ops-security-audit

Audit infrastructure security with automated scanners and compliance mapping.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/withmartian-sandbox/ghrc-x-3126672651424eddb640ecc81321a665 --skill ops-security-audit-withmartian-sandbox
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ops-security-audit
Source: https://github.com/withmartian-sandbox/ghrc-x-3126672651424eddb640ecc81321a665/tree/main/ops-team/skills/ops-security-audit
Command: npx skills add https://github.com/withmartian-sandbox/ghrc-x-3126672651424eddb640ecc81321a665 --skill ops-security-audit-withmartian-sandbox

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Ad-hoc or inconsistent infrastructure reviews miss critical vulnerabilities and compliance gaps; this workflow standardizes audits to reliably identify risks, map them to controls, and drive verified remediation so releases meet security and regulatory requirements.

Core Features & Use Cases

  • Scope and Planning: Audit scope templates for accounts, regions, services, and environments to define clear boundaries and objectives.
  • Automated Scanning Integration: Procedures and execution templates for Security Hub, GuardDuty, AWS Config, Trivy, Checkov, and ScoutSuite to gather objective findings.
  • Manual Review Checklists: IAM, network, data protection, and logging review lists plus manual finding templates for detailed analysis.
  • Compliance Mapping & Remediation: Mapping findings to SOC2 and PCI-DSS controls, prioritization matrices with SLAs, remediation plans, and verification checklists.
  • Use Case: Run a quarterly audit of production AWS accounts to detect critical misconfigurations, map gaps to SOC2 controls, and produce a prioritized remediation plan with verification criteria.

Quick Start

Run a security audit for AWS accounts 123456789 and 987654321 focused on IAM, VPC, S3, and EKS and produce an audit plan, automated scan results, a compliance mapping, and a prioritized remediation plan.

Frequently Asked Questions about ops-security-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an infrastructure security audit across AWS accounts and map findings to SOC2 controls?

An infrastructure security audit defines scope for AWS accounts, regions, and services, runs automated vulnerability scanners like Security Hub and Trivy, maps findings to SOC2 and PCI-DSS controls, and produces prioritized remediation plans with verification criteria.

What's the best way to automate vulnerability scanning and compliance validation for cloud infrastructure?

Automate vulnerability scanning and compliance validation by integrating tools like Security Hub, GuardDuty, AWS Config, Checkov, and ScoutSuite to gather objective findings, then map those results to compliance frameworks for structured remediation tracking.

Can I use this audit workflow for quarterly reviews and pre-release assessments of EKS and S3 services?

Yes, this audit workflow applies to quarterly reviews, incident post-mortems, pre-release assessments, and vendor compliance checks across cloud services including EKS, S3, VPC, and IAM to detect critical misconfigurations and compliance gaps.

How does manual review fit into an automated infrastructure security audit?

Manual review complements automated scanning by using IAM, network, data protection, and logging checklists to perform detailed analysis, documenting findings in manual finding templates for deeper investigation of vulnerabilities and compliance gaps.

Do I need specific scanner dependencies to run a cloud infrastructure compliance check?

No specific dependencies are required to run the audit workflow, which provides procedures and execution templates for integrating scanners like Security Hub, GuardDuty, Trivy, and Checkov to gather objective vulnerability and compliance findings.

How do I prioritize infrastructure vulnerability fixes and verify their remediation?

Prioritize infrastructure vulnerability fixes using prioritization matrices with SLAs, create remediation plans mapping findings to SOC2 and PCI-DSS controls, then verify remediation through re-scans and closure reports.