ai-scan

Run Whitney code scans and Shasta cloud checks for AI governance compliance.

7|2|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/kkmookhey/shasta --skill ai-scan
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ai-scan
Source: https://github.com/kkmookhey/shasta/tree/main/.claude/skills/ai-scan
Command: npx skills add https://github.com/kkmookhey/shasta --skill ai-scan

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill automates AI governance scanning by combining Whitney's code-scan outputs with Shasta's cloud AI checks to help startups verify compliance across code repositories and cloud environments.

Core Features & Use Cases

  • Code findings integration: shells Whitney results into a unified risk view for software projects, enabling rapid remediation.
  • Cloud governance checks: evaluates AWS/Azure configurations against ISO 42001, EU AI Act, and NIST AI RMF mappings.
  • Scoring & remediation: enriches findings with compliance scores and actionable remediation guidance for leadership and engineers.
  • Use Case: a founder can continuously monitor both application code and cloud setup to reduce audit time and increase governance confidence.

Quick Start

Install Whitney, configure shasta.config.json, and run the ai-scan skill to generate a governance report.

Frequently Asked Questions about ai-scan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate AI governance scanning for code repositories and cloud accounts?

AI governance scanning is automated by combining Whitney code-scan outputs with Shasta cloud checks, evaluating configurations against ISO 42001, EU AI Act, and NIST AI RMF to produce a consolidated compliance score and remediation guidance.

What is the best way to check NIST AI RMF and EU AI Act compliance across AWS and Azure?

Checking NIST AI RMF and EU AI Act compliance is done by running cloud governance checks that evaluate AWS and Azure configurations, mapping findings to regulatory frameworks to deliver a structured JSON summary with actionable remediation steps.

Do I need to install Whitney before running an AI governance scan?

Yes, you need to install Whitney and configure the shasta.config.json file to run the scan, which shells Whitney results into a unified risk view and integrates cloud SDK outputs for a complete governance report.

Can I get a consolidated compliance score for both my application code and cloud setup?

Getting a consolidated compliance score for application code and cloud setup is possible by integrating Whitney code findings and Shasta cloud checks, enriching the results with compliance scores and prioritized remediation guidance for leadership and engineers.

What limitations exist when mapping cloud SDK results to ISO 42001 compliance?

Mapping cloud SDK results to ISO 42001 relies on evaluating AWS and Azure configurations through Shasta checks, producing a structured JSON summary, but requires proper environment setup and accurate shasta.config.json configuration to avoid incomplete governance findings.

How does automated code scanning help startups reduce audit time for AI governance?

Automated code scanning helps startups reduce audit time by continuously monitoring application code and cloud environments, combining findings into a unified risk view with compliance scores and remediation guidance to increase governance confidence.