Google's official skill for the gws CLI — drive Gmail, Drive, Calendar, Sheets, Docs, Chat and Admin APIs from an agent, with Model Armor screening.

SAIL — Secure AI LifecycleSkill
Summary
Pillar Security's SAIL V2 framework as an agent skill: a 91-risk catalogue across seven lifecycle phases, for AI security gap assessments, roadmaps, and ISO 42001 / EU AI Act compliance checklists.
Features
- 91-risk catalogue across seven AI lifecycle phases and three deployment zones
- Stable SAIL IDs make findings citable across security, legal and engineering
- Gap assessment with per-risk disposition and evidence-based maturity scoring
- Compliance checklists for ISO/IEC 42001, EU AI Act, OWASP, DASF and AIUC-1
- Phase-sequenced security roadmaps generated from identified gaps
- Vendor RFP and security questionnaire generation
- Autonomy tiers scale control intensity to each agent's actual privileges
Install This Skill
Add this skill to your favorite AI agent in a few steps.
Skill Content
Usage Instructions
Learn how to use this skill with different AI agents.
Example Usage
Assess our customer-support agent architecture against SAIL and give me the unaddressed risks in the Runtime Controls phase, with mitigations.
Description
Most AI security advice an assistant can offer is generic, because the model is recalling scattered blog posts rather than working from a catalogue. SAIL fixes that by giving the agent a structured reference: Pillar Security's Secure AI Lifecycle framework, version 2, with 91 named risks organised across seven phases — Policy, Discovery, Posture, Red Teaming, Runtime Controls, Sandbox and Govern — spanning three deployment zones covering code and pipeline, cloud agents, and endpoint agents.
Because every risk has a stable identifier, answers come back citable. A finding is "SAIL 5.17", not "you should probably think about prompt injection", and that identifier means the same thing to the security team, legal, compliance and the engineers implementing the fix. Each catalogue entry carries its mitigations and its mappings to external standards.
The skill supports several concrete workflows rather than only answering questions. It runs a full gap analysis with a risk disposition across all 91 items; builds a phase-sequenced security roadmap from the gaps; scores maturity per risk as unaddressed, partially mitigated, or mitigated with evidence, producing a profile you can trend over time; generates compliance checklists filtered to whichever framework you are accountable to — ISO/IEC 42001, the EU AI Act, OWASP LLM and Agentic Top 10, DASF, or AIUC-1; and turns the catalogue into vendor RFP questionnaires. Autonomy tiers set control intensity per agent, which is how it avoids demanding the same controls for a read-only summariser and an agent with production write access.
It installs on Claude Code, Claude.ai, Claude Desktop, Cowork, OpenAI Codex, Google Antigravity, ChatGPT, opencode, pi and other SKILL.md-compatible runtimes.
Licensing needs a careful read: CC BY-NC-SA 4.0. Internal organisational use is permitted including in a commercial company, but redistributing it or building it into a product you ship requires separate licensing from Pillar Security.
Related Skills
Netlify's official skill for zero-config managed Postgres — querying from Functions, Drizzle setup, migrations and per-preview database branches.
Official WordPress skill for Gutenberg block work: block.json, attributes and serialization, dynamic rendering, and the deprecation path that keeps existing content valid.
Persistent cross-session memory for coding agents: hooks capture each session, a local SQLite + vector store compresses it, and a mem-search skill reads it back.
