SKILLEMALL.ai

CF ai-governance

Design and operate an organization's AI governance system: define governance principles, operating models and decision rights, risk frameworks, lifecycle gates, and fairness, transparency, privacy, security, regulatory, and board-oversight controls across SaaS, API, self-hosted, and agentic deployment postures. Use when standing up a governance program, tiering AI use-case risk, reviewing an LLM or agent system for governance and safety gaps, mapping a regulation to a compliance plan, scoring governance maturity, or preparing board reporting. For regulated life-sciences use cases, also cover GxP, ALCOA+, data integrity, electronic records, validation/assurance, and QMS interfaces. Do not use for interpreting regulations as legal advice (route to legal-strategy), data-governance mechanics (data-architect/data-engineering), or implementing application security (secure-software-engineering).

magnus919/agent-skills Agent Skills author: magnus919 MIT 30 files · 4 scripts body ≈ 2 752 tokens Open the sourcegithub.com↗ analyzed 27 h ago

Design and operate an organization's AI governance system: define governance principles, operating models and decision rights, risk frameworks, lifecycle…

As a process F 42/100 · Will not run — References files that are not bundled: ../legal-strategy/SKILL.md, ../data-architect/SKILL.md, ../data-engineering/SKILL.md

IntegrationQuality controlAI and agentstype and topics are labelled automatically from the skill text
JSON
Technical rating
C
84/100
safety, quality, tests
Safety 60%
89
Quality 40%
77
Run on models
none yet
Process rating
F
42/100
Will not run
References files that are not bundled: ../legal-strategy/SKILL.md, ../data-architect/SKILL.md, ../data-engineering/SKILL.md
Tools and files w 18
0
Inputs and preconditions w 11
0
Failures and branches w 10
0
the three weakest of ten parameters · all ten

What is at stake

Medium-severity findings: the skill is probably honest, but read what alarmed the scanner.

Instruction override medium severity

Below is the worst case for this category. The finding here is medium: the guard saw a sign, not a proof.

If you install

The text contains phrases like "ignore previous instructions" or "you are now…". That is an attempt to hijack the agent: it may break your rules, the system limits or company policy.

For the author

An honest skill does not need them: state the role and the rules directly without overriding other instructions. Otherwise catalog scanners and corporate filters will block the listing.

How to improve

  1. The text references files that are not there: add them or drop the references.
For the model run — optional
  • A spec.yaml with trigger phrases and assertions — a behaviour contract for CI; `skilltest init` writes a template.

Guard findings · 7

✓ No critical or high findings

Medium and low: 7
  • medium Instruction override en-ignore-previous references/llm-and-agent-security.md:88
    Instruction-override phrase ("ignore previous instructions") (documentation of a security skill)
    to override the system prompt or reveal hidden instructions. *Beyond the Algorithm* notes that
    security skill
  • low Risky intent intent-offensive-security references/llm-and-agent-security.md:50
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    | Internal services | Databases, internal APIs, backend systems the model or agent can reach | Apply least privilege; prevent unauthorized access and lateral movement |
  • low Concealment en-hide-from-user references/llm-and-agent-security.md:121
    Instruction to hide actions from the user (negated — the text forbids it)
    out, so that a compromised agent cannot quietly exfiltrate data through a channel the operator
    negated
  • low Risky intent intent-offensive-security references/llm-and-agent-security.md:264
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    A red team carries out a structured, adversarial evaluation that probes an AI system for failures —
  • low Risky intent intent-offensive-security references/llm-and-agent-security.md:269
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    penetration testing: a pen test is a point-in-time assessment of exploitable weaknesses, while red
  • low Risky intent intent-offensive-security references/llm-and-agent-security.md:271
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    red team exercises areas like hallucination triggers, bias, excessive agency, and injection with an
  • low Risky intent intent-offensive-security templates/agentic-governance-review.md:228
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    - **Independent reviewer or red team:**

Files scanned: 29. Evidence is masked. Grey chips explain why severity was lowered.

Against the Agent Skills spec

  • warning missing-ref reference to a missing file: ../legal-strategy/SKILL.md
  • warning missing-ref reference to a missing file: ../data-architect/SKILL.md
  • warning missing-ref reference to a missing file: ../data-engineering/SKILL.md
  • warning missing-ref reference to a missing file: ../secure-software-engineering/SKILL.md
  • warning missing-ref reference to a missing file: ../product-operations-and-governance/SKILL.md
  • warning missing-ref reference to a missing file: ../adr-authoring/SKILL.md

Process rating: all ten parameters 42/100

Will not run. References files that are not bundled: ../legal-strategy/SKILL.md, ../data-architect/SKILL.md, ../data-engineering/SKILL.md
  • 0Tools and files. 6 referenced file(s) missing: ../legal-strategy/SKILL.md, ../data-architect/SKILL.md, ../data-engineering/SKILL.md
  • 0Inputs and preconditions. Does not say what the process needs to start
  • 0Failures and branches. Linear process with no failure handling
  • 0Progress reporting. Says nothing while it works
  • 30Running it twice. 4 mutating operations with no state check
  • 40Result and completion. Does not say what the result is
  • 50When it triggers. No condition that starts the skill
  • 100Steps. 9 steps
  • 100Consistency. Name and required fields are in place
  • 100Execution cost. Instruction body is 2752 tokens

Everything here is measured from the skill text rather than judged by a model, so the numbers are checkable. A parameter weighs more when it is a more common reason for the process to stall.

Quality signals

  • +5Description has no quoted example phrases that should trigger the skill
  • +3Description length 901: 120–800 characters recommended
  • +3Output format is not stated: the model decides each time
  • +4No input/output examples
  • +2Single-language instructions
  • +4Description says when NOT to use the skill
  • +4Structure: 9 headings
  • +3Step-by-step instructions: 9 items
  • +4Reference files are cited in the instructions (13 of 13)
  • +3All 4 scripts are documented
  • +1License stated

Quality base 70; lint remarks subtract, signals add up to 100. Result: 77.