Agent skill

Audit Frameworks

by cartography-cncf in cartography-cncf/cartography

Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/.

Apache-2.0Auto-check passedLegal & Compliance

Install Audit Frameworks

skills CLI
$ npx skills add cartography-cncf/cartography --skill audit-frameworks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cartography-cncf/cartography audit-frameworks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cartography-cncf/cartography.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit-frameworks .claude/skills/audit-frameworks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-frameworks
GitHub stars
4.1k
Token cost
~2.8k tokens
SKILL.md length
1,233 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/.

  • Works in 5 steps: inventory → TODO triage → cross-provider to ontology candidates → …
  • The user asks to audit frameworks
  • SKILL.md covers Critical rules, Inputs, Instructions and Output report format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Frameworks is an agent skill from cartography-cncf/cartography. Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/. Surfaces TODOs that the schema can now satisfy, per-provider rules that should collapse into one ontology rule, and duplicate detections across frameworks (CIS, ISO 27001, SOC 2, NIST). Use when the user asks to "audit frameworks", "audit rules", "review rule TODOs", "find duplicate rules", "find ontology candidates", "consolidate compliance frameworks", or "map ISO/SOC2 onto CIS".

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering SOC 2 and security compliance. The repository describes itself as: Cartography is a Python tool that pulls infrastructure assets and their relationships into a Neo4j graph database. The licence is Apache-2.0.

When your agent uses it

  • The user asks to audit frameworks
  • Review rule TODOs
  • Find duplicate rules
  • Find ontology candidates

Example prompts

  • “audit frameworks”
  • “audit rules”
  • “review rule TODOs”
  • “/audit-frameworks”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. inventory
  2. TODO triage
  3. cross-provider to ontology candidates
  4. duplicate detection
  5. consolidation plan

What it can do on your machine

Read from SKILL.md and the folder at commit 20ebfa9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Frameworks loads about 2.8k tokens when it runs. Until then it costs about 123 tokens; SKILL.md has 1,233 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~123
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cartography-cncf/cartography at commit 20ebfa9, republished under its Apache-2.0 licence (© cartography-cncf). 1,233 words, ~2,835 tokens.

Download SKILL.mdSave it as .claude/skills/audit-frameworks/SKILL.md (or your agent's skills folder).
name
audit-frameworks
description
Audit Cartography's rules and compliance frameworks under `cartography/rules/data/rules/`. Surfaces TODOs that the schema can now satisfy, per-provider rules that should collapse into one ontology rule, and duplicate detections across frameworks (CIS, ISO 27001, SOC 2, NIST). Use when the user asks to "audit frameworks", "audit rules", "review rule TODOs", "find duplicate rules", "find ontology candidates", "consolidate compliance frameworks", or "map ISO/SOC2 onto CIS".

audit-frameworks

A read-only audit of cartography/rules/data/rules/. Produces a structured report with concrete consolidation proposals; does NOT modify rules unless the user explicitly approves a follow-up.

The audit covers four dimensions:

  1. TODO triage: every # TODO: ... in a rule file annotates a control that could not be implemented at the time. Re-check whether the schema now exposes the missing data.
  2. Cross-provider to ontology: find rule clusters that have one fact per provider but could collapse into a single fact using ontology semantic labels (UserAccount, Database, ObjectStorage, etc.).
  3. Duplicate rules: find rules across different framework files that detect the same condition.
  4. Framework consolidation: when duplicates exist, keep the rule from the most technical framework (CIS, NIST 800-53) and map the compliance frameworks (ISO 27001, SOC 2) onto it via frameworks=.

Critical rules

  1. Audit only. Emit a report. Do not delete rules, change __init__.py, or rewrite Cypher without explicit user confirmation per finding.
  2. Cite file and line for every finding. The user must be able to jump straight to the code.
  3. Prefer the technical framework. When consolidating, CIS and NIST 800-53 keep the rule; ISO 27001, SOC 2, PCI DSS get added to that rule's frameworks tuple.
  4. Same detection is not the same as same control. Two rules can share a Cypher pattern but enforce different controls (e.g. encryption-at-rest vs encryption-in-transit). Verify the description and the WHERE clause before flagging a duplicate.
  5. Framework control titles are not rule names. Rule.name describes the Cartography security detection; Framework.control_title describes the external framework control or requirement. Many rules may map to the same framework control.
  6. Never reference closed-source platforms or tickets in the audit report or in any rule change. Cartography is open source.

