sail
Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. Use this skill whenever the user asks about AI or agent security — assessing an AI system or agent architecture for risks, building an AI security roadmap or maturity assessment, writing or reviewing an AI security policy, creating compliance checklists (ISO/IEC 42001, EU AI Act, OWASP LLM/Agentic, DASF, AIUC-1), prioritizing AI security controls, evaluating AI vendors or tools (RFPs, security questionnaires), securing MCP servers, agent identities, or LLM apps, or asking what "SAIL" or a
npx skills add pillar-labs/sail-skill --skill sail --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# SAIL V2 — Secure AI Lifecycle Framework SAIL is Pillar Security's framework for building, deploying, and operating AI systems and agents securely. It is a working tool, not a reading exercise: users bring real systems, policies, and compliance obligations, and expect concrete, catalog-grounded answers. Whether they are writing their first AI policy or already operating hundreds of agents, SAIL is used to: 1. **Build an AI security roadmap** — walk the seven phases in order, assess coverage at each; the gaps, sequenced by phase, become the roadmap. 2. **Assess AI security maturity** — score each relevant risk (unaddressed / partially mitigated / mitigated with evidence) into a per-phase maturity profile trendable over time. 3. **Generate a compliance checklist** — filter the catalog by the framework the user is accountable to (ISO/IEC 42001, EU AI Act, OWASP, DASF, AIUC-1). 4. **Prioritize controls** — focus on risks that intersect the user's zones, assets, and weakest phase; autonomy tiers (SAIL 1.11) set control intensity per agent. 5. **Run vendor assessments and RFPs** — turn the catalog into a general RFP questionnaire (for security vendors or platform vendors), with question
- Core structure (memorize this, cite it constantly)
- Ground every answer in the catalog
- Reference files
- Interactive intake — when invoked as /sail or the intent is unclear
- Workflows
- Assess a system / gap analysis
- Build an AI security roadmap
- Assess AI security maturity
- Generate a compliance checklist
- Prioritize controls
- Vendor assessment / RFP questions
- Align security, legal, compliance, and engineering
- Guide secure AI development
- Answer questions about SAIL
What does the sail skill do?
Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. Use this skill whenever the user asks about AI or agent security — assessing an AI system or agent architecture for risks, building an AI security roadmap or maturity assessment, writing or reviewing an AI security policy, creating compliance checklists (ISO/IEC 42001, EU AI Act, OWASP LLM/Agentic, DASF, AIUC-1), prioritizing AI security controls, evaluating AI vendors or tools (RFPs, security questionnaires), securing MCP servers, agent identities, or LLM apps, or asking what "SAIL" or a
How do I install it?
Run `npx skills add pillar-labs/sail-skill --skill sail --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From pillar-labs/sail-skill, a repository with 136 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.