feat: compliance-engineer skill package v0.1.0
This commit is contained in:
31
PROVENANCE.md
Normal file
31
PROVENANCE.md
Normal file
@@ -0,0 +1,31 @@
|
||||
# Data provenance — compliance-engineer
|
||||
|
||||
Where the content of this skill package comes from, counted by
|
||||
content items (tasks, competences, tools, evidence entries, curated
|
||||
knowledge). Rendered live by Gitea:
|
||||
|
||||
```mermaid
|
||||
%%{init: {'theme':'base','themeVariables':{'pie1':'#f9a825','pie2':'#1e88e5','pie3':'#ff355e','pie4':'#d97757','pie5':'#8e24aa','pieOuterStrokeWidth':'0px','pieSectionTextColor':'#fff'}}}%%
|
||||
pie showData
|
||||
title Content sources — compliance-engineer
|
||||
"ESCO (occupation & competences)" : 39
|
||||
"O*NET (tasks & tools)" : 50
|
||||
"Job boards (market evidence)" : 47
|
||||
"Anthropic official Claude skills" : 5
|
||||
"External AI skill packs (mapped)" : 162
|
||||
```
|
||||
|
||||
| Source | Items | Share | Files |
|
||||
|---|---|---|---|
|
||||
| ESCO (occupation & competences) | 39 | 12.9 % | references/profile.md, references/skills.md |
|
||||
| O*NET (tasks & tools) | 50 | 16.5 % | references/tasks.md, references/tools.md |
|
||||
| Job boards (market evidence) | 47 | 15.5 % | references/market.md (full report) + "Market evidence" headline sections |
|
||||
| Wikipedia & AI expert curation | 0 | 0.0 % | glossary, literature, usecases, intake, quality, evals/ |
|
||||
| Anthropic official Claude skills | 5 | 1.7 % | references/ai-skills.md, section "anthropics/skills" (official Claude Code skills) |
|
||||
| External AI skill packs (mapped) | 162 | 53.5 % | references/ai-skills.md (per-source attribution inside) |
|
||||
| Stack Exchange practitioner Q&A (CC-BY-SA) | 0 | 0.0 % | references/practitioner-qa.md (per-entry attribution inside) |
|
||||
|
||||
Licensing: O*NET (USDOL/ETA, CC BY 4.0) · ESCO (© European Union) ·
|
||||
job-ad evidence via official APIs (JSearch/Adzuna) · Wikipedia content
|
||||
paraphrased with source URLs — never copied · external AI skills are
|
||||
linked, not copied (Apache-2.0/MIT/source-available, see ai-skills.md).
|
||||
56
SKILL.md
Normal file
56
SKILL.md
Normal file
@@ -0,0 +1,56 @@
|
||||
---
|
||||
name: compliance-engineer
|
||||
description: "Occupational skill for the role 'compliance engineer' (also: compliance engineering consultant, compliance engineering expert, compliance engineering specialist, compliance engineering adviser, compliance engineers). Use when the user asks for typical compliance engineer work such as: Warn violators of infractions or penalties.; Evaluate applications, records, or documents to gather information about eligibility or liability issues.; Advise licensees or other individuals or groups concerning licensing, permit, or passport regulations."
|
||||
---
|
||||
|
||||
# Compliance Engineer
|
||||
|
||||
Compliance engineers strive to keep the highest compliance of systems with engineering specifications. They can exert compliance in a varied array of engineering fields including mechanical, electrical, electronical systems. They ensure the engineering complies with regulations, safety measures, and internal directives.
|
||||
|
||||
## Core workflow
|
||||
|
||||
1. Warn violators of infractions or penalties.
|
||||
2. Evaluate applications, records, or documents to gather information about eligibility or liability issues.
|
||||
3. Advise licensees or other individuals or groups concerning licensing, permit, or passport regulations.
|
||||
4. Prepare reports of activities, evaluations, recommendations, or decisions.
|
||||
5. Report law or regulation violations to appropriate boards or agencies.
|
||||
6. Confer with or interview officials, technical or professional specialists, or applicants to obtain information or to clarify facts relevant to licensing decisions.
|
||||
|
||||
## How to use this skill
|
||||
|
||||
- Read [references/profile.md](references/profile.md) for the occupation profile and scope.
|
||||
- Consult [references/tasks.md](references/tasks.md) for the full task and activity inventory.
|
||||
- Check [references/skills.md](references/skills.md) for essential vs. optional competences.
|
||||
- Check [references/tools.md](references/tools.md) for the software commonly used in this role.
|
||||
- See [references/ai-skills.md](references/ai-skills.md) — matched external AI agent skills (per-source attribution).
|
||||
|
||||
## Key competences (essential)
|
||||
|
||||
- create manufacturing guidelines
|
||||
- define technical requirements
|
||||
- engineering principles
|
||||
- engineering processes
|
||||
- ensure compliance with legal requirements
|
||||
- interpret technical requirements
|
||||
- manage engineering project
|
||||
- manufacturing processes
|
||||
- perform inspections required by international conventions
|
||||
- perform scientific research
|
||||
- project management
|
||||
- quality standards
|
||||
- technical drawings
|
||||
- use technical drawing software
|
||||
- write specifications
|
||||
|
||||
## Hot technologies
|
||||
|
||||
- Microsoft Access
|
||||
- Microsoft Outlook
|
||||
- Microsoft Office software
|
||||
- Microsoft Windows
|
||||
- Microsoft PowerPoint
|
||||
- Microsoft Excel
|
||||
- Microsoft Word
|
||||
|
||||
---
|
||||
*Sources: ESCO v1.2.1 (http://data.europa.eu/esco/occupation/a950e88b-cb5e-4a7d-8a94-3f9460b487d7), O*NET 30.3 (13-1041.00). See manifest.json for licensing/attribution.*
|
||||
244
manifest.json
Normal file
244
manifest.json
Normal file
@@ -0,0 +1,244 @@
|
||||
{
|
||||
"name": "compliance-engineer",
|
||||
"title": "compliance engineer",
|
||||
"version": "0.1.0",
|
||||
"layer": "core",
|
||||
"language": "en",
|
||||
"generated": "2026-07-07",
|
||||
"ids": {
|
||||
"esco_uri": "http://data.europa.eu/esco/occupation/a950e88b-cb5e-4a7d-8a94-3f9460b487d7",
|
||||
"esco_code": "2149.2.7.1",
|
||||
"isco_group": "2149",
|
||||
"onet_soc": "13-1041.00",
|
||||
"crosswalk_match": "closeMatch"
|
||||
},
|
||||
"sources": [
|
||||
{
|
||||
"name": "ESCO",
|
||||
"version": "1.2.1",
|
||||
"url": "https://esco.ec.europa.eu/"
|
||||
},
|
||||
{
|
||||
"name": "O*NET",
|
||||
"version": "30.3",
|
||||
"url": "https://www.onetcenter.org/",
|
||||
"license": "CC BY 4.0"
|
||||
}
|
||||
],
|
||||
"attribution": "This package includes information from the O*NET Database (v30.3) by the U.S. Department of Labor, Employment and Training Administration (USDOL/ETA), CC BY 4.0. skillfactor is not endorsed by USDOL/ETA. ESCO data (v1.2.1) (c) European Union, used per the ESCO download conditions: https://esco.ec.europa.eu/en/use-esco/download",
|
||||
"counts": {
|
||||
"tasks": 16,
|
||||
"dwas": 17,
|
||||
"skills_essential": 15,
|
||||
"skills_optional": 23,
|
||||
"software": 16
|
||||
},
|
||||
"enrichment_ai_skills": {
|
||||
"generated": "2026-07-14",
|
||||
"method": "deterministic mapping (ISCO prefix + title/competence keywords)",
|
||||
"sources": {
|
||||
"anthropics/skills": {
|
||||
"repo": "https://github.com/anthropics/skills",
|
||||
"commit": "f6656c1",
|
||||
"license": "Apache-2.0; the document skills (docx/pdf/pptx/xlsx) are source-available \u2014 see the LICENSE.txt in the upstream skill folder",
|
||||
"skills": 2
|
||||
},
|
||||
"vibeeval/vibecosystem": {
|
||||
"repo": "https://github.com/vibeeval/vibecosystem",
|
||||
"commit": "cea9462",
|
||||
"license": "MIT",
|
||||
"skills": 3
|
||||
},
|
||||
"mukul975/Anthropic-Cybersecurity-Skills": {
|
||||
"repo": "https://github.com/mukul975/Anthropic-Cybersecurity-Skills",
|
||||
"commit": "673da1f",
|
||||
"license": "Apache-2.0",
|
||||
"skills": 8
|
||||
},
|
||||
"mohitagw15856/pm-claude-skills": {
|
||||
"repo": "https://github.com/mohitagw15856/pm-claude-skills",
|
||||
"commit": "876fa30",
|
||||
"license": "MIT",
|
||||
"skills": 2
|
||||
},
|
||||
"davila7/claude-code-templates": {
|
||||
"repo": "https://github.com/davila7/claude-code-templates",
|
||||
"commit": "fa79251",
|
||||
"license": "MIT",
|
||||
"skills": 7
|
||||
},
|
||||
"rohitg00/skillkit": {
|
||||
"repo": "https://github.com/rohitg00/skillkit",
|
||||
"commit": "d2e5c34",
|
||||
"license": "Apache-2.0",
|
||||
"skills": 1
|
||||
},
|
||||
"alirezarezvani/claude-skills": {
|
||||
"repo": "https://github.com/alirezarezvani/claude-skills",
|
||||
"commit": "0241f43",
|
||||
"license": "MIT",
|
||||
"skills": 2
|
||||
},
|
||||
"a5c-ai/babysitter": {
|
||||
"repo": "https://github.com/a5c-ai/babysitter",
|
||||
"commit": "44a5d58b",
|
||||
"license": "MIT",
|
||||
"skills": 10
|
||||
},
|
||||
"brycewang-stanford/Auto-Empirical-Research-Skills": {
|
||||
"repo": "https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills",
|
||||
"commit": "85bf545",
|
||||
"license": "CC-BY-4.0",
|
||||
"skills": 3
|
||||
},
|
||||
"nWave-ai/nWave": {
|
||||
"repo": "https://github.com/nWave-ai/nWave",
|
||||
"commit": "1d0f13c",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"zxkane/aws-skills": {
|
||||
"repo": "https://github.com/zxkane/aws-skills",
|
||||
"commit": "68530c6",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"rsmdt/the-startup": {
|
||||
"repo": "https://github.com/rsmdt/the-startup",
|
||||
"commit": "ff6a0be",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"jeremylongshore/claude-code-plugins-plus-skills": {
|
||||
"repo": "https://github.com/jeremylongshore/claude-code-plugins-plus-skills",
|
||||
"commit": "e112938a",
|
||||
"license": "MIT",
|
||||
"skills": 12
|
||||
},
|
||||
"K-Dense-AI/claude-scientific-skills": {
|
||||
"repo": "https://github.com/K-Dense-AI/claude-scientific-skills",
|
||||
"commit": "4d97e29",
|
||||
"license": "MIT",
|
||||
"skills": 4
|
||||
},
|
||||
"foryourhealth111-pixel/Vibe-Skills": {
|
||||
"repo": "https://github.com/foryourhealth111-pixel/Vibe-Skills",
|
||||
"commit": "34429a8",
|
||||
"license": "Apache-2.0",
|
||||
"skills": 4
|
||||
},
|
||||
"K-Dense-AI/scientific-agent-skills": {
|
||||
"repo": "https://github.com/K-Dense-AI/scientific-agent-skills",
|
||||
"commit": "4d97e29",
|
||||
"license": "MIT",
|
||||
"skills": 4
|
||||
},
|
||||
"zebbern/claude-code-guide": {
|
||||
"repo": "https://github.com/zebbern/claude-code-guide",
|
||||
"commit": "d2c5280",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"Sushegaad/Claude-Skills-Governance-Risk-and-Compliance": {
|
||||
"repo": "https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance",
|
||||
"commit": "71d8920",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"SnailSploit/Claude-Red": {
|
||||
"repo": "https://github.com/SnailSploit/Claude-Red",
|
||||
"commit": "aeb41ec",
|
||||
"license": "MIT",
|
||||
"skills": 2
|
||||
},
|
||||
"0xwilliamortiz/claude-red": {
|
||||
"repo": "https://github.com/0xwilliamortiz/claude-red",
|
||||
"commit": "ad8436b",
|
||||
"license": "MIT",
|
||||
"skills": 2
|
||||
},
|
||||
"kazukinagata/shinkoku": {
|
||||
"repo": "https://github.com/kazukinagata/shinkoku",
|
||||
"commit": "e610b30",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"alirezarezvani/claude-code-skill-factory": {
|
||||
"repo": "https://github.com/alirezarezvani/claude-code-skill-factory",
|
||||
"commit": "ba18b31",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"secondsky/claude-skills": {
|
||||
"repo": "https://github.com/secondsky/claude-skills",
|
||||
"commit": "c4889f6",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"open-gitagent/opengap": {
|
||||
"repo": "https://github.com/open-gitagent/opengap",
|
||||
"commit": "d7a8e2e",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"microsoft/skills": {
|
||||
"repo": "https://github.com/microsoft/skills",
|
||||
"commit": "dc543aa",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"giuseppe-trisciuoglio/developer-kit": {
|
||||
"repo": "https://github.com/giuseppe-trisciuoglio/developer-kit",
|
||||
"commit": "306f428",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"JuliusBrussee/caveman": {
|
||||
"repo": "https://github.com/JuliusBrussee/caveman",
|
||||
"commit": "0d95a81",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"luongnv89/claude-howto": {
|
||||
"repo": "https://github.com/luongnv89/claude-howto",
|
||||
"commit": "a645ffe",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"code-yeongyu/oh-my-openagent": {
|
||||
"repo": "https://github.com/code-yeongyu/oh-my-openagent",
|
||||
"commit": "b19f652",
|
||||
"license": "custom (see upstream LICENSE)",
|
||||
"skills": 1
|
||||
}
|
||||
},
|
||||
"total_skills": 80,
|
||||
"tiers": {
|
||||
"core": 78,
|
||||
"adjacent": 2
|
||||
}
|
||||
},
|
||||
"provenance": {
|
||||
"items": {
|
||||
"esco": 39,
|
||||
"onet": 50,
|
||||
"jobads": 47,
|
||||
"wiki_ai": 0,
|
||||
"anthropic": 5,
|
||||
"ai_skills": 162,
|
||||
"stackx": 0
|
||||
},
|
||||
"share_percent": {
|
||||
"esco": 12.9,
|
||||
"onet": 16.5,
|
||||
"jobads": 15.5,
|
||||
"wiki_ai": 0.0,
|
||||
"anthropic": 1.7,
|
||||
"ai_skills": 53.5,
|
||||
"stackx": 0.0
|
||||
},
|
||||
"method": "content items per source category"
|
||||
},
|
||||
"collar": "white",
|
||||
"computer_work": true
|
||||
}
|
||||
330
references/ai-skills.md
Normal file
330
references/ai-skills.md
Normal file
@@ -0,0 +1,330 @@
|
||||
# External AI agent skills — compliance-engineer
|
||||
|
||||
Proven, publicly available AI agent skills mapped to this occupation.
