← ClaudeAtlas

compliancelisted

Creates, maintains and audits COMPLIANCE.md — the project's declared compliance posture (which regimes apply, the self-assessed classification, the obligations that follow, data handling). EU-first (EU AI Act + GDPR as two independent axes). Reads BUSINESS.md's archetype as a TRIGGER for whether the AI Act may apply — it never assigns the legal tier from the archetype alone. Three modes: bootstrap, update, and `audit` (does the diff touch regulated ground — a new personal-data field, a new model/automated decision, a new data source — against the declared posture; read-only). Surfaces provisions & checklists, NEVER a legal verdict. Optionally verifies live via an EU-AI-Act MCP if one is connected; works offline without it. Do NOT use it for status (PROGRESS.md), rules (CLAUDE.md), non-goals (BUSINESS.md) or decision rationale (DECISIONS.md).
radozaprazny/attest · ★ 0 · AI & Automation · score 69
Install: claude install-skill radozaprazny/attest
# /compliance — declared compliance posture (COMPLIANCE.md) This skill maintains **`COMPLIANCE.md`** — the record of **under what rules** the project must operate: which regimes apply, the self-assessed classification, the obligations that follow, and how personal data is handled. **EU-first.** It records the project's *posture*, not the law — it cites provisions by article/ID and **never reproduces regulation text or issues a legal verdict**. The skill is **generic** — work with what you actually find in the repo, and assume nothing about the specific project. ## The control documents — keep them separate **Anti-duplication:** status → `PROGRESS.md` · rules → `CLAUDE.md` · why-it-exists → `BUSINESS.md` · why-we-chose-X-over-Y → `DECISIONS.md` · under-what-rules → `COMPLIANCE.md`. Write each fact in exactly one place. (full table: GUIDE PART 1) > The three "why" docs collide here — fence them. A specific technical **choice and its > rationale** is a `DECISIONS.md` entry; `COMPLIANCE.md` records only the **standing > obligation** that binds it, cross-referenced by ADR id. A product **boundary** is a > `BUSINESS.md` non-goal, not an obligation. ## Two axes, EU-first The AI Act and the GDPR are **independent axes** — fill each only if its own trigger fires: - **EU AI Act** — trigger: is it an **AI system** (Art 3(1)) or a **GPAI model**? The archetype in `BUSINESS.md` is only a *hint* that it *may* apply — a `service` or `data-pipeline` embedding a model is in scope