Agent skill

Assisting With Soc2 Audit Preparation

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification.

MITAuto-check passedLegal & Compliance

Install Assisting With Soc2 Audit Preparation

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace assisting-with-soc2-audit-preparation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/assisting-with-soc2-audit-preparation .claude/skills/assisting-with-soc2-audit-preparation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
assisting-with-soc2-audit-preparation
GitHub stars
2.8k
Token cost
~1.6k tokens
SKILL.md length
625 words
Files
9 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification.

  • Works in 10 steps: Define audit scope: confirm in-scope… → Assess CC1 -- Control Environment:… → Assess CC6 -- Logical and Physical… → …
  • You need to prepare for SOC 2 audits
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Assisting With Soc2 Audit Preparation is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification. Use when you need to prepare for SOC 2 audits, assess Trust Service Criteria compliance, document security controls, or generate readiness reports. Trigger with phrases like "SOC 2 audit preparation", "SOC 2 readiness assessment", "collect SOC 2 evidence", or "Trust Service Criteria compliance".

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/README.md` and `references/errors.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Audit readiness and SOC 2 and security compliance. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • You need to prepare for SOC 2 audits
  • Assess Trust Service Criteria compliance
  • Document security controls
  • Generate readiness reports

Example prompts

  • “SOC 2 audit preparation”
  • “SOC 2 readiness assessment”
  • “collect SOC 2 evidence”
  • “/assisting-with-soc2-audit-preparation”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(audit-collect:*), Bash(compliance-check:*)

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Define audit scope: confirm in-scope services, systems, data stores, and audit period (Type I: point-in-time; Type II: observation window…
  2. Assess CC1 -- Control Environment: verify organizational structure documentation, security policy, board oversight, and security…
  3. Assess CC6 -- Logical and Physical Access Controls: verify MFA implementation, RBAC policies, password policy enforcement, access review…
  4. Assess CC7 -- System Operations: check monitoring and alerting configurations, backup procedures and testing records, incident response…
  5. Assess CC8 -- Change Management: review change approval workflows, deployment pipelines, rollback procedures, and change logs for the…
  6. Collect evidence artifacts: organize evidence into the standard directory structure under ${CLAUDE_SKILL_DIR}/soc2-audit/ with…
  7. Test control effectiveness: for each control, verify design adequacy (properly designed?) and operating effectiveness (working as intended…
  8. Perform gap analysis: classify findings as missing controls (critical gap), partially implemented controls (needs improvement), improperly…
  9. Generate readiness report: produce ${CLAUDE_SKILL_DIR}/soc2-audit/readiness-report-YYYYMMDD.md with overall readiness score, per-criteria…
  10. Prepare auditor interview guide: draft expected auditor questions by criteria area with suggested evidence references and talking points.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(audit-collect:*)
    • Bash(compliance-check:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cisecurity.org
    • nist.gov
    • intentsolutions.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Assisting With Soc2 Audit Preparation loads about 1.6k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 115 tokens; SKILL.md has 625 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 625 words, ~1,618 tokens.

Download SKILL.mdSave it as .claude/skills/assisting-with-soc2-audit-preparation/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
assisting-with-soc2-audit-preparation
description
Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification. Use when you need to prepare for SOC 2 audits, assess Trust Service Criteria compliance, document security controls, or generate readiness reports. Trigger with phrases like "SOC 2 audit preparation", "SOC 2 readiness assessment", "collect SOC 2 evidence", or "Trust Service Criteria compliance".
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(audit-collect:*), Bash(compliance-check:*)
compatibility
Designed for Claude Code
version
1.30.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, compliance, audit

Assisting With SOC 2 Audit Preparation

Overview

Automate SOC 2 Type I and Type II audit preparation by assessing controls across the five AICPA Trust Service Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy). Inventory existing controls and evidence, perform gap analysis against each Common Criteria point (CC1-CC9), and produce an audit-ready evidence package with a readiness score and remediation backlog.

