content
Build and test security compliance content for any platform
All Skills in This Repository (15)
Pure Emerald Level Indicatorsmap-controls
Automate mapping of security controls to candidate rules across frameworks.
build-product
Orchestrate ComplianceAsCode product builds with MCP tools and filesystem fallbacks.
draft-pr
Generate pull request descriptions from branch commits and PR templates.
test-rule
Validate ComplianceAsCode security rules with Automatus and virsh.
onboard-control
Parse security policy PDFs, Markdown, HTML, or text into a ComplianceAsCode control file structure.
create-rule
Generate ComplianceAsCode security rule scaffolds with rule.yml, tests, and references.
inspect-control
Analyze a control file to report requirement stats and mapping status.
map-requirement
Identify candidate rules for control requirements using cross-framework mappings.
run-tests
Run ctest validation suites on built content under build/.
create-product
Creates a buildable product skeleton in the ComplianceAsCode security content project.
resolve-rule-variables
Resolves XCCDF variable selections for compliance rules into var_name=key entries.
create-template
Creates ComplianceAsCode templates that generate OVAL checks and Bash or Ansible remediations.
Frequently Asked Questions
FAQPage SchemaHow to install ComplianceAsCode content?โผ
Run `npx skills add ComplianceAsCode/content --all -g -y` in your terminal to install all skills in this suite globally.
What does ComplianceAsCode content do?โผ
It produces ready-to-use SCAP data streams, Ansible playbooks, and Bash scripts that scan systems for security compliance and automatically fix violations.
Which compliance frameworks are supported?โผ
It covers CIS, STIG, NIST 800-53, PCI DSS, ANSSI, HIPAA, and more, across products like RHEL, Ubuntu, Debian, OpenShift, and Firefox.
Can AI agents create new compliance rules?โผ
Yes. The included skills let an AI agent create rules, map controls to requirements, build products, and run Automatus validation tests automatically.
Do I need to know SCAP or OVAL to use it?โผ
No. The skills handle the technical formats for you, so you can describe the security requirement in plain language and let the agent generate the content.
Related Repositories in Legal & Compliance
View All in Legal & Complianceโclaude-for-legal
AI legal workspace for contracts, privacy, IP, litigation, and compliance
patent-disclosure-skill
Draft Chinese patent disclosures and read patents in plain language
app-privacy-policy-generator
Generate privacy policies and terms for mobile and web apps