Agent skill

AI Inventory

by zhou210712 in zhou210712/claude-for-legal-ZH

按系统逐一定义AI角色、风险等级和监管义务——判定每个系统是 AI服务提供者还是使用者,分配风险层级,并映射至中国AI法规 的义务要求。适用于建立AI系统清单、进行年度AI审计、或新法 规要求重新分类时。

Apache-2.0Auto-check passedLegal & Compliance

Install AI Inventory

skills CLI
$ npx skills add zhou210712/claude-for-legal-ZH --skill ai-inventory -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zhou210712/claude-for-legal-ZH ai-inventory --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zhou210712/claude-for-legal-ZH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance-legal/skills/ai-inventory .claude/skills/ai-inventory && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-inventory
GitHub stars
225
Token cost
~1k tokens
SKILL.md length
166 words
Files
1
Skills in repo
122
Repo updated
First seen
Licence
Apache-2.0

At a glance

按系统逐一定义AI角色、风险等级和监管义务——判定每个系统是 AI服务提供者还是使用者,分配风险层级,并映射至中国AI法规 的义务要求。适用于建立AI系统清单、进行年度AI审计、或新法 规要求重新分类时。

  • Works in 4 steps: 读取… → 运行以下工作流。 → 对每个系统:描述功能 → 判定提供者/使用者角色 → 分配风险等级 →… → …
  • Legal & Compliance work in your project
  • SKILL.md covers 目的, 加载当前状态, 单系统录入 and 全量审查 --full, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

AI Inventory is an agent skill from zhou210712/claude-for-legal-ZH. 按系统逐一定义AI角色、风险等级和监管义务——判定每个系统是 AI服务提供者还是使用者,分配风险层级,并映射至中国AI法规 的义务要求。适用于建立AI系统清单、进行年度AI审计、或新法 规要求重新分类时。

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance. The licence is Apache-2.0.

When your agent uses it

  • Legal & Compliance work in your project

Example prompts

  • “/ai-inventory”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 读取 ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → 既有AI系统清单(如有)、监管注册表。
  2. 运行以下工作流。
  3. 对每个系统:描述功能 → 判定提供者/使用者角色 → 分配风险等级 → 映射监管义务。
  4. 输出系统级条目 + 汇总表。

What it can do on your machine

Read from SKILL.md and the folder at commit 2f01c92. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Inventory loads about 1k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 166 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zhou210712/claude-for-legal-ZH at commit 2f01c92, republished under its Apache-2.0 licence (© zhou210712). 166 words, ~1,047 tokens.

Download SKILL.mdSave it as .claude/skills/ai-inventory/SKILL.md (or your agent's skills folder).
name
ai-inventory
description
按系统逐一定义AI角色、风险等级和监管义务——判定每个系统是 AI服务提供者还是使用者,分配风险层级,并映射至中国AI法规 的义务要求。适用于建立AI系统清单、进行年度AI审计、或新法 规要求重新分类时。
argument-hint
[系统名称或'--full'进行全量审查]

/ai-inventory

  1. 读取 ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → 既有AI系统清单(如有)、监管注册表。
  2. 运行以下工作流。
  3. 对每个系统:描述功能 → 判定提供者/使用者角色 → 分配风险等级 → 映射监管义务。
  4. 输出系统级条目 + 汇总表。
/ai-governance-legal:ai-inventory "智能客服系统 v3"
/ai-governance-legal:ai-inventory --full

AI系统清单编制

目的

盘点你正在使用的每一件AI——作为提供者还是使用者,风险层级如何,受哪些法规约束。这是 use-case-triage(评估新事物)和 aia-generation(深度评估单个系统)的基础层。

加载当前状态

读取 ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md:

  • ## AI系统清单 — 既有清单(如有)
  • ## 监管注册表 — 适用法规及义务
  • ## 红线 — 禁止的用例类别

单系统录入

当提供系统名称或描述时,运行单系统录入。

工作流
第1步:收集基本信息

如果用户提供的信息不足以填充以下字段,逐项询问:

字段说明
系统名称唯一标识符
功能描述一段话——系统做什么
AI技术类型机器学习/深度学习/规则系统/大语言模型/计算机视觉/其他
模型来源自主研发/基于开源模型微调/第三方API/采购的商业产品
部署方式本地部署/私有云/公有云API/SaaS
数据处理涉及的数据类别——是否包含个人信息、敏感个人信息、商业数据、公开数据
受影响人群内部员工/商业客户/公众用户/未成年人
使用场景内部辅助工具/面向客户的功能/面向公众的服务
决策类型非实质性(推荐、排序)/实质性(影响权利义务)/安全关键
第2步:判定角色
角色判定标准
提供者自主研发并向他人(包括公司内部其他部门)提供AI服务
使用者使用第三方AI服务,不对外提供AI服务本身
双重基于第三方模型训练/微调后向外部提供服务

如果系统仅在公司内部使用且不向外部提供,则通常归为使用者(即使使用了内部数据)。但如果公司开发自己的模型/系统并向外部客户提供该系统的访问权限,则归为提供者。

灰色地带:使用LLM API构建的面向用户的功能——技术上使用了第三方模型,但你构建了应用层并向用户提供服务。此类情况通常归为"双重"角色:对用户来说你是提供者,同时你是底层模型的使用者。

第3步:分配风险等级
等级定义触发特征
高风险对权利和利益有实质性影响,或面向弱势群体,或安全关键自动化决策影响信贷/就业/教育/保险;涉及敏感个人信息;面向未成年人;医疗/交通/基础设施安全场景
中风险面向公众但对权利无实质性影响内容推荐/个性化;使用个人信息但非敏感;生成合成内容
低风险内部使用,不涉及个人信息,无外部影响内部数据分析;非个人信息处理;生产力和效率工具
不适用系统中没有AI组件纯确定性的自动化、传统软件
第4步:映射监管义务

基于角色和风险等级,确定义务:

法规高风险 + 提供者中风险 + 提供者高风险 + 使用者中/低风险 + 使用者
生成式AI安全评估(《管理办法》第17条 [法条原文])✅ 必须✅ 必须❌ 不直接❌ 不直接
算法备案(《算法推荐管理规定》第24条 [法条原文])✅ 必须(如适用)✅ 必须(如适用)❌❌
科技伦理审查(《伦理审查办法》[法条原文])✅ 必须⚠️ 视具体场景⚠️ 视具体场景❌
个人信息保护影响评估(《个保法》第55条 [法条原文])✅ 必须✅ 必须✅ 必须⚠️ 视数据
算法推荐透明度(《算法推荐管理规定》第16条 [法条原文])✅ 必须✅ 必须❌❌
深度合成标识(《深度合成管理规定》第16条 [法条原文])✅ 必须(如适用)✅ 必须(如适用)❌❌
投诉举报机制(《管理办法》第15条 [法条原文])✅ 必须✅ 必须❌❌
第5步:输出单系统条目
markdown
### [系统名称]

**角色:** [提供者 / 使用者 / 双重]
**风险等级:** [高风险 / 中风险 / 低风险 / 不适用]
**状态:** [已部署 / 在评估 / 开发中 / 已退役]

| 属性 | 值 |
|------|---|
| 功能描述 | [一段话] |
| AI技术类型 | [类型] |
| 模型来源 | [来源] |
| 部署方式 | [方式] |
| 数据类别 | [类别列表] |
| 受影响人群 | [人群] |
| 面向对象 | [内部/客户/公众] |
| 决策类型 | [类型] |

**监管义务:**

| 义务 | 适用 | 状态 | 截止日期/完成日期 | 证据 |
|------|------|------|-------------------|------|
| [义务] | ✅/❌ | ✅已完成/⚠️进行中/❌未开始 | [日期] | [文档引用] |

全量审查 --full

当使用 --full 时,对 ## AI系统清单 中的每个系统运行单系统录入流程,此外:

  1. 交叉检查一致性:确保类似系统获得类似分类。当一个系统获得了与其他类似系统不同的风险等级时,标记并解释。
  2. 识别清单缺口:检查 ## AI系统清单 是否遗漏了实践中存在的AI系统(例如供应商审查中已批准但未列入清单的供应商系统)。
  3. 监管覆盖缺口:哪些法规适用于你的业务但你没有任何被分类为需要遵守该法规的系统?这是否合理?
全量审查汇总表
markdown
## AI系统清单汇总

