Source profileQuality 93/100

zgbrenner/agentcounsel/skills/setup/ai-governance-cold-start-interview/SKILL.md

AI Governance Cold-Start Interview

Use when an AI-governance practice group is adopting AgentCounsel and needs to configure its practice profile by answering a structured interview covering jurisdictions, client context, escalation thresholds, output preferences, source documents, standard positions, review requirements, and prohibited assumptions.

Source repository stars
17
Declared platforms
0
Static risk flags
0
Last source update
2026-08-04
Source checked
2026-08-04

Decision brief

What it does—and where it fits

Use when an AI-governance practice group is adopting AgentCounsel and needs to configure its practice profile by answering a structured interview covering jurisdictions, client context, escalation thresholds, output preferences, source documents, standard positions, review requirements, and prohibited assumptions.

Best for

  • Conduct a structured, staged interview with an AI-governance practice group — led by a supervising attorney or authorized designee — to gather the information required to populate practice-profiles/ai-governance.md. The…

Not for

  • Tasks that require unconfirmed production actions or broad system permissions.
  • Environments where the pinned source and install steps cannot be inspected.

Compatibility matrix

Platform support, with evidence labels

PlatformStatusEvidenceWhat to check
CodexNot declaredNo explicit evidencePortability before use
Claude CodeNot declaredNo explicit evidencePortability before use
CursorNot declaredNo explicit evidencePortability before use
Gemini CLINot declaredNo explicit evidencePortability before use
Open the compatibility checker

Installation

Inspect first. Install second.

The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

Source-detected install commandSource
npx skills add https://github.com/zgbrenner/agentcounsel --skill "skills/setup/ai-governance-cold-start-interview"
Safe inspection promptEditorial

Inspect the Agent Skill "AI Governance Cold-Start Interview" from https://github.com/zgbrenner/agentcounsel/blob/b036d17a23125d51b9714a736481865a87eee226/skills/setup/ai-governance-cold-start-interview/SKILL.md at commit b036d17a23125d51b9714a736481865a87eee226. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

Workflow

What the source asks the agent to do

  1. 01

    Workflow

    Ask the interviewee: - In which jurisdictions are the client's AI systems deployed, trained, or made available — including but not limited to EU (AI Act), US (federal and state, e.g., Colorado, NYC bias audit, California ADMT), UK, China, Brazil, and others? - Does the group adv…

    In which jurisdictions are the client's AI systems deployed, trained, or made available — including but not limited to EU (AI Act), US (federal and state, e.g., Colorado, NYC bias audit, California ADMT), UK, China, Bra…Does the group advise on sector-specific AI regimes — FDA, HIPAA, FCRA, FTC, financial services, education, employment?Are there jurisdictions where the group's clients face heightened AI regulation (e.g., EU AI Act high-risk-system obligations) that require special handling?
  2. 02

    Attorney Verification Checklist

    [ ] All eight profile sections have been reviewed by a supervising attorney or authorized practice-group representative.

    [ ] All eight profile sections have been reviewed by a supervising attorney or authorized practice-group representative.[ ] Jurisdiction coverage — including EU AI Act, US state laws, sector-specific regimes — is accurately recorded [Verify current law].[ ] High-risk use-case definitions and escalation triggers are consistent with the EU AI Act framework and any other applicable framework [verify jurisdiction].
  3. 03

    Purpose

    Conduct a structured, staged interview with an AI-governance practice group — led by a supervising attorney or authorized designee — to gather the information required to populate practice-profiles/ai-governance.md. The skill walks through all eight profile fields in sequence, r…

    Conduct a structured, staged interview with an AI-governance practice group — led by a supervising attorney or authorized designee — to gather the information required to populate practice-profiles/ai-governance.md. The…
  4. 04

    Use When

    A team is adopting AgentCounsel and needs to configure practice-profiles/ai-governance.md for the first time.