Inputs

  • cartography/rules/data/rules/: every *.py file is in scope.
  • cartography/rules/data/rules/__init__.py: registration map.
  • cartography/rules/spec/model.py: Rule, Fact, Framework, Module, Maturity definitions.
  • cartography/models/<provider>/: declarative schema. Drives the TODO triage.
  • cartography/models/ontology/mapping/data/ and docs/root/modules/ontology/schema.md: semantic labels and _ont_* properties. Drives the ontology-collapse pass.
  • cartography-rules list, cartography-rules frameworks: quick inventory.

Instructions

Step 1: inventory

Build a working set before analysing:

bash
cartography-rules list
cartography-rules frameworks
grep -rn "TODO\|FIXME" cartography/rules/data/rules/

For each rule file, record:

  • file path
  • rule ids declared (grep -E '^[a-z0-9_]+ = Rule\(')
  • frameworks attached (grep -A6 'frameworks=' <file>)
  • modules touched (parse module=Module.<X> per fact)

Keep this inventory in the working report; later steps refer back to it.

Step 2: TODO triage

For every TODO comment in scope (typical form: # TODO: CIS K8s 1.1.1: ... followed by # Missing datamodel: <thing>):

  1. Parse the TODO: extract the framework, the requirement id, and the "Missing datamodel" / "Missing datamodel or evidence" clause.
  2. Probe the schema for the named gap. Examples:
    • "Missing datamodel: control plane host filesystem metadata for kube-apiserver manifest files" suggests searching cartography/models/kubernetes/ for a node with file-permission properties.
    • "Missing datamodel: initContainers and ephemeralContainers securityContext fields" suggests searching cartography/models/kubernetes/pod.py and friends for those fields.
  3. Verdict per TODO:
    • IMPLEMENTABLE: schema now exposes the data; propose authoring the rule and link to the create-rule skill.
    • BLOCKED: schema still lacks the data; record the missing node/property names so the user can prioritise schema work.
    • OUTDATED: control is no longer relevant (e.g. CIS revision dropped it); propose deleting the TODO comment.

Do not author the implementable rules in this skill. Hand off to create-rule.

Step 3: cross-provider to ontology candidates

Goal: find rules whose facts repeat the same logic across providers but could be a single ontology fact.

  1. Identify candidate rules: rules with 2+ facts where each fact targets a different provider node label and the Cypher patterns are structurally similar. Useful starting filter:

    bash
    grep -lE "module=Module\.(AWS|AZURE|GCP)" cartography/rules/data/rules/*.py \
      | xargs grep -lE "module=Module\.[A-Z]+" \
      | sort -u
  2. Check ontology coverage: for each provider node in the rule's facts, confirm whether it carries a semantic label (UserAccount, Database, ObjectStorage, FileStorage, Tenant, DeviceInstance, etc.) and the _ont_* properties referenced in the existing query (typically _ont_email, _ont_source, _ont_public, etc.). If every relevant node is mapped, the rule is a strong collapse candidate.

  3. Output: for each candidate emit:

    • rule id and file
    • facts that would be replaced
    • proposed ontology Cypher (one fact, module=Module.CROSS_CLOUD)
    • any provider-specific facts that should remain (e.g. provider-only attributes the ontology does not normalise)
  4. Defer authoring: propose, do not write. Hand off to enrich-ontology if a node still needs to be mapped.

Step 4: duplicate detection

Two rules are duplicates when they detect the same condition on the same asset class, even if their ids, descriptions, or Cypher differ cosmetically. Cluster candidates by:

  1. Shared Cypher signature: same MATCH labels, same load-bearing WHERE predicate (ignoring identifier renames).
  2. Shared output identity field: both Findings expose the same asset_id_field (or equivalent).
  3. Shared remediation intent: descriptions paraphrase each other.

Useful one-liners:

bash
# pull every WHERE clause to spot near-duplicates
grep -nE "WHERE " cartography/rules/data/rules/*.py | sort -k2

# group rules by MATCH label
grep -nE "MATCH \([a-z]+:[A-Z]" cartography/rules/data/rules/*.py

Report each suspected duplicate as a tuple: {keeper_rule_id, duplicate_rule_id, file_paths, evidence} plus a confidence note (HIGH / MEDIUM / LOW).

