All authors
GRCEngClub avatar

Claude Skills by GRCEngClub

github.com/GRCEngClub
101 skillsA× 100C× 10 installs0 views
Us Sox ExpertA

Sarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations, Development), entity-level controls, IT-dependent manual controls, deficiency evaluation, SOC 1 vendor reliance, and the SEC/PCAOB/DOJ enforcement triangle.

developmentrustgo
0
391
Control TesterA

Designs and documents control testing procedures. Creates test plans, executes walkthroughs, and documents results for audit workpapers.

securityrustbash
0
391
Evidence ValidatorA

Validates audit evidence artifacts for completeness, timeliness, relevance, and authenticity. Reviews screenshots, logs, configurations, and policies against control requirements.

security
0
391
Finding GeneratorA

Generates professional audit findings using the Condition-Criteria-Cause-Effect format. Creates management letter comments and remediation recommendations.

securitydocumentation
0
391
DrawioA

Always use when the user asks to create, generate, draw, or design a diagram, flowchart, architecture diagram, ER diagram, sequence diagram, class diagram, network diagram, mockup, wireframe, UI sketch, GRC workflow, control map, audit process, risk register flow, compliance architecture, or mentions draw.io, drawio, drawoi, .drawio files, or diagram export to PNG/SVG/PDF.

securityrustbash
0
391
Grc Audit Workflow DiagramA

Use when creating a draw.io diagram for audit planning, request lists, evidence, testing, exceptions, remediation, and reporting in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustbash
0
391
Grc Compliance Operating Model DiagramA

Use when creating a draw.io diagram for high-level GRC program architecture, continuous compliance operating models, three lines of defense, and executive program maps in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustgo
0
391
Grc Control Map DiagramA

Use when creating a draw.io diagram for controls mapped across frameworks, systems, owners, risks, and evidence sources in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustbash
0
391
Grc Data Flow DiagramA

Use when creating a draw.io diagram for regulated data flows, data classifications, storage, processing, transfer, access, retention, and logging in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustbash
0
391
Grc Evidence Flow DiagramA

Use when creating a draw.io diagram for evidence collection, evidence lifecycle, audit evidence pipelines, and systems of record in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustbash
0
391
Grc Framework Crosswalk DiagramA

Use when creating a draw.io diagram for mapping controls and obligations across frameworks to show overlap, gaps, and conflicts in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustbash
0
391
Grc Poam DiagramA

Use when creating a draw.io diagram for POA&M items, audit findings, remediation milestones, validation, closure, and escalation paths in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustbash
0
391
Grc Raci DiagramA

Use when creating a draw.io diagram for responsibility assignments across GRC, security, engineering, legal, HR, procurement, vendors, and auditors in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustbash
0
391
Grc Risk Treatment DiagramA

Use when creating a draw.io diagram for risk intake, scoring, treatment, exception approval, residual risk, and monitoring workflows in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustbash
0
391
Grc Shared Responsibility DiagramA

Use when creating a draw.io diagram for cloud/SaaS shared responsibility, inherited controls, provider controls, customer controls, and evidence ownership in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustbash
0
391
Grc System Boundary DiagramA

Use when creating a draw.io diagram for compliance scope, authorization boundaries, trust boundaries, in-scope/out-of-scope systems, and system context diagrams in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustbash
0
391
Grc Third Party Risk DiagramA

Use when creating a draw.io diagram for vendor intake, tiering, questionnaires, security/privacy/legal review, contracting, and ongoing monitoring in a GRC, security, audit, compliance, privacy, cloud, or risk context.

securityrustgo
0
391
Access Review TriageA

Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export. For each row, recommends certify, revoke, manager confirm, or investigate using rules that catch the usual audit-fail patterns: terminated users still active, dormant admin accounts, separation-of-duty conflicts, service accounts in a human review. Drafts manager confirmation emails and writes an audit evidence packet mapped to SOC 2 CC6.1/CC6.2, PCI 7-8, ISO A.9, NIST AC-2. Bu...

developmentgobash
0
391
Audit Ready Pr ReviewerA

Reviews pull requests for compliance regressions. Scans code diffs for security and compliance violations, flags issues, and suggests fixes aligned with frameworks like SOC 2, ISO 27001, NIST 800-53.

securitybashnode
0
391
Code To Control MapperA

Maps infrastructure code (Terraform, Kubernetes, CloudFormation) to compliance controls (ISO 27001, SOC 2, NIST 800-53). Analyzes IaC files and generates compliance evidence mappings showing which controls are satisfied.

securitybashnode
0
391
Evidence Artifact CollectorA

Generates CLI commands and API scripts to collect point-in-time evidence for audit controls. Automates evidence gathering from cloud providers (AWS, Azure, GCP) and outputs formatted reports.

developmentpythongo
0
391
Interview Question GeneratorA

Generates focused assessor interview questions from a technology stack and maps them to compliance frameworks with practical CLI/API evidence hints.

securitybashnode
0
391
Policy As Code GeneratorA

Converts natural language compliance requirements into executable policies (OPA Rego, AWS Config Rules, Sentinel, Terraform). Standardizes governance by making it part of the build process.

developmentpythongo
0
391
Risk To Jira TransformerA

Converts unstructured risk assessments into structured Jira tickets. Extracts Likelihood, Impact, Mitigation from natural language and generates JSON formatted for Jira API with clear Definition of Done criteria.

securitygobash
0
391
Compliance TrackerA

Tracks compliance status across multiple frameworks. Monitors control implementation, identifies gaps, and generates compliance dashboards and reports.

