borghei/prompt-governance
> This skill should be used when the user asks to "audit prompts for safety", "check prompts for injection vulnerabilities", "manage a prompt catalog", "version control prompts", or "review prompt quality and compliance".
npx skills add https://github.com/borghei/Claude-Skills --skill prompt-governance
> Category: Engineering
> Domain: AI Governance
The Prompt Governance skill provides tools for auditing prompts for security vulnerabilities, bias, and safety issues, plus managing a versioned catalog of approved prompts. Essential for organizations deploying LLM-based applications at scale.
Before auditing or cataloging, confirm these inputs. If any is unknown or vague, ASK — do not assume:
prompt_auditor.py vs prompt_catalog_manager.py and the whole workflowStop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.
# Audit a prompt for security and safety issues
python scripts/prompt_auditor.py --file system_prompt.txt
# Audit with specific focus
python scripts/prompt_auditor.py --text "You are a helpful assistant..." --checks injection,bias,safety
# Initialize a prompt catalog
python scripts/prompt_catalog_manager.py --init --catalog-dir ./prompts
# Add a prompt to the catalog
python scripts/prompt_catalog_manager.py --add --name "customer-support-v1" --file prompt.txt --catalog-dir ./prompts
# List all prompts in catalog
python scripts/prompt_catalog_manager.py --list --catalog-dir ./prompts
| Tool | Purpose | Key Flags |
|------|---------|-----------|
| prompt_auditor.py | Audit prompts for injection, bias, and safety | --file, --text, --checks, --format |
| prompt_catalog_manager.py | Manage versioned prompt catalog | --init, --add, --list, --diff, --catalog-dir |
prompt_auditor.py for automated checksprompt_catalog_manager.py--diff to compare versions before promotionDraft -> Audit -> Review -> Approve -> Deploy -> Monitor -> Retire
Take borghei/prompt-governance from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.