|
||||
Nothing is copied from the sources: every entry is a name, a one-line
|
||||
summary and a link to the upstream skill package. Each section names
|
||||
its source repository, commit, license and retrieval date.
|
||||
|
||||
**Tiers:** `core` = the skill directly exercises a top market hard
|
||||
skill, tool or method (from gated job-ad evidence) or an essential
|
||||
ESCO competence of this occupation; `adjacent` =
|
||||
plausibly useful, secondary. Entries are capped at 12 per source
|
||||
and 80 in total per occupation (core first,
|
||||
strongest matches survive); everything beyond the caps is excluded
|
||||
and logged in the pipeline audit trail, not in this package.
|
||||
|
||||
_Matched deterministically (ISCO group + title/competence keywords,
|
||||
tiered against market evidence + ESCO essentials) by
|
||||
`pipeline/p5_enrich_ai_skills.py` on 2026-07-14._
|
||||
|
||||
## Source: anthropics/skills
|
||||
|
||||
- Repository: [https://github.com/anthropics/skills](https://github.com/anthropics/skills) (commit `f6656c1`, retrieved 2026-07-14)
|
||||
- License: Apache-2.0; the document skills (docx/pdf/pptx/xlsx) are source-available — see the LICENSE.txt in the upstream skill folder
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `docx` | adjacent | Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to … | [source](https://github.com/anthropics/skills/tree/main/skills/docx) |
|
||||
| `pdf` | adjacent | Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text/tables from PDFs, combining or merging multiple PDFs into one, splitting PDFs apart, rotating pages, adding watermarks, creating … | [source](https://github.com/anthropics/skills/tree/main/skills/pdf) |
|
||||
|
||||
## Source: 0xwilliamortiz/claude-red
|
||||
|
||||
- Repository: [https://github.com/0xwilliamortiz/claude-red](https://github.com/0xwilliamortiz/claude-red) (commit `ad8436b`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `offensive-cloud` | core | Cloud security attack methodology covering AWS, Azure, and GCP. Includes credential harvesting (IMDS, ~/.aws, env vars, leaked CI secrets, instance roles), enumeration with cloud-specific tools (pacu, ScoutSuite, Prowler, ROADtools, … | [source](https://github.com/0xwilliamortiz/claude-red/tree/ad8436b/Skills/cloud/offensive-cloud) |
|
||||
| `offensive-reporting` | core | Penetration test and red team report writing methodology. Covers executive summary structuring (risk-led narrative for non-technical readers), technical finding format (title, severity, affected scope, narrative, reproduction steps, … | [source](https://github.com/0xwilliamortiz/claude-red/tree/ad8436b/Skills/utility/offensive-reporting) |
|
||||
|
||||
## Source: a5c-ai/babysitter
|
||||
|
||||
- Repository: [https://github.com/a5c-ai/babysitter](https://github.com/a5c-ai/babysitter) (commit `44a5d58b`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `constitution-creation` | core | Establish project governing principles including dev guidelines, code quality standards, testing policies, UX requirements, performance benchmarks, and security constraints. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/methodologies/spec-kit/skills/constitution-creation) |
|
||||
| `accreditation-tracer-simulation` | core | Simulate Joint Commission tracer methodology to assess compliance with accreditation standards across patient care processes and support systems | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/social-sciences-humanities/healthcare/skills/accreditation-tracer-simulation) |
|
||||
| `regulatory-compliance-assessment` | core | Evaluate organizational compliance with healthcare regulations including HIPAA, CMS Conditions of Participation, and accreditation standards through gap analysis and audit procedures | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/social-sciences-humanities/healthcare/skills/regulatory-compliance-assessment) |
|
||||
| `compliance-checker` | core | Check compliance with SOC 2, GDPR, HIPAA, and PCI-DSS standards | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/software-architecture/skills/compliance-checker) |
|
||||
| `iso-nanotechnology-compliance-checker` | core | Regulatory compliance skill for ISO nanotechnology standards verification and documentation | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/science/nanotechnology/skills/iso-nanotechnology-compliance-checker) |
|
||||
| `production-coordination` | core | Coordinate all aspects of live performance production including scheduling, technical requirements, artist contracts, venue logistics, and show documentation | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/social-sciences-humanities/arts-culture/skills/production-coordination) |
|
||||
| `evm-analysis` | core | Deep EVM bytecode analysis and decompilation capabilities for smart contract security, gas optimization, and reverse engineering. Provides tools for analyzing opcodes, storage layouts, proxy patterns, and bytecode verification. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/evm-analysis) |
|
||||
| `license-compliance-checker` | core | Automated license compliance verification for dependencies to ensure legal compliance during migration | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/code-migration-modernization/skills/license-compliance-checker) |
|
||||
| `accessibility-compliance-auditing` | core | Evaluate learning materials and technology for WCAG, Section 508, and accessibility compliance with remediation recommendations | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/social-sciences-humanities/education/skills/accessibility-compliance-auditing) |
|
||||
| `interview-questions` | core | Generate competency-based and behavioral interview questions with legal compliance validation | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/domains/business/human-resources/skills/interview-questions) |
|
||||
|
||||
## Source: alirezarezvani/claude-code-skill-factory
|
||||
|
||||
- Repository: [https://github.com/alirezarezvani/claude-code-skill-factory](https://github.com/alirezarezvani/claude-code-skill-factory) (commit `ba18b31`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `tech-stack-evaluator` | core | Comprehensive technology stack evaluation and comparison tool with TCO analysis, security assessment, and intelligent recommendations for engineering teams | [source](https://github.com/alirezarezvani/claude-code-skill-factory/tree/ba18b31/generated-skills/tech-stack-evaluator) |
|
||||
|
||||
## Source: alirezarezvani/claude-skills
|
||||
|
||||
- Repository: [https://github.com/alirezarezvani/claude-skills](https://github.com/alirezarezvani/claude-skills) (commit `0241f43`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `ciso-advisor` | core | Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting. Use when … | [source](https://github.com/alirezarezvani/claude-skills/tree/0241f43/c-level-advisor/skills/ciso-advisor) |
|
||||
| `iso42001-specialist` | core | ISO/IEC 42001:2023 AI Management System (AIMS) specialist for compliance teams running internal audits. Three decisions: (1) Where are the gaps against Clauses 4-10 and what do we close first? (2) What goes in the AI risk register and … | [source](https://github.com/alirezarezvani/claude-skills/tree/0241f43/ra-qm-team/compliance-team-iso42001/skills/iso42001-specialist) |
|
||||
|
||||
## Source: brycewang-stanford/Auto-Empirical-Research-Skills
|
||||
|
||||
- Repository: [https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills) (commit `85bf545`, retrieved 2026-07-14)
|
||||
- License: CC-BY-4.0
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `law-skills` | core | 9 legal research skills. Trigger: legal research, case law analysis, regulatory compliance. Design: legal databases, citation networks, and judicial analytics tools. | [source](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills/tree/85bf545/skills/43-wentorai-research-plugins/skills/domains/law) |
|
||||
| `legal-research-guide` | core | Legal research methods, case law analysis, and compliance tools | [source](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills/tree/85bf545/skills/43-wentorai-research-plugins/skills/domains/law/legal-research-guide) |
|
||||
| `claude-scientific-guide` | core | Ready-to-use agent skills for scientific research and engineering | [source](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills/tree/85bf545/skills/43-wentorai-research-plugins/skills/research/methodology/claude-scientific-guide) |
|
||||
|
||||
## Source: code-yeongyu/oh-my-openagent
|
||||
|
||||
- Repository: [https://github.com/code-yeongyu/oh-my-openagent](https://github.com/code-yeongyu/oh-my-openagent) (commit `b19f652`, retrieved 2026-07-14)
|
||||
- License: custom (see upstream LICENSE)
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `debugging` | core | MUST USE for any real runtime debugging across ANY language or binary — crashes, silent failures, wrong responses, stuck processes, memory leaks, async misbehavior, unexplained timing, reverse engineering. Runs a hypothesis-driven loop: … | [source](https://github.com/code-yeongyu/oh-my-openagent/tree/b19f652/packages/shared-skills/skills/debugging) |
|
||||
|
||||
## Source: davila7/claude-code-templates
|
||||
|
||||
- Repository: [https://github.com/davila7/claude-code-templates](https://github.com/davila7/claude-code-templates) (commit `fa79251`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `security-compliance` | core | Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/development/security-compliance) |
|
||||
| `Accessibility Auditor` | core | Web accessibility specialist for WCAG compliance, ARIA implementation, and inclusive design. Use when auditing websites for accessibility issues, implementing WCAG 2.1 AA/AAA standards, testing with screen readers, or ensuring ADA … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/creative-design/accessibility-auditor) |
|
||||
| `Data Privacy Compliance` | core | Data privacy and regulatory compliance specialist for GDPR, CCPA, HIPAA, and international data protection laws. Use when implementing privacy controls, conducting data protection impact assessments, ensuring regulatory compliance, or … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/enterprise-communication/data-privacy-compliance) |
|
||||
| `lint-and-validate` | core | Automatic quality control, linting, and static analysis procedures. Use after every code modification to ensure syntax correctness and project standards. Triggers onKeywords: lint, format, check, validate, types, static analysis. | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/development/lint-and-validate) |
|
||||
| `gdpr-dsgvo-expert` | core | Senior GDPR/DSGVO expert and internal/external auditor for data protection compliance. Provides EU GDPR and German DSGVO expertise, privacy impact assessments, data protection auditing, and compliance verification. Use for GDPR compliance … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/enterprise-communication/gdpr-dsgvo-expert) |
|
||||
| `it-operations` | core | Manages IT infrastructure, monitoring, incident response, and service reliability. Provides frameworks for ITIL service management, observability strategies, automation, backup/recovery, capacity planning, and operational excellence … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/development/it-operations) |
|
||||
| `venue-templates` | core | Access comprehensive LaTeX templates, formatting requirements, and submission guidelines for major scientific publication venues (Nature, Science, PLOS, IEEE, ACM), academic conferences (NeurIPS, ICML, CVPR, CHI), research posters, and … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/scientific/venue-templates) |
|
||||
|
||||
## Source: foryourhealth111-pixel/Vibe-Skills
|
||||
|
||||
- Repository: [https://github.com/foryourhealth111-pixel/Vibe-Skills](https://github.com/foryourhealth111-pixel/Vibe-Skills) (commit `34429a8`, retrieved 2026-07-14)
|
||||
- License: Apache-2.0
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `peer-review` | core | Structured manuscript/grant review with checklist-based evaluation. Use when writing formal peer reviews with specific criteria methodology assessment, statistical validity, reporting standards compliance (CONSORT/STROBE), and constructive … | [source](https://github.com/foryourhealth111-pixel/Vibe-Skills/tree/34429a8/bundled/skills/peer-review) |
|
||||
| `scientific-reporting` | core | Write research/technical reports with strong structure + figure standards. Supports Markdown/HTML/PDF outputs (Quarto optional), executive summary, methods, results, discussion, and reproducibility appendix. | [source](https://github.com/foryourhealth111-pixel/Vibe-Skills/tree/34429a8/bundled/skills/scientific-reporting) |
|
||||
| `speckit-constitution` | core | Create or update project governing principles and development guidelines. Use at project start to establish code quality, testing standards, and architectural constraints that guide all development. | [source](https://github.com/foryourhealth111-pixel/Vibe-Skills/tree/34429a8/bundled/skills/speckit-constitution) |
|
||||
| `scholar-evaluation` | core | Systematically evaluate scholarly work using the ScholarEval framework, providing structured assessment across research quality dimensions including problem formulation, methodology, analysis, and writing with quantitative scoring and … | [source](https://github.com/foryourhealth111-pixel/Vibe-Skills/tree/34429a8/bundled/skills/scholar-evaluation) |
|
||||
|
||||
## Source: giuseppe-trisciuoglio/developer-kit
|
||||
|
||||
- Repository: [https://github.com/giuseppe-trisciuoglio/developer-kit](https://github.com/giuseppe-trisciuoglio/developer-kit) (commit `306f428`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `aws-cloudformation-iam` | core | Provides AWS CloudFormation patterns for IAM roles, policies, managed policies, permission boundaries, and trust relationships. Use when modeling least-privilege access, cross-account assumptions, service roles, or reusable IAM stacks that … | [source](https://github.com/giuseppe-trisciuoglio/developer-kit/tree/306f428/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-iam) |
|
||||
|
||||
## Source: jeremylongshore/claude-code-plugins-plus-skills
|
||||
|
||||
- Repository: [https://github.com/jeremylongshore/claude-code-plugins-plus-skills](https://github.com/jeremylongshore/claude-code-plugins-plus-skills) (commit `e112938a`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `cursor-compliance-audit` | core | Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation. Triggers on "cursor compliance", "cursor audit", "cursor security review", "cursor soc2", "cursor gdpr", "cursor … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/cursor-pack/skills/cursor-compliance-audit) |
|
||||
| `plugin-auditor` | core | Audit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance, and quality standards when user mentions audit plugin, security review, or best practices check. specific to AI … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/examples/jeremy-plugin-tool/skills/plugin-auditor) |
|
||||
| `adobe-data-handling` | core | Implement data handling for Adobe APIs including PII redaction in logs, Firefly content policy compliance, PDF document data classification, and GDPR/CCPA data subject access requests via Adobe Privacy Service. Trigger with phrases like … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/adobe-pack/skills/adobe-data-handling) |
|
||||
| `compliance-audit` | core | Performs regulatory gap analysis across 7 compliance frameworks with a scored report card and prioritized remediation roadmap. Use when assessing a website or application for GDPR, CCPA, ADA, PCI-DSS, CAN-SPAM, COPPA, or SOC 2 compliance. … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/business-tools/general-legal-assistant/skills/compliance-audit) |
|
||||
| `openrouter-compliance-review` | core | Review OpenRouter integration for regulatory compliance (SOC2, GDPR, HIPAA). Use when preparing for audits, evaluating data handling, or documenting compliance posture. Triggers: ''openrouter compliance'', ''openrouter gdpr'', ''openrouter … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/openrouter-pack/skills/openrouter-compliance-review) |
|
||||
| `snowflake-data-handling` | core | Implement Snowflake data governance with masking policies, row access policies, tagging, and GDPR/CCPA compliance patterns. Use when handling PII, implementing column masking, configuring data classification, or ensuring compliance with … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/snowflake-pack/skills/snowflake-data-handling) |
|
||||
| `deepgram-data-handling` | core | Implement audio data handling best practices for Deepgram integrations. Use when managing audio file storage, implementing data retention, or ensuring GDPR/HIPAA compliance for transcription data. Trigger: "deepgram data", "audio storage", … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/deepgram-pack/skills/deepgram-data-handling) |
|
||||
| `scanning-accessibility` | core | Validate WCAG compliance and accessibility standards (ARIA, keyboard navigation). Use when auditing WCAG compliance or screen reader compatibility. Trigger with phrases like "scan accessibility", "check WCAG compliance", or "validate … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/testing/accessibility-test-scanner/skills/scanning-accessibility) |
