Trust Center Builder
GRCEngClub/claude-grc-engineering
Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.
Agent skill
by jeremylongshore in jeremylongshore/tons-of-skills-marketplace
Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace assisting-with-soc2-audit-preparation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/assisting-with-soc2-audit-preparation .claude/skills/assisting-with-soc2-audit-preparation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "assisting-with-soc2-audit-preparation" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/assisting-with-soc2-audit-preparation into .claude/skills/assisting-with-soc2-audit-preparation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assisting-with-soc2-audit-preparation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/assisting-with-soc2-audit-preparationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace assisting-with-soc2-audit-preparation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/assisting-with-soc2-audit-preparation .agents/skills/assisting-with-soc2-audit-preparation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "assisting-with-soc2-audit-preparation" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/assisting-with-soc2-audit-preparation into .agents/skills/assisting-with-soc2-audit-preparation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assisting-with-soc2-audit-preparation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace assisting-with-soc2-audit-preparation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/assisting-with-soc2-audit-preparation .cursor/skills/assisting-with-soc2-audit-preparation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "assisting-with-soc2-audit-preparation" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/assisting-with-soc2-audit-preparation into .cursor/skills/assisting-with-soc2-audit-preparation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assisting-with-soc2-audit-preparation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/assisting-with-soc2-audit-preparation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace assisting-with-soc2-audit-preparation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/assisting-with-soc2-audit-preparation .gemini/skills/assisting-with-soc2-audit-preparation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "assisting-with-soc2-audit-preparation" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/assisting-with-soc2-audit-preparation into .gemini/skills/assisting-with-soc2-audit-preparation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assisting-with-soc2-audit-preparation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace assisting-with-soc2-audit-preparationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/assisting-with-soc2-audit-preparation .github/skills/assisting-with-soc2-audit-preparation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "assisting-with-soc2-audit-preparation" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/assisting-with-soc2-audit-preparation into .github/skills/assisting-with-soc2-audit-preparation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assisting-with-soc2-audit-preparation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace assisting-with-soc2-audit-preparation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/assisting-with-soc2-audit-preparation .opencode/skills/assisting-with-soc2-audit-preparation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "assisting-with-soc2-audit-preparation" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/assisting-with-soc2-audit-preparation into .opencode/skills/assisting-with-soc2-audit-preparation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assisting-with-soc2-audit-preparation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
assisting-with-soc2-audit-preparationExecute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification.
Assisting With Soc2 Audit Preparation is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification. Use when you need to prepare for SOC 2 audits, assess Trust Service Criteria compliance, document security controls, or generate readiness reports. Trigger with phrases like "SOC 2 audit preparation", "SOC 2 readiness assessment", "collect SOC 2 evidence", or "Trust Service Criteria compliance".
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/README.md` and `references/errors.md`). Compatibility notes: Designed for Claude Code
It sits in Legal & Compliance, covering Audit readiness and SOC 2 and security compliance. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
10 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditGrepGlobBash(audit-collect:*)Bash(compliance-check:*)From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
cisecurity.orgnist.govintentsolutions.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Assisting With Soc2 Audit Preparation loads about 1.6k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 115 tokens; SKILL.md has 625 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 625 words, ~1,618 tokens.
.claude/skills/assisting-with-soc2-audit-preparation/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.Automate SOC 2 Type I and Type II audit preparation by assessing controls across the five AICPA Trust Service Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy). Inventory existing controls and evidence, perform gap analysis against each Common Criteria point (CC1-CC9), and produce an audit-ready evidence package with a readiness score and remediation backlog.
${CLAUDE_SKILL_DIR}/docs/ (information security policy, incident response plan, BCP/DR plan, vendor management procedures)${CLAUDE_SKILL_DIR}/soc2-audit/${CLAUDE_SKILL_DIR}/soc2-audit/ with subdirectories per criteria (CC1-control-environment/, CC6-access-controls/, CC7-system-operations/, etc.).${CLAUDE_SKILL_DIR}/soc2-audit/readiness-report-YYYYMMDD.md with overall readiness score, per-criteria assessment with percentage, remediation roadmap with timelines, and evidence collection checklist.See ${CLAUDE_SKILL_DIR}/references/implementation.md for the six-phase implementation guide. See ${CLAUDE_SKILL_DIR}/references/readiness-by-trust-service-category.md for example per-criteria readiness breakdowns.
