Implementing Compliance
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy…
$ npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install SCStelz/security-investigator ca-policy-investigation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/ca-policy-investigation .claude/skills/ca-policy-investigation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ca-policy-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/ca-policy-investigation into .claude/skills/ca-policy-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ca-policy-investigation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/SCStelz/security-investigator/tree/main/.github/skills/ca-policy-investigationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install SCStelz/security-investigator ca-policy-investigation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/ca-policy-investigation .agents/skills/ca-policy-investigation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ca-policy-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/ca-policy-investigation into .agents/skills/ca-policy-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ca-policy-investigation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install SCStelz/security-investigator ca-policy-investigation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/ca-policy-investigation .cursor/skills/ca-policy-investigation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ca-policy-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/ca-policy-investigation into .cursor/skills/ca-policy-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ca-policy-investigation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/SCStelz/security-investigator.git --path .github/skills/ca-policy-investigation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install SCStelz/security-investigator ca-policy-investigation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/ca-policy-investigation .gemini/skills/ca-policy-investigation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ca-policy-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/ca-policy-investigation into .gemini/skills/ca-policy-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ca-policy-investigation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install SCStelz/security-investigator ca-policy-investigationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/ca-policy-investigation .github/skills/ca-policy-investigation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ca-policy-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/ca-policy-investigation into .github/skills/ca-policy-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ca-policy-investigation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install SCStelz/security-investigator ca-policy-investigation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/ca-policy-investigation .opencode/skills/ca-policy-investigation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ca-policy-investigation" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/ca-policy-investigation into .opencode/skills/ca-policy-investigation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ca-policy-investigation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ca-policy-investigationA skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy…
Ca Policy Investigation is an agent skill from SCStelz/security-investigator. Use this skill when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy bypass/manipulation. Triggers on keywords like "Conditional Access", "CA policy", "device compliance", "policy bypass", "53000", "50074", or when investigating why a user was blocked then suddenly unblocked. This skill provides forensic analysis of CA policy modifications correlated with sign-in failures.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering Regulatory compliance and Digital forensics. The repository describes itself as: Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 51e1385. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are kql and json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ca Policy Investigation loads about 3.8k tokens when it runs. Until then it costs about 126 tokens; SKILL.md has 1,407 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from SCStelz/security-investigator at commit 51e1385, republished under its MIT licence (© SCStelz). 1,407 words, ~3,752 tokens.
.claude/skills/ca-policy-investigation/SKILL.md (or your agent's skills folder).This skill investigates Conditional Access (CA) policy changes in correlation with sign-in failures to detect:
The key distinction is whether policy changes were authorized and necessary vs self-service bypass of security controls.
When investigating sign-in failures (error codes 53000, 50074) with CA policy correlation:
⚠️ MANDATORY STEPS - DO NOT SKIP:
Key Questions to Answer:
| Error Code | Description | Typical Cause |
|---|---|---|
| 53000 | Device not compliant | Device not enrolled in Intune or failing compliance checks |
| 50074 | Strong authentication required | MFA not satisfied |
| 50074 | User must enroll in MFA | MFA not configured for user |
| 530032 | Blocked by CA policy | Generic CA policy block |
| 65001 | User consent required | Application consent needed |
| 53003 | Access blocked by CA policy | Explicit block condition met |
| 70044 | Session expired | User needs to re-authenticate |
| Priority | Error Codes | Investigation Focus |
|---|---|---|
| HIGH | 53000, 530032, 53003 | Device compliance, CA policy blocks - check for policy manipulation |
| MEDIUM | 50074 | MFA requirements - check if MFA was bypassed |
| LOW | 65001, 70044 | Consent/session issues - usually not security-related |
| State | What It Means | Security Impact |
|---|---|---|
| enabled | Policy actively enforcing | Blocks non-compliant access (intended behavior) |
| disabled | Policy not enforcing | Security control bypassed - all access allowed |
| enabledForReportingButNotEnforced | Report-only mode | Logs violations but doesn't block - defeats purpose |
| Transition | Risk Level | Interpretation |
|---|---|---|
enabled → disabled | HIGH | Complete security bypass |
enabled → enabledForReportingButNotEnforced | MEDIUM-HIGH | Partial bypass (monitoring only) |
disabled → enabled | LOW | Security restored (good) |
enabledForReportingButNotEnforced → enabled | LOW | Security strengthened (good) |
Query sign-in failures with CA context:
// Get failures with CA context
union isfuzzy=true SigninLogs, AADNonInteractiveUserSignInLogs
| where TimeGenerated between (datetime(<START>) .. datetime(<END>))
| where UserPrincipalName =~ '<UPN>'
| where ResultType != '0'
| where AppDisplayName has '<APPLICATION>' // e.g., "Visual Studio Code"
| project TimeGenerated, IPAddress, Location, ResultType, ResultDescription,
ConditionalAccessStatus, UserAgent
| order by TimeGenerated ascWhat to Look For:
ResultType values: 53000, 50074, 530032, 53003ConditionalAccessStatus: "failure", "notApplied"CRITICAL: Query ±2 days from the first failure time
let failure_time = datetime(<FIRST_FAILURE_TIME>);
let start = failure_time - 2d;
let end = failure_time + 2d;
AuditLogs
| where TimeGenerated between (start .. end)
| where OperationName has_any ("Conditional Access", "policy")
| where Identity =~ '<UPN>' or tostring(InitiatedBy) has '<UPN>'
| extend InitiatorUPN = tostring(parse_json(InitiatedBy).user.userPrincipalName)
| extend InitiatorIPAddress = tostring(parse_json(InitiatedBy).user.ipAddress)
| extend TargetName = tostring(parse_json(TargetResources)[0].displayName)
| project TimeGenerated, OperationName, Result, InitiatorUPN, InitiatorIPAddress,
TargetName, CorrelationId
| order by TimeGenerated asc // CRITICAL: Chronological orderCritical Analysis Points:
For each CorrelationId from Step 2, get detailed changes:
// Get detailed property changes for a specific policy modification
AuditLogs
| where CorrelationId == "<CORRELATION_ID>"
| extend ModifiedProperties = parse_json(TargetResources)[0].modifiedProperties
| mv-expand ModifiedProperties
| extend PropertyName = tostring(ModifiedProperties.displayName)
| extend OldValue = tostring(ModifiedProperties.oldValue)
| extend NewValue = tostring(ModifiedProperties.newValue)
| project TimeGenerated, PropertyName, OldValue, NewValueKey Properties to Extract:
"state" property in the JSONOldValue and NewValue for state transitionsenabled → disabled → enabledForReportingButNotEnforcedManual JSON Parsing:
The OldValue and NewValue fields contain JSON. Look for the "state" field:
{
"state": "enabled",
"conditions": { ... },
"grantControls": { ... }
}Build the Timeline:
"state" from each OldValue and NewValueenabled → disabled → enabledForReportingButNotEnforcedCompare timelines and assess intent:
| Pattern | Interpretation | Risk Level |
|---|---|---|
| Failures → Policy Disabled | User bypassed security control to unblock self | HIGH - Privilege abuse |
| Failures → Policy Changed to Report-Only | User weakened security control | MEDIUM-HIGH - Partial bypass |
| Policy Disabled → Failures Continue | Cached tokens (5-15 min propagation delay) | INFO - Expected behavior |
| Policy Changed → No More Failures | Policy change resolved issue | Context-dependent - May be legitimate troubleshooting |
| Different user made change | Admin assisted with access issue | LOW - Likely legitimate (verify authorization) |
Risk Escalation Criteria:
| Criteria | Risk Level |
|---|---|
| Same user blocked AND made policy change | HIGH |
| Policy disabled within 30 minutes of first failure | HIGH |
| Multiple policies modified | HIGH |
| Change made outside business hours | MEDIUM-HIGH |
| No change request ticket/approval | MEDIUM-HIGH |
| Admin made change for blocked user (with ticket) | LOW |
Scenario: User blocked by device compliance policy, then modifies policy
| Time | Event | Details |
|---|---|---|
| 19:05 | Sign-in failure | Error 53000: device not compliant |
| 19:06 | Sign-in failure | Error 53000: device not compliant |
| 19:07 | Sign-in failure | Error 53000: device not compliant |
| 19:09 | Policy change | enabled → disabled |
| 19:09 | Policy change | disabled → enabledForReportingButNotEnforced |
| 19:12 | Sign-in failure | Error 53000 (cached token) |
| 19:14 | Sign-in success | Access granted |
✅ Policy was correctly blocking non-compliant device
🚨 User disabled security control to bypass block
⚠️ User partially reversed by enabling report-only
❌ Report-only mode is NOT a valid security posture
| Field | Value |
|---|---|
| Risk Level | MEDIUM-HIGH |
| Finding | Self-service security bypass using privileged role |
| Root Cause | User's device is non-compliant (not enrolled/failing compliance) |
| Policy Impact | Device compliance checks now ineffective for all users |
Immediate Actions:
enabled stateUser-Specific:
Process Improvements:
| Mistake | Why It's Wrong |
|---|---|
| Query only ONE policy change event | You'll miss the sequence of changes |
| Read policy changes in reverse chronological order | Confuses cause/effect relationship |
| Assume policy was already disabled | Must check starting state from OldValue |
| Skip verifying "does this make logical sense?" | Disabled policies can't block users |
| Ignore the initiator identity | Same user = suspicious, different admin = verify authorization |
| Focus only on final state | The transition sequence reveals intent |
| Best Practice | Why It Matters |
|---|---|
| Query ALL policy changes in the timeframe | Complete picture of modifications |
| Order chronologically (oldest first) | See cause/effect sequence |
| Parse the full JSON for state transitions | Extract exact policy states |
| Cross-check: blocked user → policy must be enabled | Logical consistency verification |
| Ask: "Why would user disable this policy?" | Usually to bypass a legitimate block |
| Check if initiator had authorization | Ticket, approval, documented reason |
| Action | Priority |
|---|---|
Restore policy to enabled state if unauthorized | IMMEDIATE |
| Investigate root cause (why was user blocked?) | HIGH |
| Fix underlying issue (device compliance, MFA enrollment) | HIGH |
| Review who has permission to modify CA policies | MEDIUM |
| Implement approval workflows for policy changes | MEDIUM |
| Create alerts for future CA policy modifications | MEDIUM |
| Improvement | Benefit |
|---|---|
| Use PIM for Security Administrator role | Requires approval for elevated access |
| Implement CA policy change alerts | Real-time notification of modifications |
| Require multi-admin approval for state changes | Prevents single-person bypass |
| Document approved procedures | Clear guidance for legitimate troubleshooting |
| Regular access reviews | Ensure only necessary users have CA admin rights |
This skill requires:
mcp_sentinel-data_query_lake: Execute KQL queriesmcp_sentinel-data_search_tables: Discover table schemasTo view CA policy changes in AuditLogs, ensure:
CA Policy Investigation often follows a user-investigation:
Key Integration Points:
© SCStelz, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/ca-policy-investigation of SCStelz/security-investigator.
Open the folder on GitHubat commit 51e1385
Ca Policy Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ca Policy Investigation this skillSCStelz/security-investigator | 249 | — | ~3.8k | Automated safety check: Pass | MIT | |
| Implementing Complianceancoleman/ai-design-components | 525 | — | ~4k | Automated safety check: Pass | MIT | |
| PCI DSS Compliancewshobson/agents | 40k | 11 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Oss Reviewanthropics/claude-for-legal | 9.6k | 3 repos | ~5k | Automated safety check: Pass | Apache-2.0 | |
| Security Automationsickn33/agentic-awesome-skills | 47k | 2 repos | ~1k | Automated safety check: Pass | MIT | |
| Dependency Auditoralirezarezvani/claude-skills | 28k | — | ~1.1k | Automated safety check: Pass | MIT |
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
wshobson/agents
Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.
anthropics/claude-for-legal
Open source license compliance check for a dependency list, a single library, or outbound code.
sickn33/agentic-awesome-skills
Automate security workflows and remediation. An agent skill from sickn33/agentic-awesome-skills.
alirezarezvani/claude-skills
Audit and manage dependencies across multi-language projects.
cwinvestments/memstack
A skill your agent uses when the user says 'licensing', 'license audit', 'can I use this commercially', 'OSS license check', 'license compatibility', 'GPL', 'MIT', 'AGPL', 'copyleft'.
SCStelz/security-investigator
Weekly review of an investigation tenant-context memory file against the most recent SOC scan reports (e.g.
SCStelz/security-investigator
A skill your agent uses when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format.
SCStelz/security-investigator
Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield…
SCStelz/security-investigator
Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents.
SCStelz/security-investigator
Audit Entra ID app registration and service principal security posture.
SCStelz/security-investigator
A skill your agent uses when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins.
Categories
A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy…. Ca Policy Investigation is an agent skill from SCStelz/security-investigator. Use this skill when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy bypass/manipulation.
Ca Policy Investigation fits situations like: asked to investigate Conditional Access policy changes; sign-in failures related to CA policies (error codes 53000; suspected policy bypass/manipulation; keywords like Conditional Access.
Run `npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a claude-code`. Or copy the skill folder (.github/skills/ca-policy-investigation in SCStelz/security-investigator) into .claude/skills/ca-policy-investigation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a codex`. Or copy the skill folder (.github/skills/ca-policy-investigation in SCStelz/security-investigator) into .agents/skills/ca-policy-investigation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SCStelz/security-investigator --skill ca-policy-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ca-policy-investigation, .gemini/skills/ca-policy-investigation, .github/skills/ca-policy-investigation and .opencode/skills/ca-policy-investigation in your project.
SKILL.md names no scripts, command-line tools or credentials: Ca Policy Investigation is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ca Policy Investigation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ca Policy Investigation: Implementing Compliance (ancoleman/ai-design-components, 525 stars), PCI DSS Compliance (wshobson/agents, 40k stars), Oss Review (anthropics/claude-for-legal, 9.6k stars) and Security Automation (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
SCStelz (a GitHub user) maintains it in SCStelz/security-investigator, which has 249 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 8, 2026.
Source: SCStelz/security-investigator on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.