|
||||
| `validating-api-responses` | core | Validate API responses against schemas to ensure contract compliance and data integrity. Use when ensuring API response correctness. Trigger with phrases like "validate responses", "check API responses", or "verify response format". | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/api-development/api-response-validator/skills/validating-api-responses) |
|
||||
| `windsurf-code-privacy` | core | Configure code privacy and data retention policies. Activate when users mention "code privacy", "data retention", "privacy settings", "data governance", or "gdpr compliance". Handles privacy and data protection configuration. Use when … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/skill-databases/windsurf/skills/windsurf-code-privacy) |
|
||||
| `anth-data-handling` | core | Implement data privacy, PII handling, and compliance patterns for Claude API. Use when handling sensitive data, implementing PII redaction, or configuring data retention for GDPR/CCPA compliance with Claude. Trigger with phrases like … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/anthropic-pack/skills/anth-data-handling) |
|
||||
| `clay-data-handling` | core | Implement GDPR/CCPA-compliant data handling for Clay enrichment pipelines. Use when handling PII from enrichments, implementing data retention policies, or ensuring regulatory compliance for Clay-enriched lead data. Trigger with phrases … | [source](https://github.com/jeremylongshore/claude-code-plugins-plus-skills/tree/e112938a/plugins/saas-packs/clay-pack/skills/clay-data-handling) |
|
||||
|
||||
## Source: JuliusBrussee/caveman
|
||||
|
||||
- Repository: [https://github.com/JuliusBrussee/caveman](https://github.com/JuliusBrussee/caveman) (commit `0d95a81`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `caveman-compress` | core | Compress natural language memory files (CLAUDE.md, todos, preferences) into caveman format to save input tokens. Preserves all technical substance, code, URLs, and structure. Compressed version overwrites the original file. Human-readable … | [source](https://github.com/JuliusBrussee/caveman/tree/0d95a81/plugins/caveman/skills/caveman-compress) |
|
||||
|
||||
## Source: K-Dense-AI/claude-scientific-skills
|
||||
|
||||
- Repository: [https://github.com/K-Dense-AI/claude-scientific-skills](https://github.com/K-Dense-AI/claude-scientific-skills) (commit `4d97e29`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `peer-review` | core | Structured manuscript/grant review with checklist-based evaluation. Use when writing formal peer reviews with specific criteria methodology assessment, statistical validity, reporting standards compliance (CONSORT/STROBE), and constructive … | [source](https://github.com/K-Dense-AI/claude-scientific-skills/tree/4d97e29/skills/peer-review) |
|
||||
| `exa-search` | core | Web toolkit powered by Exa, tuned for scientific and technical content. Use this skill when the user needs to search the web or fetch/extract URL content. Covers: web search (semantic lookups, research, current info — with optional … | [source](https://github.com/K-Dense-AI/claude-scientific-skills/tree/4d97e29/skills/exa-search) |
|
||||
| `scholar-evaluation` | core | Systematically evaluate scholarly work using the ScholarEval framework, providing structured assessment across research quality dimensions including problem formulation, methodology, analysis, and writing with quantitative scoring and … | [source](https://github.com/K-Dense-AI/claude-scientific-skills/tree/4d97e29/skills/scholar-evaluation) |
|
||||
| `venue-templates` | core | Access comprehensive LaTeX templates, formatting requirements, and submission guidelines for major scientific publication venues (Nature, Science, PLOS, IEEE, ACM), academic conferences (NeurIPS, ICML, CVPR, CHI), research posters, and … | [source](https://github.com/K-Dense-AI/claude-scientific-skills/tree/4d97e29/skills/venue-templates) |
|
||||
|
||||
## Source: K-Dense-AI/scientific-agent-skills
|
||||
|
||||
- Repository: [https://github.com/K-Dense-AI/scientific-agent-skills](https://github.com/K-Dense-AI/scientific-agent-skills) (commit `4d97e29`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `peer-review` | core | Structured manuscript/grant review with checklist-based evaluation. Use when writing formal peer reviews with specific criteria methodology assessment, statistical validity, reporting standards compliance (CONSORT/STROBE), and constructive … | [source](https://github.com/K-Dense-AI/scientific-agent-skills/tree/4d97e29/skills/peer-review) |
|
||||
| `exa-search` | core | Web toolkit powered by Exa, tuned for scientific and technical content. Use this skill when the user needs to search the web or fetch/extract URL content. Covers: web search (semantic lookups, research, current info — with optional … | [source](https://github.com/K-Dense-AI/scientific-agent-skills/tree/4d97e29/skills/exa-search) |
|
||||
| `scholar-evaluation` | core | Systematically evaluate scholarly work using the ScholarEval framework, providing structured assessment across research quality dimensions including problem formulation, methodology, analysis, and writing with quantitative scoring and … | [source](https://github.com/K-Dense-AI/scientific-agent-skills/tree/4d97e29/skills/scholar-evaluation) |
|
||||
| `venue-templates` | core | Access comprehensive LaTeX templates, formatting requirements, and submission guidelines for major scientific publication venues (Nature, Science, PLOS, IEEE, ACM), academic conferences (NeurIPS, ICML, CVPR, CHI), research posters, and … | [source](https://github.com/K-Dense-AI/scientific-agent-skills/tree/4d97e29/skills/venue-templates) |
|
||||
|
||||
## Source: kazukinagata/shinkoku
|
||||
|
||||
- Repository: [https://github.com/kazukinagata/shinkoku](https://github.com/kazukinagata/shinkoku) (commit `e610b30`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `tax-ebookkeeping-context` | core | Background context for the Electronic Bookkeeping Act (電子帳簿保存法) in the shinkoku tax filing plugin. Contains requirements for electronic bookkeeping, scanner storage, mandatory electronic transaction data storage, and shinkoku's compliance … | [source](https://github.com/kazukinagata/shinkoku/tree/e610b30/skills/tax-ebookkeeping-context) |
|
||||
|
||||
## Source: luongnv89/claude-howto
|
||||
|
||||
- Repository: [https://github.com/luongnv89/claude-howto](https://github.com/luongnv89/claude-howto) (commit `a645ffe`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `code-refactor` | core | Systematic code refactoring based on Martin Fowler's methodology. Use when users ask to refactor code, improve code structure, reduce technical debt, clean up legacy code, eliminate code smells, or improve code maintainability. This skill … | [source](https://github.com/luongnv89/claude-howto/tree/a645ffe/03-skills/refactor) |
|
||||
|
||||
## Source: microsoft/skills
|
||||
|
||||
- Repository: [https://github.com/microsoft/skills](https://github.com/microsoft/skills) (commit `dc543aa`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `wiki-page-writer` | core | Generates rich technical documentation pages with dark-mode Mermaid diagrams, source code citations, and first-principles depth. Use when writing documentation, generating wiki pages, creating technical deep-dives, or documenting specific … | [source](https://github.com/microsoft/skills/tree/dc543aa/.github/plugins/deep-wiki/skills/wiki-page-writer) |
|
||||
|
||||
## Source: mohitagw15856/pm-claude-skills
|
||||
|
||||
- Repository: [https://github.com/mohitagw15856/pm-claude-skills](https://github.com/mohitagw15856/pm-claude-skills) (commit `876fa30`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `engineering-hiring-rubric` | core | Build an engineering hiring rubric and technical interview scorecard for evaluating software engineers at a specific level. Use when asked to create an interview rubric, design a hiring process, build a technical scorecard, or standardize … | [source](https://github.com/mohitagw15856/pm-claude-skills/tree/876fa30/plugins/pm-engineering/skills/engineering-hiring-rubric) |
|
||||
| `compliance-checklist` | core | Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any … | [source](https://github.com/mohitagw15856/pm-claude-skills/tree/876fa30/plugins/pm-legal/skills/compliance-checklist) |
|
||||
|
||||
## Source: mukul975/Anthropic-Cybersecurity-Skills
|
||||
|
||||
- Repository: [https://github.com/mukul975/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills) (commit `673da1f`, retrieved 2026-07-14)
|
||||
- License: Apache-2.0
