๐ŸŽฏ .github/skills/

April 24, 2026 ยท View on GitHub

This directory contains 91 skill packages that teach GitHub Copilot how to approach specific domains when working in Riksdagsmonitor. Skills are strategic, reusable, rule-based instruction sets โ€” not step-by-step runbooks. They load automatically when a Copilot agent determines a task touches the relevant domain.

Canonical long-form skill catalog with detailed mappings: see SKILLS.md at the repository root. Agent โ†’ skill recommendations: see AGENTS.md ยง"Skills Mapping by Agent" and .github/agents/README.md.


๐Ÿง  How skills work

Each skill is a directory containing a SKILL.md file (and optional supporting assets). When Copilot begins a task, skills are matched against the request. If relevant, they are loaded into the agent's context alongside the persona and repository-wide copilot-instructions.md.

PropertyValue
ScopeRepository-local (.github/skills/) + implicit project-level skills listed in copilot-instructions.md <available_skills>
InvocationAutomatic (when relevant) or explicit via skill tool
GovernanceCEO approval for material changes per Change_Management.md
AttributionAI-assisted edits require human review + DCO sign-off per AI_Policy.md

๐Ÿ“š Skill catalog (91 skills)

Skills are grouped into 12 functional categories that mirror the Riksdagsmonitor capability areas. Each row links to the skill's SKILL.md.

๐Ÿ›ก๏ธ Core Infrastructure & Governance (9)

SkillPurpose
hack23-isms-complianceStrategic ISMS compliance enforcement across repositories
security-by-designSecurity architecture principles from requirement to delivery
static-site-securityHardening static HTML/CSS sites hosted on GitHub Pages
ci-cd-securitySecurity for GitHub Actions, supply chain, and pipelines
documentation-standardsHack23 technical writing standards and Mermaid conventions
documentation-portfolioRequired C4 / data / SWOT / threat-model docs for every repo
hack23-future-architecture-standardsRules for the future-state document portfolio
html-accessibilityWCAG 2.1 AA compliance for static sites
multi-language-localization14-language support with RTL (Arabic, Hebrew) and hreflang

๐Ÿ•ต๏ธ Political Intelligence (11)

SkillPurpose
political-science-analysisComparative politics, policy analysis, frameworks
osint-methodologiesOpen-source intelligence collection and verification
intelligence-analysis-techniquesACH, SWOT, Devil's Advocate, Red Team, key assumptions check
swedish-political-systemRiksdag structure, 8 parties, electoral system, coalition dynamics
electoral-analysisElection forecasting, coalition prediction, voter behaviour
behavioral-analysisPolitical psychology, cognitive biases, leadership analysis
strategic-communication-analysisNarrative analysis, media monitoring, messaging detection
legislative-monitoringVoting patterns, committee effectiveness, bill tracking
risk-assessment-frameworksPolitical risk and corruption-indicator taxonomies
data-science-for-intelligenceStatistics, ML, NLP, time series, network analysis
gdpr-complianceGDPR for political-data processing and public-official data

๐Ÿ” ISMS & Security (14)

SkillPurpose
iso-27001-controlsISO 27001:2022 Annex A controls for static sites
nist-csf-mappingNIST CSF 2.0 function / category / subcategory mapping
cis-controlsCIS Controls v8.1 implementation for static sites
threat-modelingSTRIDE, MITRE ATT&CK, attack-tree methodology
secure-code-reviewHTML / CSS / JS / TS security-focused review
security-documentationISMS documentation standards
incident-responseNIST + ISO 27001 incident-response lifecycle
input-validationXSS/injection prevention, safe output encoding
vulnerability-managementSLA-driven remediation (Critical 24h / High 7d / Med 30d / Low 90d)
data-protectionClassification, privacy-by-design, encryption
ai-governanceEU AI Act, OWASP LLM security, responsible AI
information-security-strategyProgram-level security strategy and risk management
compliance-checklistUnified mapping across ISO/NIST/CIS/GDPR/NIS2/EU CRA/SOC 2/PCI DSS/HIPAA
secrets-managementGitHub secrets, PATs, OIDC, token rotation

โš™๏ธ Development & Operations (14)

SkillPurpose
c4-architecture-documentationC4 (Context/Container/Component) + Mermaid diagrams
github-actions-workflowsWorkflow patterns, reusable workflows, caching
code-quality-checksHTMLHint, linkinator, ESLint, JSON validation
code-review-practicesReview quality gates and constructive feedback
testing-strategyUnit / integration / E2E strategy (Vitest + Cypress)
performance-optimizationCore Web Vitals, bundle size, caching
api-integrationREST / GraphQL clients, rate limiting, auth
data-pipeline-engineeringETL, scheduling, versioned caching, freshness monitoring
change-managementITIL-aligned change flow (Normal/Standard/Emergency)
contribution-guidelinesPR workflows, DCO/CLA, community engagement
open-source-governanceOSS licensing, SBOM, supply-chain posture
secure-development-policyHack23 Secure Development Policy enforcement
secure-development-lifecycleSDL phases from requirement to retirement
product-management-patternsRoadmapping, issue hygiene, prioritization

๐Ÿงช Testing & Quality Assurance (2)

SkillPurpose
playwright-testingPlaywright automation, visual regression, a11y audits
issue-managementGitHub issue creation, labeling, milestones

๐ŸŽจ UI/UX & Design (8)

SkillPurpose
responsive-designMobile-first CSS Grid/Flexbox, 320-1440px breakpoints
design-system-managementCyberpunk theme, CSS custom properties, component library
political-data-visualizationCSS-only charts, heat maps, dashboards
advanced-data-visualizationChart.js / D3.js interactive dashboards
data-visualization-principlesChart selection, colour theory, storytelling
ui-ux-designUX heuristics, information architecture
seo-optimizationSchema.org, OpenGraph, Twitter Cards, hreflang
seo-best-practicesCanonical URLs, sitemap, robots.txt

Note: the UI/UX category lists 8 rows; seo-best-practices and seo-optimization are two distinct skills โ€” one content/strategy-focused, one technical.

๐Ÿ“ก Data Integration (6)

SkillPurpose
riksdag-regering-mcp32-tool MCP coverage for Riksdag + Regering data
cia-data-integrationCIA platform JSON export consumption and validation
european-parliament-apiEuropean Parliament Open Data integration
mcp-server-developmentBuilding / packaging MCP servers
mcp-gateway-configurationGateway routing, tool wiring, access control
mcp-gateway-securityToken management, request validation, audit logging

๐Ÿ“ฐ Journalism & Media (5)

SkillPurpose
editorial-standardsOSINT/INTOP editorial standards, attribution, fact-checking
investigative-journalismSource verification, document analysis, FOI requests
prospective-news-coverageForward-looking / week-ahead / month-ahead coverage
comparative-politics-reportingCross-country context for Swedish developments
automated-content-generationTemplate-based content rendering in 14 languages

๐Ÿ›๏ธ Government, Regulatory & Economics (7)

SkillPurpose
global-government-analysisComparative government systems, cross-country governance
myndigheter-monitoringSwedish government-agency monitoring
regulatory-affairsRegulatory change tracking and compliance impact
economic-policy-analysisFiscal / monetary / trade policy analysis
business-developmentStakeholder engagement, partnerships, community growth
business-model-canvasBusiness Model Canvas for open-source sustainability
marketingDigital marketing, SEO, content marketing, analytics

๐Ÿ—ฃ๏ธ Language & Localization (1)

SkillPurpose
language-expertiseLinguistic and cultural expertise for all 14 supported languages (EN, SV, DA, NB, FI, DE, FR, ES, NL, AR, HE, JA, KO, ZH)

๐Ÿค– GitHub Agentic Workflows (13)

These skills encode the gh-aw framework's upstream rules. They underpin every .github/workflows/news-*.md workflow and the prompt modules in .github/prompts/. The index lives in gh-aw-README.md.

SkillPurpose
github-agentic-workflowsRoot skill: v0.69.1 overview, five-layer security, safe outputs, MCP
gh-aw-workflow-authoringMarkdown syntax, YAML frontmatter, compilation to .lock.yml
gh-aw-mcp-configurationMCP server setup, transport protocols, lifecycle, tool discovery
gh-aw-mcp-gatewayExpert-level MCP gateway: routing, Docker, security, deployment
gh-aw-safe-outputsSanitisation, controlled AI actions, write-operation patterns
gh-aw-security-architectureDefense-in-depth, threat model, sandboxing, attack vectors
gh-aw-firewallSquid proxy domain allow-listing, iptables, credential management
gh-aw-containerizationDocker isolation, multi-stage builds, image optimisation
gh-aw-github-actions-integrationWorkflow triggers, env config, secrets, matrix, deployment
gh-aw-authentication-credentialsToken types, rotation, least-privilege, MCP auth, API keys
gh-aw-logging-monitoringStructured logging, metrics, alerting, debugging
gh-aw-tools-ecosystemTool capabilities, limits, integration patterns, custom tools
gh-aw-continuous-ai-patternsContinuous-AI triage / review / maintenance patterns

๐Ÿ“‹ Copilot Patterns (1)

SkillPurpose
copilot-agent-patternsCustom agent design patterns, collaboration workflows, orchestration

๐Ÿ—ž๏ธ How skills feed the news aggregator

The news-generation pipeline (scripts/aggregate-analysis.ts โ†’ scripts/render-articles.ts โ†’ scripts/render-lib/) derives every published article from three static inputs: analysis/methodologies/, analysis/templates/, and the per-day artifacts in analysis/daily/$DATE/$SUB/. Skills shape how each of those inputs is authored:

SkillRole in the pipeline
automated-content-generationDefines the 9-artifact section schema every per-type analysis run must hit (executive-brief โ†’ synthesis โ†’ significance โ†’ stakeholders โ†’ SWOT โ†’ scenarios โ†’ comparative โ†’ intel-assessment โ†’ classification). An artifact authored with this skill can be dropped into analysis/daily/$DATE/$SUB/ and the aggregator will process it without modification.
editorial-standardsGoverns tone (inverted-pyramid structure, AP/Reuters attribution, balanced reporting), source-citation density, and the rule that every factual claim must link to a specific Riksdag/Regering source. Artifacts that violate these rules will fail the analysis gate in .github/prompts/05-analysis-gate.md.
data-pipeline-engineeringProvides the contract for how MCP query results are cached, deduplicated, and inlined into artifacts so the aggregator's SHA-256 manifest remains reproducible: same source data โ†’ same article.md.

Because these three skills are primary for the aggregator flow, any workflow that produces news artifacts MUST load them. The per-type .lock.yml workflows implicitly do so via tools: ["*"]; if you author an artifact manually, invoke these skills explicitly.

๐Ÿ”ข Count reconciliation

CategoryCount
Core Infrastructure & Governance9
Political Intelligence11
ISMS & Security14
Development & Operations14
Testing & Quality Assurance2
UI/UX & Design8
Data Integration6
Journalism & Media5
Government, Regulatory & Economics7
Language & Localization1
GitHub Agentic Workflows13
Copilot Patterns1
Total91

Source of truth: ls .github/skills/ | grep -v '^gh-aw-README\.md$' | wc -l โ†’ 91.


โœ๏ธ Authoring a new skill

  1. Create a directory <skill-name>/ in this folder (kebab-case).
  2. Add a SKILL.md describing: When to use, Rules to follow, Examples.
  3. Keep it strategic โ€” principles and rules, not runbooks.
  4. Cross-link to any related skills under "See also".
  5. Open a PR; CEO approval required per Change_Management.md.
  6. Update this README's catalog table and the total in SKILLS.md.


๐Ÿ“‹ Document owner: CEO | ๐Ÿท๏ธ Classification: Public | ๐Ÿ”„ Review cycle: Quarterly