protofire-am-agent

Automate GRC lifecycle management, risk scoring, and compliance gate enforcement.

3|2|Updated Apr 13, 2026
One-click install
npx skills add https://github.com/protofire/Protofire-GRC-Agent-Skill-Suite --skill protofire-am-agent
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: protofire-am-agent
Source: https://github.com/protofire/Protofire-GRC-Agent-Skill-Suite/tree/main/am-agent
Command: npx skills add https://github.com/protofire/Protofire-GRC-Agent-Skill-Suite --skill protofire-am-agent

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill streamlines the complex GRC (Governance, Risk, and Compliance) lifecycle for Protofire engagements, ensuring consistent risk assessment and adherence to non-negotiable hard stops.

Core Features & Use Cases

  • Composite Risk Scoring: Automatically calculates C/B/P risk scores based on OPS-001 standards to determine engagement tiers.
  • Hard Stop Enforcement: Monitors critical compliance gates (HS-01 to HS-09) to prevent unauthorized project progression.
  • Use Case: Use this agent to perform an initial assessment of a new DeFi project, calculate its risk tier, and verify that all mandatory security clauses are present in the MSA before project kickoff.

Quick Start

Initiate the protofire-am-agent to perform a Phase 1 assessment for a new project by providing the project brief and client jurisdiction.

Frequently Asked Questions about protofire-am-agent

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate GRC lifecycle management and risk scoring for new engagements?

Automate GRC lifecycle management by initiating an initial Phase 1 assessment using the project brief and client jurisdiction. The agent calculates composite C/B/P risk scores based on OPS-001 standards to determine engagement tiers and enforce compliance gates.

What compliance gates are enforced during project proposal security validation?

Project proposal security validation enforces critical compliance hard stops (HS-01 to HS-09) to prevent unauthorized project progression. It also satisfies strict regulatory requirements including OFAC checks, TVL-based audit mandates, and internal Separation of Duties (SoD) protocols.

How do I verify mandatory security clauses are present in an MSA before project kickoff?

Verify mandatory MSA security clauses by initiating the agent to perform MSA clause verification. It checks that all required security clauses are present across multiple tracks and ensures strict compliance gates are met before project kickoff.

When do I need to perform a TVL-based audit mandate or OFAC check for a DeFi project?

Perform TVL-based audit mandates and OFAC checks when assessing new DeFi projects to satisfy strict regulatory requirements. The agent applies these checks during the Phase 1 assessment to calculate the project's risk tier and validate compliance.

Can I calculate engagement risk tiers based on OPS-001 standards automatically?

Calculate engagement risk tiers automatically by providing the project brief and client jurisdiction to the agent. It applies composite risk scoring based on OPS-001 standards to determine the appropriate engagement tier for the DeFi project.

What are the limitations of using automated compliance hard stops for project progression?

Automated compliance hard stops (HS-01 to HS-09) act as non-negotiable barriers that strictly prevent unauthorized project progression. They cannot be bypassed if mandatory regulatory requirements, such as OFAC checks or internal SoD protocols, are not fully satisfied.