${CLAUDE_SKILL_DIR}/soc2-audit/readiness-report-YYYYMMDD.md with overall score and per-criteria pass/gap status| Error | Cause | Solution |
|---|---|---|
Cannot locate security policy in ${CLAUDE_SKILL_DIR}/docs/ | Documentation stored elsewhere or not yet created | Request document locations; flag as critical evidence gap requiring immediate creation |
| Log retention < SOC 2 requirement (1 year) | Insufficient log retention configuration | Note current retention period; flag as gap; recommend extending to 12+ months |
| No incident response playbook found | Undocumented procedure | Flag as critical gap; provide template for creating IR playbook |
| Cannot assess cloud controls without API access | No CloudTrail/Audit Log exports available | Request console screenshots or JSON exports as alternative evidence |
Production and dev configs mixed in ${CLAUDE_SKILL_DIR}/ | Environment separation unclear | Request environment labeling; risk of auditing wrong environment |
${CLAUDE_SKILL_DIR}/references/readiness-by-trust-service-category.md -- example per-criteria readiness breakdown${CLAUDE_SKILL_DIR}/references/errors.md -- full error handling reference${CLAUDE_SKILL_DIR}/references/examples.md -- additional usage examples© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files (scripts, references, assets) in skills/.curated/assisting-with-soc2-audit-preparation of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Assisting With Soc2 Audit Preparation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Assisting With Soc2 Audit Preparation this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Trust Center BuilderGRCEngClub/claude-grc-engineering | 419 | — | ~2.6k | Automated safety check: Pass | Custom licence | |
| Isms Audit Expertalirezarezvani/claude-skills | 28k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Performing Soc2 Type2 Audit Preparationmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Compliance Osalirezarezvani/claude-skills | 28k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Implementing Complianceancoleman/ai-design-components | 525 | — | ~4k | Automated safety check: Pass | MIT |
GRCEngClub/claude-grc-engineering
Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.
alirezarezvani/claude-skills
Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support.
mukul975/Anthropic-Cybersecurity-Skills
Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing…
alirezarezvani/claude-skills
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
borghei/Claude-Skills
ISMS auditing for ISO 27001 compliance, control assessment, and certification support.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Categories
Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification. Assisting With Soc2 Audit Preparation is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification.
Assisting With Soc2 Audit Preparation fits situations like: you need to prepare for SOC 2 audits; assess Trust Service Criteria compliance; document security controls; generate readiness reports.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a claude-code`. Or copy the skill folder (skills/.curated/assisting-with-soc2-audit-preparation in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/assisting-with-soc2-audit-preparation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a codex`. Or copy the skill folder (skills/.curated/assisting-with-soc2-audit-preparation in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/assisting-with-soc2-audit-preparation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill assisting-with-soc2-audit-preparation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/assisting-with-soc2-audit-preparation, .gemini/skills/assisting-with-soc2-audit-preparation, .github/skills/assisting-with-soc2-audit-preparation and .opencode/skills/assisting-with-soc2-audit-preparation in your project.
Going by SKILL.md and its folder, Assisting With Soc2 Audit Preparation needs Python for the scripts in its folder. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(audit-collect:*), Bash(compliance-check:*). Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 3 domains. As links in the text: cisecurity.org, nist.gov and intentsolutions.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Assisting With Soc2 Audit Preparation is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Assisting With Soc2 Audit Preparation: Trust Center Builder (GRCEngClub/claude-grc-engineering, 419 stars), Isms Audit Expert (alirezarezvani/claude-skills, 28k stars), Performing Soc2 Type2 Audit Preparation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Compliance Os (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.