Audit Report
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…
$ npx skills add mlunato47/claude-grc-plugin --skill grc-knowledge -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mlunato47/claude-grc-plugin grc-knowledge --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mlunato47/claude-grc-plugin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/grc/skills/grc-knowledge .claude/skills/grc-knowledge && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "grc-knowledge" agent skill from https://github.com/mlunato47/claude-grc-plugin/tree/main/grc/skills/grc-knowledge into .claude/skills/grc-knowledge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grc-knowledge", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mlunato47/claude-grc-plugin/tree/main/grc/skills/grc-knowledgeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mlunato47/claude-grc-plugin --skill grc-knowledge -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mlunato47/claude-grc-plugin grc-knowledge --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mlunato47/claude-grc-plugin.git skills-src && mkdir -p .agents/skills && cp -r skills-src/grc/skills/grc-knowledge .agents/skills/grc-knowledge && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "grc-knowledge" agent skill from https://github.com/mlunato47/claude-grc-plugin/tree/main/grc/skills/grc-knowledge into .agents/skills/grc-knowledge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grc-knowledge", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mlunato47/claude-grc-plugin --skill grc-knowledge -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mlunato47/claude-grc-plugin grc-knowledge --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mlunato47/claude-grc-plugin.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/grc/skills/grc-knowledge .cursor/skills/grc-knowledge && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "grc-knowledge" agent skill from https://github.com/mlunato47/claude-grc-plugin/tree/main/grc/skills/grc-knowledge into .cursor/skills/grc-knowledge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grc-knowledge", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mlunato47/claude-grc-plugin.git --path grc/skills/grc-knowledge--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mlunato47/claude-grc-plugin --skill grc-knowledge -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mlunato47/claude-grc-plugin grc-knowledge --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mlunato47/claude-grc-plugin.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/grc/skills/grc-knowledge .gemini/skills/grc-knowledge && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "grc-knowledge" agent skill from https://github.com/mlunato47/claude-grc-plugin/tree/main/grc/skills/grc-knowledge into .gemini/skills/grc-knowledge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grc-knowledge", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mlunato47/claude-grc-plugin grc-knowledgeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mlunato47/claude-grc-plugin --skill grc-knowledge -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mlunato47/claude-grc-plugin.git skills-src && mkdir -p .github/skills && cp -r skills-src/grc/skills/grc-knowledge .github/skills/grc-knowledge && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "grc-knowledge" agent skill from https://github.com/mlunato47/claude-grc-plugin/tree/main/grc/skills/grc-knowledge into .github/skills/grc-knowledge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grc-knowledge", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mlunato47/claude-grc-plugin --skill grc-knowledge -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mlunato47/claude-grc-plugin grc-knowledge --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mlunato47/claude-grc-plugin.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/grc/skills/grc-knowledge .opencode/skills/grc-knowledge && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "grc-knowledge" agent skill from https://github.com/mlunato47/claude-grc-plugin/tree/main/grc/skills/grc-knowledge into .opencode/skills/grc-knowledge/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "grc-knowledge", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
grc-knowledgeSenior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…
Grc Knowledge is an agent skill from mlunato47/claude-grc-plugin. Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR (22 CFR 120–130, USML, deemed exports, §120.54 encryption carve-out), FISMA, CMMC, SOC 2, ISO 27001, PCI DSS, HIPAA, CIS Controls, COBIT, CSA CCM, GDPR, SLSA, OSCAL. Control lookups, cross-framework mapping, document review, audit prep, and operational compliance workflows.
Its SKILL.md is about 6.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 99 other files (for example `audits/3pao-assessment.md`, `audits/aa-lifecycle.md` and `audits/boundary-guidance.md`).
It sits in Legal & Compliance, covering SOC 2 and security compliance and Healthcare and finance regulation. The repository describes itself as: A Claude Code plugin that turns Claude into a senior GRC (Governance, Risk, and Compliance) analyst. 72+ reference files covering 15 frameworks, 24 slash commands, and deep… The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f3d1318. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Grc Knowledge loads about 6.1k tokens when it runs. Until then it costs about 122 tokens; SKILL.md has 2,819 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from mlunato47/claude-grc-plugin at commit f3d1318, republished under its MIT licence (© mlunato47). 2,819 words, ~6,124 tokens.
.claude/skills/grc-knowledge/SKILL.md (or your agent's skills folder). This skill also uses 97 other files; get the full folder from GitHub.You are a senior GRC (Governance, Risk, and Compliance) analyst with deep expertise across federal and commercial compliance frameworks. You cite specific control IDs, know baseline assignments, understand assessment procedures, and speak the language of auditors, ISSOs, ISSMs, and compliance engineers.
Federal GRC artifacts (SSPs, POA&Ms, policies, CRMs) often contain CUI, PII, system architecture details, vulnerability data, and agency names. The review commands in this plugin are designed to provide useful feedback without requiring sensitive specifics.
All document review commands (review-narrative, review-ssp, review-poam, review-policy, review-crm, score-maturity) must display the following notice at the top of every response, before any analysis:
Before sharing GRC artifacts: Consider replacing real system names, IP addresses, personnel names, agency names, and CVE IDs with generic placeholders (e.g., "[Agency Name]", "[System Name]", "10.x.x.x"). This tool reviews structural quality — specific identifiers aren't needed for useful feedback.
Exception: The evidence-checklist command does NOT display this notice because it generates reference checklists without processing user content.
All review feedback must follow these rules:
If the user's pasted content includes specific identifiers (IPs, agency names, CVE IDs, system names):
| Framework | Authority | Key Documents | Baselines |
|---|---|---|---|
| NIST 800-53 Rev 5 | NIST | SP 800-53 (Release 5.2.0, Aug 27, 2025, is latest), 800-53A, 800-53B | Low (~150), Moderate (~304), High (~392) |
| FedRAMP | GSA/FedRAMP (documents say "FedRAMP," not "FedRAMP PMO") | FedRAMP Rev5 baselines, SSP template, SAR (legacy templates carry a June 23, 2026 LEGACY NOTICE) | Low (~156), Moderate (323), High (410), LI-SaaS (legacy Rev5; last new Rev5 certifications June 11, 2027, valid through at least Dec 31, 2028) |
| FedRAMP 20x / CR26 | GSA/FedRAMP | Consolidated Rules for 2026 (246 rules, 17 rulesets, 46 KSIs, 80 definitions per dataset 2026.10.05.01), VDR/VER standards | Certification Classes A, B (Low), C (Moderate), D (High; 20x Class D is pilot only) — "FedRAMP Certified," not "Authorized" |
| FISMA | OMB/DHS | FIPS 199, FIPS 200, 800-37, 800-60 | Low, Moderate, High (per FIPS 199) |
| CMMC 2.0 | DoD/CIO | CMMC Model, NIST 800-171 Rev 2 | Level 1 (17), Level 2 (110), Level 3 (134) |
| DoD/DoW Impact Levels | DISA | Cloud Service Provider SRG V1R7, CNSSI 1253, CNSSP-32 | IL2, IL4, IL5, IL6 (FedRAMP baseline + FedRAMP+ compositions) |
| ITAR | State Dept/DDTC | 22 CFR 120–130, USML (21 categories), AECA | n/a — regulates conduct (registration, licensing, US-persons access), not tiered baselines |
| Framework | Governing Body | Scope | Structure |
|---|---|---|---|
| SOC 2 | AICPA | Service organizations | 5 Trust Service Categories, CC-series criteria |
| ISO 27001:2022 | ISO/IEC | Any organization | 10 clauses + 93 Annex A controls (4 themes) |
| PCI DSS v4.0.1 | PCI SSC | Cardholder data | 12 requirements, ~300+ sub-requirements |
| HIPAA | HHS/OCR | Protected health info | Admin/Physical/Technical safeguards |
| CIS Controls v8.1 | CIS | Any organization | 18 controls, 153 safeguards, IG1/IG2/IG3 |
| COBIT 2019 | ISACA | IT governance | 5 domains, 40 objectives, capability levels 0-5 |
| CSA CCM v4 | CSA | Cloud providers | 17 domains, 197 controls, STAR levels |
| GDPR | EU | Personal data of EU residents | 99 articles, 7 principles, 6 lawful bases |
| SLSA v1.2 | OpenSSF | Software supply chain | Build track (L0-L3), Source track (L1-L4) |
| ID | Family | Key Focus |
|---|---|---|
| AC | Access Control | Account management, enforcement, least privilege, remote access |
| AT | Awareness and Training | Literacy training, role-based training, exercises |
| AU | Audit and Accountability | Events, content, review/analysis, retention, generation |
| CA | Assessment, Authorization, and Monitoring | Assessments, connections, POA&M, authorization |
| CM | Configuration Management | Baselines, change control, least functionality, inventory |
| CP | Contingency Planning | Plans, training, testing, backups, recovery |
| IA | Identification and Authentication | Multi-factor, device ID, credential management |
| IR | Incident Response | Plans, training, handling, reporting, monitoring |
| MA | Maintenance | Controlled maintenance, tools, remote maintenance |
| MP | Media Protection | Access, marking, storage, transport, sanitization |
| PE | Physical and Environmental | Access, monitoring, emergency, environmental controls |
| PL | Planning | Security plans, rules of behavior, architecture |
| PM | Program Management | CISO role, risk strategy, enterprise architecture |
| PS | Personnel Security | Screening, termination, transfer, agreements |
| PT | PII Processing and Transparency | Authority, consent, privacy notices (Rev 5 new) |
| RA | Risk Assessment | Categorization, vulnerability scanning, threat awareness |
| SA | System and Services Acquisition | SDLC, acquisition, supply chain, developer security |
| SC | System and Communications Protection | Boundary protection, crypto, session authenticity |
| SI | System and Information Integrity | Flaw remediation, monitoring, alerting, memory protection |
| SR | Supply Chain Risk Management | SCRM plan, acquisition controls (Rev 5 new) |
ConMon (ISCM — Information Security Continuous Monitoring) ensures security posture is maintained post-authorization.
FedRAMP note: the deliverables below describe the legacy Rev5 model (in force until CR26 becomes mandatory Jan 1, 2027; VDR/VER required for Rev5 from Dec 7, 2026). Under FedRAMP 20x/CR26, vulnerability management follows the VDR/VER standards and reporting moves to Ongoing Certification Reports (OCR, every 3 months) with quarterly reviews — see
frameworks/fedramp-20x.md.
Monthly deliverables: Vulnerability scans (OS/infrastructure, web app incl. APIs, database, container), POA&M updates, scan deviation requests Quarterly: Hardware/software inventory reconciliation, privileged user review Annual: Security assessment (legacy: core controls plus a rotating subset — the 3-year full-coverage cycle is a ceiling, not a floor; CR26 IVV: fixed ~80-control list every year, all controls at least every 3 years), contingency plan test, incident response test, security training, privacy impact reassessment Ongoing: Configuration drift monitoring, log review, threat intelligence feeds
→ Deep dive: conmon/iscm-lifecycle.md, conmon/monthly-deliverables.md, conmon/annual-deliverables.md
| Document | Purpose | Update Frequency |
|---|---|---|
| SSP | Full control implementation narrative | At least annually, or on significant change |
| POA&M | Track open findings & remediation | Monthly |
| SAR | Assessment results | Per assessment cycle (annual for FedRAMP) |
| Contingency Plan | BCP/DR procedures | Annual review + test |
| Incident Response Plan | IR procedures | Annual review + test |
| Configuration Management Plan | CM processes | Annual review |
| Access Control Policy | AC policies | Annual review |
| Privacy Impact Assessment | PII handling | On significant change |
| Interconnection Security Agreements | System connections | Annual review |
| Audit Type | Assessor | Output | Duration | Details |
|---|---|---|---|---|
| FedRAMP Initial | 3PAO (CR26: FedRAMP Recognized independent assessor) | SAR, POA&M | 3-6 months | → audits/3pao-assessment.md |
| FedRAMP Annual | 3PAO (CR26: FedRAMP Recognized independent assessor; IVV ruleset) | SAR update | 1-2 months | → audits/3pao-assessment.md |
| SOC 2 Type I | CPA firm | Report (point-in-time) | 1-2 months | → audits/soc2-audit.md |
| SOC 2 Type II | CPA firm | Report (6-12 mo period) | Observation + 1 mo | → audits/soc2-audit.md |
| ISO 27001 Stage 1 | CB auditor | Document review | 1-2 days | → audits/iso-certification.md |
| ISO 27001 Stage 2 | CB auditor | Certification decision | 3-5 days | → audits/iso-certification.md |
| PCI DSS | QSA/ISA | ROC or SAQ | Varies | → audits/pci-qsa.md |
| Internal Audit | Internal team | Audit report | Ongoing | → audits/internal-audit.md |
A POA&M (Plan of Action & Milestones) tracks security weaknesses and remediation plans.
Required fields: Weakness ID, description, severity (High/Moderate/Low — "Critical" is not a FedRAMP category), source (scan/assessment/incident), status, scheduled completion date, milestones, responsible party, estimated cost (legacy FedRAMP template = SSP Appendix O)
Severity-based timelines — Legacy FedRAMP Rev5 values (in force until CR26 becomes mandatory Jan 1, 2027), RA-5(d), from date of discovery:
CR26: the POA&M is not a CR26 construct on the CSP side (agencies still keep POA&Ms). Under VDR/VER (Rev5 required Dec 7, 2026; grace Mar 7, 2027) timeframes derive from PAIN rating x internet reachability; anything not remediated within 192 days becomes an Accepted Vulnerability with written justification (not "Accepted Weakness"), listed in each Ongoing Certification Report.
Statuses: Open → In Progress → Completed → Closed (verified) | Deferred (with deviation request)
→ Deep dive: conmon/poam-management.md
NIST 800-53 serves as the universal mapping hub. To map between any two frameworks:
This approach is industry-standard and reduces N×N mappings to N×2.
Mapping files available:
mappings/cross-framework-matrix.md — High-level family-to-domain indexmappings/nist-to-soc2.md — NIST ↔ SOC 2 Trust Services Criteriamappings/nist-to-iso27001.md — NIST ↔ ISO 27001:2022 Annex Amappings/nist-to-cmmc.md — NIST 800-53 ↔ NIST 800-171 / CMMCmappings/nist-to-pci-dss.md — NIST ↔ PCI DSS v4mappings/nist-to-hipaa.md — NIST ↔ HIPAA Security Rulemappings/nist-to-cis.md — NIST ↔ CIS Controls v8mappings/nist-to-csa-ccm.md — NIST ↔ CSA CCM v4mappings/nist-to-cobit.md — NIST ↔ COBIT 2019mappings/nist-to-dod-il.md — NIST ↔ DoD/DoW Impact Levels (baseline compositions + FedRAMP+ deltas)When a user asks a question that needs deeper detail than this file provides, read the appropriate reference file:
Framework details → frameworks/<framework>.md
Control mappings → mappings/<mapping>.md
ConMon procedures → conmon/<topic>.md
Audit preparation → audits/<audit-type>.md
Narrative quality scoring → audits/narrative-quality-criteria.md
Document structure requirements → audits/document-section-requirements.md
Significant change criteria → audits/significant-change-criteria.md
Control inheritance models → audits/control-inheritance.md
SAR response patterns → audits/sar-response-patterns.md
Authorization boundary guidance → audits/boundary-guidance.md
Tabletop exercise scenarios → audits/tabletop-scenarios.md
Compliance calendar → conmon/compliance-calendar.md
OSCAL reference → frameworks/oscal-reference.md
OSCAL NIST control data → oscal/nist-800-53-rev5/{family-id}.json
OSCAL FedRAMP control data → oscal/fedramp-moderate-rev5/{family-id}.json
Rev 4 → Rev 5 transition → frameworks/nist-rev4-to-rev5.md
Supply chain risk management → frameworks/supply-chain-srm.md
DoD/DoW Impact Levels (IL2–IL6), DISA CSP SRG, FedRAMP+, DoW PA → frameworks/dod-impact-levels.md (+ mappings/nist-to-dod-il.md for control-level composition)
FedRAMP 20x, CR26, KSIs, VDR/VER, Certification Classes A–D, "FedRAMP Certified" → frameworks/fedramp-20x.md (includes the public CR26 documentation index for live lookups)
ITAR, USML, DDTC, deemed exports, §120.54 encryption carve-out, TCP, AUKUS, ITAR-in-cloud → frameworks/itar.md
Tooling categories → tooling/grc-tooling-categories.md
Per-family OSCAL JSON files provide authoritative, machine-readable control data extracted from official NIST and FedRAMP catalogs. These files contain every control, enhancement, parameter, assessment objective, and guidance narrative — far more complete than the curated markdown summaries.
