oscal-assess

Map security findings to SBS and CSA SSCF controls, generating Markdown gap matrices and JSON remediation backlogs.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/dfirs1car1o/saas-posture --skill oscal-assess
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: oscal-assess
Source: https://github.com/dfirs1car1o/saas-posture/tree/main/skills/oscal-assess
Command: npx skills add https://github.com/dfirs1car1o/saas-posture --skill oscal-assess

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill automates the complex and time-consuming process of mapping security control findings against various compliance frameworks, generating clear gap analyses and actionable remediation plans.

Core Features & Use Cases

  • Automated Gap Mapping: Directly maps findings to specific controls within the Security Benchmark for Salesforce (SBS) catalog and the CSA SSCF framework.
  • Gap Matrix Generation: Produces a human-readable Markdown table detailing control gaps, their status, and mapping confidence.
  • Remediation Backlog Creation: Generates a structured JSON output that prioritizes remediation efforts based on identified gaps.
  • Use Case: After an initial security assessment of Salesforce, use this Skill to automatically determine which SSCF controls are not met, visualize these gaps in a report, and create a prioritized list of tasks for the security team to address.

Quick Start

Run the oscal-assess skill to map the provided gap analysis JSON file against the SBS controls and output a gap matrix markdown file and a remediation backlog JSON file.

Frequently Asked Questions about oscal-assess

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map security assessment findings to the SSCF framework?

Security gap analysis for Salesforce automates mapping assessment findings against the SBS control catalog and CSA SSCF framework. It generates a gap matrix in Markdown and a prioritized remediation backlog in JSON format.

Can I generate a remediation backlog from Salesforce security assessment results?

Yes, you can generate a remediation backlog in JSON format directly from Salesforce security assessment results. The output prioritizes remediation efforts based on identified control gaps and mapping confidence.

What is the best way to visualize security control gaps for compliance mapping?

The best way to visualize security control gaps is by generating a Markdown gap matrix table. This report details specific control gaps, their current status, and mapping confidence for compliance tracking.

Do I need to provide the SBS control catalog to perform a gap analysis?

Providing the SBS control catalog is optional for performing a gap analysis. The process requires gap analysis data and control mappings as input, but you can optionally include the SBS control catalog itself.

Does oscal-assess work with CSA SSCF and Salesforce security benchmarks?

oscal-assess works directly with both the CSA SSCF framework and the Security Benchmark for Salesforce (SBS) control catalog. It maps your findings to these specific frameworks to produce actionable compliance reports.