Hipaa Compliance
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws.
$ npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install zebbern/claude-code-guide regulatory-audit-generator --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/regulatory-audit-generator .claude/skills/regulatory-audit-generator && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "regulatory-audit-generator" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/regulatory-audit-generator into .claude/skills/regulatory-audit-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-audit-generator", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/zebbern/claude-code-guide/tree/main/skills/regulatory-audit-generatorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install zebbern/claude-code-guide regulatory-audit-generator --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/regulatory-audit-generator .agents/skills/regulatory-audit-generator && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "regulatory-audit-generator" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/regulatory-audit-generator into .agents/skills/regulatory-audit-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-audit-generator", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install zebbern/claude-code-guide regulatory-audit-generator --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/regulatory-audit-generator .cursor/skills/regulatory-audit-generator && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "regulatory-audit-generator" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/regulatory-audit-generator into .cursor/skills/regulatory-audit-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-audit-generator", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/zebbern/claude-code-guide.git --path skills/regulatory-audit-generator--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install zebbern/claude-code-guide regulatory-audit-generator --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/regulatory-audit-generator .gemini/skills/regulatory-audit-generator && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "regulatory-audit-generator" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/regulatory-audit-generator into .gemini/skills/regulatory-audit-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-audit-generator", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install zebbern/claude-code-guide regulatory-audit-generatorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/regulatory-audit-generator .github/skills/regulatory-audit-generator && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "regulatory-audit-generator" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/regulatory-audit-generator into .github/skills/regulatory-audit-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-audit-generator", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install zebbern/claude-code-guide regulatory-audit-generator --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/regulatory-audit-generator .opencode/skills/regulatory-audit-generator && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "regulatory-audit-generator" agent skill from https://github.com/zebbern/claude-code-guide/tree/main/skills/regulatory-audit-generator into .opencode/skills/regulatory-audit-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "regulatory-audit-generator", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
regulatory-audit-generatorBuilds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws.
Regulatory Audit Generator is an agent skill from zebbern/claude-code-guide. Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like "run a compliance check," "GDPR/PIPL compliance," "pre-launch review," "privacy impact assessment (PIA/DPIA)," or asking if a feature is compliant.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It sits in Legal & Compliance, covering Regulatory compliance and Privacy and GDPR. The repository describes itself as: Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user! The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 7ff9fbb. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Regulatory Audit Generator loads about 3.5k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 1,474 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from zebbern/claude-code-guide at commit 7ff9fbb, republished under its MIT licence (© zebbern). 1,474 words, ~3,500 tokens.
.claude/skills/regulatory-audit-generator/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Identifies applicable laws and regulations based on the user's business scenario description, and outputs a structured compliance checklist covering major regulations such as GDPR, PIPL (Personal Information Protection Law), Advertising Law, Cybersecurity Law, and Data Security Law.
Users simply describe their business scenario, and the Agent will:
Users just need to say:
"We're launching a user profiling feature — help me create a compliance checklist."
The Agent will guide the user to provide necessary information, then output a complete compliance checklist.
| Regulation | Abbreviation | Scope | Key Focus Areas |
|---|---|---|---|
| Personal Information Protection Law | PIPL | Processing personal information within China | Informed consent, data minimization, cross-border data transfer |
| General Data Protection Regulation | GDPR | Involving EU user data | Lawful basis, data subject rights, DPO, DPIA |
| Data Security Law | DSL | Data processing activities within China | Data classification & grading, security assessment, important data export |
| Cybersecurity Law | CSL | Network operators | Multi-Level Protection Scheme (MLPS), log retention, security incident reporting |
| Advertising Law | — | Advertising publishing and operations | Prohibited superlative claims, false advertising, medical advertising |
| E-Commerce Law | — | E-commerce operators | Information disclosure, user reviews, bundled sales |
| Anti-Unfair Competition Law | — | Market business activities | Commercial bribery, false advertising, trade secret infringement |
| Consumer Protection Law | — | Consumer rights related | Right to know, fair trade rights, personal information |
| Industry | Relevant Regulations / Standards |
|---|---|
| Finance | Technical Specification for Personal Financial Information Protection (JR/T 0171), Data Security Management Measures for Banking and Insurance Institutions |
| Healthcare | Population Health Information Management Measures, Medical Big Data Standards |
| Education | Online Protection Chapter of the Minors Protection Law, Provisions on Protection of Children's Personal Information Online |
| Automotive | Several Provisions on Automobile Data Security Management |
| Mobile Apps | Methods for Identifying Illegal Collection and Use of Personal Information by Apps, Provisions on the Scope of Necessary Personal Information for Common Types of Mobile Applications |
Confirm the following key information with the user:
| Dimension | Information to Confirm | Example |
|---|---|---|
| Business Description | Specific content of the feature/service | "User profiling feature that recommends products based on behavioral data" |
| User Group | Geographic region and demographics of target audience | "Mainland China users, including minors" |
| Data Types | What data is collected/processed | "Name, phone number, browsing history, location data" |
| Data Flow | Data storage, transmission, and sharing details | "Stored on Alibaba Cloud East China nodes, shared with third-party ad platforms" |
| Business Stage | New launch / existing system needing remediation / M&A due diligence | "New feature, planned for launch next month" |
| Existing Measures | Current compliance measures already in place | "Has a privacy policy, but no DPIA completed" |
If the user has not provided certain information, the Agent should proactively ask follow-up questions rather than assume or skip.