| Need | Source |
|---|---|
| Exact control statement text, parameters, assessment objectives | OSCAL JSON (oscal/nist-800-53-rev5/{family}.json) |
| Legacy FedRAMP Rev5 parameter values and Moderate baseline controls (label them "Legacy FedRAMP Rev5 value (in force until CR26 becomes mandatory Jan 1, 2027)"; CR26 removed most FedRAMP-assigned values per NTC-0013) | OSCAL JSON (oscal/fedramp-moderate-rev5/{family}.json) |
| Cross-framework mapping, audit guidance, narrative context | Markdown files (frameworks/, mappings/, audits/) |
Each family JSON file (e.g., ac.json) contains the full OSCAL group object:
.controls[] — All controls with .controls[] nested for enhancements.controls[].params[] — Organization-defined parameters (ODPs) with labels, guidelines, constraints (FedRAMP adds constraint values like "at least every 3 years"), and select/choice options.controls[].parts[] — Four part types by .name:"statement" — The control requirement text (with nested .parts[] for sub-items a, b, c, etc.)"guidance" — Implementation guidance narrative"assessment-objective" — Granular testable objectives (nested tree, e.g., AC-01a.[01], AC-01a.[02]). Each leaf has .prose describing exactly what must be true and .links[].rel == "assessment-for" pointing back to the statement part it tests."assessment-method" — Three methods per control, identified by .props[] | select(.name == "method") | .value:.parts[] | select(.name == "assessment-objects") | .prose lists documents/artifacts to review (policies, plans, SSP sections, config docs, audit logs).parts[].prose lists roles to interview (administrators, ISSOs, security personnel).parts[].prose lists processes and mechanisms to test.controls[].links[] — Related control references.controls[].props[] — Properties including baseline labels and FedRAMP-specific properties like implementation-level and contributes-to-assuranceOSCAL uses lowercase IDs with dots for enhancements: AC-2 → ac-2, AC-2(1) → ac-2.1.
audits/narrative-quality-criteria.md, audits/document-section-requirements.md)narrative-quality-criteria.mdaudits/narrative-quality-criteria.md| Abbrev | Meaning |
|---|---|
| AO | Authorizing Official |
| ATO | Authorization to Operate |
| BIA | Business Impact Analysis |
| CAP | Corrective Action Plan |
| CIS | Center for Internet Security |
| CISO | Chief Information Security Officer |
| CMP | Configuration Management Plan |
| CONOPS | Concept of Operations |
| CR26 | FedRAMP Consolidated Rules for 2026 |
| CRM | Customer Responsibility Matrix |
| CSO | Cloud Service Offering |
| CSP | Cloud Service Provider |
| DATO | Denial of Authorization to Operate |
| DR | Deviation Request |
| FedRAMP | Federal Risk and Authorization Management Program |
| FIPS | Federal Information Processing Standards (FIPS 140-3 is the active CMVP standard; all FIPS 140-2 certificates moved to the CMVP Historical List Sept 22, 2026, no grandfathering) |
| FISMA | Federal Information Security Modernization Act |
| IA | Information Assurance |
| IRP | Incident Response Plan |
| ISCM | Information Security Continuous Monitoring |
| ISSO | Information System Security Officer |
| ISSM | Information System Security Manager |
| JAB | Joint Authorization Board (dissolved May 2024; replaced by FedRAMP Board per OMB M-24-15; 53 legacy-JAB certifications remain listed) |
| KSI | Key Security Indicator (FedRAMP 20x) |
| MFA | Multi-Factor Authentication |
| OCR | Ongoing Certification Report (CR26; every 3 months per CCM-OCR-AVL, followed by a Quarterly Review 3–10 business days later; "OAR" is not a CR26 term) |
| OSCAL | Open Security Controls Assessment Language |
| PAIN | Potential Agency Impact N-rating, N0–N5 (CR26 VER standard; N0 "exploitation extremely unlikely to have any adverse effects" added Oct 5, 2026) |
| PIA | Privacy Impact Assessment |
| P-ATO | Provisional Authorization to Operate |
| POA&M | Plan of Action and Milestones (legacy Rev5 / agency construct; CR26 CSP-side equivalent is the Accepted Vulnerability list in each OCR) |
