13 skills.
Open source. Run anywhere.
The compliance methodology lives in two forms here: 13 agentic skills (open source, Apache 2.0) that any LLM or MCP-compatible agent can run, and structured self-assessments you can take in your browser. Both are grounded in the CFR sections and framework catalogs they address.
One-click install from ClawHub. Risk Assessment alone has crossed 1,500 installs — from practitioners who chose this framework specifically. All 13 skills also install as one package via the Claude Code / Cowork plugin.
Browse skills on ClawHub →The 13 compliance skills
Assess compliance documents against HIPAA Security Rule and Privacy Rule requirements. Get structured findings with coverage status, evidence citations, confidence scores, and remediation recommendations for every control.
Clause-by-clause Business Associate Agreement analysis against 45 CFR 164.504. Evaluates all required HIPAA BAA provisions with risk scoring, contract language citations, and specific remediation recommendations.
Bidirectional mapping between document sections and compliance framework controls (NIST CSF 2.0, ISO 27001, SOC 2, HIPAA). Produces per-section mappings and per-control coverage summaries with confidence scores.
Evaluate individual framework controls against organizational documentation with evidence extraction, quality evaluation, severity classification, and actionable remediation recommendations.
Identifies threats and vulnerabilities, evaluates likelihood and impact via a 3x3 risk matrix, maps findings to any compliance framework (NIST CSF 2.0 by default, or any framework you specify), and recommends risk treatment options with prioritization guidance.
Public-document triangulation for healthcare-AI vendors. Reads a company's product pages, Terms of Service, and Privacy Policy, then surfaces where its market claims, legal commitments, and HIPAA's business-associate and de-identification rules fail to reconcile. Every gap is cited at both ends and framed as a public-documentation gap a covered entity would hit during vendor review.
Public-document assessment for substance use disorder treatment programs subject to 42 CFR Part 2. Checks a program's publicly posted patient confidentiality notice against every element §2.22(b) requires — the single-consent statement, legal-proceedings protections, redisclosure language, and patient rights — and flags the Part 2-specific elements a generic HIPAA notice typically omits.
RAG-style compliance question answering with regulatory interpretation guardrails. Answers questions strictly from provided context with source attribution, confidence scoring, and escalation triggers for critical issues.
Guides a structured compliance posture assessment covering all Seven Elements of an effective compliance program. Combines self-reported answers with analysis of any compliance documents you provide. Produces a posture snapshot with maturity stage, enterprise blocker flags, gap prioritization, and a 30/60/90 day roadmap.
Scans a directory of documents, classifies each file by compliance type (BAA, security policy, risk assessment, IR plan, and more), resolves version conflicts with your input, and produces a prioritized analysis plan mapping confirmed-current documents to the right compliance skill. Routes to the analysis skills rather than performing analysis itself.
Triangulates a website's sitemap, robots.txt, footer/nav links across multiple pages, and common compliance path guesses to find every privacy policy, HIPAA/Part 2 notice, terms page, and consent form actually posted, including pages the site's own navigation doesn't link to. Retrieves each page's verbatim text, classifies its content and controlling entity, and flags nav-label or entity mismatches.
Reads document manifests from legal-page-discovery and/or document-finder alongside the full skill catalog, and reasons about which skill (if any) is a good candidate for each document. Produces an Analysis Plan grounded in specific document and skill-description phrases, and surfaces documents that match nothing as explicit toolkit-coverage gaps.
Builds the inventory of AI capability an organization is actually running, across the five ways it enters. Four of those five leave no transaction behind: tools built in-house on a subscription already held, vendor features switched on inside approved products, third-party integrations attached to approved platforms, and free tools staff signed up for with a work email. Classifies entry path, evaluates ePHI contact and third-party disclosure, and produces structured findings on ownership, agreements, verification, and risk-analysis scope.
Take them in your browser. No agent required.
The skills above run agentically. These are for direct use: two interactive diagnostics and one practitioner guide. Benchmark your compliance program against the 7 Elements framework, place your organization on the three stages of compliance maturity, or work through how to adopt AI tooling without losing track of it. No account required.
Based on the Federal Sentencing Guidelines' seven elements of an effective compliance program. 31 yes/no questions across standards, oversight, delegation, training, monitoring, enforcement, and response. Produces a readiness score and tier with specific next steps.
Identifies which stage of compliance maturity your organization occupies: Foundation, Active Management, or Proactive Defense. Helps align program investment with deal size and target market.
For organizations about to start using generative AI on regulated work. How to decide whether you can verify an output before picking a tool, which of the three routes to take, and what to record on day one so an inventory never has to be reconstructed later. Includes a starting register that runs in your browser.
Two ways to run the skills
If you use an OpenClaw-compatible agent, install any Rote skill in one click from ClawHub. Skills appear as native tools with no configuration required. clawhub.ai/dangsllc →
Install all 13 skills as one package: claude plugin marketplace add Rote-Compliance/rote-compliance-skills then claude plugin install rote-compliance-skills@rote-compliance-skills. Skills fire automatically when relevant — e.g. /rote-compliance-skills:hipaa-gap-analysis — on whatever you paste or attach. No connectors, no server, nothing here ever sees your documents unless you hand them over yourself.
Download a SKILL.md file from GitHub and paste it as a system prompt. The methodology is in the file. It runs on any model that supports structured instructions.
What the Rote platform adds
Both paths run the full methodology. The difference is scope. Running a skill standalone means analyzing one document per session, manually provided. The Rote platform indexes your full document corpus in workspace-isolated Qdrant collections, so the same skills retrieve from your entire policy library, vendor agreement stack, or framework set simultaneously. Cross-document analysis, persistent audit trails, and citation back to specific document sections and pages are all platform-layer capabilities. The HIPAA Gap Analysis skill run against a single policy is useful. Run against 40 policies across a health system, with every finding traced to the exact section it came from, it becomes the output a compliance program actually needs.
Download the skills as SKILL.md files
Each skill is a single SKILL.md file. Download the full toolkit as a ZIP or browse individual skills on GitHub. Apache 2.0 licensed.
Framework-directable 3x3 risk assessment for any compliance program
Download SKILL.mdCheck a healthcare-AI vendor's public claims against its own legal language and HIPAA
Download SKILL.mdCheck a Part 2 program's posted patient notice against §2.22(b)'s required elements
Download SKILL.mdA structured Seven Elements assessment of your compliance program
Download SKILL.mdScan a directory, classify your compliance documents, get an analysis plan
Download SKILL.mdFind every legal and compliance page on a live website, not just the ones in the nav
Download SKILL.mdMatch discovered documents to the right compliance skill, and flag what nothing covers yet
Download SKILL.mdFind the AI your organization is actually running, including the four ways it arrives without a purchase
Download SKILL.mdWant this run
for your organization?
The AI Governance Snapshot applies these skills to your compliance documents and delivers structured findings, a maturity score, and a remediation roadmap. Free. Delivered by Dan within a week.