Agent skill

Generating Compliance Reports

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Generate comprehensive compliance reports for security standards.

MITAuto-check passedLegal & Compliance

Install Generating Compliance Reports

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-compliance-reports -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace generating-compliance-reports --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/generating-compliance-reports .claude/skills/generating-compliance-reports && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
generating-compliance-reports
GitHub stars
2.8k
Token cost
~1.6k tokens
SKILL.md length
715 words
Files
5 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Generate comprehensive compliance reports for security standards.

  • Works in 9 steps: Determine the target compliance… → Enumerate the control requirements for… → Scan the codebase for evidence of… → …
  • Creating compliance documentation
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Generating Compliance Reports is an agent skill from jeremylongshore/tons-of-skills-marketplace. Generate comprehensive compliance reports for security standards. Use when creating compliance documentation. Trigger with 'generate compliance report', 'compliance status', or 'audit compliance'.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/README.md` and `scripts/README.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance, covering Healthcare and finance regulation and SOC 2 and security compliance. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Creating compliance documentation
  • With generate compliance report
  • Compliance status
  • Audit compliance

Example prompts

  • “generate compliance report”
  • “compliance status”
  • “audit compliance”
  • “/generating-compliance-reports”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(security:*), Bash(scan:*), Bash(audit:*)

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Determine the target compliance framework (PCI DSS, HIPAA, SOC 2, GDPR, ISO 27001, or custom) and identify applicable control domains…
  2. Enumerate the control requirements for the target framework -- for PCI DSS, map the 12 requirements and their sub-controls; for HIPAA, map…
  3. Scan the codebase for evidence of control implementation: encryption at rest and in transit (TLS configuration, database encryption)…
  4. Evaluate each control as Compliant, Partially Compliant, Non-Compliant, or Not Applicable -- document the evidence file path and line…
  5. For Partially Compliant and Non-Compliant controls, describe the specific gap: what is missing, what risk it introduces, and what…
  6. Calculate an overall compliance score as percentage of applicable controls that are fully compliant.
  7. Generate the report with these sections: Executive Summary, Scope and Methodology, Control-by-Control Assessment, Gap Analysis, Risk…
  8. Write the report to ${CLAUDE_SKILL_DIR}/compliance-report-[framework]-[date].md using the Write tool.
  9. Validate the report against the config schema in ${CLAUDE_SKILL_DIR}/references/README.md if applicable.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(security:*)
    • Bash(scan:*)
    • Bash(audit:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • pcisecuritystandards.org
    • hhs.gov
    • iso.org
    • nist.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Generating Compliance Reports loads about 1.6k tokens when it runs, and up to ~1.6k if it reads all its reference files. Until then it costs about 57 tokens; SKILL.md has 715 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 715 words, ~1,588 tokens.

Download SKILL.mdSave it as .claude/skills/generating-compliance-reports/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
generating-compliance-reports
description
Generate comprehensive compliance reports for security standards. Use when creating compliance documentation. Trigger with 'generate compliance report', 'compliance status', or 'audit compliance'.
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(security:*), Bash(scan:*), Bash(audit:*)
compatibility
Designed for Claude Code
version
1.25.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
security, compliance, audit

Generating Compliance Reports

Overview

Generate structured compliance reports for major security frameworks including PCI DSS, HIPAA, SOC 2, GDPR, and ISO 27001. This skill scans codebases, configurations, and infrastructure definitions to assess compliance posture, maps findings to specific framework controls, and produces audit-ready documentation with evidence references and gap analysis.

Prerequisites

  • Access to the target codebase, infrastructure configs, and policy documents in ${CLAUDE_SKILL_DIR}/
  • Knowledge of the target compliance framework and its applicable scope
  • Standard shell utilities and Grep/Glob available for evidence gathering
  • Reference: ${CLAUDE_SKILL_DIR}/references/README.md for PCI DSS guidelines, HIPAA compliance checklist, SOC 2 framework overview, config schema, and API documentation

Instructions

  1. Determine the target compliance framework (PCI DSS, HIPAA, SOC 2, GDPR, ISO 27001, or custom) and identify applicable control domains based on the system under audit.
  2. Enumerate the control requirements for the target framework -- for PCI DSS, map the 12 requirements and their sub-controls; for HIPAA, map Administrative, Physical, and Technical Safeguards; for SOC 2, map Trust Services Criteria (CC1-CC9).
  3. Scan the codebase for evidence of control implementation: encryption at rest and in transit (TLS configuration, database encryption), access controls (RBAC definitions, IAM policies), logging and monitoring (audit log configuration, SIEM integration), and data retention policies.
  4. Evaluate each control as Compliant, Partially Compliant, Non-Compliant, or Not Applicable -- document the evidence file path and line number for each assessment.
  5. For Partially Compliant and Non-Compliant controls, describe the specific gap: what is missing, what risk it introduces, and what remediation is required.
  6. Calculate an overall compliance score as percentage of applicable controls that are fully compliant.
  7. Generate the report with these sections: Executive Summary, Scope and Methodology, Control-by-Control Assessment, Gap Analysis, Risk Rating, Remediation Roadmap with priority and effort estimates, and Evidence Appendix.
  8. Write the report to ${CLAUDE_SKILL_DIR}/compliance-report-[framework]-[date].md using the Write tool.
  9. Validate the report against the config schema in ${CLAUDE_SKILL_DIR}/references/README.md if applicable.

Output

  • Compliance report: Markdown document with Executive Summary, Scope, Control Assessment (table with Control ID, Description, Status, Evidence, Gap), Risk Rating, and Remediation Roadmap
  • Compliance score: Percentage of applicable controls rated Compliant, broken down by control domain
  • Gap analysis: Prioritized list of non-compliant controls with risk impact and remediation effort (high/medium/low)
  • Evidence index: File paths and line references for each control assessment
  • Remediation roadmap: Prioritized action items with estimated effort, owner assignment placeholders, and target dates
Show full SKILL.md (328 more words)Show less

Error Handling

ErrorCauseSolution
Unknown compliance framework requestedFramework not in supported listMap the custom framework controls manually or select the closest standard framework as a baseline
Insufficient evidence for control assessmentCodebase lacks configuration files or documentationMark the control as "Evidence Not Available" and recommend documenting the control implementation
Mixed framework versionsCodebase references multiple versions of a standard (e.g., PCI DSS 3.2.1 vs 4.0)Clarify the target version and assess against that version only; note version discrepancies in the report
Large codebase scan timeoutToo many files to scan within time limitsScope the scan to relevant directories (e.g., src/, config/, infra/) and exclude generated code
Conflicting control evidenceDifferent parts of the codebase implement conflicting security policiesFlag as Partially Compliant and document both implementations; recommend standardization

Examples

PCI DSS Compliance Report

Scan an e-commerce application in ${CLAUDE_SKILL_DIR}/ for PCI DSS v4.0 compliance. Assess Requirement 2 (Apply Secure Configurations) by checking for default credentials in config files, Requirement 3 (Protect Stored Account Data) by verifying encryption of cardholder data fields, and Requirement 6 (Develop and Maintain Secure Systems) by checking dependency vulnerability status. Produce a report rating each requirement as Compliant/Non-Compliant with file-level evidence.

HIPAA Technical Safeguards Audit

Evaluate a healthcare application against HIPAA Technical Safeguards. Check 164.312(a)(1) Access Control by reviewing authentication and RBAC implementations, 164.312(e)(1) Transmission Security by verifying TLS 1.2+ enforcement, and 164.312(b) Audit Controls by confirming audit logging captures access to PHI. Generate a gap analysis with remediation steps for each non-compliant safeguard.

SOC 2 Type II Readiness Assessment

Assess SOC 2 Trust Services Criteria CC6 (Logical and Physical Access Controls) and CC7 (System Operations) by scanning for access control policies, change management procedures, incident response documentation, and monitoring configurations. Produce a readiness report indicating which criteria need additional evidence or implementation before a formal SOC 2 audit.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/.curated/generating-compliance-reports of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • references/README.md
  • scripts/README.md
  • scripts/generate_report.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Generating Compliance Reports next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Generating Compliance Reports compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Generating Compliance Reports this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: PassMIT
Grc Knowledgemlunato47/claude-grc-plugin184—~6.1kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT
Eks Securityaws-samples/appmod-blueprints115—~4.7kAutomated safety check: PassMIT-0

Similar skills

  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Compliance

    RightNow-AI/openfang

    Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

    18k GitHub stars~921 tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Generating Compliance Reports

What does Generating Compliance Reports do?

Generate comprehensive compliance reports for security standards. Generating Compliance Reports is an agent skill from jeremylongshore/tons-of-skills-marketplace. Generate comprehensive compliance reports for security standards.

When should I use Generating Compliance Reports?

Generating Compliance Reports fits situations like: creating compliance documentation; with generate compliance report; compliance status; audit compliance.

How do I install Generating Compliance Reports in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-compliance-reports -a claude-code`. Or copy the skill folder (skills/.curated/generating-compliance-reports in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/generating-compliance-reports in your project. Claude Code loads it when a task matches its description.

How do I install Generating Compliance Reports in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-compliance-reports -a codex`. Or copy the skill folder (skills/.curated/generating-compliance-reports in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/generating-compliance-reports in your project. Codex loads it when a task matches its description.

Can I use Generating Compliance Reports in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-compliance-reports -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/generating-compliance-reports, .gemini/skills/generating-compliance-reports, .github/skills/generating-compliance-reports and .opencode/skills/generating-compliance-reports in your project.

What does Generating Compliance Reports need to run?

Going by SKILL.md and its folder, Generating Compliance Reports needs Python for the scripts in its folder. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(security:*), Bash(scan:*), Bash(audit:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Generating Compliance Reports access the network?

SKILL.md names 4 domains. As links in the text: pcisecuritystandards.org, hhs.gov, iso.org and nist.gov. This is read from the text; nothing was executed.

Is Generating Compliance Reports safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Generating Compliance Reports use?

Generating Compliance Reports is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Generating Compliance Reports use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 18 tokens, read only when the agent opens those files.

What are the alternatives to Generating Compliance Reports?

Skills that share tags, products or a category with Generating Compliance Reports: Grc Knowledge (mlunato47/claude-grc-plugin, 184 stars), Audit Report (harness/harness-skills, 115 stars), Security Compliance (sangrokjung/claude-forge, 852 stars) and Ciso Advisor (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Generating Compliance Reports?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.