Install
$ agentstack add skill-bromso-metapowers-compliance-priorities ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Compliance Priorities
Prioritize the applicable regulations for "$ARGUMENTS" by business impact, enforcement deadlines, and customer demand to determine the optimal compliance sequence.
Prerequisites
None — this is a Phase 0 (Scope) skill.
Process
- Read context files:
- Read
plugins/compliance/shared/grc-lifecycle-guide.mdfor GRC methodology reference - Read
.metapowers/compliance/$ARGUMENTS/00-scope.mdfor the regulation inventory
- Business impact scoring:
- For each applicable regulation, score revenue at risk without certification (0-10)
- Assess deal-blocking potential — how often is this certification requested in sales cycles?
- Estimate market access impact — does non-compliance lock out entire markets or verticals?
- Urgency scoring:
- Score enforcement deadline proximity (0-10) — active enforcement vs. upcoming vs. future
- Score customer deadline pressure (0-10) — immediate customer requirements vs. nice-to-have
- Flag any regulations with imminent deadlines or recent enforcement actions
- Effort scoring:
- Score implementation complexity (0-10) — scope of changes needed
- Estimate time to certification (months)
- Assess internal capability gaps — can this be done in-house or requires external help?
- Priority ranking:
- Calculate weighted priority score (business impact 40%, urgency 35%, inverse effort 25%)
- Rank regulations from highest to lowest priority
- Identify quick wins (high impact, low effort) vs. strategic investments (high impact, high effort)
- Group into tiers: Tier 1 (immediate), Tier 2 (next 6 months), Tier 3 (12+ months)
- Write the artifact to
.metapowers/compliance/$ARGUMENTS/00-scope.md(append to existing) with sections:
- Scoring Matrix — table with impact, urgency, effort, and weighted scores per regulation
- Priority Tiers — Tier 1/2/3 groupings with rationale
- Quick Wins — low-effort, high-impact regulations to tackle first
- Strategic Investments — high-effort certifications that unlock major business value
- Dependencies — regulations that build on each other (e.g., ISO 27001 before CSA STAR)
Output
The priority analysis appended to .metapowers/compliance/$ARGUMENTS/00-scope.md. Present a summary to the user highlighting:
- Top 3 priority regulations and why
- Identified quick wins
- Key dependencies between certifications
- Recommended next step: run
/compliance:control-framework $ARGUMENTS
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: bromso
- Source: bromso/metapowers
- License: MIT
- Homepage: https://bromso.github.io/metapowers/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.