Show full SKILL.md (459 more words)Show less
Step 5: consolidation plan

For every HIGH-confidence duplicate cluster:

  1. Pick the keeper in this priority order: CIS, then NIST 800-53, then NIST CSF / NIST AI RMF, then ISO 27001, then SOC 2, then PCI DSS, then custom. Tie-breaker: the rule with the more specific Cypher and richer Finding.
  2. Plan the merge:
    • Add the duplicate's Framework(...) entries to the keeper's frameworks= tuple. Preserve name, short_name, scope, revision, requirement, and control_title exactly.
    • Delete the duplicate file or rule symbol.
    • Remove the duplicate's import + registration line from cartography/rules/data/rules/__init__.py.
    • If the duplicate had references the keeper lacks, merge them into the keeper's references= list.
  3. Sanity check: keeper's module set still covers every provider the duplicate covered. If not, downgrade the merge to "needs an extra fact first" and stop.

Hand the plan to the user as a numbered list. Apply only after explicit confirmation, one cluster at a time.

Output report format

# Cartography rules audit, <YYYY-MM-DD>

## 1. TODO triage
- IMPLEMENTABLE (n)
  - <file>:<line>: CIS K8s 1.1.x. Schema now exposes <Node.property>. Author via the create-rule skill.
- BLOCKED (n)
  - <file>:<line>: needs <Node>/<property>. Suggest opening a schema task.
- OUTDATED (n)
  - <file>:<line>: control dropped in revision X.

## 2. Ontology collapse candidates
- <rule_id> (<file>): facts aws_*, azure_*, gcp_* could become a single Module.CROSS_CLOUD fact using :<SemanticLabel>.

## 3. Duplicate clusters
- HIGH: aws_public_rds_instances (<file>) vs iso27001_public_databases (<file>): same MATCH(:AWSRDSInstance) WHERE publicly_accessible=true.

## 4. Consolidation plan
1. Keep aws_public_rds_instances. Add Framework(short_name="ISO27001", requirement="A.13.1.1", control_title=..., ...). Remove iso27001_public_databases. Update __init__.py.
2. ...

Always end the report with Recommended next: ... listing the highest-impact item.

Examples

Example: TODO triage hit

User says: audit the cartography frameworks.

  1. Inventory finds # TODO: CIS K8s 5.2.6: Partial control coverage. Missing datamodel or evidence: initContainers and ephemeralContainers securityContext fields.
  2. Probe cartography/models/kubernetes/pod.py (or related). If init_containers is now a property with security_context fields, mark IMPLEMENTABLE.
  3. Report references the new schema fields and points at the create-rule skill for authoring.
Example: ontology collapse

User says: find rules we can move to ontology only.

  1. Find database_instance_exposed.py with three facts (RDS, Azure SQL, Cloud SQL).
  2. Confirm all three node types carry the :Database semantic label and _ont_public property.
  3. Propose a single Module.CROSS_CLOUD fact: MATCH (db:Database) WHERE db._ont_public = true RETURN db.id AS id, db._ont_source AS source.
Example: duplicate consolidation

User says: find duplicate rules across frameworks.

  1. aws_s3_public_buckets and storage_public_exposure both MATCH (b:AWSS3Bucket) WHERE b.public = true.
  2. Keeper: aws_s3_public_buckets. Action: append Framework(name="ISO/IEC 27001:2022 Annex A", short_name="ISO27001", requirement="A.13.1.1", control_title="...") to its frameworks= tuple, delete storage_public_exposure, drop the import from __init__.py.
  3. Wait for the user's go-ahead before editing.

Hand-offs

  • Authoring a missing rule: create-rule skill.
  • Mapping a provider node to a semantic label so an ontology collapse becomes possible: enrich-ontology skill.
  • Adding the missing schema property surfaced by a BLOCKED TODO: add-node-type skill.

