Agent skill

GRC Report Context Bootstrap

by GRCEngClub in GRCEngClub/claude-grc-engineering

Checks that plugins, collected findings and history exist before a GRC /report command runs, and walks the user through setup instead of producing an empty report.

Custom licenceAuto-check: notesLegal & Compliance

Install GRC Report Context Bootstrap

skills CLI
$ npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install GRCEngClub/claude-grc-engineering context-bootstrap --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/GRCEngClub/claude-grc-engineering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/grc-reporter/skills/context-bootstrap .claude/skills/context-bootstrap && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
context-bootstrap
GitHub stars
419
Token cost
~1.4k tokens
SKILL.md length
644 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
Custom licence

At a glance

Checks that plugins, collected findings and history exist before a GRC /report command runs, and walks the user through setup instead of producing an empty report.

  • Works in 5 steps: Plugins installed. Run /plugin list or… → Findings cache populated. Look in… → Framework metadata available. Each… → …
  • A /report command finds an empty findings cache or no framework plugin installed
  • SKILL.md covers What to check, Command-specific minimums, The three paths and The empty-context setup script, plus 2 more sections
  • Calls gh

What it does

Meant to run ahead of any /report command in the GRC Engineering Club toolkit, this skill makes the agent confirm that the inputs exist rather than invent a report from nothing. It checks that the grc-engineer hub plugin, at least one connector (such as github-inspector, aws-inspector or okta-inspector) and at least one framework plugin (such as soc2, fedramp-rev5 or iso27001) are installed.

It then looks for collected findings under ~/.cache/claude-grc/findings with recent timestamps, a framework_metadata block in each framework plugin's plugin.json, metric snapshots in ./grc-data/metrics taken at least 7 days apart for week-over-week reports, and optional risk, metrics and incident files under ./grc-data.

Each command has its own minimum. The exec-summary report needs one connector, one framework and recent findings, while program-health needs two framework plugins and a gap-assessment run for each. When context is complete the agent finds it automatically and asks only a couple of questions; when it is partial, the agent names what is missing and offers an interview mode to fill the gaps.

When your agent uses it

  • A /report command finds an empty findings cache or no framework plugin installed
  • Preparing a board brief and needing to know what history and risk data it requires
  • Setting up the GRC toolkit for the first time and deciding what to install
  • Checking whether enough metric snapshots exist for an automation coverage report

Example prompts

  • “Run /report:exec-summary for our SOC 2 program and set up whatever is missing first.”
  • “The board brief came out thin, so check what context the toolkit is lacking.”
  • “Which plugins do I need installed before I can generate a program health report.”

Requirements

  • The grc-engineer plugin plus one connector and one framework plugin
  • Bash and file read access to the findings cache and the grc-data folder
  • Pre-approved tools (allowed-tools): Read, Glob, Bash

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Plugins installed. Run /plugin list or inspect the marketplace. Need at least
  2. Findings cache populated. Look in ~/.cache/claude-grc/findings//*.json. Timestamps within the last 30 days mean the pipeline is active.
  3. Framework metadata available. Each framework plugin's plugin.json should have a framework_metadata block. Without it, coverage math fails…
  4. History depth (for week-over-week commands). /report:automation-coverage needs at least 2 metric snapshots in ./grc-data/metrics/ that are…
  5. Optional GitOps state. ./grc-data/risks/*, ./grc-data/metrics/*, ./grc-data/incidents/*.md. The JSON contracts live in docs/GRC-DATA.md…

What it can do on your machine

Read from SKILL.md and the folder at commit 784fd9a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GRC Report Context Bootstrap loads about 1.4k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 644 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 644 words (~1,423 tokens).

“Hollow reports are worse than no reports. When a user runs /report:exec-summary with an empty findings cache, the right move is to teach them the setup, not to make up a report.”

— opening of SKILL.md by GRCEngClub, Custom licence
name
context-bootstrap
allowed-tools
Read, Glob, Bash

Read the full SKILL.md on GitHub

Files

Just SKILL.md in plugins/grc-reporter/skills/context-bootstrap of GRCEngClub/claude-grc-engineering.

Open the folder on GitHubat commit 784fd9a

Compare with similar skills

GRC Report Context Bootstrap next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GRC Report Context Bootstrap compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GRC Report Context Bootstrap this skillGRCEngClub/claude-grc-engineering419—~1.4kAutomated safety check: NotesCustom licence
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~3.7kAutomated safety check: PassMIT
PCI DSS Compliancewshobson/agents40k11 repos~1.9kAutomated safety check: PassMIT
Quality Manager Qms Iso13485alirezarezvani/claude-skills28k1 repos~4.4kAutomated safety check: PassMIT
Implementing Complianceancoleman/ai-design-components526—~4kAutomated safety check: PassMIT

Similar skills

  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    942 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • PCI DSS Compliance

    wshobson/agents

    Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

    40k GitHub starsUsed in 11 repos~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Quality Manager Qms Iso13485

    alirezarezvani/claude-skills

    ISO 13485 Quality Management System implementation and maintenance for medical device organizations.

