Every L1+ skill must declare how fast it decays and what forces immediate revalidation. Skills that miss this are non-compliant. They do not get promoted past DRAFT.
decay_trigger: a named external event that forces revalidation - e.g. "EUPTD transposition update", "EU AI Act entry into force"
STABLE status: requires a live_fire.v1 registry entry with real client name, specific measurable outcome, timestamp, and second-party verification
Skills missing GVC fields are flagged at the next quality-audit run. Silence = downgrade to BETA on the next compliance sweep
Pre-commit CI hook checks GVC compliance on every push. Non-compliant skills block the commit
Skill Series
7 skill series
226 skills organised by domain. Each skill has explicit triggers, anti-triggers, input/output contracts, quality gates, and a fragility declaration.
Series breakdown
H series — 73 skills — HR core: job evaluation, pay equity, EUPTD, salary bands, ADKAR, workforce planning, AI-human RACI
S series — 40 skills — Sales and GTM: pre-sales agent, cold email pipeline, deal qualification, proposals, LinkedIn outreach
D series — 22 skills — Document forensics: anti-cherry-picking audit, intent archaeology, mediocrity detection, polyphony reading
M series — 59 skills — Methodology and meta: quality audit, skill lifecycle, synapse builder, governance decision logger, system pulse
L series — 12 skills — Legal and regulatory: EU AI Act compliance, EUPTD readiness, NIS2 org design, regulatory lookup
T series — 12 skills — Technology: MCP patterns, telemetry, deploy gates, trace emitter, Hermes gateway, dev-setup
P series — 8 skills — Personal and brand: SEO content, metodyk, brand content, crypto decision brief
What makes it governed
01
Hash-chain evidence
Every agent run produces a trace bundle. Every trace is hash-linked to the decision that triggered it. An auditor can trace any claim from decision to source in under 2 hours.
Every push to the skills repository runs the compliance checker. Non-compliant skills block the commit. 37 controls verified on every change. Fail-closed by default.
Get the pack
Pelayo OS for Claude Code
Two tiers. No subscriptions. Immediate download. Installs into Claude Code in 45 minutes. Every skill is a structured logic file, not a prompt trick.
Most AI platforms invest in the middle layers: models, tools, orchestration. Pelayo OS invests in the edges. L0 is what is true. L6 is who is accountable.
L1 Model: Claude (Anthropic), Kimi (Moonshot), Codex (OpenAI) - model-agnostic skill contracts
L0 Substrate: Source of truth, data contracts, provenance, freshness SLAs - what is true and verifiable
Regulatory Response Protocol
All systems active
Skills that know when they go stale.
Every skill declares a regulatory dependency and a half-life. When the horizon scan detects a change, the 3-gate protocol fires: auto-patch in 4 hours, quarantine in 24, sunset in 72 if unresolved. No stale outputs reach clients.
4h
Auto-patch SLA
Cosmetic regulatory changes patched automatically without human review.
24h
Quarantine SLA
Substantive changes quarantine the skill. Output blocked. Human review mandatory.
72h
Auto-sunset SLA
No patch decision after 48h of quarantine. Skill is retired. Light switch, not rheostat.
SkillHalf-lifeLast verifiedStatus
/euptd-readiness7 days (C)Jul 14Active
/comp-metrics-strategic30 days (B)Jul 01Active
/job-evaluation-engine90 days (A)Jun 28Active
/mow-jak-mentzen90 days (A)Jul 12Active
+ 221 more skills0 quarantined
The 48-hour promise
Report in 48 hours. 2 hours of your team's time.
Every diagnostic ships within 48 hours of intake. The audit trail is hash-chained. The skill that produced it shows its last verified date. You can see exactly what data it was built on.
30 minutes. We map your use case to the relevant skill cluster, walk through the governance model, and tell you exactly what the deployment looks like.