Common pitfalls

  • Treating tags as frameworks. tags=("compliance", "cis:1.14") is legacy. Use frameworks=(Framework(...),) and keep tags for category labels only.
  • Collapsing rules whose facts diverge in WHERE semantics. Public-network exposure and missing-encryption look similar in Cypher but are different controls; do not merge.
  • Dropping the duplicate before updating __init__.py. The CLI inventory will break. Always edit __init__.py in the same change.
  • Mapping ISO 27001 to a CIS rule that does not actually satisfy the ISO control. Read the ISO control text before claiming coverage; partial coverage means keep both rules and add a TODO instead.

© cartography-cncf, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/audit-frameworks of cartography-cncf/cartography.

Open the folder on GitHubat commit 20ebfa9

Compare with similar skills

Audit Frameworks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Frameworks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Frameworks this skillcartography-cncf/cartography4.1k—~2.8kAutomated safety check: PassApache-2.0
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~3.3kAutomated safety check: PassMIT
Soc2Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~2.7kAutomated safety check: PassMIT
Grc Knowledgemlunato47/claude-grc-plugin183—~6.1kAutomated safety check: PassMIT
Information Security Manager Iso27001davila7/claude-code-templates32k1 repos~2.9kAutomated safety check: PassMIT
Trust Center BuilderGRCEngClub/claude-grc-engineering419—~2.6kAutomated safety check: PassCustom licence

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    942 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    942 GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    183 GitHub stars~6.1k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Information Security Manager Iso27001

    davila7/claude-code-templates

    Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies.

    32k GitHub starsUsed in 1 repo~2.9k tokens
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed

More from cartography-cncf/cartography

All 11 skills in this repo
  • Add Node Type

    cartography-cncf/cartography

    Define a new node schema under cartography/models/MODULENAME/, including required properties, sub-resource relationships, extra labels, conditional labels, scoped cleanup, and one-to-many transforms.

    4.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Add Relationship

    cartography-cncf/cartography

    Define a CartographyRelSchema (standard relationship), one-to-many edge, or MatchLink connecting existing nodes.

    4.1k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Analysis Jobs

    cartography-cncf/cartography

    Add a post-ingestion typed analysis job to a Cartography module to enrich the graph after sync.

    4.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Create Module

    cartography-cncf/cartography

    Author a new Cartography intel module end-to-end (entry point, sync GET/TRANSFORM/LOAD/CLEANUP, declarative data model, integration test, schema docs).

    4.1k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Enrich Ontology

    cartography-cncf/cartography

    Map a Cartography node into the Ontology system using semantic labels (UserAccount, DeviceInstance, Tenant, Database, ObjectStorage, FileStorage) or canonical nodes (User, Device).

    4.1k GitHub stars~2.4k tokensUpdated today
    Auto-check passed

Questions about Audit Frameworks

What does Audit Frameworks do?

Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/. Audit Frameworks is an agent skill from cartography-cncf/cartography. Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/.

When should I use Audit Frameworks?

Audit Frameworks fits situations like: the user asks to audit frameworks; review rule TODOs; find duplicate rules; find ontology candidates.

How do I install Audit Frameworks in Claude Code?

Run `npx skills add cartography-cncf/cartography --skill audit-frameworks -a claude-code`. Or copy the skill folder (.agents/skills/audit-frameworks in cartography-cncf/cartography) into .claude/skills/audit-frameworks in your project. Claude Code loads it when a task matches its description.

How do I install Audit Frameworks in Codex?

Run `npx skills add cartography-cncf/cartography --skill audit-frameworks -a codex`. Or copy the skill folder (.agents/skills/audit-frameworks in cartography-cncf/cartography) into .agents/skills/audit-frameworks in your project. Codex loads it when a task matches its description.

Can I use Audit Frameworks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cartography-cncf/cartography --skill audit-frameworks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-frameworks, .gemini/skills/audit-frameworks, .github/skills/audit-frameworks and .opencode/skills/audit-frameworks in your project.

What does Audit Frameworks need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Frameworks is instructions for the agent only.

Does Audit Frameworks access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Frameworks safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Frameworks use?

Audit Frameworks is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Frameworks use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Frameworks?

Skills that share tags, products or a category with Audit Frameworks: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars), Soc2 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars), Grc Knowledge (mlunato47/claude-grc-plugin, 183 stars) and Information Security Manager Iso27001 (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Frameworks?

cartography-cncf (a GitHub organization) maintains it in cartography-cncf/cartography, which has 4,125 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.

Source: cartography-cncf/cartography on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.