agency-compliance-auditor

Assess and remediate technical compliance gaps for SOC 2, ISO 27001, HIPAA, and PCI-DSS.

Updated Feb 11, 2026
One-click install
npx skills add https://github.com/augustoheiss/LogicDefense --skill agency-compliance-auditor-augustoheiss
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: agency-compliance-auditor
Source: https://github.com/augustoheiss/LogicDefense/tree/main/.gemini/skills/agency-compliance-auditor
Command: npx skills add https://github.com/augustoheiss/LogicDefense --skill agency-compliance-auditor-augustoheiss

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps organizations prepare for and pass technical security and privacy certifications by assessing controls, organizing evidence, and producing prioritized, auditor-ready remediation plans that demonstrate control operation over time.

Core Features & Use Cases

  • Gap Assessments & Remediation Roadmaps: Perform control-by-control readiness assessments against SOC 2, ISO 27001, HIPAA, and PCI-DSS and produce prioritized remediation steps with estimated effort and owners.
  • Evidence Collection & Packaging: Design evidence matrices, automate evidence exports from systems like Okta and Datadog where possible, and assemble evidence packages organized by control objective for auditor review.
  • Controls Design, Testing & Continuous Compliance: Recommend pragmatic, right-sized technical controls and monitoring that integrate into engineering workflows, and set up recurring control testing and sampling strategies.
  • Use Case: A startup preparing for SOC 2 Type II uses this Skill to map existing access and change controls, replace shared credentials, automate access review exports, and deliver a gap report and evidence package before the audit window.

Quick Start

Conduct a SOC 2 readiness assessment for our production environment, identify critical control gaps, and return a prioritized remediation plan with concrete evidence collection steps.

Frequently Asked Questions about agency-compliance-auditor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for a SOC 2 Type II audit and collect technical evidence?

To prepare for a SOC 2 Type II audit, you perform a readiness assessment to map access and change controls, identify gaps, and automate evidence exports from systems like Okta and Datadog into auditor-ready packages.

What is a compliance gap assessment for ISO 27001 and how does it work?

A compliance gap assessment for ISO 27001 evaluates your current security controls against framework requirements, producing a prioritized remediation roadmap with concrete steps, estimated effort, and assigned owners to achieve certification readiness.

How do I build an evidence collection matrix for HIPAA and PCI-DSS controls?

Building an evidence collection matrix involves mapping system boundaries to HIPAA and PCI-DSS control objectives, defining sampling approaches, and organizing evidence packages to demonstrate control operation over the audit period.

Can I use this approach to map security controls across multiple compliance frameworks?

Yes, you can assess and remediate technical compliance gaps across multiple frameworks simultaneously, mapping controls for SOC 2, ISO 27001, HIPAA, and PCI-DSS to define right-sized technical controls and continuous monitoring workflows.

What is the best way to automate evidence collection for security audits?

The best way to automate evidence collection is integrating with systems like Okta and Datadog to automatically export logs and configurations, demonstrating continuous control operation over time without manual effort.

What are the limitations of continuous compliance testing for DevOps teams?

Continuous compliance testing requires mapping controls to system boundaries and defining sampling strategies, which may be limited by systems lacking automated export capabilities or environments with shared credentials needing replacement.