Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Org Policy Model Rules Audit

ASecurity

Audit an organization's AI coding tool model-access policies across GitHub Copilot Business/Enterprise, OpenAI org-level controls, and xAI API governance. Reach for this skill when an enterprise team reports unexpected model access, when a compliance review requires documenting which models the org has allowed or blocked, or before rolling out a new model to a large org.

7 stars
0 votes
0 copies
0 views
Added 9/23/2026
ai-agentsgogitapisecurity

Works with

api

Security Analysis

A100/100

Scanned 9/23/2026

$npx -y skills add mcorbett51090/RavenClaude --skill org-policy-model-rules-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Org Policy Model Rules Audit?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Org Policy Model Rules Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/mcorbett51090-org-policy-model-rules-audit/badge)](https://www.skillsdirectory.com/skills/mcorbett51090-org-policy-model-rules-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: org-policy-model-rules-audit
description: "Audit an organization's AI coding tool model-access policies across GitHub Copilot Business/Enterprise, OpenAI org-level controls, and xAI API governance. Reach for this skill when an enterprise team reports unexpected model access, when a compliance review requires documenting which models the org has allowed or blocked, or before rolling out a new model to a large org."
---

# Skill: Org Policy Model Rules Audit

Enterprise and business teams govern which models their developers can use. A model available in the public picker may be blocked by org policy; a policy intended to restrict a model may be misconfigured. This skill structures the audit so gaps are found before they produce compliance findings or unexpected bills.

**Security-reviewer escalation rule:** any finding that involves API key scope, token storage, or a compliance verdict (SOC 2 / FedRAMP / GDPR applicability) escalates immediately to `ravenclaude-core/security-reviewer`. This skill audits policy configuration; it does not produce compliance opinions.

## Step 1 — Identify the platforms in scope

The three ecosystems in this plugin have different governance surfaces:

| Platform | Governance surface | Scope |
|---|---|---|
| GitHub Copilot Business | GitHub org settings → Copilot → Model rules | Allow/deny specific models for all org members |
| GitHub Copilot Enterprise | Same as Business + GHEC-level policy | Broader controls; enterprise-managed users |
| OpenAI Codex / API | OpenAI org settings → Usage policies | Org-level model access; project-scoped API keys |
| xAI Grok API | API key ownership | No org-level picker controls as of this writing [verify-at-use] |

## Step 2 — Audit GitHub Copilot model rules (Business / Enterprise)

For each org on Business or Enterprise:

```
[ ] Navigate to: org → Settings → Copilot → Policies → Model availability
[ ] Document the current model access state:
    - "Allow all models" (default)
    - "Allow selected models only" (explicit allow-list)
    - "Block specific models" (explicit deny-list)
[ ] Cross-reference the allow/deny list against the verified lineup
    — are any models in the deny-list already unavailable (redundant)?
    — are any models the team needs blocked unintentionally?
[ ] Confirm whether model rules apply to all surfaces (completions, chat, coding agent)
    or only to specific surfaces [verify-at-use — Copilot org docs]
[ ] Document who has admin rights to change the policy
```

## Step 3 — Audit OpenAI org-level controls

```
[ ] Log into platform.openai.com → org settings → Usage
[ ] Document any project-scoped API keys (limited to specific models or rate limits)
[ ] Identify any spending limits that would cap access to frontier models
[ ] Confirm whether the org's usage policy restricts specific model families [verify-at-use]
[ ] Document API key rotation cadence — stale keys are a governance gap
```

## Step 4 — Produce the audit summary

```
Audit date: YYYY-MM-DD
Platforms audited: [list]
Findings:

| Platform | Policy state | Gap found? | Risk level | Recommendation |
|---|---|---|---|---|
| Copilot (org: X) | Allow all | No | Low | Maintain; review quarterly |
| Copilot (org: Y) | Block list | Yes — [model] unintentionally blocked | Medium | Update deny-list |
| OpenAI org | Project key scoped | Yes — frontier model unreachable | High | Add frontier model to project key scope |
| Grok API | API key only | No org controls [verify-at-use] | Low | Document key rotation schedule |

Escalation to security-reviewer: [yes/no — reason if yes]
```

## Step 5 — Flag escalation-worthy findings

Escalate to `ravenclaude-core/security-reviewer` when any of these are found:
- API keys with broader-than-needed scope
- Org policy blocks that appear designed for compliance but are misconfigured
- A model in the allow-list that has known security or data-handling concerns [verify-at-use]
- Any finding touching GDPR, SOC 2, FedRAMP, or a similar framework

## Pitfalls

- Auditing only the Copilot model picker without checking org policy — org policy overrides individual developer choices.
- Treating Grok API access as ungoverneable because it lacks a picker — API key scope and rotation are the governance levers.
- Marking a finding as resolved without documenting the person who changed the policy and when.
- Recommending a compliance verdict without escalating to security-reviewer.

## See also

- [`../../agents/copilot-model-strategist.md`](../../agents/copilot-model-strategist.md) — Copilot org model rules in depth
- [`../../CLAUDE.md`](../../CLAUDE.md) — §2 routing rule: org model rules escalate to security-reviewer
- [`../../knowledge/cross-tool-model-lineup-2026.md`](../../knowledge/cross-tool-model-lineup-2026.md) — the verified lineup to cross-reference against policy allow/deny lists

Attribution

mcorbett51090mcorbett51090
View sourceSee grades on GitHubMore from mcorbett51090 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →