shasta
Unified cloud, AI, SOC, and compliance security monitoring
All Skills in This Repository (23)
Pure Emerald Level Indicatorshipaa
Map cloud findings to HIPAA safeguards and generate remediation-ready reports.
connect-aws
Connect Shasta to an AWS account and validate credentials.
vendor-risk
Scan a vendor domain and report risk score, grade, signals, and findings.
evidence
Collect and store point-in-time compliance evidence snapshots for audit trails.
sbom
Generate an SBOM from AWS environments and scan for vulnerable packages.
risk-register
Automate SOC 2 risk register creation and maintenance from scan findings.
iso27001
Identify gaps between AWS environments and ISO 27001:2022 Annex A controls.
review-access
Compile AWS IAM user permissions and activity for quarterly SOC 2 access reviews.
pentest
Automate security assessments of AWS and Azure cloud environments.
scan
Scan AWS and Azure accounts for SOC 2 compliance gaps and generate Markdown and HTML reports.
questionnaire
Convert Shasta scan data and policy documents into security questionnaire responses.
dashboard
Launch the Shasta dashboard in a browser to monitor cloud compliance posture.
Frequently Asked Questions
FAQPage SchemaHow to install Shasta?βΌ
Run `npx skills add transilienceai/shasta --all -g -y` in your terminal to install all skills in this suite globally.
What does Shasta scan for?βΌ
It scans AWS, Azure, GCP, and Entra for misconfigurations, exploitable CVEs, identity risks, and AI workload exposure, tagging every finding across 8 compliance frameworks.
How does Shasta handle AI security?βΌ
It discovers AI workloads like Bedrock, SageMaker, and Vertex AI, audits Gemini Workspace activity, and scans connected GitHub repos for risky AI code patterns such as exposed secrets and MCP servers.
Which compliance frameworks does Shasta support?βΌ
Findings are automatically mapped to NIST AI RMF, ISO 42001, EU AI Act, SOC 2, ISO 27001, PCI DSS, FedRAMP, and CIS Benchmarks with per-finding provenance for auditors.
Can non-engineers use Shasta?βΌ
Yes. Findings are accessible through a web console, chat interface, voice queries, and an iOS app, so security and compliance teams can review posture without writing code.
Related Repositories in Legal & Compliance
View All in Legal & Complianceβclaude-for-legal
AI legal workspace for contracts, privacy, IP, litigation, and compliance
patent-disclosure-skill
Draft Chinese patent disclosures and read patents in plain language
app-privacy-policy-generator
Generate privacy policies and terms for mobile and web apps