agentsclimarketplace

Agile v compliance

Skill Agile-V/agile_v_skills/agile-v-compliance

🔬 Verifiable AI-Augmented Engineering Framework - Stop AI hallucinations with formal traceability (REQ→ART→TC). Agent Skills for Claude Code, Cursor, VS Code & Copilot. Enterprise-grade: ISO 9001, ISO 27001, GxP-ready. Red Team verification, multi-cycle lifecycle, behavioral anti-patterns.

Install
npx -y skills add Agile-V/agile_v_skills --skill agile-v-compliance

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Risk management, CAPA protocol, human gate approval records, AI agent security controls, and periodic revalidation. Load when running gates, handling CAPAs, or auditing compliance and security posture.

The file declares its own license as CC-BY-SA-4.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

4.2 KB, as published. Nobody here has run it

Instructions

Compliance protocols for Agile V. Requires agile-v-core loaded first.

Risk Management (ISO 9001 6.1 / AS9100D 8.1.1)

Append-only, cycle-tagged register in .agile-v/RISK_REGISTER.md: RISK-ID | Cycle | Level(L0-L4) | Category | Description | Likelihood | Impact | Controls | Residual Decision | Owner | Status. Apply docs/agile-v-runtime/04_RISK_CLASSIFICATION.md; legacy R0-R3 maps only as documented there.

Categories: Technical, Process, Compliance, Security. Severity matrix: High x High = Critical, High x Med = High, High x Low / Med x Med = Medium, rest = Low. Critical risks require Human resolution or documented acceptance before Gate 2.

When: draft persisted = Req Architect identifies; independent findings = Logic Gatekeeper flags constraints; Stage 4 = Red Team finds residual; cycle boundary = Compliance Auditor reviews. Baselining requires Gate 1 approval and no unresolved mandatory finding.

CAPA Protocol (ISO 13485 8.5 / ISO 9001 10.1-10.2)

Triggers: CRITICAL finding, recurring NC across cycles, regression FAIL with no CR, 3-attempt escalation.

Record in .agile-v/CAPA_LOG.md: CAPA-XXXX with Cycle, Trigger, Nonconformity, Root Cause (5-Whys), Corrective Action, Preventive Action, Effectiveness Verification, Status (open -> corrective-complete -> preventive-complete -> verified-effective -> closed), Owner.

Workflow: Detect -> Record -> Analyze -> Correct -> Prevent -> Verify effectiveness. Compliance Auditor tracks open CAPAs at Gate 2, flags overdue (>2 cycles).

Human Gate Approval Records (21 CFR Part 11 / Annex 11)

Append-only in .agile-v/APPROVALS.md: GATE-XXXX with Gate type, Cycle, Scope, Decision (Approved/Conditional/Rejected), Conditions, Approver (full name), Role/Authority, Timestamp (ISO 8601), Signature Method, Evidence Reference (commit hash). Durable HITL (Phase 2): when closing a pending interrupt, include resume_token=[value] and INTERRUPT-ID=[INT-XXXX] matching .agile-v/CHECKPOINTS.md; Compliance Auditor verifies token pairing on Gate 2.

Rules: Name + role required (not just "Human"). Authority from matrix in config.json. Rejected = pipeline halts.

Checkpoint SLA: If CHECKPOINTS.md shows due_at passed with PENDING, escalate per project policy; append ESCALATED or EXPIRED row before forcing resume.

Regulatory ContextMinimum Signature
Non-regulatedAPPROVALS.md entry with name + timestamp
ISO 9001/27001+ Git commit attribution
GxP / 21 CFR Part 11+ Signed commit + authority verification
ISO 13485+ Digital signature + authority matrix + retention

AI Agent Security Controls (ISO 27001 A.5.23 / A.8.3)

LLM Provider Registry in config.json: per provider record name, models, data_residency, retention, api_data_usage, approved_for classifications, review_date. Verify input classification vs provider approval before sending. Never send credentials/patient data unless provider approved. Least privilege per agent. Context sanitization on session end.

File Integrity: Git-tracked = verify clean status. Store hashes in STATE.md at Gates; verify before next stage. Flag unverifiable files to Human.

Periodic Review & Revalidation (GxP / GAMP 5)

Triggers: LLM model change, runtime/platform major update, skill file change, >5 CRs since last revalidation, 12-month interval.

Record in .agile-v/REVALIDATION_LOG.md: REVAL-XXXX with Date, Trigger, Scope, Results, Decision, Reviewer. Regression failure = new cycle trigger.

Model Tracking in config.json: model_versions with tier IDs + last_validated + validated_by. Any change triggers revalidation.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.