/intake
Intake and risk-tier an AI use case, then produce the governance/oversight record (NIST AI RMF / EU AI Act / ISO 42001).
$ npx -y skills add jassics/awesome-claude-security --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/intake
Context preview
What this command does when you run it.
Intake and risk-tier an AI use case, then produce the governance/oversight record (NIST AI RMF / EU AI Act / ISO 42001).
Command definition
intake.mddescription: Intake and risk-tier an AI use case, then produce the governance/oversight record (NIST AI RMF / EU AI Act / ISO 42001). argument-hint: [AI use case / system to register]
Run AI governance intake for: **$ARGUMENTS**
Walk it, using installed skills (note any whose plugin is missing):
1. **Intake** — `/responsible-ai-officer:ai-use-case-intake` to capture purpose, data, users, autonomy, and context. 2. **Risk-tier** — classify against the relevant regime (EU AI Act risk tiers / NIST AI RMF / ISO 42001) and decide the oversight level required. 3. **Assess** — `/ai-safety:responsible-ai-assessment` to evaluate the use case against responsible-AI principles and surface obligations. 4. **Document & oversee** — produce the governance record: risk tier, required controls/evals, accountable owner, and review cadence. Reference `/security-knowledge:framework-mapping` to align obligations to frameworks. 5. **Report** — `/security-reporting:executive-summary` for the approval record; route higher-risk cases to `/ai-safety-engineer:safety-review`.
For deep execution, hand off to the `responsible-ai-officer` agent. Tier first — the risk tier sets how much scrutiny everything downstream needs. No high-risk use case ships without an owner and a review date.
A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. A pentester knows which OWASP test bends a broken-access-control endpoint.
Repo: jassics/awesome-claude-security
Other commands on awesome-claude-security.
- /safety-review
Run an AI safety review for a feature/model — harms, evaluations, guardrails, and a documented safety case.
Open command - /defend
Run a threat-informed defense cycle for a technique or threat — coverage check, hunt, detection, and purple-team validation.
Open command - /board-brief
Build a board/executive security brief — strategy, quantified risk, and a board-ready deck.
Open command - /tech-review
Assess technology/security risk for a strategic decision and frame the secure-by-design path.
Open command - /precommit
Run the pre-commit security gate on the current changeset and report a single pass/fail verdict.
Open command - /assessment
Run a compliance gap-assessment for a framework, tie gaps to risk, and produce findings + remediation.
Open command

