| name | compliance-policy-check |
| description | Validate planned changes against local framework rules and policy guardrails before implementation or creation. |
| version | 1.1.0 |
| model | sonnet |
| invoked_by | both |
| user_invocable | true |
| tools | ["Read","Glob","Grep","Skill"] |
| agents | ["planner","technical-program-manager","reflection-agent","evolution-orchestrator"] |
| error_handling | graceful |
| streaming | supported |
| verified | true |
| lastVerifiedAt | "2026-02-22T00:00:00.000Z" |
| source | builtin |
| trust_score | 100 |
| provenance_sha | 0b1bc6cde6c722e2 |
Compliance Policy Check
Overview
Evaluate a design/plan against framework policy and rule constraints before execution. Use this for regulated or high-risk changes.
When to Use
- Before creator workflows for new artifacts
- Before HIGH/EPIC implementation phases
- During reflection when repeated policy violations are observed
Iron Laws
- NEVER execute or modify code during compliance checks — this skill assesses policy alignment only; any implementation must happen separately after compliance is confirmed.
- ALWAYS run compliance check before HIGH/EPIC implementation — high-risk changes that bypass compliance checks create undetected policy drift that compounds over time into systemic violations.
- ALWAYS report findings with specific remediation tasks and owning agent — vague "policy violation" reports without actionable remediation steps don't produce fixes; every FAIL and CONDITIONAL must include a concrete task.
- NEVER report PASS on partial compliance — a plan that satisfies 80% of policies is a CONDITIONAL, not a PASS; partial compliance masks the remaining violations and gives false confidence.
- ALWAYS recheck after remediation, not just once — a single compliance check before implementation is insufficient; verify again after major changes to confirm remediations are complete.
Workflow
Step 1: Gather Policy Context
- Read relevant files in
.claude/rules/
- Read applicable workflow/agent constraints
- Read enforcement hook docs if needed
Step 2: Evaluate Proposed Change
Assess against:
- Creator guard and artifact lifecycle rules
- Routing and specialist-first requirements
- Security and quality gate requirements
- Memory/search/token-saver policy expectations
Step 3: Produce Decision
Return one policy decision:
PASS: policy-aligned
CONDITIONAL: allowed with required mitigations
FAIL: not policy-compliant
Use this output shape:
{
"decision": "PASS|CONDITIONAL|FAIL",
"policyFindings"