Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Standards Drift

ASecurity

Detecting configuration drift against an established baseline: CIPP standards checks and Best Practice Analyser results, Liongard change detections and inspection timelines, the three conditions that make a diff real drift rather than noise, the signals that separate intentional or authorized change from unauthorized weakening (ticket correlation, reversion pattern, direction of change), and the priority order for ranking several drift findings at once.

48 stars
0 votes
0 copies
0 views
Added 10/2/2026
ai-agentsgoreactsecurity

Works with

cli

Security Analysis

A100/100

Scanned 10/2/2026

$npx -y skills add wyre-technology/msp-claude-plugins --skill standards-drift --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Standards Drift?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Standards Drift
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/wyre-technology-standards-drift/badge)](https://www.skillsdirectory.com/skills/wyre-technology-standards-drift)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: "Standards Drift Detection"
description: >
  Detecting configuration drift against an established baseline: CIPP standards
  checks and Best Practice Analyser results, Liongard change detections and
  inspection timelines, the three conditions that make a diff real drift rather
  than noise, the signals that separate intentional or authorized change from
  unauthorized weakening (ticket correlation, reversion pattern, direction of
  change), and the priority order for ranking several drift findings at once.
when_to_use: >-
  When comparing current tenant or infrastructure state against a known-good baseline,
  when a standards check or inspection shows something changed, or when deciding which
  of several drift findings is most urgent. Use when: control drift, configuration
  drift, standards drift, has anything changed, drift detection, baseline comparison,
  unauthorized change, what changed since last check, security drift.
---

# Standards Drift Detection

## Overview

A compliance control that was met last quarter is not guaranteed to still be met today. Tenants change constantly — a conditional access policy gets edited during a troubleshooting session and never reverted, a firewall rule gets loosened for a vendor's "temporary" remote session, a new admin account gets created without MFA during an emergency. None of this shows up unless something actively compares current state against a baseline. That comparison is what this skill covers.

Drift detection has two distinct data sources in this pack's grounding:

- **CIPP standards checks** (`cipp__list_standards`, `cipp__run_standards_check`, `cipp__list_bpa`) — these represent MSP-defined or CIS-aligned configuration standards applied to a tenant. A standard that previously passed and now fails is drift. `cipp__list_standards` shows which standards are assigned to a tenant and their last-known state; `cipp__run_standards_check` re-evaluates live.
- **Liongard change detection** (`liongard__detections_list`, `liongard__detections_get`, `liongard__timeline_list`) — Liongard inspects systems on a schedule and diffs each inspection against the prior one, surfacing detections when tracked properties change. The timeline is the authoritative "what changed and when" record for anything Liongard inspects (network gear, servers, cloud tenants, and whatever else an org has connected inspectors for).

## Anti-triggers

- **Running or reading a CIPP standards check** — the Report/Alert/Remediate
  modes, BPA reports, and domain-health results are the connector's own
  surface; use `cipp-standards`. This skill decides whether a delta is real
  drift, whether it was authorized, and how it ranks against other findings.
- **Liongard detection and alert-rule configuration** — detection types,
  severities, alert rules, and custom metrics live in `liongard-detections`.
- **Inforcer baseline alignment scores** — Inforcer computes tenant-versus-
  baseline drift natively with its own alignment model; use
  `inforcer-baseline-alignment`.

## What Counts as Drift

Drift is any observed difference between the current state of a tracked control or configuration item and its last known-good (i.e., previously verified-compliant) state. Three things are required to call something drift rather than noise:

1. A **baseline** exists — a prior standards check that passed, or a prior Liongard inspection/detection that was reviewed and accepted.
2. A **current observation** exists that differs from that baseline.
3. The difference is in a property that matters for compliance or security posture — not every diff Liongard surfaces is drift in the compliance sense (a device's uptime counter changing is not drift; a firewall rule set changing is).

