Agent skill

Trust Center Builder

by GRCEngClub in GRCEngClub/claude-grc-engineering

Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

Custom licenceAuto-check passedLegal & Compliance

Install Trust Center Builder

skills CLI
$ npx skills add GRCEngClub/claude-grc-engineering --skill trust-center -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install GRCEngClub/claude-grc-engineering trust-center --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/GRCEngClub/claude-grc-engineering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/trust-center/skills/trust-center .claude/skills/trust-center && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
trust-center
GitHub stars
419
Token cost
~2.6k tokens
SKILL.md length
1,184 words
Files
14 (incl. references)
Skills in repo
12
Repo updated
First seen
Licence
Custom licence

At a glance

Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

  • Works in 7 steps: Gather Company Information → Read Uploaded Documents → Generate the Trust Center Code → …
  • Publishing certifications, policies and audit reports on a public page
  • SKILL.md covers What This Skill Produces, Workflow, NDA Integration — Choose Your… and Important Notes, plus 1 more section
  • Runs JavaScript, Python and Shell scripts from its folder; calls aws; needs ESIGN_API_KEY

What it does

The finished trust center has a public page with a company overview, certification badges, compliance stats and downloadable public reports. Visitors request access to sensitive documents such as a SOC 2 report, an admin approves or denies, and the visitor downloads. An admin dashboard manages requests, documents and the audit log, with Cognito login and serverless AWS infrastructure of S3, CloudFront, WAF, API Gateway, Lambda and DynamoDB. An optional NDA step uses the e-signature provider you choose. The skill estimates roughly $5 to $15 a month for the infrastructure.

It starts by interviewing you, two or three questions at a time: company name, what it does, admin email and certifications such as SOC 2, SOC 3, ISO 27001, HIPAA, PCI DSS or FedRAMP, with status, audit period and auditor for each. It also asks which documents are public or gated, and optionally a custom domain, contact email, logo and brand color. If you share a SOC 2 report, it can pull certification details, control counts and the audit period. The references folder holds an API handler, a deploy script, an infrastructure template, frontend files and seed data.

When your agent uses it

  • Publishing certifications, policies and audit reports on a public page
  • Gating SOC 2 reports behind an access request or an NDA
  • Replacing a paid trust center product with a self-hosted serverless one

Example prompts

  • “Build a trust center for our company with public SOC 2 badges and gated audit reports.”
  • “I need a place to share my SOC 2 report with customers behind an NDA.”
  • “Create a compliance portal with an admin dashboard to approve access requests.”

Requirements

  • An AWS account to deploy the serverless infrastructure
  • An e-signature provider if you want the NDA step (optional)

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Gather Company Information
  2. Read Uploaded Documents
  3. Generate the Trust Center Code
  4. Project Structure
  5. Deploy
  6. Upload Documents
  7. Set Up NDA Integration (Optional)

What it can do on your machine

Read from SKILL.md and the folder at commit 784fd9a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript, Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • documenso.com
    • opensignlabs.com
    • docuseal.com
    • developers.docusign.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ESIGN_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Trust Center Builder loads about 2.6k tokens when it runs, and up to ~33k if it reads all its reference files. Until then it costs about 141 tokens; SKILL.md has 1,184 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~141
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~33k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,184 words (~2,627 tokens).

“Build a serverless trust center that publishes a company's compliance posture — certifications, policies, and audit reports — with gated access for sensitive documents.”

— opening of SKILL.md by GRCEngClub, Custom licence
name
trust-center

Read the full SKILL.md on GitHub

Files

SKILL.md and 13 other files (references) in plugins/trust-center/skills/trust-center of GRCEngClub/claude-grc-engineering.

  • SKILL.md
  • references/api-handler.py
  • references/deploy-script.sh
  • references/frontend-files/index.html
  • references/frontend-files/package.json
  • references/frontend-files/src/hooks/useAuth.jsx
  • references/frontend-files/src/main.jsx
  • references/frontend-files/src/pages/AdminDashboard.jsx
  • references/frontend-files/src/pages/LoginPage.jsx
  • references/frontend-files/src/pages/TrustCenter.jsx
  • references/frontend-files/src/utils/api.js
  • references/frontend-files/vite.config.js
  • references/infrastructure-template.yaml
  • references/seed-data.md

Open the folder on GitHubat commit 784fd9a

Compare with similar skills

Trust Center Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Trust Center Builder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Trust Center Builder this skillGRCEngClub/claude-grc-engineering419—~2.6kAutomated safety check: PassCustom licence
Performing Soc2 Type2 Audit Preparationmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
AWS Solution Architectalirezarezvani/claude-skills28k1 repos~2.5kAutomated safety check: PassMIT
Dt Obs AWSDynatrace/dynatrace-for-ai163—~4.2kAutomated safety check: PassApache-2.0
AWS Serverless Deploymentawslabs/agent-plugins916—~1.3kAutomated safety check: PassApache-2.0
AWS Lambda Managed Instancesaws/agent-toolkit-for-aws2.8k—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Performing Soc2 Type2 Audit Preparation

    mukul975/Anthropic-Cybersecurity-Skills

    Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Backend & APIsAuto-check passed
  • Dt Obs AWS

    Dynatrace/dynatrace-for-ai

    AWS cloud resource monitoring including EC2, RDS, Lambda, ECS/EKS, VPC networking, load balancers, S3, DynamoDB, SQS/SNS, and cost optimization.