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `implementing-aws-security-hub-compliance` | core | Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-aws-security-hub-compliance) |
|
||||
| `achieving-cmmc-level-2-compliance` | core | Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/achieving-cmmc-level-2-compliance) |
|
||||
| `hardening-linux-endpoint-with-cis-benchmark` | core | Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Linux servers, remediating audit … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/hardening-linux-endpoint-with-cis-benchmark) |
|
||||
| `hardening-windows-endpoint-with-cis-benchmark` | core | Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. Use when deploying new Windows workstations or servers, … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/hardening-windows-endpoint-with-cis-benchmark) |
|
||||
| `implementing-aws-security-hub` | core | This skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that aggregates findings from GuardDuty, Inspector, Macie, and third-party tools. It details enabling security standards like CIS AWS … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-aws-security-hub) |
|
||||
| `auditing-cloud-with-cis-benchmarks` | core | This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/auditing-cloud-with-cis-benchmarks) |
|
||||
| `securing-aws-iam-permissions` | core | This skill guides practitioners through hardening AWS Identity and Access Management configurations to enforce least privilege access across cloud accounts. It covers IAM policy scoping, permission boundaries, Access Analyzer integration, … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/securing-aws-iam-permissions) |
|
||||
| `implementing-security-chaos-engineering` | core | Implements security chaos engineering experiments that deliberately disable or degrade security controls to verify detection and response capabilities. Tests WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-security-chaos-engineering) |
|
||||
|
||||
## Source: nWave-ai/nWave
|
||||
|
||||
- Repository: [https://github.com/nWave-ai/nWave](https://github.com/nWave-ai/nWave) (commit `1d0f13c`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `nw-security-and-governance` | core | Database security (encryption, access control, injection prevention), data governance (lineage, quality, MDM), and compliance frameworks (GDPR, CCPA, HIPAA) | [source](https://github.com/nWave-ai/nWave/tree/1d0f13c/nWave/skills/nw-security-and-governance) |
|
||||
|
||||
## Source: open-gitagent/opengap
|
||||
|
||||
- Repository: [https://github.com/open-gitagent/opengap](https://github.com/open-gitagent/opengap) (commit `d7a8e2e`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `document-review` | core | Reviews financial documents (prospectuses, ADVs, marketing materials) for FINRA 2210 compliance, required disclosures, and balanced presentation. Use when reviewing financial statements, audit documents, regulatory filings, or when the … | [source](https://github.com/open-gitagent/opengap/tree/d7a8e2e/examples/full/skills/document-review) |
|
||||
|
||||
## Source: rohitg00/skillkit
|
||||
|
||||
- Repository: [https://github.com/rohitg00/skillkit](https://github.com/rohitg00/skillkit) (commit `d2e5c34`, retrieved 2026-07-14)
|
||||
- License: Apache-2.0
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `structured-code-review` | core | Performs a structured five-stage code review covering requirements compliance, correctness, code quality, testing, and security/performance. Each stage uses targeted checklists and categorized feedback (Blocker/Major/Minor/Nit) with … | [source](https://github.com/rohitg00/skillkit/tree/d2e5c34/packages/core/src/methodology/packs/collaboration/structured-review) |
|
||||
|
||||
## Source: rsmdt/the-startup
|
||||
|
||||
- Repository: [https://github.com/rsmdt/the-startup](https://github.com/rsmdt/the-startup) (commit `ff6a0be`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `code-quality-review` | core | Unified code review skill for correctness, design, readability, security, performance, testability, accessibility, and error-handling conventions. Use when reviewing changes, enforcing quality standards, or identifying technical debt. | [source](https://github.com/rsmdt/the-startup/tree/ff6a0be/plugins/team/skills/quality/code-quality-review) |
|
||||
|
||||
## Source: secondsky/claude-skills
|
||||
|
||||
- Repository: [https://github.com/secondsky/claude-skills](https://github.com/secondsky/claude-skills) (commit `c4889f6`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `woocommerce-code-review` | core | Review WooCommerce code changes for coding standards compliance. Use when reviewing code locally, performing automated PR reviews, or checking code quality in WooCommerce projects. | [source](https://github.com/secondsky/claude-skills/tree/c4889f6/plugins/woocommerce-code-review/skills/woocommerce-code-review) |
|
||||
|
||||
## Source: SnailSploit/Claude-Red
|
||||
|
||||
- Repository: [https://github.com/SnailSploit/Claude-Red](https://github.com/SnailSploit/Claude-Red) (commit `aeb41ec`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `offensive-cloud` | core | Cloud security attack methodology covering AWS, Azure, and GCP. Includes credential harvesting (IMDS, ~/.aws, env vars, leaked CI secrets, instance roles), enumeration with cloud-specific tools (pacu, ScoutSuite, Prowler, ROADtools, … | [source](https://github.com/SnailSploit/Claude-Red/tree/aeb41ec/Skills/cloud/offensive-cloud) |
|
||||
| `offensive-reporting` | core | Penetration test and red team report writing methodology. Covers executive summary structuring (risk-led narrative for non-technical readers), technical finding format (title, severity, affected scope, narrative, reproduction steps, … | [source](https://github.com/SnailSploit/Claude-Red/tree/aeb41ec/Skills/utility/offensive-reporting) |
|
||||
|
||||
## Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
|
||||
|
||||
- Repository: [https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) (commit `71d8920`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `gdpr-compliance` | core | Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing Agreements (DPAs), and consent notices, … | [source](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/71d8920/plugins/gdpr-compliance/skills/gdpr-compliance) |
|
||||
|
||||
## Source: vibeeval/vibecosystem
|
||||
|
||||
- Repository: [https://github.com/vibeeval/vibecosystem](https://github.com/vibeeval/vibecosystem) (commit `cea9462`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `hipaa-compliance` | core | HIPAA compliance - PHI protection, technical/administrative/physical safeguards, minimum necessary standard, BAA requirements, de-identification, access logging | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/hipaa-compliance) |
|
||||
| `compliance-patterns` | core | GDPR data handling, audit logging, data classification, retention policies, and consent management for regulatory compliance. | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/compliance-patterns) |
|
||||
| `kvkk-compliance` | core | KVKK and GDPR compliance patterns - consent management, right to erasure, breach notification, audit logging, cookie consent, and data classification. | [source](https://github.com/vibeeval/vibecosystem/tree/cea9462/skills/kvkk-compliance) |
|
||||
|
||||
## Source: zebbern/claude-code-guide
|
||||
|
||||
- Repository: [https://github.com/zebbern/claude-code-guide](https://github.com/zebbern/claude-code-guide) (commit `d2c5280`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `regulatory-audit-generator` | core | Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like \"run … | [source](https://github.com/zebbern/claude-code-guide/tree/d2c5280/skills/regulatory-audit-generator) |
|
||||
|
||||
## Source: zxkane/aws-skills
|
||||
|
||||
- Repository: [https://github.com/zxkane/aws-skills](https://github.com/zxkane/aws-skills) (commit `68530c6`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `aws-cost-operations` | core | AWS cost optimization, monitoring, and operational excellence expert. Use when analyzing AWS bills, estimating costs, setting up CloudWatch alarms, querying logs, auditing CloudTrail activity, or assessing security posture. Essential when … | [source](https://github.com/zxkane/aws-skills/tree/68530c6/plugins/aws-cost-ops/skills/aws-cost-operations) |
|
||||
90
references/market.md
Normal file
90
references/market.md
Normal file
@@ -0,0 +1,90 @@
|
||||
# Market evidence report — compliance-engineer
|
||||
|
||||
Source: **20 real job ads** (JSearch API, countries: us 20), extracted into the MSSQL evidence store; as of 2026-07-10.
|
||||
This report contains extracted, aggregated facts only — no ad text is
|
||||
reproduced (copyright / platform terms).
|
||||
|
||||
## Seniority distribution
|
||||
|
||||
| Seniority | Ads | Share |
|
||||
|---|---|---|
|
||||
| mid | 9 | 45 % |
|
||||
| senior | 6 | 30 % |
|
||||
| junior | 2 | 10 % |
|
||||
| lead | 2 | 10 % |
|
||||
| n/a | 1 | 5 % |
|
||||
|
||||
## Tools — full market ranking
|
||||
|
||||
| # | Item | Ads | Share |
|
||||
|---|---|---|---|
|
||||
| 1 | Azure | 4 | 20 % |
|
||||
| 2 | AWS | 3 | 15 % |
|
||||
| 3 | CAD | 3 | 15 % |
|
||||
| 4 | Jenkins | 3 | 15 % |
|
||||
| 5 | Microsoft Office | 3 | 15 % |
|
||||
| 6 | Terraform | 3 | 15 % |
|
||||
|
||||
## Hard skills — full market ranking
|
||||
|
||||
| # | Item | Ads | Share |
|
||||
|---|---|---|---|
|
||||
| 1 | regulatory compliance | 6 | 30 % |
|
||||
| 2 | risk management | 5 | 25 % |
|
||||
| 3 | incident response | 4 | 20 % |
|
||||
| 4 | technical documentation | 4 | 20 % |
|
||||
| 5 | compliance implementation | 3 | 15 % |
|
||||
| 6 | risk assessment | 3 | 15 % |
|
||||
|
||||
## Methods — full market ranking
|
||||
|
||||
| # | Item | Ads | Share |
|
||||
|---|---|---|---|
|
||||
|
||||
## Responsibilities — full market ranking
|
||||
|
||||
| # | Item | Ads | Share |
|
||||
|---|---|---|---|
|
||||
| 1 | compliance documentation maintenance | 3 | 15 % |
|
||||
|
||||
## Regional breakdown
|
||||
|
||||
> **Corpus note:** 20 relevant ads in total — below the 100-ad target for a fully reliable ranking. Percentages above should be read as indicative.
|
||||
|
||||
### US (us)
|
||||
|
||||
**Insufficient evidence** — 20 ads (minimum for a regional ranking: 30). No ranking is reported for this region.
|
||||
|
||||
### UK (gb)
|
||||
|
||||
**Insufficient evidence** — 0 ads (minimum for a regional ranking: 30). No ranking is reported for this region.
|
||||
|
||||
### EU/DACH (de, at, ch, nl)
|
||||
|
||||
**Insufficient evidence** — 0 ads (minimum for a regional ranking: 30). No ranking is reported for this region.
|
||||
|
||||
|
||||
## Job title variants in the market
|
||||
|
||||
| Title | Ads |
|
||||
|---|---|
|
||||
| Compliance Engineer | 3 |
|
||||
| Certification Engineer: AI‑Driven Compliance & Product Safety | 1 |
|
||||
| Compliance Engineering | 1 |
|
||||
| Data Governance & Compliance Engineer | 1 |
|
||||
| DevSecOps Compliance Engineer | 1 |
|
||||
| Global Safety & Compliance Engineer - High-Power Systems | 1 |
|
||||
| Governance Risk and Compliance Engineer | 1 |
|
||||
| Lead Compliance Engineer | 1 |
|
||||
| Principal Compliance Engineer | 1 |
|
||||
| REGULATORY AND COMPLIANCE ENGINEER/ ARCHITECT I | 1 |
|
||||
| Regulatory Compliance Engineer - Electrical Power Systems | 1 |
|
||||
| Security & Compliance Engineer | 1 |
|
||||
| Senior Cybersecurity Compliance Engineer | 1 |
|
||||
| Senior Governance, Risk, and Compliance Engineer | 1 |
|
||||
| Senior Product Safety & Compliance Engineer High-Voltage & MIL-STD | 1 |
|
||||
| Senior Security & Compliance Engineer | 1 |
|
||||
| Senior Security & Compliance Engineer Manager | 1 |
|
||||
| Technical Lead, Compliance Engineering & Automation | 1 |
|
||||
|
||||
Methodology: entities extracted per ad ({hard_skills, tools, methods, responsibilities, seniority}), normalized, counted as DISTINCT ads per entity; report threshold ≥ 3 ads. Headline sections in skills.md/tools.md use the stricter ≥ 20 % threshold.
|
||||
22
references/profile.md
Normal file
22
references/profile.md
Normal file
@@ -0,0 +1,22 @@
|
||||
# Occupation profile — compliance engineer
|
||||
|
||||
- **ESCO URI:** http://data.europa.eu/esco/occupation/a950e88b-cb5e-4a7d-8a94-3f9460b487d7
|
||||
- **ESCO code:** 2149.2.7.1
|
||||
- **ISCO-08 group:** 2149 — Engineering professionals not elsewhere classified
|
||||
- **O*NET-SOC:** 13-1041.00 — Compliance Officers (match: closeMatch)
|
||||
|
||||
## Description (ESCO)
|
||||
|
||||
Compliance engineers strive to keep the highest compliance of systems with engineering specifications. They can exert compliance in a varied array of engineering fields including mechanical, electrical, electronical systems. They ensure the engineering complies with regulations, safety measures, and internal directives.
|
||||
|
||||
## Definition
|
||||
|
||||
nan
|
||||
|
||||
## Alternative labels
|
||||
|
||||
- compliance engineering consultant
|
||||
- compliance engineering expert
|
||||
- compliance engineering specialist
|
||||
- compliance engineering adviser
|
||||
- compliance engineers
|
||||
62
references/skills.md
Normal file
62
references/skills.md
Normal file
@@ -0,0 +1,62 @@
|
||||
# Competences — compliance engineer
|
||||
|
||||
Source: ESCO v1.2.1 occupation-skill relations (http://data.europa.eu/esco/occupation/a950e88b-cb5e-4a7d-8a94-3f9460b487d7).
