evidence

Collect and store point-in-time compliance evidence snapshots for audit trails.

145|28|Updated Apr 4, 2026
One-click install
npx skills add https://github.com/transilienceai/shasta --skill evidence-transilienceai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: evidence
Source: https://github.com/transilienceai/shasta/tree/main/.claude/skills/evidence
Command: npx skills add https://github.com/transilienceai/shasta --skill evidence-transilienceai

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Collects and stores point-in-time compliance evidence snapshots to support auditable trails for audits and assessments.

Core Features & Use Cases

  • Automatically collect evidence after scans to build a comprehensive audit trail.
  • Supports multiple artifact types and stores evidence in a structured, navigable format.
  • Use case: generate ready-to-share evidence packs for SOC 2, ISO 27001, and HIPAA audits.

Quick Start

Run the evidence collection workflow after configuring shasta.config.json to generate an auditable snapshot set.

Frequently Asked Questions about evidence

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I capture point-in-time compliance evidence for SOC 2 audit trails?

To capture point-in-time compliance evidence for SOC 2 audit trails, run the evidence collection workflow after configuring shasta.config.json. This generates structured, navigable snapshot sets and logs artifact types for ready-to-share reporting across cloud governance programs.

What compliance frameworks are supported for cloud evidence management?

Cloud evidence management supports SOC 2, ISO 27001, HIPAA, ISO 42001, and EU AI Act frameworks. It collects and stores structured compliance evidence snapshots to build comprehensive audit trails for these cloud-based governance programs.

Do I need a specific configuration file to generate audit-ready evidence packs?

Yes, you need to configure shasta.config.json to generate audit-ready evidence packs. This configuration file determines the Python command used to execute the evidence collection workflow within the Shasta stack integration.

When do I need to collect point-in-time compliance snapshots?

You need to collect point-in-time compliance snapshots after completing scans to support auditable trails during assessments. This ensures your evidence packs accurately reflect your cloud governance posture at the exact moment of evaluation.

Can I automatically collect evidence after cloud security scans?

Yes, you can automatically collect evidence after scans to build a comprehensive audit trail. The collection process supports multiple artifact types and stores the evidence in a structured, navigable format for compliance reporting.

What is the best way to prepare evidence for ISO 27001 and HIPAA audits?

The best way to prepare evidence for ISO 27001 and HIPAA audits is to generate ready-to-share evidence packs using an automated collection workflow. This captures structured point-in-time snapshots and logs artifact types for audit-ready reporting.