    A team is adopting AgentCounsel and needs to configure practice-profiles/ai-governance.md for the first time.An AI-governance practice group is being onboarded to the library and no current profile exists.The library is being stood up for the first time and the AI-governance area is included in scope.
  5. 05

    Required Inputs

    A knowledgeable person from the AI-governance practice group — a supervising attorney or an authorized designee — who can answer questions about the group's jurisdiction, positions, escalation rules, and review requirem…

    A knowledgeable person from the AI-governance practice group — a supervising attorney or an authorized designee — who can answer questions about the group's jurisdiction, positions, escalation rules, and review requirem…Any existing playbooks, templates, source-of-truth documents, or standard-form documents the group already uses, so they can be referenced or cited in the profile.- A knowledgeable person from the AI-governance practice group — a supervising attorney or an authorized designee — who can answer questions about the group's jurisdiction, positions, escalation rules, and review requir…

Permission review

Static risk signals and limitations

No configured static risk pattern was detected

This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.

Evidence record

Why each signal appears

EvidenceSourceComputedTestedEditorial
SignalValueEvidence typeMeaning
Quality score93/100ComputedDocumentation, specificity, maintenance, and trust rules
Repository stars17SourceRepository attention, not individual Skill quality
Compatibility0 platformsSourceDeclared in the catalog source record
Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

Pinned source

Provenance and original SKILL.md

Repository
zgbrenner/agentcounsel
Skill path
skills/setup/ai-governance-cold-start-interview/SKILL.md
Commit
b036d17a23125d51b9714a736481865a87eee226
License
MIT
Collected
2026-08-04
Default branch
main
View the original SKILL.md

AI Governance Cold-Start Interview

Purpose

Conduct a structured, staged interview with an AI-governance practice group — led by a supervising attorney or authorized designee — to gather the information required to populate practice-profiles/ai-governance.md. The skill walks through all eight profile fields in sequence, records every answer, and assembles a filled draft of the profile for the practice group's review and approval. It produces draft legal work product for attorney review — not legal advice and not a final configuration.

Use When

  • A team is adopting AgentCounsel and needs to configure practice-profiles/ai-governance.md for the first time.
  • An AI-governance practice group is being onboarded to the library and no current profile exists.
  • The library is being stood up for the first time and the AI-governance area is included in scope.
  • A practice group wishes to revisit or rebuild its profile from scratch rather than make incremental updates.

Required Inputs

  • A knowledgeable person from the AI-governance practice group — a supervising attorney or an authorized designee — who can answer questions about the group's jurisdiction, positions, escalation rules, and review requirements.
  • Any existing playbooks, templates, source-of-truth documents, or standard-form documents the group already uses, so they can be referenced or cited in the profile.

Do Not Use When

  • The group is actively working a live AI-governance matter. This skill configures the library; it does not support an open matter.
  • A practice-profiles/ai-governance.md already exists and is current. In that case this is a refresh, not a cold start — though the skill may still be used to rebuild the profile deliberately.
  • No authorized person is available to answer. Do not complete the interview with guessed or inferred answers; record all gaps as [CONFIRM: ...] placeholders.
  • The purpose is to handle a specific AI-governance matter (use the appropriate matter-level skill for that task).

Legal Safety Rules

  • Produce draft legal work product for attorney review. This is not legal advice.
  • Never guess or infer an answer to any interview question. If the interviewee cannot answer a question, record [CONFIRM: answer required from practice group] and move on.
  • The filled profile is a draft. It must be reviewed and explicitly approved by the supervising attorney or practice group before it governs any AgentCounsel work product.
  • Do not invent standard positions, clause preferences, escalation thresholds, or review rules. Record only what the interviewee provides.
  • Do not include client-specific facts, client names, matter identifiers, or privileged details in the profile. The profile is a reusable group-level configuration, not a matter record.
  • Do not state or imply that any threshold, position, or rule in the profile satisfies a legal requirement under any jurisdiction. Jurisdiction-specific legal obligations are for the attorney to verify.
  • Flag every item the interviewee defers or leaves open with a visible [CONFIRM: ...] placeholder so the reviewer can see exactly what is unresolved.

Workflow

Stage 1 — Jurisdictions

Ask the interviewee:

  • In which jurisdictions are the client's AI systems deployed, trained, or made available — including but not limited to EU (AI Act), US (federal and state, e.g., Colorado, NYC bias audit, California ADMT), UK, China, Brazil, and others?
  • Does the group advise on sector-specific AI regimes — FDA, HIPAA, FCRA, FTC, financial services, education, employment?
  • Are there jurisdictions where the group's clients face heightened AI regulation (e.g., EU AI Act high-risk-system obligations) that require special handling?
  • Are there jurisdictions or sectors the group treats as out of scope, requiring specialist outside counsel?
  • Does the group maintain jurisdiction-by-jurisdiction tracking of AI regulatory developments, and where is it stored?

