gap-analysis

Run SOC 2 gap analysis on AWS and generate remediation reports.

7|2|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/kkmookhey/shasta --skill gap-analysis-kkmookhey
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: gap-analysis
Source: https://github.com/kkmookhey/shasta/tree/main/.claude/skills/gap-analysis
Command: npx skills add https://github.com/kkmookhey/shasta --skill gap-analysis-kkmookhey

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

SOC 2 readiness is hard and manual, leaving organizations exposed to gaps in controls; this skill runs a comprehensive SOC 2 gap analysis against your AWS environment and surfaces actionable remediation guidance to close those gaps.

Core Features & Use Cases

  • Automated SOC 2 gap analysis across your AWS account with actionable remediation recommendations.
  • Reuse recent scans or perform a fresh assessment and generate audit-ready Markdown/HTML reports.
  • Group findings by SOC 2 control, explain auditor expectations, and provide concrete remediation steps.
  • Export concise, stakeholder-friendly reports for governance reviews and audit preparation.

Quick Start

Ask Shasta to run a SOC 2 gap analysis against your connected AWS account and review the remediation guidance in the generated report.

Frequently Asked Questions about gap-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a SOC 2 gap analysis on my AWS account?

To run a SOC 2 gap analysis on your AWS account, connect your environment and trigger an assessment. The tool reads configuration files, uses existing scans or runs fresh ones, and generates a report grouped by SOC 2 control with remediation steps.

What is SOC 2 gap analysis and how does it work with AWS?

SOC 2 gap analysis evaluates your AWS environment against SOC 2 controls to identify security and compliance shortfalls. It works by scanning account configurations, mapping findings to specific SOC 2 controls, and outputting actionable remediation guidance for auditors.

How do I generate an audit-ready report for SOC 2 compliance?

You can generate an audit-ready report for SOC 2 compliance by running a gap analysis that outputs Markdown or HTML formats. The report groups findings by SOC 2 control, explains auditor expectations, and provides concrete remediation steps for stakeholders.

Can I reuse existing AWS scan data for SOC 2 gap analysis?

Yes, you can reuse existing AWS scan data for SOC 2 gap analysis. The tool automatically checks for recent scan data and uses it when available, but it also supports re-running a fresh analysis if no recent data exists in your environment.

Does SOC 2 gap analysis provide specific remediation guidance for AWS?

Yes, SOC 2 gap analysis provides specific remediation guidance for AWS. It evaluates your account against SOC 2 controls and presents results grouped by control, offering explicit, actionable remediation steps to close identified security gaps.