Based on collected information, determine applicable regulations using the following rules:
IF processing personal information → PIPL
IF involving EU users → GDPR
IF involving data storage/transmission → Data Security Law + Cybersecurity Law
IF involving advertising/marketing content → Advertising Law
IF involving e-commerce transactions → E-Commerce Law
IF involving minors → Minors Protection Law + Provisions on Protection of Children's Personal Information Online
IF cross-border data transfer (overseas storage/transmission/access) → PIPL Chapter 3 + Measures for Security Assessment of Data Export
IF involving sensitive personal information → PIPL Chapter 2 Section 2 (separate consent + PIIA)
IF involving automated decision-making → PIPL Article 24 (transparency + right to refuse)
IF involving financial data → JR/T 0171Output the checklist in the following structure:
# [Business Scenario Name] Compliance Checklist
**Assessment Date**: YYYY-MM-DD
**Business Description**: [Brief description]
**Applicable Regulations**: [List of regulations]
## Checklist
| No. | Check Item | Legal Basis | Risk Level | Current Status | Remediation Advice |
|-----|-----------|-------------|------------|----------------|-------------------|
| 1 | [Check item description] | [Regulation name + article number] | High/Medium/Low | Compliant/Non-compliant/To be confirmed | [Specific advice] |
## Risk Summary
- High-risk items: X items
- Medium-risk items: X items
- Low-risk items: X items
## Priority Remediation Recommendations
1. [Highest priority remediation item and rationale]
2. [Second highest priority item and rationale]Prioritize remediation actions according to the following rules:
| Priority | Criteria | Description |
|---|---|---|
| P0 — Immediate Action | High risk + currently non-compliant | May face administrative penalties, service shutdown |
| P1 — Complete This Week | High risk + to be confirmed, or medium risk + non-compliant | Significant compliance exposure |
| P2 — Complete This Month | Medium risk + to be confirmed | Requires further assessment and improvement |
| P3 — Ongoing Optimization | Low risk | Recommended improvement but not urgent |
| Check Item | Legal Basis | Description |
|---|---|---|
| Is there a privacy policy / user agreement? | PIPL Art. 17 | Must be displayed and consent obtained before registration |
| Is only necessary personal information collected? | PIPL Art. 6 | Registration stage should only require phone number/email; should not mandate ID numbers, etc. |
| Does third-party login disclose data sharing? | PIPL Art. 23 | Login via WeChat/Alipay must disclose what information is shared |
| Are passwords stored encrypted? | CSL Art. 21 | Plaintext password storage is prohibited |
| Is account deletion supported? | PIPL Art. 47 | A convenient account deletion channel must be provided |
| Check Item | Legal Basis | Description |
|---|---|---|
| Is consent obtained for marketing SMS/emails? | PIPL Art. 13, Advertising Law Art. 43 | Explicit user consent is required |
| Is an unsubscribe mechanism provided? | Advertising Law Art. 43 | Each marketing message must include an opt-out method |
| Does ad copy contain prohibited superlative terms? | Advertising Law Art. 9 | Absolute terms like "best," "number one," "national-level" are prohibited |
| Can profiling-based recommendations be disabled? | PIPL Art. 24 | An option for non-personalized content must be provided |
| Are advertisements clearly labeled as "Ad"? | Advertising Law Art. 14 | Mass media channels must clearly mark advertisements |
| Check Item | Legal Basis | Description |
|---|---|---|
| Does it meet the security assessment filing threshold? | Measures for Security Assessment of Data Export Art. 4 | Processing personal information of 1M+ individuals, or cumulative export of 100K individuals / 10K sensitive records |
| Has the standard contract been signed? | Standard Contract Measures for Personal Information Export | Can sign the standard contract if below the filing threshold |
| Has a Personal Information Protection Impact Assessment been completed? | PIPL Art. 55 | PIIA must be completed before data export |
| Has the user been informed and separate consent obtained? | PIPL Art. 39 | Must disclose overseas recipient information |
| Overseas recipient's data protection capability | PIPL Art. 38 | Must assess the recipient's data protection standards |
| Check Item | Legal Basis | Description |
|---|---|---|
| Is the automated decision-making logic disclosed? | PIPL Art. 24 | Must be transparent to users |
| Is an option to disable personalized recommendations provided? | PIPL Art. 24 | Users have the right to refuse |
| Has a PIIA been conducted for user profiling? | PIPL Art. 55 | Assessment is required when using personal information for automated decision-making |
| Do profiling tags involve sensitive information? | PIPL Art. 28 | Tags related to religion, health, finance, etc. are classified as sensitive information |
| Is the use scope of profiling results restricted? | PIPL Art. 24 | Must not impose unreasonable differential treatment in areas such as transaction pricing |
| Check Item | Legal Basis | Description |
|---|---|---|
| Has a lawful basis for processing been established? | GDPR Art. 6 | One of six bases: consent, contract, legal obligation, legitimate interest, etc. |
| Has a DPO been appointed? | GDPR Art. 37 | Required for large-scale processing or processing of special category data |
