Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Ai Usage Policy

ASecurity

Write an AI usage policy people can actually follow — approved tools, data rules, disclosure duties, and review obligations, in one page instead of legal fog. Use when asked for a company AI policy, acceptable-use rules for ChatGPT/Claude/Copilot at work, guidance on what data may go into AI tools, or to fix a policy nobody reads. Produces a one-page usable policy plus the decision log behind it. Not a substitute for legal advice; pairs with compliance-checklist for regulatory mapping and ai-...

1,330 stars
0 votes
0 copies
0 views
Added 9/3/2026
ai-agentsgorailsgit

Works with

cli

Security Analysis

A100/100

Scanned 9/3/2026

$npx -y skills add mohitagw15856/pm-claude-skills --skill ai-usage-policy --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ai Usage Policy?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Ai Usage Policy
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/mohitagw15856-ai-usage-policy/badge)](https://www.skillsdirectory.com/skills/mohitagw15856-ai-usage-policy)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: ai-usage-policy
description: "Write an AI usage policy people can actually follow — approved tools, data rules, disclosure duties, and review obligations, in one page instead of legal fog. Use when asked for a company AI policy, acceptable-use rules for ChatGPT/Claude/Copilot at work, guidance on what data may go into AI tools, or to fix a policy nobody reads. Produces a one-page usable policy plus the decision log behind it. Not a substitute for legal advice; pairs with compliance-checklist for regulatory mapping and ai-ethics-review for system-level assessments."
homepage: https://mohitagw15856.github.io/pm-claude-skills/skill/ai-usage-policy.html
metadata:
  {
    "openclaw": { "emoji": "🤖" }
  }
---

# AI Usage Policy Skill

Most corporate AI policies fail in one of two ways: a fearful ban everyone quietly ignores (shadow AI, zero visibility), or legal fog nobody can apply to the question they actually have — "can I paste this customer email into Claude?" This skill writes the policy as a *decision aid*: one page, answerable in the moment of use, with the reasoning logged separately for counsel.

## What This Skill Produces

- A **one-page policy**: approved tools, the data traffic-light, disclosure duties, review obligations, and how to get a tool approved
- A **decision log**: the reasoning behind each rule, for legal/leadership review
- A **rollout note**: how the policy lands without becoming shelfware

## Required Inputs

Ask for (if not already provided):
- **The org**: size, industry, regulatory exposure (health, finance, gov contracts change the answers)
- **Current reality**: which AI tools are already in use — officially and (honestly) unofficially
- **Data landscape**: what sensitive classes exist (customer PII, PHI, source code, financials, client-confidential)
- **Enterprise agreements in place**: which tools have zero-retention/no-training terms signed vs consumer accounts
- **Risk appetite**: enable-with-guardrails or restrict-hard? (Get the sponsor's one-word answer.)

## Policy Method

1. **Legalise reality first.** Shadow AI is the largest risk *created by* strict policies. Start from what people already use; the policy's first job is making the sanctioned path easier than the unsanctioned one — approved tools with enterprise terms, clearly listed, with a fast approval lane for new ones (named owner, ≤2-week SLA).
2. **Rule on data, not tools.** Tools churn monthly; data classes don't. The core artifact is a traffic-light table people can apply in three seconds:
   - 🟢 **Fine in approved tools** — public info, your own drafts, non-confidential work product
   - 🟡 **Approved tools with enterprise terms only** — internal business data, code, unreleased plans
   - 🔴 **Never in any AI tool** (until a named exception is granted) — regulated data (PHI, card data), client-confidential under NDA, credentials, anything under legal hold
   Each row names *examples from this org's actual work*, not abstract categories.
3. **Set the accountability rule once, clearly.** The human who ships it owns it — AI-assisted or not. From that root, the review duties follow: outputs going to customers/public/regulators get human review *by someone competent to catch the errors*; internal drafts don't need ceremony. State both halves; policies that demand review-everything get review-nothing.
4. **Decide disclosure deliberately.** Internal: generally not required (it's a tool). External: disclose where the audience would feel deceived otherwise (bylined content, legal filings, anything presented as human judgment — expert reports, references) or where law/regulator requires it. Write the *specific* disclosure lines for this org's cases, not a principle.
5. **Keep the enforcement honest.** First violations of 🟡 rules are coaching moments; 🔴 violations follow the existing data-handling discipline process (don't invent a parallel one). The policy names its owner, its review cadence (quarterly — the landscape moves), and where questions go *today*.
6. **Log the reasoning separately.** Every rule gets one line in the decision log: what we ruled, why, what we considered. Counsel reviews the log; humans read the page.

## Output Format

### AI Usage Policy: [org] — v1, [date] · owner: [role] · review: quarterly

**Approved tools:** [tool → account type (enterprise/consumer-banned) → what it's approved for]
**Getting a tool approved:** [the lane: who, what they check, SLA]

**The data rule** *(the table above, with org-specific examples per row)*

**Your accountability:** [the ship-it-you-own-it rule + review duties by output destination]

**Disclosure:** [the org's specific cases with the exact lines to use]

**If something goes wrong:** [pasted the wrong thing / AI error shipped → who to tell, framed as no-fault-if-fast]

---
**Decision log** *(separate artifact)*: [rule → reasoning → alternatives considered → open questions for counsel]

**Rollout note:** [announce with the *enabling* frame; 30-min manager briefing; the three examples everyone actually asks about, answered]

## Quality Checks

- [ ] A stressed employee can answer "can I paste X into Y?" from the page in under a minute
- [ ] Every data-class row carries examples from this org's real work
- [ ] The sanctioned path is genuinely easier than shadow use (tools listed, approval lane fast)
- [ ] Disclosure rules are specific lines for specific cases, not a value statement
- [ ] The policy names its owner, review cadence, and question channel
- [ ] The decision log exists — counsel reviews reasoning, not just conclusions

## Anti-Patterns

- [ ] Do not ban broadly and enforce never — that policy trains people to hide usage you most need to see
- [ ] Do not write rules per-tool as primary structure — tools churn; data classes are the stable spine
- [ ] Do not require human review of *everything* — undifferentiated duty guarantees zero real review
- [ ] Do not copy another company's policy without the data-class mapping — the table is the policy
- [ ] Do not present this as legal advice — it's the draft counsel refines, and the page says so

Attribution

mohitagw15856mohitagw15856
View sourceSee grades on GitHubMore from mohitagw15856 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →