github Sushegaad/Claude-Skills-Governance-Risk-and-Compliance v1.6.1

latest release: v1.6.2
one month ago

v1.6.0 / v1.6.1 — 2026-07-03

Governance release: eval-credibility infrastructure, currency guardrails, five skill
expansions, benchmark re-run extended to 12 of 30 skills with primary-source assertions —
and remediation of every skill that scored below baseline. All 30 plugins at 1.6.1.

Benchmark — suite headline: 94% with skills vs 81% baseline (705/612 of 752, +13 pts)

  • Assertions for re-run skills authored from primary sources (regulation text, official
    notices) — never from skill content; post-cutoff facts embedded for graders.
  • Re-run in 1.6.0: NIS2 100%/84% (+16, expansion validated), EU AI Act 92%/72% (+20),
    VN-PDPL 68%/60% (+8), EU CRA 80%/80% — plus four honest negative deltas.
  • Remediated in 1.6.1 (skills revised against exact graded failures, same assertions,
    both arms re-run): CCPA/CPRA 100%/80% (+20, was −16); NZISM 96%/64% (+32, was −4);
    NIST AI RMF 92%/84% (+8, was −4); CMMC 88%/80% (+8, was −8). No skill below baseline.
  • First committed grading artifacts for NZISM, VN-PDPL, EU CRA — all 30 skills now
    have machine-checkable eval artifacts (grc-workspace/rerun-2026-07b, -07c).

Skill content

  • Expanded five thinnest skills (NIS2 82→~190 lines incl. the Art. 3 essential-vs-important
    size-cap test; EU AI Act deployer duties Art. 26 + FRIA Art. 27 + Annex III area guidance;
    CCPA/CPRA full rights workflows; CMMC level/SPRS/scoping/assessment readiness;
    NIST AI RMF categories, risk-register template, profiles).
  • 1.6.1 hardening: CMMC DFARS clause family (7012/7019/7020/7021) + conditional-certification
    math (≥88 + all-1-point gate) + flow-down remediation menu; CCPA tiered verification
    (§§7060–7062), 10-business-day acknowledgment, categorical §7050(c) CCBA rule,
    notice-at-collection as a named GDPR-gap item; NIST AI RMF Playbook/voluntary framing,
    SR 11-7 mapping, GOVERN mini-templates; NZISM verified control-ID reference
    (never-invent-a-CID rule), offshore/cloud approval-chain workflow, SRMP in C&A.
  • Fixes: CCPA precise-geolocation radius corrected to 1,850 ft (§1798.140) and
    right-to-know lookback to the §1798.130(a)(2)(B) formulation; CMMC POA&M rule
    sharpened to 1-point eligibility with the 88 floor.

Guardrails & process

  • Every SKILL.md now carries a Last-verified date and a standard not-legal-advice
    disclaimer; new CI tests fail stale (>120 days), relative-time language, or missing
    disclaimers; quarterly review checklist with per-framework primary sources documented.
  • New summary-block consistency tests: suite stats identical across all three pages,
    deltas arithmetically derived, per-skill cells sum to published totals, and any
    negative delta must be explicitly acknowledged (allowance currently empty).
    Caught and fixed a live bug on day one (GDPR cell 25/25 next to 88% → 22/25).
  • Eval integrity: 3 grader judgments amended with documented notes after verification
    (Decree 356/2025/ND-CP is real); 2 assertion-writer errors acknowledged; grader-flagged
    assertions reviewed against primary sources and upheld.

Don't miss a new Claude-Skills-Governance-Risk-and-Compliance release

NewReleases is sending notifications on new releases.