From provectus-governance
The Provectus Governance Charter — the FSI policy this project operates under. Use this whenever you need to know what actions are permitted, forbidden, or audited. Consult before any file, git, or network operation in a governed repository.
How this skill is triggered — by the user, by Claude, or both
Slash command
/provectus-governance:governance-charterThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
This project operates under a governed agentic-AI policy. These rules are
This project operates under a governed agentic-AI policy. These rules are enforced deterministically by PreToolUse hooks — they are not suggestions, and they cannot be disabled by changing permission mode.
.env, *.pem, *.key, credentials*, or paths under secrets/.git push to
main or master; open a pull request instead.curl, wget, nc) — outbound data movement is blocked.Every tool call is recorded to an append-only audit log with timestamp, tool, target, and the policy decision, so any action is answerable to an auditor after the fact.
In regulated environments, "the model usually behaves" is not a control. Deterministic, auditable enforcement is what lets a CISO say yes to agents.
npx claudepluginhub diegouis/ccw-governance-demo --plugin provectus-governanceCreates, edits, and optimizes skills for Claude Code, including drafting, evaluating with test prompts, iterating on performance, and improving skill descriptions for better triggering accuracy.