github-inspector-expert

Map GitHub repository security checks to SCF controls from gh CLI output.

367|83|Updated Dec 26, 2025
One-click install
npx skills add https://github.com/GRCEngClub/claude-grc-engineering --skill github-inspector-expert-grcengclub
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: github-inspector-expert
Source: https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/connectors/github-inspector/skills/github-inspector-expert
Command: npx skills add https://github.com/GRCEngClub/claude-grc-engineering --skill github-inspector-expert-grcengclub

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Evaluates GitHub repository configurations to map checks to SCF controls and translate gh CLI outputs into actionable compliance insights.

Core Features & Use Cases

  • Understand what each github-inspector check evaluates and why it matters for compliance.
  • Interpret failure modes correctly — distinguish genuinely non-compliant from inconclusive results.
  • Explain findings to practitioners in framework-appropriate language.

Quick Start

Analyze a repository with github-inspector-expert to map checks to SCF controls and generate a compliance report.

Frequently Asked Questions about github-inspector-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check GitHub repository compliance with SCF controls?

To validate GitHub security configurations across multiple repositories, this Skill analyzes default protections, secret scanning, code scanning, and vulnerability alerts using gh CLI output. It produces structured results with clear remediation guidance for diverse teams and projects.

Do I need read access to run GitHub security checks on an organization?

Yes, running GitHub compliance checks requires read access to target repositories and organization-level info. You also need access to the gh CLI to extract configuration data and evaluate default protections, secret scanning, and vulnerability alerts across teams.

How do I interpret inconclusive GitHub compliance check results?

To interpret inconclusive GitHub compliance check results, this Skill distinguishes between genuinely non-compliant configurations and inconclusive findings. It explains failure modes correctly and translates them into framework-appropriate language for practitioners.

What is the best way to generate a compliance report from gh CLI output?

The best way to generate a compliance report from gh CLI output is to map repository checks directly to SCF controls. This Skill translates raw CLI data into structured compliance findings with clear, actionable remediation guidance for your teams.

Can I evaluate secret scanning and code scanning vulnerabilities across diverse teams?

Yes, you can evaluate secret scanning and code scanning vulnerabilities across diverse teams by applying this Skill to organizations with multiple repositories. It validates security controls and provides structured results for each project.