Record answers. Mark any unanswered item [CONFIRM: jurisdiction not yet specified].

Stage 2 — Client and Team Context

Ask the interviewee:

  • Who are the primary clients of the AI-governance group — product teams, AI engineering, vendor management, executives, board, external clients?
  • What types of AI-governance matters does the group handle most frequently — use-case intake, vendor terms review, feature reviews, incident response, policy work, regulatory advice?
  • How is the team structured, and how does it coordinate with privacy counsel, security counsel, and product counsel?
  • Are there model types (foundation models, fine-tuned models, retrieval-augmented systems, agentic systems) or use cases (employment decisions, biometric, child-facing, healthcare) that require special handling?
  • How does the group engage with the client's AI risk committee, ethics board, or analogous governance function?

Record answers. Mark any unanswered item [CONFIRM: client/team context not yet specified].

Stage 3 — Escalation Thresholds

Ask the interviewee:

  • Which use-case categories automatically require escalation — EU AI Act high-risk uses, biometric categorization or remote biometric identification, automated employment decisions, education decisions, lending decisions, child-directed systems?
  • What model events trigger escalation — base-model change, training-data source change, deployment to new region, deployment to consumer-facing context?
  • When does an AI incident (model failure, hallucination causing harm, prompt-injection-driven action, bias finding) require immediate attorney involvement?
  • What vendor-terms scenarios require escalation — vendor training rights on customer data, retention rights, indemnification gaps, sub-processor scope?
  • Who is the designated escalation contact for AI-governance matters, and what is the expected turnaround?

Record answers. Mark any unanswered item [CONFIRM: escalation threshold not yet specified].

Stage 4 — Preferred Output Style

Ask the interviewee:

  • Should AI-governance work product default to AI impact assessment format, use-case intake checklist format, gap analysis, or memo format?
  • What level of detail does the practice group expect — executive summary only, full risk register, both layered?
  • Are there house style rules for risk ratings, mitigation recommendations, or open questions in AI work product?
  • Does the group produce model cards, AI system inventories, or AI registers, and if so, in what format?
  • Are there particular deliverable types — vendor terms review, feature launch review, incident memo — for which the group has mandatory format requirements?

Record answers. Mark any unanswered item [CONFIRM: output style preference not yet specified].

Stage 5 — Source-of-Truth Documents

Ask the interviewee:

  • What is the group's authoritative source of truth for the AI policy, AI principles, and risk-classification taxonomy?
  • Is there an authoritative AI use-case register or inventory? Where is it stored, and how is it kept current?
  • What document governs the group's vendor-evaluation criteria for AI vendors?
  • Is there an AI-incident response playbook, and what document governs it?
  • Are there sector-specific reference materials (e.g., FDA AI/ML guidance, HHS guidance on AI in healthcare) the group treats as authoritative?

Record answers and document names. Mark any unanswered item [CONFIRM: source document not yet identified].

Stage 6 — Standard Positions and Playbooks

Ask the interviewee:

  • What is the group's default posture on training-data sourcing — permissible sources, prohibited sources, due-diligence requirements?
  • What is the group's default consent posture for personalization, profiling, or training-data uses involving personal data?
  • What is the group's default human-in-the-loop posture for decision-supporting AI vs. decision-making AI?
  • What is the group's default logging, audit, and explainability posture for high-risk uses?
  • What is the group's default vendor-terms position on training rights, retention rights, and indemnification?

Record answers. Mark any unanswered item [CONFIRM: standard position not yet specified].

Stage 7 — Attorney Review Requirements

Ask the interviewee:

  • At what stage does attorney review of AI work product become mandatory — at use-case intake, before any model deployment, before any vendor signing, before any high-risk deployment, before any consumer-facing launch?
  • Are there matter types for which attorney review is always required regardless of stage — any high-risk system, any biometric system, any automated employment or lending decision?
  • What is the designated reviewer's role — AI counsel, supervising attorney, AI risk committee chair, general counsel?
  • What is the expected turnaround for standard AI-governance review, and how are urgent reviews (incident, regulator inquiry) handled?
  • Is there a formal sign-off step before an AI feature is launched, a vendor agreement is signed, or an incident response is communicated externally?

