compliance-theater

Detect compliance theater conditions mapped to MITRE ATLAS and ATT&CK TTPs.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill compliance-theater-blamejs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: compliance-theater
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/compliance-theater
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill compliance-theater-blamejs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Organizations frequently pass security and compliance audits (SOC 2, ISO 27001, PCI DSS, etc.) while remaining exposed to modern AI-era threats because legacy compliance frameworks were designed for pre-cloud, pre-AI threat environments. This Skill eliminates this blind spot by identifying specific, testable conditions where audit-passing controls provide no real protection against current attack patterns.

Core Features & Use Cases

  • 7 Documented Theater Patterns: Covers patch management, network segmentation, access control, incident response, change management, vendor risk, and security awareness gaps specific to AI and modern infrastructure.
  • Framework Gap Mapping: Directly links each theater pattern to outdated controls in major global compliance frameworks including FedRAMP, CMMC, EU NIS2, DORA, and the AI Act.
  • TTP Correlation: Maps all findings to MITRE ATLAS and ATT&CK adversary techniques to ensure theater claims are tied to real, current attack behavior.
  • Use Case: Ideal for GRC teams, security auditors, and compliance officers running annual audits or gap analyses to surface unaddressed risks that would otherwise be marked as "passed" in audit reports.

Quick Start

Use the compliance-theater skill to assess your organization's SOC 2 and ISO 27001 programs for hidden AI-era exposure gaps and generate a prioritized remediation list with auditor-ready language.

Frequently Asked Questions about compliance-theater

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is compliance theater in security audits and how does it leave organizations exposed?

Compliance theater occurs when organizations pass security audits but remain vulnerable to modern threats. Legacy frameworks like SOC 2 and ISO 27001 lack coverage for AI prompt injection and supply chain attacks, creating dangerous blind spots in GRC assessments.

How do I perform an audit gap analysis for AI-era threats like prompt injection?

Perform an audit gap analysis by mapping existing controls against MITRE ATLAS and ATT&CK TTPs. This identifies testable conditions where passing controls fail to mitigate modern threats like prompt injection, kernel LPE, and MCP supply chain attacks.

How do legacy frameworks like SOC 2 and FedRAMP handle AI-era security gaps?

Legacy frameworks like SOC 2 and FedRAMP often miss AI-era security gaps because they were designed for pre-cloud, pre-AI environments. They fail to address prompt injection and modern infrastructure threats, requiring specialized theater pattern analysis to surface unaddressed risks.

Can I map compliance theater findings to MITRE ATLAS and ATT&CK techniques?

Yes, compliance theater findings can be directly mapped to MITRE ATLAS and ATT&CK adversary techniques. This correlation ensures that identified audit gaps in controls are tied to real, current attack behaviors for accurate security posture reviews.

Does this audit gap analysis cover EU NIS2, DORA, and the AI Act compliance requirements?

Yes, the audit gap analysis covers EU NIS2, DORA, and the AI Act. It directly links documented theater patterns across patch management, access control, and vendor risk to outdated controls within these specific global compliance frameworks.

What are the limitations of relying solely on standard GRC assessments for modern threat protection?

Standard GRC assessments are limited by outdated framework designs that often miss modern infrastructure and AI threats. Without theater pattern detection across seven documented areas, organizations risk passing audits while remaining fully exposed to unaddressed kernel and supply chain attacks.