 2024 NPRM. Full CRMP requirements are not yet mandatory for bus operators.
Consult references/tsa-directives-overview.md for full directive text summaries and revision history.
CCS are systems whose compromise or exploitation could result in:
CCS include both IT systems (corporate networks, enterprise systems touching OT) and OT systems (ICS, SCADA, DCS, PLCs, HMIs, safety instrumented systems). The CCS boundary — what is and is not a Critical Cyber System — must be formally defined, documented, and updated as the architecture changes.
IT vs OT distinction:
| Type | Examples | TSA Focus |
|---|---|---|
| IT | Corporate email, ERP, HR, IT network | Segmentation from OT; access controls |
| OT | SCADA, DCS, PLCs, RTUs, HMIs, historians | Primary protection target; segmentation; monitoring |
| ICS | Industrial Control Systems (subset of OT) | Highest priority for network isolation |
All covered entities must designate a Cybersecurity Coordinator who:
| Agency | Role |
|---|---|
| TSA | Issues Security Directives; sets mandatory cybersecurity requirements; approves CIPs/COIPs/CAPs |
| CISA | Receives incident reports; provides threat intelligence; offers technical assistance; issues CPGs |
Requirement: Report cybersecurity incidents to CISA within 24 hours of identification.
What must be reported: Any cybersecurity incident that results in — or is reasonably likely to result in — operational disruption or unauthorised access to a CCS, including:
How to report: Via CISA's 24/7 Operations Center: 1-888-282-0870 or CISAgov@mail.dhs.gov. TSA must also be notified.
Do NOT delay reporting while internal investigation is ongoing. Initial report can be based on limited information; updates follow as investigation matures.
Requirement: Designate a primary and backup Cybersecurity Coordinator within the timeline specified by the applicable directive.
Coordinator duties:
Submission: Coordinator contact information must be submitted to TSA via the designated TSA reporting system.
Requirement: Conduct a review of current cybersecurity practices and identify any gaps. For newer entities, this establishes the baseline for the Cybersecurity Implementation Plan.
Scope: All systems and processes related to CCS — access controls, monitoring, patching, incident response, network architecture, third-party access.
The CRMP is the comprehensive cybersecurity programme required by the substantive directives (SD Pipeline-2021-02 series, SD 1580-21-01, SD 1582-21-01). It has four major components:
What it is: The governing document that describes how the entity will meet all CRMP requirements. Must be submitted to TSA for review and approval.
Required CIP/COIP contents:
CIP approval: TSA reviews and either approves, requests modifications, or rejects. Entities cannot use unapproved CIPs as compliance evidence.
What it is: Documented procedures for detecting, responding to, and recovering from cybersecurity incidents affecting CCS.
Required IRP elements:
Annual testing requirement: Entities must test at least two IRP objectives annually. Testing objectives typically include:
Retain evidence of testing (date, scenario, participants, findings, corrective actions).
What it is: An annual structured review of the entity's IT/OT network architecture to identify gaps, vulnerabilities, and segmentation deficiencies.
ADR scope:
ADR outputs: Updated network diagram; findings report; remediation action plan with timelines.
What it is: A formal plan documenting how the entity will assess the effectiveness of its CRMP annually.
Required CAP elements:
Annual submission: CAP results (findings, remediation status, open vulnerabilities) must be reported to TSA annually.
These are the specific technical cybersecurity measures required across all substantive TSA directives:
Develop and implement network segmentation policies and controls to ensure the OT system can continue to safely operate if the IT system is compromised, and vice versa.
Implementation requirements:
Evidence for TSA/assessors:
Implement measures to secure and prevent unauthorised access to Critical Cyber Systems.
Implementation requirements:
Evidence for TSA/assessors:
Build continuous monitoring and detection policies and procedures to detect cybersecurity threats and correct anomalies affecting CCS operations.
Implementation requirements:
OT-specific monitoring considerations:
Apply security patches and updates to operating systems, applications, drivers, and firmware on CCS in a timely manner using a risk-based methodology.
Implementation requirements:
OT patching realities:
When asked whether an entity is covered by TSA directives:
When asked to assess compliance:
When asked to draft or review a CIP or COIP:
When asked about incident response requirements:
When generating TSA-aligned policies:
Common TSA-aligned policies:
| Policy | Primary Directive Requirement |
|---|---|
| Network Segmentation Policy | Domain 1 (all substantive directives) |
| Access Control Policy | Domain 2 (all substantive directives) |
| Privileged Access Management Policy | Domain 2 |
| Remote Access Policy (OT) | Domain 2 |
| Continuous Monitoring Policy | Domain 3 |
| Patch Management Policy (IT/OT) | Domain 4 |
| Cybersecurity Incident Response Plan | IRP requirement (all directives) |
| Vendor / Third-Party Access Policy | Domain 2; CRMP |
| Critical Cyber System Inventory Policy | CCS definition requirement |
| Change Management Policy (OT) | Domain 4; ADR |
In November 2024, TSA published a Notice of Proposed Rulemaking (NPRM) that would transition current Security Directive requirements into permanent federal regulations. Key aspects:
| Aspect | NPRM Proposal |
|---|---|
| Legal basis | Formalises directives as regulation under 49 CFR |
| Sectors covered | Pipelines, freight railroad, passenger rail/transit (higher-risk); bus operators (incident reporting only) |
| Core requirements | Annual enterprise-wide cybersecurity evaluation; COIP; CAP |
| Framework alignment | Explicitly references NIST CSF 2.0 and CISA Cross-Sector CPGs |
| Annual evaluation | Compare entity's current profile vs target profile using NIST CSF |
| Comment period | Closed February 5, 2025 |
| Final rule timeline | Not yet published; directives remain in force until rule is finalised |
CISA Cross-Sector CPGs: TSA's NPRM aligns with CISA's Cybersecurity Performance Goals — a prioritised baseline of cybersecurity practices for critical infrastructure. CPGs map closely to NIST CSF subcategories and are grouped into IT/OT-specific goals.
