identity-assurance

Assess identity assurance gaps across AAL/IAL/FAL, MFA, and OAuth/JWT controls.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill identity-assurance
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: identity-assurance
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/identity-assurance
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill identity-assurance

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Legacy identity and compliance frameworks (NIST 800-53, ISO 27001, SOC 2, etc.) were designed for pre-AI, network-centric environments and lack controls for AI agent-as-principal identity, phishing-resistant authentication requirements, and modern OAuth/JWT threat models. This skill fills that gap by providing a structured assessment process aligned with mid-2026 threat reality and current identity standards like NIST 800-63 rev4, FIDO2/WebAuthn, and RFC 9700.

Core Features & Use Cases

  • Full Identity Assurance Assessment: Generates a complete scorecard covering per-principal AAL/IAL/FAL posture, phishing-resistant MFA coverage, token lifetime audits, JWT validation checks, and federation surface mapping.
  • Compliance Gap Analysis: Maps identity control gaps to 20+ global regulatory frameworks (NIS2, DORA, UK CAF, AU ISM, ISO 27001, NY DFS, etc.) and MITRE ATT&CK/ATLAS TTPs to identify where paper compliance fails.
  • Actionable Remediation Roadmap: Prioritizes fixes for critical gaps like agent identity inheritance, non-phishing-resistant MFA deployment, and non-compliant OAuth token lifetimes, with clear ownership and target dates.
  • Use Case: A security team preparing for a SOC 2 audit can use this skill to run a full identity assessment, identify that 40% of privileged users are on TOTP instead of phishing-resistant MFA, and generate a prioritized roadmap to close the gap before the audit.

Quick Start

Use the identity-assurance skill to run a full identity assurance assessment for your organization, including principal inventory, phishing-resistant MFA coverage, and cross-jurisdictional compliance gap analysis.

Frequently Asked Questions about identity-assurance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess NIST 800-63 AAL/IAL/FAL compliance for AI agent identity workflows?

Identity assurance assessments evaluate per-principal AAL/IAL/FAL posture, mapping AI agent-as-principal identity and phishing-resistant MFA coverage to NIST 800-63 requirements. This generates a complete scorecard covering authentication strength and federation surfaces.

What is phishing-resistant MFA coverage and how does it impact SOC 2 audits?

Phishing-resistant MFA coverage measures the percentage of users on FIDO2/WebAuthn instead of vulnerable TOTP. For SOC 2 audits, insufficient coverage indicates paper compliance failure, requiring a prioritized remediation roadmap to close security gaps.

How do I map OAuth security gaps to MITRE ATT&CK and ATLAS TTPs?

Mapping OAuth security gaps to MITRE ATT&CK and ATLAS TTPs identifies where legacy token lifetimes and JWT validation failures expose threats. This aligns modern OAuth/JWT threat models with active adversary techniques for targeted remediation.

Does this identity assurance approach work with OIDC/SAML federation and cloud workload identity?

Identity assurance assessments support OIDC/SAML federation and cloud workload identity by mapping federation surfaces and token lifetimes. They evaluate zero trust architecture reviews and regulatory compliance for environments using MCP/agent workflows.

How to prepare for NIS2 and DORA compliance gap analysis for identity controls?

Compliance gap analysis maps identity control gaps to NIS2, DORA, and ISO 27001 requirements by auditing phishing-resistant MFA and agent identity inheritance. It generates cross-jurisdictional evidence and prioritizes fixes with clear ownership.

Why does legacy identity compliance fail for AI agent-as-principal authentication?

Legacy identity compliance fails for AI agent-as-principal authentication because pre-AI frameworks lack controls for modern OAuth/JWT threat models and MCP workflows. Updated assessments align with mid-2026 threat reality and RFC 9700 best practices.