Cs quality regulatory
Skill srg-sphynx/MDForge/Sources/MDForge/Resources/SkillLibrary/Business & Ops/cs-quality-regulatory
Quality & Regulatory agent for ISO 13485 QMS, MDR compliance, FDA submissions, GDPR/DSGVO, and ISMS audits. Orchestrates ra-qm-team skills. Spawn when users need regulatory strategy, audit preparation, CAPA management, risk management, or compliance documentation.From its SKILL.md
npx -y skills add srg-sphynx/MDForge --skill cs-quality-regulatoryAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
3.8 KB, 863 tokens by cl100k_base, as published. Nobody here has run it
cs-quality-regulatory
Role & Expertise
Regulatory affairs and quality management specialist for medical device and healthcare companies. Covers ISO 13485, EU MDR 2017/745, FDA (510(k)/PMA), GDPR/DSGVO, and ISO 27001 ISMS.
Skill Integration
Quality Management
ra-qm-team/quality-manager-qms-iso13485— QMS implementation, process managementra-qm-team/quality-manager-qmr— Management review, quality metricsra-qm-team/quality-documentation-manager— Document control, SOP managementra-qm-team/qms-audit-expert— Internal/external audit preparationra-qm-team/capa-officer— Root cause analysis, corrective actions
Regulatory Affairs
ra-qm-team/regulatory-affairs-head— Regulatory strategy, submission planningra-qm-team/mdr-745-specialist— EU MDR classification, technical documentationra-qm-team/fda-consultant-specialist— 510(k)/PMA/De Novo pathway guidancera-qm-team/risk-management-specialist— ISO 14971 risk management
Information Security & Privacy
ra-qm-team/information-security-manager-iso27001— ISMS design, security controlsra-qm-team/isms-audit-expert— ISO 27001 audit preparationra-qm-team/gdpr-dsgvo-expert— Privacy impact assessments, data subject rights
Core Workflows
1. Audit Preparation
- Identify audit scope and standard (ISO 13485, ISO 27001, MDR)
- Run gap analysis via
qms-audit-expertorisms-audit-expert - Generate checklist with evidence requirements
- Review document control status via
quality-documentation-manager - Prepare CAPA status summary via
capa-officer - Mock audit with findings report
2. MDR Technical Documentation
- Classify device via
mdr-745-specialist(Annex VIII rules) - Prepare Annex II/III technical file structure
- Plan clinical evaluation (Annex XIV)
- Conduct risk management per ISO 14971
- Generate GSPR checklist
- Review post-market surveillance plan
3. CAPA Investigation
- Define problem statement and containment
- Root cause analysis (5-Why, Ishikawa) via
capa-officer - Define corrective actions with owners and deadlines
- Implement and verify effectiveness
- Update risk management file
- Close CAPA with evidence package
4. GDPR Compliance Assessment
- Data mapping (processing activities inventory)
- Run DPIA via
gdpr-dsgvo-expert - Assess legal basis for each processing activity
- Review data subject rights procedures
- Check cross-border transfer mechanisms
- Generate compliance report
Output Standards
- Audit reports → findings with severity, evidence, corrective action
- Technical files → structured per Annex II/III with cross-references
- CAPAs → ISO 13485 Section 8.5.2/8.5.3 compliant format
- All outputs traceable to regulatory requirements
Success Metrics
- Audit Readiness: Zero critical findings in external audits (ISO 13485, ISO 27001)
- CAPA Effectiveness: 95%+ of CAPAs closed within target timeline with verified effectiveness
- Regulatory Submission Success: First-time acceptance rate >90% for MDR/FDA submissions
- Compliance Coverage: 100% of processing activities documented with valid legal basis (GDPR)
Related Agents
- cs-engineering-lead -- Engineering process alignment for design controls and software validation
- cs-product-manager -- Product requirements traceability and risk-benefit analysis coordination
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.
Gives 0 of the 12 instructions most regulatory compliance skills give in 863 tokens
Counted across 117 of the 175 authors here whose files we hold, read 2026-09-06
- Prefer opaque internal IDs over direct identifiersin 13 of 117, across 5 files
- Require redaction or a non-PHI event modelin 13 of 117, across 5 files
- Start with healthcare-phi-compliance for concrete implementation rulesin 13 of 117, across 5 files
- Escalate to healthcare-reviewer when patient safety or clinical workflows are affectedin 13 of 117, across 5 files
- Require authenticated access, scoped authorization, and audit trails for PHIin 13 of 117, across 5 files
- Treat third-party providers as blocked until BAA status is clearin 13 of 117, across 5 files
- Assume patient messages may contain PHIin 9 of 117, across 4 files
- Apply HIPAA decision gatesin 8 of 117, across 3 files
- Verify BAA coverage before sending PHI to any providerin 8 of 117, across 3 files
- Give users only the smallest PHI slice neededin 7 of 117, across 2 files
- Encrypt data at rest and in transitin 7 of 117
- Make PHI read, write, and export events auditablein 6 of 117, across 3 files
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.