| Has a DPIA been completed? | GDPR Art. 35 | Required for high-risk processing activities |
| Is the right to data portability supported? | GDPR Art. 20 | Data must be provided in a structured, machine-readable format |
| Can data breaches be reported within 72 hours? | GDPR Art. 33 | Supervisory authority must be notified within 72 hours of discovering a breach |
| Is the cookie banner compliant? | GDPR + ePrivacy | Active consent required; pre-checked boxes are not permitted |
| Are records of processing activities maintained? | GDPR Art. 30 | Required for organizations with 250+ employees or non-occasional processing |
| Risk Level | Criteria | Potential Consequences |
|---|---|---|
| High | Violation of mandatory legal provisions; unlawful processing of sensitive personal information; lack of lawful basis; data export without assessment | Administrative penalties (fines), service shutdown, criminal liability |
| Medium | Compliance measures incomplete but foundational; insufficient notice; flawed consent mechanism; partial security measure gaps | Regulatory interview, ordered remediation within deadline, user complaints |
| Low | Best practices not met but not unlawful; incomplete documentation; processes can be optimized | Audit findings, internal improvements |
The Agent should ultimately deliver the following to the user:
© zebbern, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/regulatory-audit-generator of zebbern/claude-code-guide.
Open the folder on GitHubat commit 7ff9fbb
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in zebbern/claude-code-guide, which our catalogue first saw on October 7, 2026.
Regulatory Audit Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Regulatory Audit Generator this skillzebbern/claude-code-guide | 4.7k | 1 repos | ~3.5k | Automated safety check: Pass | MIT | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Age Gating Servicesmukul975/Privacy-Data-Protection-Skills | 301 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | |
| Reg Gap Analysisanthropics/claude-for-legal | 9.6k | 2 repos | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Policy OpaAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3.5k | Automated safety check: Pass | Custom licence | |
| Compliance Checkjosstei/maestro-orchestrate | 465 | — | ~237 | Automated safety check: Pass | Apache-2.0 |
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
anthropics/claude-for-legal
Diff a new or changed regulation against current privacy policy and practice — outputs a gap list and a remediation plan with owners and dates.
AgentSecOps/SecOpsAgentKit
Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).
josstei/maestro-orchestrate
Run a Maestro-style regulatory compliance review for GDPR/CCPA, cookie consent, data handling, and licensing
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
zebbern/claude-code-guide
This skill should be used when setting up, auditing, or enforcing internationalization/localization in UI codebases (React/TS, i18next or similar, JSON locales), including installing/configuring the…
zebbern/claude-code-guide
Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.
zebbern/claude-code-guide
Generate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts.
zebbern/claude-code-guide
Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts.
zebbern/claude-code-guide
Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.
zebbern/claude-code-guide
This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…
Categories
Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Regulatory Audit Generator is an agent skill from zebbern/claude-code-guide. Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws.
Regulatory Audit Generator fits situations like: tasks that involve Regulatory compliance; tasks that involve Privacy and GDPR.
Run `npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a claude-code`. Or copy the skill folder (skills/regulatory-audit-generator in zebbern/claude-code-guide) into .claude/skills/regulatory-audit-generator in your project. Claude Code loads it when a task matches its description.
Run `npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a codex`. Or copy the skill folder (skills/regulatory-audit-generator in zebbern/claude-code-guide) into .agents/skills/regulatory-audit-generator in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zebbern/claude-code-guide --skill regulatory-audit-generator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/regulatory-audit-generator, .gemini/skills/regulatory-audit-generator, .github/skills/regulatory-audit-generator and .opencode/skills/regulatory-audit-generator in your project.
SKILL.md names no scripts, command-line tools or credentials: Regulatory Audit Generator is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Regulatory Audit Generator is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Regulatory Audit Generator: Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Age Gating Services (mukul975/Privacy-Data-Protection-Skills, 301 stars), Reg Gap Analysis (anthropics/claude-for-legal, 9.6k stars) and Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
zebbern (a GitHub user) maintains it in zebbern/claude-code-guide, which has 4,650 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 10, 2026.
Source: zebbern/claude-code-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.