    163 GitHub stars~4.2k tokensUpdated 9 days ago
    DevOps & CloudAuto-check passed
  • AWS Serverless Deployment

    awslabs/agent-plugins

    Official

    AWS SAM and AWS CDK deployment for serverless applications. An agent skill from awslabs/agent-plugins.

    916 GitHub stars~1.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • AWS Lambda Managed Instances

    aws/agent-toolkit-for-aws

    Official

    Evaluates, configures, and migrates workloads to AWS Lambda Managed Instances (LMI).

    2.8k GitHub stars~3.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Solution Architect

    borghei/Claude-Skills

    Design AWS serverless architectures for startups with IaC. An agent skill from borghei/Claude-Skills.

    891 GitHub stars~1.8k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed

More from GRCEngClub/claude-grc-engineering

All 12 skills in this repo
  • GRC Report Context Bootstrap

    GRCEngClub/claude-grc-engineering

    Checks that plugins, collected findings and history exist before a GRC /report command runs, and walks the user through setup instead of producing an empty report.

    419 GitHub stars~1.4k tokensUpdated 7 days ago
    Auto-check: notes
  • Draw.io Diagram Generator

    GRCEngClub/claude-grc-engineering

    Generates draw.io diagrams as native .drawio files, including GRC workflows and control maps, with optional PNG, SVG or PDF export that stays editable.

    419 GitHub stars~1.3k tokensUpdated 7 days ago
    Auto-check: notes
  • Academic Research Companion

    GRCEngClub/claude-grc-engineering

    Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication.

    419 GitHub stars~2.2k tokensUpdated 7 days ago
    Auto-check passed
  • Access Review Triage

    GRCEngClub/claude-grc-engineering

    Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export.

    419 GitHub stars~2.4k tokensUpdated 7 days ago
    Auto-check: notes
  • Audit Ready PR Reviewer

    GRCEngClub/claude-grc-engineering

    Reviews pull requests for compliance regressions. An agent skill from GRCEngClub/claude-grc-engineering.

    419 GitHub stars~587 tokensUpdated 7 days ago
    Auto-check: notes
  • Automation Coverage Analysis

    GRCEngClub/claude-grc-engineering

    Composes week-over-week automation coverage narratives. An agent skill from GRCEngClub/claude-grc-engineering.

    419 GitHub stars~1.3k tokensUpdated 7 days ago
    Auto-check: notes

Questions about Trust Center Builder

What does Trust Center Builder do?

Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard. The finished trust center has a public page with a company overview, certification badges, compliance stats and downloadable public reports. Visitors request access to sensitive documents such as a SOC 2 report, an admin approves or denies, and the visitor downloads.

When should I use Trust Center Builder?

Trust Center Builder fits situations like: publishing certifications, policies and audit reports on a public page; gating SOC 2 reports behind an access request or an NDA; replacing a paid trust center product with a self-hosted serverless one.

How do I install Trust Center Builder in Claude Code?

Run `npx skills add GRCEngClub/claude-grc-engineering --skill trust-center -a claude-code`. Or copy the skill folder (plugins/trust-center/skills/trust-center in GRCEngClub/claude-grc-engineering) into .claude/skills/trust-center in your project. Claude Code loads it when a task matches its description.

How do I install Trust Center Builder in Codex?

Run `npx skills add GRCEngClub/claude-grc-engineering --skill trust-center -a codex`. Or copy the skill folder (plugins/trust-center/skills/trust-center in GRCEngClub/claude-grc-engineering) into .agents/skills/trust-center in your project. Codex loads it when a task matches its description.

Can I use Trust Center Builder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add GRCEngClub/claude-grc-engineering --skill trust-center -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/trust-center, .gemini/skills/trust-center, .github/skills/trust-center and .opencode/skills/trust-center in your project.

What does Trust Center Builder need to run?

Going by SKILL.md and its folder, Trust Center Builder needs JavaScript, Python and a shell for the scripts in its folder, the command-line tools its instructions call (aws) and credentials named ESIGN_API_KEY. Our summary lists: An AWS account to deploy the serverless infrastructure; An e-signature provider if you want the NDA step (optional).

Does Trust Center Builder access the network?

SKILL.md names 4 domains. As links in the text: documenso.com, opensignlabs.com, docuseal.com and developers.docusign.com. This is read from the text; nothing was executed.

Is Trust Center Builder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Trust Center Builder use?

Trust Center Builder has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Trust Center Builder use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 31k tokens, read only when the agent opens those files.

What are the alternatives to Trust Center Builder?

Skills that share tags, products or a category with Trust Center Builder: Performing Soc2 Type2 Audit Preparation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), AWS Solution Architect (alirezarezvani/claude-skills, 28k stars), Dt Obs AWS (Dynatrace/dynatrace-for-ai, 163 stars) and AWS Serverless Deployment (awslabs/agent-plugins, 916 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Trust Center Builder?

GRCEngClub (a GitHub organization) maintains it in GRCEngClub/claude-grc-engineering, which has 419 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 4, 2026.

Source: GRCEngClub/claude-grc-engineering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.