GRCEngClubGRCEngClubOfficialยท46 Agent Skills Included

claude-grc-engineering

Automated compliance evidence collection, gap assessments, and audit reporting

Collects compliance evidence from AWS, Azure, GCP, GitHub, Okta, and security tools, then maps findings to SOC 2, FedRAMP, ISO 27001, PCI DSS, HIPAA, and 40+ other frameworks. Eliminates manual screenshot gathering, spreadsheet crosswalks, and repetitive audit prep work. Generates gap assessments, remediation code, policies, OSCAL documents, executive reports, and audit-ready evidence packages from one pipeline.
npx skills add GRCEngClub/claude-grc-engineering --all -g -y
Available:

Explains the plugin architecture, connector-to-findings data contract, and command namespaces so the agent can route compliance requests to the right plugin and run evidence collection, gap assessments, and reporting workflows correctly.

All Skills in This Repository (46)

Pure Emerald Level Indicators
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

aws-inspector-expert

Map AWS Inspector findings to SCF controls for SOC 2, FedRAMP, PCI DSS, and NIST 800-53.

Official
Intermediate
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

github-inspector-expert

Map GitHub repository security checks to SCF controls from gh CLI output.

Official
Advanced
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

gcp-inspector-expert

Map raw GCP configuration data to SCF controls for compliance guidance.

Official
Advanced
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

okta-inspector-expert

Audit Okta configurations for security and compliance gaps across policies, MFA, and admin accounts.

Official
Advanced
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

code-to-control-mapper

Map Terraform, Kubernetes, and CloudFormation files to compliance controls.

Official
Intermediate
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

evidence-artifact-collector

Generate CLI commands and API scripts to collect cloud audit evidence.

Official
Advanced
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

audit-ready-pr-reviewer

Detect compliance regressions in GitHub and GitLab pull request diffs.

Official
Intermediate
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

policy-as-code-generator

Translate natural-language compliance requirements into executable policies in OPA Rego, AWS Config Rules, HashiCorp Sentinel, and Terraform.

Official
Advanced
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

risk-to-jira-transformer

Extract risk components and generate Jira-compatible JSON ticket payloads.

Official
Advanced
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

tprm-scorer

Compute vendor risk scores from inherent and control risk factors.

Official
Advanced
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

vendor-assessor

Assess third-party vendor security posture and generate risk reports.

Official
Advanced
๐Ÿ“ฆ In Repo
GRCEngClubGRCEngClub

questionnaire-analyzer

Analyze vendor security questionnaire responses for red flags, gaps, and follow-up needs.

Official
Intermediate

Frequently Asked Questions

FAQPage Schema
How to install claude-grc-engineering?โ–ผ

Run `npx skills add GRCEngClub/claude-grc-engineering --all -g -y` in your terminal to install the full plugin set globally.

How to automate SOC 2 evidence collection?โ–ผ

Install a connector like github-inspector or aws-inspector, run its collect command, then run a gap assessment against SOC 2. Findings are normalized to a shared schema and mapped to controls automatically.

Which compliance frameworks are supported?โ–ผ

Over 40 frameworks including SOC 2, ISO 27001, NIST 800-53, FedRAMP, PCI DSS, CMMC, HIPAA, GDPR, DORA, and regional regimes, all crosswalked through the Secure Controls Framework.

Can it map one control across multiple frameworks?โ–ผ

Yes. The cross-framework analyzer maps a single control across all frameworks, finds conflicting requirements, and builds an optimization roadmap that can cut multi-framework effort by roughly half.

Do I need cloud credentials to try it?โ–ผ

No. You can start with the GitHub connector using your existing gh CLI login, run a collection against your own repos, and produce a first gap assessment without any cloud accounts.

Related Repositories in Legal & Compliance

View All in Legal & Complianceโ†’