Record answers. Mark any unanswered item [CONFIRM: review requirement not yet specified].

Stage 8 — Prohibited Assumptions

Ask the interviewee:

  • Are there facts agents must never assume without explicit confirmation — that training data is lawfully sourced, that a model output is non-hallucinated, that a vendor's model card is current, that a use case is low-risk?
  • Are there AI-specific risks — bias, hallucination, prompt injection, data exfiltration, model inversion, IP leakage — where an agent must stop and escalate rather than reason through independently?
  • Are there matter types where agents must never proceed beyond intake without direct attorney involvement — incidents, regulator inquiries, high-risk deployments?
  • Are there prior incidents, regulator findings, or lessons learned that should be encoded as explicit prohibitions for agents working on AI-governance matters?

Record answers. Mark any unanswered item [CONFIRM: prohibited assumption not yet specified].

Stage 9 — Assemble the Draft Profile

Compile all answers into a filled draft of practice-profiles/ai-governance.md, populating each of the eight profile sections. For every item that was not answered, insert a visible [CONFIRM: ...] placeholder with enough context for the reviewer to understand what needs to be supplied. Append a list of all open placeholders so the reviewing attorney can see at a glance what remains unresolved.

Output Format

Deliver:

  1. Filled draft of practice-profiles/ai-governance.md — all eight sections populated with answers from the interview. Every unanswered item is a visible [CONFIRM: ...] placeholder.
  2. Open-items list — an explicit enumeration of every placeholder inserted, with the stage and question it corresponds to, so the reviewing attorney can resolve them efficiently.

Label the entire output: Draft legal work product for attorney review. Not legal advice. This profile draft must be reviewed and approved by the supervising attorney or practice group before it is relied upon.

Attorney Verification Checklist

  • All eight profile sections have been reviewed by a supervising attorney or authorized practice-group representative.
  • Jurisdiction coverage — including EU AI Act, US state laws, sector-specific regimes — is accurately recorded [Verify current law].
  • High-risk use-case definitions and escalation triggers are consistent with the EU AI Act framework and any other applicable framework [verify jurisdiction].
  • Vendor-terms default positions reflect the current threat landscape (training rights, data retention, indemnification, sub-processor flow-down).
  • Incident-response posture is current and aligned with applicable breach-notification obligations [verify jurisdiction] and all incident deadlines are marked [deadline verification required].
  • AI register / inventory is referenced and the maintenance owner is named.
  • No client-specific facts, matter identifiers, or privileged details appear in the profile.
  • All [CONFIRM: ...] placeholders have been resolved or explicitly accepted as pending.
  • The approved profile has been saved to practice-profiles/ai-governance.md and its effective date recorded.
  • A process for periodic profile review and update has been identified.

Alternatives

Compare before choosing

Computed 10023,781

alirezarezvani/claude-skills

app-store-optimization

App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist

Computed 10014,225

wanshuiyin/Auto-claude-code-research-in-sleep

citation-audit

Use it for operations and research tasks; the detail page covers purpose, installation, and practical steps.

Computed 1004,922

dotnet/skills

migrate-vstest-to-mtp

Migrates .NET test projects from VSTest to Microsoft.Testing.Platform (MTP). Use when user asks to "migrate to MTP", "switch from VSTest", "enable Microsoft.Testing.Platform", "use MTP runner", set OutputType=Exe only for test projects in Directory.Build.props, or mentions EnableMSTestRunner, EnableNUnitRunner, or UseMicrosoftTestingPlatformRunner. USE FOR: MTP behavioral differences vs VSTest (exit code 8, zero tests discovered, --ignore-exit-code, TESTINGPLATFORM_EXITCODE_IGNORE); centralizing

Computed 1002,504

aaron-he-zhu/aaron-marketing-skills

social-selling-planner

Use when the user asks to "set up my founder social-selling routine", "build a daily engagement block for target accounts", or "turn funding / hiring signals into selling plays"; produces the founder/seller daily operating block — a time-boxed engagement-block spec (substantive value-add comments on target-account posts, never a pitch), warm-touch-before-ask cadence rules, trigger-response plays consuming the social-pulse-monitor B2B trigger watchlist (funding / hiring / launch signals), and a q