Agent skill

Checking Infrastructure Compliance

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Execute use when you need to work with compliance checking. An agent skill from jeremylongshore/tons-of-skills-marketplace.

MITAuto-check passedLegal & Compliance

Install Checking Infrastructure Compliance

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-infrastructure-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace checking-infrastructure-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/checking-infrastructure-compliance .claude/skills/checking-infrastructure-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
checking-infrastructure-compliance
GitHub stars
2.8k
Token cost
~1.1k tokens
SKILL.md length
456 words
Files
8 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Execute use when you need to work with compliance checking. An agent skill from jeremylongshore/tons-of-skills-marketplace.

  • Works in 9 steps: Identify the applicable compliance… → Scan Terraform files with checkov -d .… → Scan Kubernetes manifests for security… → …
  • You need to work with compliance checking
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs Python scripts from its folder; calls aws and terraform

What it does

Checking Infrastructure Compliance is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute use when you need to work with compliance checking. This skill provides compliance monitoring and validation with comprehensive guidance and automation. Trigger with phrases like "check compliance", "validate policies", or "audit compliance".

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/README.md`, `assets/compliance_report_template.md` and `assets/compliance_rules.json`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Infrastructure as code and SOC 2 and security compliance. It works with Kubernetes and Terraform. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • You need to work with compliance checking
  • With phrases like check compliance
  • Validate policies
  • Audit compliance

Example prompts

  • “check compliance”
  • “validate policies”
  • “audit compliance”
  • “/checking-infrastructure-compliance”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(cmd:*)

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Identify the applicable compliance framework(s) based on industry and data classification
  2. Scan Terraform files with checkov -d . or tfsec . to detect misconfigurations
  3. Scan Kubernetes manifests for security issues: missing resource limits, privileged containers, missing network policies
  4. Validate IAM policies for least-privilege violations using cloud-native tools (aws iam access-analyzer)
  5. Check encryption at rest and in transit: verify S3 bucket encryption, database TLS, and EBS volume encryption
  6. Audit logging configurations: confirm CloudTrail/Cloud Audit Logs are enabled and sent to immutable storage
  7. Generate a compliance report mapping each finding to the relevant control (e.g., CIS AWS 2.1.1)
  8. Produce remediation Terraform/YAML patches for each violation with severity ranking (Critical, High, Medium, Low)
  9. Set up CI/CD integration so compliance checks block merges on Critical/High violations

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(cmd:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • terraform

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • checkov.io
    • aquasecurity.github.io
    • openpolicyagent.org
    • cisecurity.org
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Checking Infrastructure Compliance loads about 1.1k tokens when it runs, and up to ~1.1k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 456 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 456 words, ~1,066 tokens.

Download SKILL.mdSave it as .claude/skills/checking-infrastructure-compliance/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
checking-infrastructure-compliance
description
Execute use when you need to work with compliance checking. This skill provides compliance monitoring and validation with comprehensive guidance and automation. Trigger with phrases like "check compliance", "validate policies", or "audit compliance".
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(cmd:*)
compatibility
Designed for Claude Code
version
1.26.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
devops, monitoring, compliance, audit

Checking Infrastructure Compliance

Overview

Audit infrastructure configurations against compliance frameworks (CIS Benchmarks, SOC 2, HIPAA, PCI-DSS, GDPR) using policy-as-code tools like Open Policy Agent (OPA), Checkov, and tfsec. Generate compliance reports, identify violations, and produce remediation plans for Terraform, Kubernetes, and cloud provider configurations.

Prerequisites

  • Policy-as-code tool installed: checkov, tfsec, opa, or kube-bench
  • Infrastructure-as-code files (Terraform, CloudFormation, Kubernetes manifests) in the project
  • Cloud provider CLI authenticated with read access to resources
  • Compliance framework requirements documented (CIS, SOC 2, HIPAA, PCI-DSS)
  • jq for parsing JSON policy outputs

Instructions

  1. Identify the applicable compliance framework(s) based on industry and data classification
  2. Scan Terraform files with checkov -d . or tfsec . to detect misconfigurations
  3. Scan Kubernetes manifests for security issues: missing resource limits, privileged containers, missing network policies
  4. Validate IAM policies for least-privilege violations using cloud-native tools (aws iam access-analyzer)
  5. Check encryption at rest and in transit: verify S3 bucket encryption, database TLS, and EBS volume encryption
  6. Audit logging configurations: confirm CloudTrail/Cloud Audit Logs are enabled and sent to immutable storage
  7. Generate a compliance report mapping each finding to the relevant control (e.g., CIS AWS 2.1.1)
  8. Produce remediation Terraform/YAML patches for each violation with severity ranking (Critical, High, Medium, Low)
  9. Set up CI/CD integration so compliance checks block merges on Critical/High violations