    28k GitHub starsUsed in 1 repo~4.4k tokens
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    526 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Owns legal, contracts, intellectual property, regulatory compliance, privacy, security governance, enterprise risk, and audit readiness.

    2k GitHub stars~1.6k tokensUpdated 20 days ago
    Legal & ComplianceAuto-check passed

More from GRCEngClub/claude-grc-engineering

All 12 skills in this repo
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 4 days ago
    Auto-check passed
  • Draw.io Diagram Generator

    GRCEngClub/claude-grc-engineering

    Generates draw.io diagrams as native .drawio files, including GRC workflows and control maps, with optional PNG, SVG or PDF export that stays editable.

    419 GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check: notes
  • Academic Research Companion

    GRCEngClub/claude-grc-engineering

    Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication.

    419 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check passed
  • Access Review Triage

    GRCEngClub/claude-grc-engineering

    Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export.

    419 GitHub stars~2.4k tokensUpdated 4 days ago
    Auto-check: notes
  • Audit Ready PR Reviewer

    GRCEngClub/claude-grc-engineering

    Reviews pull requests for compliance regressions. An agent skill from GRCEngClub/claude-grc-engineering.

    419 GitHub stars~587 tokensUpdated 4 days ago
    Auto-check: notes
  • Automation Coverage Analysis

    GRCEngClub/claude-grc-engineering

    Composes week-over-week automation coverage narratives. An agent skill from GRCEngClub/claude-grc-engineering.

    419 GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check: notes

Questions about GRC Report Context Bootstrap

What does GRC Report Context Bootstrap do?

Checks that plugins, collected findings and history exist before a GRC /report command runs, and walks the user through setup instead of producing an empty report. Meant to run ahead of any /report command in the GRC Engineering Club toolkit, this skill makes the agent confirm that the inputs exist rather than invent a report from nothing. It checks that the grc-engineer hub plugin, at least one connector (such as github-inspector, aws-inspector or okta-inspector) and at least one framework plugin (such as soc2, fedramp-rev5 or iso27001) are installed.

When should I use GRC Report Context Bootstrap?

GRC Report Context Bootstrap fits situations like: A /report command finds an empty findings cache or no framework plugin installed; preparing a board brief and needing to know what history and risk data it requires; setting up the GRC toolkit for the first time and deciding what to install; checking whether enough metric snapshots exist for an automation coverage report.

How do I install GRC Report Context Bootstrap in Claude Code?

Run `npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a claude-code`. Or copy the skill folder (plugins/grc-reporter/skills/context-bootstrap in GRCEngClub/claude-grc-engineering) into .claude/skills/context-bootstrap in your project. Claude Code loads it when a task matches its description.

How do I install GRC Report Context Bootstrap in Codex?

Run `npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a codex`. Or copy the skill folder (plugins/grc-reporter/skills/context-bootstrap in GRCEngClub/claude-grc-engineering) into .agents/skills/context-bootstrap in your project. Codex loads it when a task matches its description.

Can I use GRC Report Context Bootstrap in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add GRCEngClub/claude-grc-engineering --skill context-bootstrap -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/context-bootstrap, .gemini/skills/context-bootstrap, .github/skills/context-bootstrap and .opencode/skills/context-bootstrap in your project.

What does GRC Report Context Bootstrap need to run?

Going by SKILL.md and its folder, GRC Report Context Bootstrap needs the command-line tools its instructions call (gh). Our summary lists: The grc-engineer plugin plus one connector and one framework plugin; Bash and file read access to the findings cache and the grc-data folder. Its frontmatter pre-approves these tools: Read, Glob, Bash.

Does GRC Report Context Bootstrap access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is GRC Report Context Bootstrap safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does GRC Report Context Bootstrap use?

GRC Report Context Bootstrap has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does GRC Report Context Bootstrap use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GRC Report Context Bootstrap?

Skills that share tags, products or a category with GRC Report Context Bootstrap: ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars), Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars), PCI DSS Compliance (wshobson/agents, 40k stars) and Quality Manager Qms Iso13485 (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GRC Report Context Bootstrap?

GRCEngClub (a GitHub organization) maintains it in GRCEngClub/claude-grc-engineering, which has 419 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 4, 2026.

Source: GRCEngClub/claude-grc-engineering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.