Prerequisites

  • Policy and procedure documentation accessible in ${CLAUDE_SKILL_DIR}/docs/ (information security policy, incident response plan, BCP/DR plan, vendor management procedures)
  • Infrastructure-as-code and configuration files available for control verification
  • Cloud provider audit logs accessible (AWS CloudTrail, Azure Activity Log, GCP Audit Logs) or exported
  • Employee onboarding/offboarding and security awareness training records available
  • Change management and access review logs accessible
  • Write permissions for audit workspace in ${CLAUDE_SKILL_DIR}/soc2-audit/

Instructions

  1. Define audit scope: confirm in-scope services, systems, data stores, and audit period (Type I: point-in-time; Type II: observation window, typically 3-12 months). Identify applicable Trust Service Categories beyond the required Security criteria.
  2. Assess CC1 -- Control Environment: verify organizational structure documentation, security policy, board oversight, and security role/responsibility matrix. Check for gaps in documented accountability.
  3. Assess CC6 -- Logical and Physical Access Controls: verify MFA implementation, RBAC policies, password policy enforcement, access review cadence, and automated deprovisioning. Flag privileged access without monitoring.
  4. Assess CC7 -- System Operations: check monitoring and alerting configurations, backup procedures and testing records, incident response logs, and capacity planning documentation.
  5. Assess CC8 -- Change Management: review change approval workflows, deployment pipelines, rollback procedures, and change logs for the audit period.
  6. Collect evidence artifacts: organize evidence into the standard directory structure under ${CLAUDE_SKILL_DIR}/soc2-audit/ with subdirectories per criteria (CC1-control-environment/, CC6-access-controls/, CC7-system-operations/, etc.).
  7. Test control effectiveness: for each control, verify design adequacy (properly designed?) and operating effectiveness (working as intended during the audit period?). Document test results with screenshots, log excerpts, or configuration exports.
  8. Perform gap analysis: classify findings as missing controls (critical gap), partially implemented controls (needs improvement), improperly documented controls (evidence gap), or ineffective controls (design/operating failure).
  9. Generate readiness report: produce ${CLAUDE_SKILL_DIR}/soc2-audit/readiness-report-YYYYMMDD.md with overall readiness score, per-criteria assessment with percentage, remediation roadmap with timelines, and evidence collection checklist.
  10. Prepare auditor interview guide: draft expected auditor questions by criteria area with suggested evidence references and talking points.

See ${CLAUDE_SKILL_DIR}/references/implementation.md for the six-phase implementation guide. See ${CLAUDE_SKILL_DIR}/references/readiness-by-trust-service-category.md for example per-criteria readiness breakdowns.

Show full SKILL.md (241 more words)Show less

Output

  • Readiness Report: ${CLAUDE_SKILL_DIR}/soc2-audit/readiness-report-YYYYMMDD.md with overall score and per-criteria pass/gap status
  • Evidence Inventory: organized artifact list mapped to specific CC control points
  • Gap Analysis: missing and partially implemented controls with severity and remediation priority
  • Remediation Backlog: prioritized tasks with effort estimates, owners, and target dates
  • Auditor Interview Guide: expected questions by criteria with evidence pointers

Error Handling

ErrorCauseSolution
Cannot locate security policy in ${CLAUDE_SKILL_DIR}/docs/Documentation stored elsewhere or not yet createdRequest document locations; flag as critical evidence gap requiring immediate creation
Log retention < SOC 2 requirement (1 year)Insufficient log retention configurationNote current retention period; flag as gap; recommend extending to 12+ months
No incident response playbook foundUndocumented procedureFlag as critical gap; provide template for creating IR playbook
Cannot assess cloud controls without API accessNo CloudTrail/Audit Log exports availableRequest console screenshots or JSON exports as alternative evidence
Production and dev configs mixed in ${CLAUDE_SKILL_DIR}/Environment separation unclearRequest environment labeling; risk of auditing wrong environment

Examples

  • "Prepare a SOC 2 evidence checklist for Security and Availability criteria for production systems."
  • "Generate a readiness gap analysis with remediation backlog for SOC 2 Type II, covering CC1 through CC9."
  • "Assess CC6 access control compliance: verify MFA, RBAC, deprovisioning, and privileged access monitoring."

