Traction scoreGitHub stars can be faked, so popularity alone can be misleading. Traction Score looks for broader signs of recent attention, adoption, and active maintenance.
This collection provides specialized guidance for GRC analysts and privacy officers navigating the complexities of regulatory compliance. It structures the technical requirements of diverse frameworks, from ISO 27001 and SOC 2 to regional data protection laws like GDPR and CCPA.
By codifying the specific mandates of standards such as NIST CSF, FedRAMP, and CMMC 2.0, the skill set helps professionals align internal controls with external legal and security obligations more consistently.
WHO IT'S FOR
GRC Analysts
mapping controls across multiple compliance frameworks
Privacy Officers
navigating global data protection regulations
Information Security Managers
conducting readiness gap assessments for certifications
Financial Services Compliance Teams
implementing digital operational resilience standards
Compatible AgentsThe repository documents support for these agents. The skills may also work with other agents that can load SKILL.md files, but they may need some setup or small changes.
Installs: Installs the complete documented GRC suite of 36 plugins from the grc-skills marketplace. The skillPaths list is a bounded selection of positively supported paths, not the complete bundle inventory. · Claude Code
Before you start
Claude Code installed
Git installed and accessible on PATH
An active Claude subscription or configured API key
In a Claude Code session, register the GRC Skills marketplace. This is required only once per machine.
The organization or system included in the ISMS scope
The small set of controls or processes to assess
Current implementation details
Available evidence or document excerpts
Use the iso27001 skill to perform a focused ISO 27001:2022 gap analysis for the limited ISMS scope and controls I provide. Return a table with Control ID, Control Name, Status, Evidence Needed, and Gap Notes. Keep this to an initial assessment and identify assumptions where evidence is missing.
Data storage, transmission, access-control, encryption, and audit-logging details
Use the hipaa-compliance skill to review this system design for an initial set of HIPAA privacy and technical-safeguard issues. Summarize the most important concerns, missing information, and practical next checks. Include the skill's required informational-purpose disclaimer.
Data categories and approximate volume the vendor can access
Business impact if the service becomes unavailable
How difficult the vendor would be to replace
Compliance frameworks the organization must satisfy
Use the tprm skill to assess one vendor using its data access, business criticality, and substitutability. Recommend an initial risk tier and a concise due-diligence plan appropriate to that tier, clearly identifying any information still needed.