Agent skill

Infrastructure Compliance Auditor

by borghei in borghei/Claude-Skills

Cross-framework infrastructure security audit across cloud, network, and CI/CD.

MITAuto-check passedLegal & Compliance

Install Infrastructure Compliance Auditor

skills CLI
$ npx skills add borghei/Claude-Skills --skill infrastructure-compliance-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills infrastructure-compliance-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/infrastructure-compliance-auditor .claude/skills/infrastructure-compliance-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
infrastructure-compliance-auditor
GitHub stars
886
Token cost
~2.1k tokens
SKILL.md length
839 words
Files
10 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

Cross-framework infrastructure security audit across cloud, network, and CI/CD.

  • Infrastructure and cloud security audits
  • SKILL.md covers Core Capabilities, When to Use, Clarify First and Quick Start, plus 4 more sections
  • Runs Python scripts from its folder; calls python
  • Security posture assessment

What it does

Infrastructure Compliance Auditor is an agent skill from borghei/Claude-Skills. Cross-framework infrastructure security audit across cloud, network, and CI/CD. Use for infrastructure and cloud security audits, security posture assessment, and validating technical controls for SOC 2, ISO 27001, and NIST CSF.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts and reference files (for example `references/access-control-standards.md`, `references/audit-control-catalog.md` and `references/audit-workflows.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance, Security review and Cloud security. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Infrastructure and cloud security audits
  • Security posture assessment
  • Validating technical controls for SOC 2

Example prompts

  • “/infrastructure-compliance-auditor”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Infrastructure Compliance Auditor loads about 2.1k tokens when it runs, and up to ~34k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 839 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~34k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 839 words, ~2,074 tokens.

Download SKILL.mdSave it as .claude/skills/infrastructure-compliance-auditor/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
infrastructure-compliance-auditor
description
Cross-framework infrastructure security audit across cloud, network, and CI/CD. Use for infrastructure and cloud security audits, security posture assessment, and validating technical controls for SOC 2, ISO 27001, and NIST CSF.
license
MIT + Commons Clause
metadata.version
1.1.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
infrastructure-security
metadata.updated
2026-06-15
metadata.tags
infrastructure-audit, cloud-security, dns, tls, compliance-automation

Infrastructure Compliance Auditor

Cross-cutting infrastructure security audit across ALL compliance frameworks. Replaces manual Vanta-style checks with deterministic, repeatable, evidence-generating infrastructure audits covering cloud, DNS, TLS, endpoints, access control, network, containers, CI/CD, secrets, logging, and physical security. Maps 250+ controls to 10 standards (SOC 2, ISO 27001, HIPAA, GDPR, PCI-DSS, NIS2, DORA, NIST CSF, FedRAMP, CCPA) with severity-weighted scoring.

Core Capabilities

  • 11 audit domains — cloud (AWS/Azure/GCP), DNS, TLS/SSL, endpoints, access control, network, container/K8s, CI/CD, secrets, logging/monitoring, physical security
  • 250+ controls — each with a check ID, severity rating, and multi-framework mapping
  • Framework mapping — collect-evidence-once, map-to-many strategy across 10 standards
  • Deterministic scoring — severity-weighted per-domain and overall scores (0-100) with an audit-readiness rating
  • Evidence generation — JSON and markdown reports suitable for auditor consumption

When to Use

Reach for this skill on: "infrastructure audit", "cloud security audit", "infrastructure compliance", "DNS security audit", "TLS audit", "endpoint security", "access control audit", "network security assessment", "infrastructure security", "cloud compliance", "Vanta alternative", "compliance automation", "security posture assessment", "hardware security keys", or "YubiKey compliance".

Clarify First

Before running the audit, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Audit domains — which of the 11 (cloud, DNS, TLS, endpoints, access, network, container, CI/CD, secrets, logging, physical) are in scope (determines which checks run)
  • Target frameworks — which standards to map findings to (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIS2…) (drives the control mapping and report)
  • Infrastructure config — the JSON describing actual state, including cloud provider (AWS/Azure/GCP) (the checks and CIS baseline depend on it)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the audit report.

