compliance-review

compliance-review is a skill for Claude Code from BlueprintOS/analysis-to-delivery. It costs 48 tokens per session (905 once invoked), scanned A, original, MIT.

A compliance review workflow for checking a signed business requirements document against applicable rules for areas such as healthcare, payments, personal data, and pharmaceutical tracking.

In plain words
What is it for?
It is for producing a compliance review with evidence, defect severity, pass or fail status, and an overall approval decision.
Why use it?
It creates a documented decision for every relevant rule and exposes serious gaps before development proceeds.

Skill for Claude Code

Written for Claude Code: disable-model-invocation in frontmatter.

Good fit It is for producing a compliance review with evidence, defect severity, pass or fail status, and an overall approval decision.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/blueprintos/analysis-to-delivery/compliance-review
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add BlueprintOS/analysis-to-delivery --skill compliance-review
Clone the repo
git clone --depth 1 https://github.com/BlueprintOS/analysis-to-delivery

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for compliance-review

README.md
[![agentmods](https://agentmods.dev/badge/skills/blueprintos/analysis-to-delivery/compliance-review/github.svg)](https://agentmods.dev/skills/blueprintos/analysis-to-delivery/compliance-review)
Your own site
<a href="https://agentmods.dev/skills/blueprintos/analysis-to-delivery/compliance-review"><img src="https://agentmods.dev/badge/skills/blueprintos/analysis-to-delivery/compliance-review/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for compliance-review

Your own site · 80×15
<a href="https://agentmods.dev/skills/blueprintos/analysis-to-delivery/compliance-review"><img src="https://agentmods.dev/badge/skills/blueprintos/analysis-to-delivery/compliance-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 48 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 905 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00048 $0.00905
Opus 5 $0.00024 $0.00452
Sonnet 5 $0.00010 $0.00181
Haiku 4.5 $0.00005 $0.00090

Measured 11d ago against content hash ab512d4d45f2, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

compliance-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/user-invoked/compliance-review/SKILL.md · 83 lines

What it actually says

Compliance-Review — 合规评审

Contract

  • 输入: 已签字的 01-业务需求文档 BRD.mdcompliance-path.md
  • 输出: 04-合规评审.md
  • 门控: 所有适用合规条款均已判定;严重缺陷已修复或显式接受;用户 + 合规方签字
  • Required rules: stage-gate, context-pointer
  • Required paths: compliance-path, doc-naming-path
  • 下一步: /test-case-design

适用场景

需求类型 是否需要
涉及个人健康信息(PHI) ✅ 必须
涉及支付/金融 ✅ 必须
涉及个人身份信息(PII) ✅ 必须
涉及医药追溯(GSP) ✅ 必须
纯内部工具 ⚠️ 按团队规范

流程步骤

1. 加载合规规则

  • 读项目根 compliance-path.md
  • 加载其引用的合规规则文件(config/compliance/<行业>.md 或 skill 级 fallback)
  • 列出所有适用条款

2. 逐条评估 BRD

对每条合规条款,按以下格式输出:

条款编号 缺陷等级 检查要点 合规设计 证据位置 状态
**{条款编号} {严重/主要/一般} {检查要点} {合规设计摘要} FSD §{章节号} ✅/⚠️/🔄

判定标准:

  • ✅ 符合:完全满足
  • ⚠️ 不符合:存在合规缺口
  • 🔄 不适用:条款不适用本功能

3. 写评审结论

按条款输出后,给出整体结论:

  • ✅ 全部通过 → 进入下一阶段
  • ⚠️ 带条件通过(列出条件)
  • ❌ 不通过(回 BRD 修复)

输出

  • 04-合规评审.md

调用的 rule

  • rules/context-pointer — 三层合规规则加载(项目级 > skill 级 > 默认)
  • rules/stage-gate — 阶段 4 门控

结束条件

  • 所有适用条款已评审(无遗漏)
  • 每条都有 ✅/⚠️/🔄 判定
  • 整体结论签字(用户 + 合规方)
  • 缺陷等级为"严重"的条款全部 ✅

反模式

  • ❌ 留 {待评估}/{TBD}/{N/A} — compliance-check.py 视为未判定,直接 fail;必须给 ✅/⚠️/🔄
  • ❌ 严重条款状态为 ⚠️ — 必须修复或豁免到 ✅/🔄 后才能签字
  • ❌ 跳过 evidence(证据位置)列 — 每条必须标具体位置(FSD §X / PRD §Y / 设计回测报告)
  • ❌ 不分缺陷等级(严重/主要/一般) — 必须分级,否则整改建议无法排序
  • ❌ 条款数量 ≠ compliance-path.md 引用的合规清单 — 必须 1:1 全覆盖
  • ❌ 仅做技术合规(代码层面)忽略业务流程合规 — 两者必须都覆盖
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 83 lines · 48 tokens per session scan A ab512d4d45f2

Subscribe to this mod's changes

compliance-review is a skill published in the GitHub repository BlueprintOS/analysis-to-delivery (26 stars, last pushed 2mo ago), licensed MIT. It adds 48 tokens to every session and 905 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

juristischer-argumentationskern

Schaltet sich ein, wenn in Agb Recht Prüfer ein juristisches Arbeitsprodukt tragfähig begründet werden muss; verbindet konkrete Aktenfundstellen mit Tatbestandsmerkmal, Beweislast, stärkster Gegenposition und Rechtsfolge.

Klotzkette/claude-fuer-deutsches-recht · 58 tokens

begriff-vorformuliert-digitalen-produkten-iso

Für AGB Begriff Vorformuliert 305: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: begriff-vorformuliert-digitalen-produkten-iso.

Klotzkette/claude-fuer-deutsches-recht · 78 tokens

aenderungsvorbehalt-308

Für Änderungsvorbehalt 308: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt.

Klotzkette/claude-fuer-deutsches-recht · 41 tokens

agb-begriff-vorformuliert-305

Für AGB Begriff Vorformuliert 305: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: agb-begriff-vorformuliert-305.

Klotzkette/claude-fuer-deutsches-recht · 68 tokens

battle-forms-bau-vob-beweislast-zugang

Für Battle of Forms AGB Kollision: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Beweislast- und Substantiierungsmatrix.

Klotzkette/claude-fuer-deutsches-recht · 47 tokens

beweislast-und-zugang-309

Für Beweislast und Zugang 309: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Beweislast- und Substantiierungsmatrix.

Klotzkette/claude-fuer-deutsches-recht · 43 tokens