Output

  • Compliance scan results in JSON/SARIF format for CI integration
  • Markdown compliance report with control mappings and pass/fail status
  • Remediation code patches (Terraform diffs, Kubernetes manifest updates)
  • OPA/Rego policy files for custom organizational rules
  • CI/CD pipeline step configuration for automated compliance gating
Show full SKILL.md (198 more words)Show less

Error Handling

ErrorCauseSolution
checkov: no Terraform files foundScanner run from wrong directorySpecify path explicitly with -d path/to/terraform/
tfsec: failed to parse HCLSyntax error in Terraform filesRun terraform validate first to fix HCL syntax before compliance scan
False positive on compliance checkRule too broad for the specific use caseAdd inline skip comments (#checkov:skip=CKV_AWS_18:Reason) or create a .checkov.yml skip list
OPA policy evaluation errorRego syntax error or missing input dataTest policies with opa eval -d policy.rego -i input.json and validate Rego syntax
Scan timeout on large codebaseToo many files or complex module referencesUse --compact mode, scan directories individually, or increase timeout limits

Examples

  • "Run a CIS Benchmark compliance check against all Terraform files and generate a report with remediation steps for Critical findings."
  • "Create OPA policies that enforce: all S3 buckets must have encryption, all EC2 instances must have IMDSv2, and all security groups must not allow 0.0.0.0/0 ingress."
  • "Scan Kubernetes manifests for PCI-DSS compliance: verify no privileged containers, all pods have resource limits, and network policies exist for every namespace."

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/.curated/checking-infrastructure-compliance of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • assets/compliance_report_template.md
  • assets/compliance_rules.json
  • assets/example_infrastructure_config.yaml
  • references/README.md
  • scripts/README.md
  • scripts/compliance_scan.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Checking Infrastructure Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Checking Infrastructure Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Checking Infrastructure Compliance this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Code To Control MapperGRCEngClub/claude-grc-engineering419—~524Automated safety check: NotesCustom licence
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Eks Best Practicesaws-samples/appmod-blueprints115—~5kAutomated safety check: PassMIT-0
Audit Infrastructure As Codecyberful/cyberful135—~649Automated safety check: PassAGPL-3.0
Code Securitysemgrep/skills324—~1.2kAutomated safety check: PassCustom licence

Similar skills

  • Code To Control Mapper

    GRCEngClub/claude-grc-engineering

    Maps infrastructure code (Terraform, Kubernetes, CloudFormation) to compliance controls (ISO 27001, SOC 2, NIST 800-53).

    419 GitHub stars~524 tokensUpdated 7 days ago
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Eks Best Practices

    aws-samples/appmod-blueprints

    Official

    Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

    115 GitHub stars~5k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    135 GitHub stars~649 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    324 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Asdf

    jjmartres/opencode

    A skill your agent uses whenever the user wants to install, configure, or use asdf (asdf-vm), the universal version manager.

    133 GitHub stars~2.1k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Checking Infrastructure Compliance

What does Checking Infrastructure Compliance do?

Execute use when you need to work with compliance checking. An agent skill from jeremylongshore/tons-of-skills-marketplace. Checking Infrastructure Compliance is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute use when you need to work with compliance checking.

When should I use Checking Infrastructure Compliance?

Checking Infrastructure Compliance fits situations like: you need to work with compliance checking; with phrases like check compliance; validate policies; audit compliance.

How do I install Checking Infrastructure Compliance in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-infrastructure-compliance -a claude-code`. Or copy the skill folder (skills/.curated/checking-infrastructure-compliance in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/checking-infrastructure-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Checking Infrastructure Compliance in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-infrastructure-compliance -a codex`. Or copy the skill folder (skills/.curated/checking-infrastructure-compliance in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/checking-infrastructure-compliance in your project. Codex loads it when a task matches its description.

Can I use Checking Infrastructure Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill checking-infrastructure-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/checking-infrastructure-compliance, .gemini/skills/checking-infrastructure-compliance, .github/skills/checking-infrastructure-compliance and .opencode/skills/checking-infrastructure-compliance in your project.

What does Checking Infrastructure Compliance need to run?

Going by SKILL.md and its folder, Checking Infrastructure Compliance needs Python for the scripts in its folder and the command-line tools its instructions call (aws and terraform). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(cmd:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Checking Infrastructure Compliance access the network?

SKILL.md names 5 domains. As links in the text: checkov.io, aquasecurity.github.io, openpolicyagent.org, cisecurity.org and github.com. This is read from the text; nothing was executed.

Is Checking Infrastructure Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Checking Infrastructure Compliance use?

Checking Infrastructure Compliance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Checking Infrastructure Compliance use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16 tokens, read only when the agent opens those files.

What are the alternatives to Checking Infrastructure Compliance?

Skills that share tags, products or a category with Checking Infrastructure Compliance: Code To Control Mapper (GRCEngClub/claude-grc-engineering, 419 stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Eks Best Practices (aws-samples/appmod-blueprints, 115 stars) and Audit Infrastructure As Code (cyberful/cyberful, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Checking Infrastructure Compliance?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.