Quick Start

Run Full Infrastructure Audit
bash
python scripts/infra_audit_runner.py --config infrastructure.json --output audit_report.json
Audit DNS Security for a Domain
bash
python scripts/dns_security_checker.py --domain example.com --output dns_report.json
Audit Access Controls
bash
python scripts/access_control_auditor.py --config access_controls.json --output access_report.json
Generate Compliance-Mapped Report
bash
python scripts/infra_audit_runner.py --config infrastructure.json --frameworks soc2,iso27001,hipaa --format markdown --output compliance_report.md

Tools

ToolPurposeInput
infra_audit_runner.pyFull infrastructure audit across all 11 domainsJSON config describing infrastructure
dns_security_checker.pyDNS-specific security audit (SPF, DKIM, DMARC, DNSSEC, CAA, MTA-STS)Domain name
access_control_auditor.pyAccess control, MFA, SSO, PAM, RBAC auditJSON config describing access controls

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • references/audit-control-catalog.md — the full 250+ control catalog across all 11 audit domains plus the framework coverage matrix. Read when you need exact check IDs, controls, severities, and framework mappings for any domain.
  • references/audit-workflows.md — audit workflows, pre/post-audit validation checklists, the severity-weighted scoring methodology, and success criteria. Read when planning or executing an audit and interpreting scores.
  • references/tool-reference.md — CLI flag reference for the three audit scripts plus a troubleshooting table. Read when running the tools or diagnosing unexpected output.
  • references/cloud-security-baseline.md — AWS / Azure / GCP CIS Benchmark deep-dive. Read for cloud-provider hardening detail beyond the catalog.
  • references/access-control-standards.md — MFA, SSO, PAM, Zero Trust, and YubiKey implementation standards. Read when designing identity and access controls.
  • references/compliance-framework-mapping.md — control-to-framework master mapping. Read when aligning evidence across multiple certifications.
Show full SKILL.md (367 more words)Show less

Scope & Limitations

In Scope:

  • Infrastructure security audit across 11 domains: Cloud, DNS, TLS/SSL, Endpoints, Access Control, Network, Containers/K8s, CI/CD, Secrets, Logging/Monitoring, Physical Security
  • Framework mapping to 10 compliance standards: SOC 2, ISO 27001, HIPAA, GDPR, PCI-DSS, NIS2, DORA, NIST CSF, FedRAMP, CCPA
  • 250+ individual control checks with severity-weighted scoring
  • DNS security validation including SPF, DKIM, DMARC, DNSSEC, CAA, MTA-STS, and subdomain takeover risk
  • Access control audit covering IdP, SSO, MFA, FIDO2/hardware keys, PAM, RBAC, service accounts, SSH keys, API keys, and Zero Trust
  • Evidence-generating reports in JSON and markdown formats for auditor consumption

Out of Scope:

  • Actual penetration testing, vulnerability scanning, or active exploitation -- this skill performs configuration-based assessment, not active testing
  • Cloud provider API calls or live infrastructure scanning -- the tool works with JSON configuration input describing your infrastructure state
  • Compliance certification or attestation -- this skill identifies gaps but does not replace formal SOC 2, ISO 27001, or PCI-DSS audits
  • Application security testing (SAST/DAST) beyond CI/CD pipeline configuration checks
  • Compliance program management, policy writing, or governance documentation

Important Notes:

  • SOC 2 2026 best practices demand real-time monitoring dashboards flagging control deficiencies within 48 hours; periodic spot-checks are no longer sufficient
  • Zero Trust architecture is increasingly expected across all frameworks; perimeter-based security alone is insufficient for SOC 2, ISO 27001, and NIS2
  • Compliance automation platforms (Drata, Vanta, Sprinto) complement but do not replace the deterministic checks this tool provides

Integration Points

SkillIntegrationWhen to Use
soc2-compliance-expertSOC 2 Trust Services Criteria mapped to infrastructure controls; evidence collection for SOC 2 Type IIWhen infrastructure audit supports SOC 2 certification
information-security-manager-iso27001ISO 27001 Annex A technological controls validated by infrastructure checksWhen ISO 27001 certification requires evidence of technical control implementation
nist-csf-specialistNIST CSF 2.0 Protect and Detect functions mapped to infrastructure domainsWhen building unified security posture across NIST and other frameworks
dora-compliance-expertDORA Pillar 1 and Pillar 3 controls validated by infrastructure security checksWhen financial entity requires infrastructure evidence for DORA compliance
pci-dss-specialistPCI-DSS v4.0 network security, encryption, and access control requirements mapped to checksWhen cardholder data environment requires infrastructure compliance validation
gdpr-dsgvo-expertTechnical privacy controls (encryption, access controls, data masking) supporting GDPR Art. 32When infrastructure controls support personal data protection requirements

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts, references) in ra-qm-team/infrastructure-compliance-auditor of borghei/Claude-Skills.

  • SKILL.md
  • references/access-control-standards.md
  • references/audit-control-catalog.md
  • references/audit-workflows.md
  • references/cloud-security-baseline.md
  • references/compliance-framework-mapping.md
  • references/tool-reference.md
  • scripts/access_control_auditor.py
  • scripts/dns_security_checker.py
  • scripts/infra_audit_runner.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Infrastructure Compliance Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Infrastructure Compliance Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Infrastructure Compliance Auditor this skillborghei/Claude-Skills886—~2.1kAutomated safety check: PassMIT
Find Cybersecurity Firmjeremylongshore/tons-of-skills-marketplace2.8k—~3.7kAutomated safety check: NotesMIT
Security Auditoraiskillstore/marketplace4306 repos~2.6kAutomated safety check: PassNone
Isms Audit Expertdavila7/claude-code-templates32k1 repos~3.1kAutomated safety check: PassMIT
Senior Secopsalirezarezvani/claude-skills28k1 repos~4kAutomated safety check: PassMIT
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence

Similar skills

  • Find Cybersecurity Firm

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…

    2.8k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    430 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Isms Audit Expert

    davila7/claude-code-templates

    Senior ISMS Audit Expert for internal and external information security management system auditing.

    32k GitHub starsUsed in 1 repo~3.1k tokens
    SecurityAuto-check passed
  • Senior Secops

    alirezarezvani/claude-skills

    Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

    28k GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Implementing AWS Security Hub

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST…

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    886 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    886 GitHub stars~4.2k tokensUpdated 2 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    886 GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    886 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    886 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Infrastructure Compliance Auditor

What does Infrastructure Compliance Auditor do?

Cross-framework infrastructure security audit across cloud, network, and CI/CD. Infrastructure Compliance Auditor is an agent skill from borghei/Claude-Skills. Cross-framework infrastructure security audit across cloud, network, and CI/CD.

When should I use Infrastructure Compliance Auditor?

Infrastructure Compliance Auditor fits situations like: infrastructure and cloud security audits; security posture assessment; validating technical controls for SOC 2.

How do I install Infrastructure Compliance Auditor in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill infrastructure-compliance-auditor -a claude-code`. Or copy the skill folder (ra-qm-team/infrastructure-compliance-auditor in borghei/Claude-Skills) into .claude/skills/infrastructure-compliance-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Infrastructure Compliance Auditor in Codex?

Run `npx skills add borghei/Claude-Skills --skill infrastructure-compliance-auditor -a codex`. Or copy the skill folder (ra-qm-team/infrastructure-compliance-auditor in borghei/Claude-Skills) into .agents/skills/infrastructure-compliance-auditor in your project. Codex loads it when a task matches its description.

Can I use Infrastructure Compliance Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill infrastructure-compliance-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/infrastructure-compliance-auditor, .gemini/skills/infrastructure-compliance-auditor, .github/skills/infrastructure-compliance-auditor and .opencode/skills/infrastructure-compliance-auditor in your project.

What does Infrastructure Compliance Auditor need to run?

Going by SKILL.md and its folder, Infrastructure Compliance Auditor needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Infrastructure Compliance Auditor access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Infrastructure Compliance Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Infrastructure Compliance Auditor use?

Infrastructure Compliance Auditor is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Infrastructure Compliance Auditor use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 31k tokens, read only when the agent opens those files.

What are the alternatives to Infrastructure Compliance Auditor?

Skills that share tags, products or a category with Infrastructure Compliance Auditor: Find Cybersecurity Firm (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Security Auditor (aiskillstore/marketplace, 430 stars), Isms Audit Expert (davila7/claude-code-templates, 32k stars) and Senior Secops (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Infrastructure Compliance Auditor?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 886 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.