|
||||
|
||||
## Essential
|
||||
|
||||
- **create manufacturing guidelines** (skill/competence)
|
||||
- **define technical requirements** (skill/competence)
|
||||
- **engineering principles** (knowledge)
|
||||
- **engineering processes** (knowledge)
|
||||
- **ensure compliance with legal requirements** (skill/competence)
|
||||
- **interpret technical requirements** (skill/competence)
|
||||
- **manage engineering project** (skill/competence)
|
||||
- **manufacturing processes** (knowledge)
|
||||
- **perform inspections required by international conventions** (skill/competence)
|
||||
- **perform scientific research** (skill/competence)
|
||||
- **project management** (knowledge)
|
||||
- **quality standards** (knowledge)
|
||||
- **technical drawings** (knowledge)
|
||||
- **use technical drawing software** (skill/competence)
|
||||
- **write specifications** (skill/competence)
|
||||
|
||||
## Optional
|
||||
|
||||
- advise on equipment maintenance (skill/competence)
|
||||
- advise on safety improvements (skill/competence)
|
||||
- analyse production processes for improvement (skill/competence)
|
||||
- apply radiation protection procedures (skill/competence)
|
||||
- archive documentation related to work (skill/competence)
|
||||
- collaborate with designers (skill/competence)
|
||||
- communicate regulations (skill/competence)
|
||||
- consult with technical staff (skill/competence)
|
||||
- develop licensing agreements (skill/competence)
|
||||
- electrical engineering (knowledge)
|
||||
- electronics (knowledge)
|
||||
- ensure compliance with radiation protection regulations (skill/competence)
|
||||
- ensure cross-department cooperation (skill/competence)
|
||||
- identify customer's needs (skill/competence)
|
||||
- industrial engineering (knowledge)
|
||||
- manage contracts (skill/competence)
|
||||
- mechanical engineering (knowledge)
|
||||
- meet deadlines (skill/competence)
|
||||
- radiation protection (knowledge)
|
||||
- security engineering (knowledge)
|
||||
- train employees (skill/competence)
|
||||
- train staff about product features (skill/competence)
|
||||
- troubleshoot (skill/competence)
|
||||
|
||||
<!-- market-evidence -->
|
||||
|
||||
## Market evidence (job-ad analysis, 20 ads, as of 2026-07-10)
|
||||
|
||||
Share of analyzed job ads mentioning the item (threshold ≥ 20 %). Source: JSearch/Adzuna APIs.
|
||||
|
||||
### Hard skills
|
||||
|
||||
- regulatory compliance — **30 %**
|
||||
- risk management — **25 %**
|
||||
- technical documentation — **20 %**
|
||||
- incident response — **20 %**
|
||||
|
||||
<!-- market-evidence -->
|
||||
42
references/tasks.md
Normal file
42
references/tasks.md
Normal file
@@ -0,0 +1,42 @@
|
||||
# Tasks & work activities — compliance engineer
|
||||
|
||||
Source: O*NET 30.3, occupation 13-1041.00 (Compliance Officers).
|
||||
|
||||
## Task statements
|
||||
|
||||
- **[Core]** Warn violators of infractions or penalties.
|
||||
- **[Core]** Evaluate applications, records, or documents to gather information about eligibility or liability issues.
|
||||
- **[Core]** Advise licensees or other individuals or groups concerning licensing, permit, or passport regulations.
|
||||
- **[Core]** Prepare reports of activities, evaluations, recommendations, or decisions.
|
||||
- **[Core]** Report law or regulation violations to appropriate boards or agencies.
|
||||
- **[Core]** Confer with or interview officials, technical or professional specialists, or applicants to obtain information or to clarify facts relevant to licensing decisions.
|
||||
- **[Supplemental]** Issue licenses to individuals meeting standards.
|
||||
- **[Supplemental]** Collect fees for licenses.
|
||||
- **[Supplemental]** Administer oral, written, road, or flight tests to license applicants.
|
||||
- **[Supplemental]** Visit establishments to verify that valid licenses or permits are displayed and that licensing standards are being upheld.
|
||||
- **[Supplemental]** Score tests and observe equipment operation and control to rate ability of applicants.
|
||||
- **[Supplemental]** Prepare correspondence to inform concerned parties of licensing decisions or appeals processes.
|
||||
- **[nan]** Identify compliance issues that require follow-up or investigation.
|
||||
- **[nan]** Keep informed regarding pending industry changes, trends, or best practices.
|
||||
- **[nan]** Provide assistance to internal or external auditors in compliance reviews.
|
||||
- **[nan]** Verify that all firm and regulatory policies and procedures have been documented, implemented, and communicated.
|
||||
|
||||
## Detailed work activities
|
||||
|
||||
- Administer personnel recruitment or hiring activities.
|
||||
- Advise others on legal or regulatory compliance matters.
|
||||
- Collect payments for goods or services.
|
||||
- Communicate organizational policies and procedures.
|
||||
- Communicate with government agencies.
|
||||
- Conduct eligibility or selection interviews.
|
||||
- Evaluate information related to legal matters in public or personal records.
|
||||
- Examine financial records.
|
||||
- Implement organizational process or policy changes.
|
||||
- Inform individuals or organizations of status or findings.
|
||||
- Inspect facilities, equipment or supplies to ensure conformance to standards.
|
||||
- Maintain knowledge of current developments in area of expertise.
|
||||
- Prepare research reports.
|
||||
- Review license or permit applications.
|
||||
- Stay informed about current developments in field of specialization.
|
||||
- Update knowledge about emerging industry or technology trends.
|
||||
- Verify accuracy of records.
|
||||
34
references/tools.md
Normal file
34
references/tools.md
Normal file
@@ -0,0 +1,34 @@
|
||||
# Tools & technology — compliance engineer
|
||||
|
||||
Source: O*NET 30.3 'Software Skills' for 13-1041.00.
|
||||
|
||||
| Software | Category | Hot technology |
|
||||
|---|---|---|
|
||||
| Microsoft Access | Data base user interface and query software | yes |
|
||||
| Microsoft Outlook | Electronic mail software | yes |
|
||||
| Microsoft Office software | Office suite software | yes |
|
||||
| Microsoft Windows | Operating system software | yes |
|
||||
| Microsoft PowerPoint | Presentation software | yes |
|
||||
| Microsoft Excel | Spreadsheet software | yes |
|
||||
| Microsoft Word | Word processing software | yes |
|
||||
| Driving simulators | Computer based training software | |
|
||||
| Commercial driver's license information system CDLIS | Data base user interface and query software | |
|
||||
| Computer-assisted testing software | Data base user interface and query software | |
|
||||
| Database software | Data base user interface and query software | |
|
||||
| National Driver Register NDR | Data base user interface and query software | |
|
||||
| Safety Status Measurement System SafeStat | Data base user interface and query software | |
|
||||
| Traffic record databases | Data base user interface and query software | |
|
||||
| Digital imaging system software | Graphics or photo imaging software | |
|
||||
| Document scanning software | Optical character reader OCR or scanning software | |
|
||||
|
||||
<!-- market-evidence -->
|
||||
|
||||
## Market evidence (job-ad analysis, 20 ads, as of 2026-07-10)
|
||||
|
||||
Share of analyzed job ads mentioning the item (threshold ≥ 20 %). Source: JSearch/Adzuna APIs.
|
||||
|
||||
### Tools
|
||||
|
||||
- Azure — **20 %**
|
||||
|
||||
<!-- market-evidence -->
|
||||
Reference in New Issue
Block a user