orca-compliance-gap

Analyze and rank compliance gaps across frameworks by account and asset.

47|7|Updated May 3, 2026
One-click install
npx skills add https://github.com/orcasecurity/orca-skills --skill orca-compliance-gap
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: orca-compliance-gap
Source: https://github.com/orcasecurity/orca-skills/tree/main/skills/orca-compliance-gap
Command: npx skills add https://github.com/orcasecurity/orca-skills --skill orca-compliance-gap

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Deep-dive compliance gap analysis for any framework — failing controls ranked by impact, quick wins, account breakdown, and remediation plan. Use when user asks about compliance gaps, failures, or status (e.g., "compliance gaps", "PCI DSS status", "where are we failing", "SOC 2").

Core Features & Use Cases

  • Analyze multiple compliance frameworks to identify worst-performing controls and cross-framework patterns.
  • Break down gaps by account or business unit and generate a prioritized remediation plan.
  • Propose quick wins and a phased remediation timeline, with automated format-specific remediation code.

Quick Start

Ask for a full remediation plan across all frameworks or a focused deep-dive into a specific framework.

Frequently Asked Questions about orca-compliance-gap

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify and prioritize compliance gaps across multiple frameworks?

To identify compliance gaps across multiple frameworks, analyze and rank failing controls by risk impact. This surfaces highest-risk controls and generates a prioritized remediation plan with quick wins and phased work streams.

Can I scope my compliance gap analysis by specific accounts and assets?

Yes, compliance gap analysis applies scoping by framework, account, and asset. This breakdown isolates failing controls per business unit, generating targeted remediation priorities and quick wins for specific environments.

What is the best way to generate a remediation plan for failing audit controls?

The best way to remediate failing audit controls is generating a prioritized plan that proposes quick wins and a phased timeline. This includes automated, format-specific remediation code and an updated compliance score projection.

How does cross-framework gap analysis detect worst-performing controls?

Cross-framework gap analysis detects worst-performing controls by analyzing multiple compliance frameworks simultaneously. It identifies cross-framework patterns and ranks failing controls by impact to surface highest-risk remediation priorities.

Can I get automated remediation code for my compliance failures?

Yes, you can get automated remediation code for compliance failures. The analysis provides actionable outputs, including an option to generate remediation code in your preferred format alongside an updated score projection.

Does compliance gap analysis work for frameworks like PCI DSS and SOC 2?

Yes, compliance gap analysis works for frameworks like PCI DSS and SOC 2. It deep-dives into any framework to identify failing controls, break down gaps by account, and generate a prioritized remediation plan.