ComplianceAsCodeComplianceAsCodeOfficialยท15 Agent Skills Included

content

Build and test security compliance content for any platform

Generates SCAP data streams, Ansible playbooks, and Bash scripts for compliance scanning and remediation across Linux, Kubernetes, and applications. Eliminates manual writing of OVAL checks, control mappings, and test scenarios for frameworks like CIS, STIG, NIST, and PCI DSS. Guides AI agents through creating rules, mapping controls, building products, and running validation tests end to end.
npx skills add ComplianceAsCode/content --all -g -y
Available:

Teaches the AI agent the repository structure, rule format, templates, and Jinja2 conventions so it can correctly create and build compliance content.

All Skills in This Repository (15)

Pure Emerald Level Indicators
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

map-controls

Automate mapping of security controls to candidate rules across frameworks.

Official
Advanced
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

build-product

Orchestrate ComplianceAsCode product builds with MCP tools and filesystem fallbacks.

Official
Advanced
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

draft-pr

Generate pull request descriptions from branch commits and PR templates.

Official
Advanced
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

test-rule

Validate ComplianceAsCode security rules with Automatus and virsh.

Official
Advanced
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

onboard-control

Parse security policy PDFs, Markdown, HTML, or text into a ComplianceAsCode control file structure.

Official
Advanced
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

create-rule

Generate ComplianceAsCode security rule scaffolds with rule.yml, tests, and references.

Official
Advanced
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

inspect-control

Analyze a control file to report requirement stats and mapping status.

Official
Intermediate
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

map-requirement

Identify candidate rules for control requirements using cross-framework mappings.

Official
Advanced
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

run-tests

Run ctest validation suites on built content under build/.

Official
Advanced
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

create-product

Creates a buildable product skeleton in the ComplianceAsCode security content project.

Official
Advanced
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

resolve-rule-variables

Resolves XCCDF variable selections for compliance rules into var_name=key entries.

Official
Intermediate
๐Ÿ“ฆ In Repo
ComplianceAsCodeComplianceAsCode

create-template

Creates ComplianceAsCode templates that generate OVAL checks and Bash or Ansible remediations.

Official
Advanced

Frequently Asked Questions

FAQPage Schema
How to install ComplianceAsCode content?โ–ผ

Run `npx skills add ComplianceAsCode/content --all -g -y` in your terminal to install all skills in this suite globally.

What does ComplianceAsCode content do?โ–ผ

It produces ready-to-use SCAP data streams, Ansible playbooks, and Bash scripts that scan systems for security compliance and automatically fix violations.

Which compliance frameworks are supported?โ–ผ

It covers CIS, STIG, NIST 800-53, PCI DSS, ANSSI, HIPAA, and more, across products like RHEL, Ubuntu, Debian, OpenShift, and Firefox.

Can AI agents create new compliance rules?โ–ผ

Yes. The included skills let an AI agent create rules, map controls to requirements, build products, and run Automatus validation tests automatically.

Do I need to know SCAP or OVAL to use it?โ–ผ

No. The skills handle the technical formats for you, so you can describe the security requirement in plain language and let the agent generate the content.

Related Repositories in Legal & Compliance

View All in Legal & Complianceโ†’