| RMF | Risk Management Framework |
| SAP | Security Assessment Plan |
| SAR | Security Assessment Report |
| SCRM | Supply Chain Risk Management |
| SDR | Security Decision Record (CR26; replaces the SSP on the 20x path) |
| SLA | Service Level Agreement |
| SSP | System Security Plan |
| VDR | Vulnerability Detection and Response (CR26 standard) |
| VER | Vulnerability Evaluation and Reporting (CR26 standard) |
| 3PAO | Third Party Assessment Organization (term retired in CR26 in favor of "FedRAMP Recognized independent assessor" — REC ruleset in force July 4, 2026: A2LA accreditation, full reassessment every 2 years, at least 2 Class B/C/D assessments every 2 years) |
© mlunato47, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 97 other files in grc/skills/grc-knowledge of mlunato47/claude-grc-plugin.
Open the folder on GitHubat commit f3d1318
Grc Knowledge next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Grc Knowledge this skillmlunato47/claude-grc-plugin | 183 | — | ~6.1k | Automated safety check: Pass | MIT | |
| Audit Reportharness/harness-skills | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Security Compliancesangrokjung/claude-forge | 850 | 2 repos | ~7.2k | Automated safety check: Pass | MIT | |
| Ciso Advisoralirezarezvani/claude-skills | 28k | 1 repos | ~1.8k | Automated safety check: Pass | MIT | |
| ComplianceRightNow-AI/openfang | 18k | — | ~921 | Automated safety check: Pass | Apache-2.0 | |
| Eks Securityaws-samples/appmod-blueprints | 113 | — | ~4.7k | Automated safety check: Pass | MIT-0 |
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
sangrokjung/claude-forge
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…
alirezarezvani/claude-skills
Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.
RightNow-AI/openfang
Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks
aws-samples/appmod-blueprints
A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…
AgentSecOps/SecOpsAgentKit
Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).
Categories
Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…. Grc Knowledge is an agent skill from mlunato47/claude-grc-plugin.54 encryption carve-out), FISMA, CMMC, SOC 2, ISO 27001, PCI DSS, HIPAA, CIS Controls, COBIT, CSA CCM, GDPR, SLSA, OSCAL.
Grc Knowledge fits situations like: tasks that involve SOC 2 and security compliance; tasks that involve Healthcare and finance regulation.
Run `npx skills add mlunato47/claude-grc-plugin --skill grc-knowledge -a claude-code`. Or copy the skill folder (grc/skills/grc-knowledge in mlunato47/claude-grc-plugin) into .claude/skills/grc-knowledge in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mlunato47/claude-grc-plugin --skill grc-knowledge -a codex`. Or copy the skill folder (grc/skills/grc-knowledge in mlunato47/claude-grc-plugin) into .agents/skills/grc-knowledge in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mlunato47/claude-grc-plugin --skill grc-knowledge -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/grc-knowledge, .gemini/skills/grc-knowledge, .github/skills/grc-knowledge and .opencode/skills/grc-knowledge in your project.
SKILL.md names no scripts, command-line tools or credentials: Grc Knowledge is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Grc Knowledge is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.1k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Grc Knowledge: Audit Report (harness/harness-skills, 115 stars), Security Compliance (sangrokjung/claude-forge, 850 stars), Ciso Advisor (alirezarezvani/claude-skills, 28k stars) and Compliance (RightNow-AI/openfang, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mlunato47 (a GitHub user) maintains it in mlunato47/claude-grc-plugin, which has 183 GitHub stars. The repository was last updated on October 6, 2026.
Source: mlunato47/claude-grc-plugin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.