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references, assets) in skills/.curated/assisting-with-soc2-audit-preparation of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • references/README.md
  • references/errors.md
  • references/examples.md
  • references/implementation.md
  • references/readiness-by-trust-service-category.md
  • scripts/README.md
  • scripts/generate_soc2_report.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Assisting With Soc2 Audit Preparation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Assisting With Soc2 Audit Preparation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Assisting With Soc2 Audit Preparation this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: PassMIT
Trust Center BuilderGRCEngClub/claude-grc-engineering419—~2.6kAutomated safety check: PassCustom licence
Isms Audit Expertalirezarezvani/claude-skills28k1 repos~1.9kAutomated safety check: PassMIT
Performing Soc2 Type2 Audit Preparationmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Implementing Complianceancoleman/ai-design-components525—~4kAutomated safety check: PassMIT

Similar skills

  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 7 days ago
    Legal & ComplianceAuto-check passed
  • Isms Audit Expert

    alirezarezvani/claude-skills

    Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support.

    28k GitHub starsUsed in 1 repo~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Performing Soc2 Type2 Audit Preparation

    mukul975/Anthropic-Cybersecurity-Skills

    Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Isms Audit Expert

    borghei/Claude-Skills

    ISMS auditing for ISO 27001 compliance, control assessment, and certification support.

    891 GitHub stars~4.9k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Assisting With Soc2 Audit Preparation

What does Assisting With Soc2 Audit Preparation do?

Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification. Assisting With Soc2 Audit Preparation is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification.

When should I use Assisting With Soc2 Audit Preparation?

Assisting With Soc2 Audit Preparation fits situations like: you need to prepare for SOC 2 audits; assess Trust Service Criteria compliance; document security controls; generate readiness reports.

How do I install Assisting With Soc2 Audit Preparation in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a claude-code`. Or copy the skill folder (skills/.curated/assisting-with-soc2-audit-preparation in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/assisting-with-soc2-audit-preparation in your project. Claude Code loads it when a task matches its description.

How do I install Assisting With Soc2 Audit Preparation in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a codex`. Or copy the skill folder (skills/.curated/assisting-with-soc2-audit-preparation in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/assisting-with-soc2-audit-preparation in your project. Codex loads it when a task matches its description.

Can I use Assisting With Soc2 Audit Preparation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/assisting-with-soc2-audit-preparation, .gemini/skills/assisting-with-soc2-audit-preparation, .github/skills/assisting-with-soc2-audit-preparation and .opencode/skills/assisting-with-soc2-audit-preparation in your project.

What does Assisting With Soc2 Audit Preparation need to run?

Going by SKILL.md and its folder, Assisting With Soc2 Audit Preparation needs Python for the scripts in its folder. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(audit-collect:*), Bash(compliance-check:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Assisting With Soc2 Audit Preparation access the network?

SKILL.md names 3 domains. As links in the text: cisecurity.org, nist.gov and intentsolutions.io. This is read from the text; nothing was executed.

Is Assisting With Soc2 Audit Preparation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Assisting With Soc2 Audit Preparation use?

Assisting With Soc2 Audit Preparation is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Assisting With Soc2 Audit Preparation use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Assisting With Soc2 Audit Preparation?

Skills that share tags, products or a category with Assisting With Soc2 Audit Preparation: Trust Center Builder (GRCEngClub/claude-grc-engineering, 419 stars), Isms Audit Expert (alirezarezvani/claude-skills, 28k stars), Performing Soc2 Type2 Audit Preparation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Compliance Os (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Assisting With Soc2 Audit Preparation?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.