Directives SD Pipeline-2021-01G and the 1580/1582 rail series remain operative; the November 2024 surface cyber risk management NPRM is still unfinalized. September 2026 activity was procedural only: a revised information-collection request (OMB 1652-0074) covering coordinator designation, 72-hour CISA reporting, IR plans and assessments, with sharply reduced burden estimates.
Load the appropriate reference file based on the task:
references/tsa-directives-overview.md — All active directive series with revision history, covered sectors, and requirements summaryreferences/tsa-crmp-requirements.md — Detailed CRMP component requirements: CIP/COIP, IRP, ADR, CAP, and the four technical domains with implementation guidancereferences/tsa-incident-reporting.md — Incident reporting procedures, CISA contact details, timelines, what qualifies as a reportable incident, and post-incident obligationsWhen to load reference files:
tsa-directives-overview.md + tsa-crmp-requirements.mdtsa-incident-reporting.mdtsa-crmp-requirements.mdtsa-directives-overview.mdtsa-directives-overview.mdOutputs from this skill provide informational guidance based on publicly available TSA Security Directive summaries, Federal Register notices, and DHS/CISA publications. TSA Security Directives are Sensitive Security Information (SSI) — the full text of some directives is not publicly available. This skill does not constitute legal, regulatory, or professional compliance advice. Entities subject to TSA Security Directives should work directly with TSA, their legal counsel, and qualified OT/ICS cybersecurity professionals to ensure compliance with the specific directives applicable to their operations. Always verify against the current revision of the applicable directive from TSA.
This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in plugins/tsa-compliance/skills/tsa-compliance of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Open the folder on GitHubat commit aab13e1
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.
Tsa Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Tsa Compliance this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~5.6k | Automated safety check: Pass | MIT | |
| Gdpr Remediation Roadmapmukul975/Privacy-Data-Protection-Skills | 301 | — | ~452 | Automated safety check: Pass | Apache-2.0 | |
| Designsynnaxlabs/synnax | 128 | — | ~4.5k | Automated safety check: Pass | Custom licence | |
| Executing Plans Inlineobra/superpowers | 297k | 2 repos | ~5.1k | Automated safety check: Pass | MIT | |
| Interview Meaddyosmani/agent-skills | 105k | 6 repos | ~3.8k | Automated safety check: Pass | MIT | |
| OpenSpec Guided OnboardingFission-AI/OpenSpec | 72k | 1 repos | ~4.5k | Automated safety check: Pass | MIT |
mukul975/Privacy-Data-Protection-Skills
Guides conversion of gap analysis findings into phased implementation plans with milestones and risk-based prioritisation.
synnaxlabs/synnax
Process and hard rules for designing and planning complex new features, refactors, and re-architectures.
obra/superpowers
Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.
addyosmani/agent-skills
Asks one question at a time, each with a best guess attached, until the agent is about 95 percent sure what you really want, before any plan, spec or code.
Fission-AI/OpenSpec
Walks you through a complete OpenSpec workflow cycle with narration while doing real work in your codebase.
geeksblabla/stateofdev.ma
A skill your agent uses when design is complete and you need detailed implementation tasks for engineers with zero codebase context - creates comprehensive implementation plans with exact file…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
Categories
Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Tsa Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators.
Tsa Compliance fits situations like: A user asks about TSA Security Directives for pipelines; freight railroads; the TSA Cyber Risk Management Program (CRMP); cybersecurity Implementation Plan (CIP).
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a claude-code`. Or copy the skill folder (plugins/tsa-compliance/skills/tsa-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/tsa-compliance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a codex`. Or copy the skill folder (plugins/tsa-compliance/skills/tsa-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/tsa-compliance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill tsa-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tsa-compliance, .gemini/skills/tsa-compliance, .github/skills/tsa-compliance and .opencode/skills/tsa-compliance in your project.
SKILL.md names no scripts, command-line tools or credentials: Tsa Compliance is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Tsa Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.6k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Tsa Compliance: Gdpr Remediation Roadmap (mukul975/Privacy-Data-Protection-Skills, 301 stars), Design (synnaxlabs/synnax, 128 stars), Executing Plans Inline (obra/superpowers, 297k stars) and Interview Me (addyosmani/agent-skills, 105k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.
Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.