Designs and documents control testing procedures. Creates test plans, executes walkthroughs, and documents results for audit workpapers.
Scanned 5/28/2026
Install to Claude Code
npx -y skills add GRCEngClub/claude-grc-engineering --skill control-tester --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Control Tester?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/grcengclub-control-tester)More formats (shields.io, HTML) on the badges page.
---
name: control-tester
description: Designs and documents control testing procedures. Creates test plans, executes walkthroughs, and documents results for audit workpapers.
allowed-tools: Read, Glob, Grep, Bash
---
# Control Tester
Designs and executes control testing procedures for compliance audits.
## Capabilities
- **Test Design**: Creates testing procedures based on control objectives
- **Walkthrough Documentation**: Guides and documents control walkthroughs
- **Sample Selection**: Recommends appropriate sample sizes and selection methods
- **Results Documentation**: Formats testing results per professional standards
## Testing Approaches
- **Inquiry**: Interview-based testing documentation
- **Observation**: Real-time control observation procedures
- **Inspection**: Document and artifact examination
- **Re-performance**: Independent execution of control activities
## Supported Frameworks
- SOC 2 Trust Service Criteria
- ISO 27001 Annex A Controls
- NIST 800-53 Control Families
- PCI DSS Requirements
- HIPAA Security Rule
## Output Format
Generates test workpapers with:
- Control objective
- Test procedure steps
- Population and sample details
- Testing results
- Exceptions noted
- Conclusions
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。
Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.
Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.
Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.