**审查日期:** [日期]
**系统总数:** [N] | 提供者:[N] | 使用者:[N] | 双重:[N]
**按风险等级:** 高风险:[N] | 中风险:[N] | 低风险:[N]

| 系统 | 角色 | 风险等级 | 适用法规数 | 备案状态 | 上次评估 | 差距数 |
|------|------|----------|-----------|----------|----------|--------|
| [名称] | [角色] | [等级] | [N] | [状态] | [日期] | [N] |

## 监管覆盖缺口

| 法规 | 适用系统数 | 是否有覆盖缺口? | 说明 |
|------|-----------|----------------|------|
| [法规] | [N] | 是/否 | [说明] |

## 不一致标记

[标记任何类似系统获得不同分类的情况,附说明]

输出

保存到 ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/outputs/ai-inventory-[日期].md。同时更新 ## AI系统清单 中的条目。

markdown
[工作成果头 — 按照插件配置 ## 输出]

与 use-case-triage 的衔接

use-case-triage 在系统进入开发之前评估新提议。ai-inventory 是为已存在(或即将部署)的系统创建记录。一个已通过分类的系统在部署前通常需要完成清单编制。当 triage 给出"附条件-高"分类时,应自动触发清单编制。

收尾

以 CLAUDE.md ## 输出 规定的下一步决策树收尾。定制选项:完成缺失系统的录入、处理不一致标记、填补监管覆盖缺口、升级至法律顾问。


本技能不做的事

  • 不执行深度评估——那是 aia-generation 的职责。此技能是对系统进行分类和分配义务,不做逐项条款的合规分析。
  • 不做出"这个风险等级是正确的"的法律判断。分类基于当前法规和技术理解;当法规发生变化时,重新分类。
  • 不替代网信办的官方分类——监管机构可能不同意你的风险等级判定。

© zhou210712, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in ai-governance-legal/skills/ai-inventory of zhou210712/claude-for-legal-ZH.

Open the folder on GitHubat commit 2f01c92

Compare with similar skills

AI Inventory next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Inventory compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Inventory this skillzhou210712/claude-for-legal-ZH225—~1kAutomated safety check: PassApache-2.0
Paper to Chinese Patent DrafterYuan1z0825/nature-skills47k1 repos~1.1kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
Contract Reviewevolsb/claude-legal-skill4641 repos~3.6kAutomated safety check: PassMIT
Legal Clinic Client Intakeanthropics/claude-for-legal9.6k3 repos~3.2kAutomated safety check: PassApache-2.0
Paper To Cn Patentsnipp-zha/Paper-to-patent-Skill1071 repos~959Automated safety check: PassNone

Similar skills

  • Paper to Chinese Patent Drafter

    Yuan1z0825/nature-skills

    Drafts Chinese invention patent applications and technical disclosures from research papers or inventor materials, tying each claim feature to source evidence.

    47k GitHub starsUsed in 1 repo~1.1k tokens
    Legal & ComplianceAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Contract Review

    evolsb/claude-legal-skill

    Review legal contracts, NDAs, employment agreements, SaaS terms, and M&A documents.

    464 GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check passed
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Legal & ComplianceAuto-check passed
  • Paper To Cn Patent

    snipp-zha/Paper-to-patent-Skill

    Convert scientific papers, theses, technical reports, source code, figures, or research manuscripts into evidence-grounded Chinese invention patent drafts.

    107 GitHub starsUsed in 1 repo~959 tokens
    Legal & ComplianceAuto-check passed
  • Employment Contract Templates

    ynulihao/AgentSkillOS

    Create employment contracts, offer letters, and HR policy documents following legal best practices.

    618 GitHub starsUsed in 12 repos~4.1k tokens
    Legal & ComplianceAuto-check passed

More from zhou210712/claude-for-legal-ZH

All 122 skills in this repo
  • Claim Chart

    zhou210712/claude-for-legal-ZH

    构建或审查要件分析表——专利权利要求对照表(侵权、无效或审查)或 民事构成要件分析表(任何诉讼请求或抗辩),每个单元格附精确引用, 缺口检测为优先输出。当用户要求要件分析表、权利要求对照表、 证据对照表、侵权或无效主张、逐要件映射,或问"我们证明[主张]还缺什么"时使用。

    225 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Client Intake

    zhou210712/claude-for-legal-ZH

    结构化接待——实践领域模板、跨领域考点识别、利益冲突标记、分流分类. An agent skill from zhou210712/claude-for-legal-ZH.