securitydocumentation
0
391
Policy LifecycleA

Manages policy documents through their full lifecycle. Reviews policies for gaps, suggests updates based on framework changes, and tracks approval workflows.

securitysecuritydocumentation
0
391
Risk Register ManagerA

Manages organizational risk registers. Performs risk assessments, calculates risk scores, tracks mitigations, and generates risk reports for leadership.

securitygogit
0
391
Grc Portfolio PlannerA

GRC-specific portfolio questionnaire that creates a site-config.json and SITE-PLAN.md tailored to GRC engineers — certifications, frameworks, audit experience, tools, and projects.

developmentpythonrust
0
391
Website BuildA

Scaffolds a complete React/Vite website project from site-config.json. Generates components, styles, and configuration based on the site type and plan data.

developmentgobash
0
391
Website CicdA

Sets up GitHub Actions CI/CD workflow for automatic deployment to AWS on push to main. Uses GitHub OIDC for keyless AWS authentication.

securityrustbash
0
391
Website DeployA

Builds the React/Vite site, syncs to S3, and invalidates CloudFront cache. Uses the plugin's bundled deploy.sh script.

developmentbashreact
0
391
Website InfraA

Deploys AWS CloudFormation infrastructure stacks for the website (S3, CloudFront, Route 53, ACM, and optionally contact form API).

developmentbashaws
0
391
Website PreflightA

Validates AWS readiness for website deployment. Checks CLI tools, credentials, SES, Route 53, and ACM. Produces a report with pass/fail and action items.

securitybashnode
0
391
Website RepoA

Creates a GitHub repository for the website project, initializes git, and pushes the code.

securitybashnode
0
391
Automation Coverage AnalysisA

Composes week-over-week automation coverage narratives. Use when /report:automation-coverage is running. Frames the delta for leadership around time saved, quality of evidence, and forward-looking compounding value.

developmentgobash
0
391
Context BootstrapA

Setup guidance for users running a /report:* command before their toolkit has enough context. Use when a report command detects missing findings, frameworks, or history. Walks the user through installation and first collection rather than generating a hollow report.

securityrustbash
0
391
Exec Narrative PatternsA

Audience-specific tone and format guidance for leadership communications. Use when drafting any /report:* output to tune length, framing, and technical depth to the reader (board, audit committee, CEO, weekly CISO, regulator).

security
0
391
Program Portfolio CompositionA

Patterns for synthesizing findings across multiple frameworks into one readable portfolio view. Use when a /report:* command is pulling from more than one framework plugin and needs to avoid drowning the reader in control IDs.

security
0
391
So What TranslationA

Translates GRC findings, risks, and program activity into language leadership actually reads. Use when any /report:* command is composing output intended for a CISO, CIO, or above. Opinionated rules on what lands and what doesn't.

securityrustgo
0
391
Questionnaire AnalyzerA

Analyzes vendor security questionnaire responses. Identifies red flags, gaps, and areas requiring follow-up. Supports SIG, CAIQ, and custom questionnaires.

securityrustsecurity
0
391
Tprm ScorerA

Calculates vendor risk scores using inherent and residual risk factors. Generates risk ratings, comparisons, and treatment recommendations.

securitygosecurity
0
391
Vendor AssessorA

Conducts comprehensive vendor security assessments. Evaluates vendor security posture, identifies risks, and generates assessment reports with recommendations.

securitysecurity
0
391
Gcp Docs ExpertA

Use `gcp-docs` when implementation guidance needs current Google Cloud, Google Workspace, Firebase, Android, Chrome, or related public Google developer documentation. This is a knowledge-source plugin. It does not emit Findings. It returns citations and grounded answers that other plugins can use in remediation guidance, evidence procedures, and control implementation notes. Requirements: - Enable the Google Developer Knowledge API in a Google Cloud project. - Create an API key restricted to ...

developmentgogcp
0
391
Oscal ExpertA

Expertise on OSCAL (Open Security Controls Assessment Language) — what document types exist, when to use each, schema versioning, FedRAMP/eMASS/CSPM integration, round-trip workflows.

developmentgosecurity
0
391
Control ExplainerA

Explains a single control once and shows every framework it maps to via the SCF crosswalk. Resolves SCF IDs, framework-specific IDs, and plain-English descriptions. Never reproduces normative text.

securitygobash
0
391
Framework TutorA

Tutor that produces working primers on GRC frameworks and roles. Adapts depth to the learner's background. Never reproduces copyrighted standard text — paraphrases and references control IDs.

developmentrustgo
0
391
Socratic DrillA

Drills the user on a framework with application-level scenario questions. Inspired by mattpocock/skills/grill-me. Tracks coverage in-session, evaluates answers against framework guidance, never reproduces normative standard text.

developmentgobash
0
391
Trust CenterA

Build and deploy a production-ready Trust Center for any company. Use this skill whenever someone asks to create a trust center, compliance portal, security page, or wants to publish their SOC 2/SOC 3/ISO 27001/HIPAA/compliance posture publicly. Also triggers when someone mentions gated document access for audit reports, NDA-based document sharing, or wants to replace paid trust center tools like Secureframe, Vanta, Drata, or SafeBase. Even if they just say "I need a place to share my SOC 2 w...

developmentrustgo
0
391
Academic Research CompanionA

Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources or a literature review, asks about methodology or research design, wants to write or structure a paper, asks about peer review, publishing (independent, conference, journal, or preprint), co-authorship, author order, o...

developmentgogit
0
391
Aws Secrets Inspector ExpertC

Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS / public-access / inactive-access findings, or troubleshooting an aws-secrets-inspector run.

securityawsgit
0
391