claude-grc-engineering
Automated compliance evidence collection, gap assessments, and audit reporting
Explains the plugin architecture, connector-to-findings data contract, and command namespaces so the agent can route compliance requests to the right plugin and run evidence collection, gap assessments, and reporting workflows correctly.
All Skills in This Repository (46)
Pure Emerald Level Indicatorsaws-inspector-expert
Map AWS Inspector findings to SCF controls for SOC 2, FedRAMP, PCI DSS, and NIST 800-53.
github-inspector-expert
Map GitHub repository security checks to SCF controls from gh CLI output.
gcp-inspector-expert
Map raw GCP configuration data to SCF controls for compliance guidance.
okta-inspector-expert
Audit Okta configurations for security and compliance gaps across policies, MFA, and admin accounts.
code-to-control-mapper
Map Terraform, Kubernetes, and CloudFormation files to compliance controls.
evidence-artifact-collector
Generate CLI commands and API scripts to collect cloud audit evidence.
audit-ready-pr-reviewer
Detect compliance regressions in GitHub and GitLab pull request diffs.
policy-as-code-generator
Translate natural-language compliance requirements into executable policies in OPA Rego, AWS Config Rules, HashiCorp Sentinel, and Terraform.
risk-to-jira-transformer
Extract risk components and generate Jira-compatible JSON ticket payloads.
tprm-scorer
Compute vendor risk scores from inherent and control risk factors.
vendor-assessor
Assess third-party vendor security posture and generate risk reports.
questionnaire-analyzer
Analyze vendor security questionnaire responses for red flags, gaps, and follow-up needs.
Frequently Asked Questions
FAQPage SchemaHow to install claude-grc-engineering?โผ
Run `npx skills add GRCEngClub/claude-grc-engineering --all -g -y` in your terminal to install the full plugin set globally.
How to automate SOC 2 evidence collection?โผ
Install a connector like github-inspector or aws-inspector, run its collect command, then run a gap assessment against SOC 2. Findings are normalized to a shared schema and mapped to controls automatically.
Which compliance frameworks are supported?โผ
Over 40 frameworks including SOC 2, ISO 27001, NIST 800-53, FedRAMP, PCI DSS, CMMC, HIPAA, GDPR, DORA, and regional regimes, all crosswalked through the Secure Controls Framework.
Can it map one control across multiple frameworks?โผ
Yes. The cross-framework analyzer maps a single control across all frameworks, finds conflicting requirements, and builds an optimization roadmap that can cut multi-framework effort by roughly half.
Do I need cloud credentials to try it?โผ
No. You can start with the GitHub connector using your existing gh CLI login, run a collection against your own repos, and produce a first gap assessment without any cloud accounts.
Related Repositories in Legal & Compliance
View All in Legal & Complianceโclaude-for-legal
AI legal workspace for contracts, privacy, IP, litigation, and compliance
patent-disclosure-skill
Draft Chinese patent disclosures and read patents in plain language
app-privacy-policy-generator
Generate privacy policies and terms for mobile and web apps