    225 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Gap Surfacer

    zhou210712/claude-for-legal-ZH

    参考资料:支持 /regulatory-legal:gaps 和 /regulatory-legal:comments 的共享差距和意见征集跟踪框架。跟踪未关闭的政策差距及其整改状态, 从 policy-diff 中获取差距,呈现开放和即将到期的事项,路由给负责人, 并通过企业通讯工具通知差距负责人,每次发送前需确认。

    225 GitHub stars~757 tokensUpdated 4 mo ago
    Auto-check passed
  • Launch Review

    zhou210712/claude-for-legal-ZH

    对照您的框架和风险校准进行全面产品上线审查。当用户说"审查这个上线" "[功能]法务审查""我们能上线吗""[产品]有什么法律问题"或引用了需要 逐类审查备忘录的产品需求文档或上线追踪工单时使用。

    225 GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check passed
  • Reg Feed Watcher

    zhou210712/claude-for-legal-ZH

    检查法规动态源,报告自上次检查以来的新事项,按重要度阈值过滤。适用于用户说"检查法规动态"、"有什么新规定"、"法规更新"、从定时任务触发执行,或手动粘贴法规动态进行分类和差异分析时。

    225 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Renewal Tracker

    zhou210712/claude-for-legal-ZH

    展示具有即将到来的取消截止日期的合同,在通知窗口关闭前发出预警, 基于维护的续约登记册运行。当用户询问"什么即将续约""哪些续约即将到期" "我们是否错过了取消窗口""将此添加到续约追踪器"时使用,或按计划运行。

    225 GitHub stars~681 tokensUpdated 4 mo ago
    Auto-check passed

Questions about AI Inventory

What does AI Inventory do?

按系统逐一定义AI角色、风险等级和监管义务——判定每个系统是 AI服务提供者还是使用者,分配风险层级,并映射至中国AI法规 的义务要求。适用于建立AI系统清单、进行年度AI审计、或新法 规要求重新分类时。. AI Inventory is an agent skill from zhou210712/claude-for-legal-ZH.

When should I use AI Inventory?

AI Inventory fits situations like: legal & Compliance work in your project.

How do I install AI Inventory in Claude Code?

Run `npx skills add zhou210712/claude-for-legal-ZH --skill ai-inventory -a claude-code`. Or copy the skill folder (ai-governance-legal/skills/ai-inventory in zhou210712/claude-for-legal-ZH) into .claude/skills/ai-inventory in your project. Claude Code loads it when a task matches its description.

How do I install AI Inventory in Codex?

Run `npx skills add zhou210712/claude-for-legal-ZH --skill ai-inventory -a codex`. Or copy the skill folder (ai-governance-legal/skills/ai-inventory in zhou210712/claude-for-legal-ZH) into .agents/skills/ai-inventory in your project. Codex loads it when a task matches its description.

Can I use AI Inventory in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zhou210712/claude-for-legal-ZH --skill ai-inventory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-inventory, .gemini/skills/ai-inventory, .github/skills/ai-inventory and .opencode/skills/ai-inventory in your project.

What does AI Inventory need to run?

SKILL.md names no scripts, command-line tools or credentials: AI Inventory is instructions for the agent only.

Does AI Inventory access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AI Inventory safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AI Inventory use?

AI Inventory is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Inventory use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AI Inventory?

Skills that share tags, products or a category with AI Inventory: Paper to Chinese Patent Drafter (Yuan1z0825/nature-skills, 47k stars), C15t (c15t/c15t, 1.9k stars), Contract Review (evolsb/claude-legal-skill, 464 stars) and Legal Clinic Client Intake (anthropics/claude-for-legal, 9.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Inventory?

zhou210712 (a GitHub user) maintains it in zhou210712/claude-for-legal-ZH, which has 225 GitHub stars. The repository holds 122 skills in this directory. The repository was last updated on May 15, 2026.

Source: zhou210712/claude-for-legal-ZH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.