If there is no established baseline (first-ever check, or the client has never had a standards check run), there is nothing to diff against — run the check, record the result as the new baseline, and say so rather than reporting phantom drift.

## Intentional vs. Unauthorized Drift

Not all drift is bad. A technician who disabled a conditional access policy to unblock a locked-out executive, then re-enabled it an hour later, produced drift that resolved itself. A vendor who was granted temporary elevated access for a migration and had it revoked on schedule is not a finding. The skill is in telling these apart from a policy that was quietly loosened and never restored, or a change nobody remembers authorizing.

Signals to check, in order of reliability:

- **Change ticket correlation** — if a PSA is connected (HaloPSA, Autotask, or similar) and a change/service ticket exists covering the same time window and system, treat the drift as authorized and documented. Cite the ticket.
- **Reversion pattern** — if Liongard's timeline shows the setting changed and then changed back within a short window, treat it as transient/intentional unless the "back" state is itself non-compliant.
- **Direction of change** — a change that *weakens* a security-relevant control (MFA requirement removed, conditional access policy scope narrowed, a previously-required standard disabled) is presumptively risky until shown otherwise. A change that *tightens* a control is low-risk by default and rarely needs escalation.
- **No corroboration** — if there is no ticket, no reversion, and the change weakens posture, treat it as unauthorized/risky drift and escalate. Absence of a ticket is not proof of malice, but it is the trigger for asking, not for silently accepting the new state as fine.

## Prioritizing Drift Findings

When a drift pass surfaces multiple findings (common — a single re-run of `cipp__run_standards_check` against a client that hasn't been checked in months can return a dozen deltas), prioritize using this order:

1. **Security-weakening + unauthorized** — a control got weaker and there is no ticket or reversion explaining why. Always highest priority regardless of which framework it maps to.
2. **Security-weakening + authorized** — still worth surfacing (the new state may still be non-compliant even if intentional), but not urgent in the same way.
3. **Administrative/cosmetic drift** — naming changes, non-security metadata, license reassignment within the same tier. Report but do not escalate.
4. **Security-tightening drift** — informational only; note it as a positive change.

Within priority tier 1, further rank by the criticality of the underlying control: identity/MFA and admin-access findings outrank mailbox-rule or naming-convention findings, and anything that touches a system in scope for an active compliance framework (e.g., a system holding PHI for a HIPAA-scoped client) outranks the same finding on an out-of-scope system.

## Common Workflows

1. **Scheduled/on-demand re-check**: pull the last recorded baseline (from a prior standards check or accepted Liongard inspection) → re-run the live check (`cipp__run_standards_check`, fresh `liongard__inspections_run` if a re-inspection is warranted, or just diff against `liongard__timeline_list`) → diff → classify each delta as intentional/unauthorized → prioritize → report.
2. **Reactive investigation** ("has anything changed for this client?"): pull `liongard__timeline_list` and `liongard__detections_list` for the requested window, cross-reference against `cipp__list_audit_logs` for identity-plane changes in the same window, and correlate against PSA tickets if connected.

## Error Handling

- If no baseline exists for a client, do not report drift — report "no baseline established; this check now serves as baseline" and recommend a follow-up check on a defined cadence.
- If `conduit__search_tools` shows no Liongard or CIPP connector for a client, drift detection for that plane is unavailable — say so explicitly rather than reporting "no drift found" (which implies a check occurred).
- If change-ticket correlation cannot be performed because no PSA is connected, do not guess at authorization — report the drift as "unauthorized/unconfirmed" and note that PSA correlation was unavailable.

## Related Skills

- [Evidence Mapping](../evidence-mapping/SKILL.md) — how to resolve the underlying controls being drift-checked to their evidence sources in the first place.
- [Insurance Questionnaires](../insurance-questionnaires/SKILL.md) — a stale or drifted control is exactly the kind of finding that should change how a questionnaire answer is worded.

Attribution

WYRE-AIWYRE-AI
View sourceSee grades on GitHubMore from wyre-technology →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →