Infrastructure Compliance Auditor
borghei/Claude-Skills
Cross-framework infrastructure security audit across cloud, network, and CI/CD.
When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer…
$ npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install shawnpang/startup-founder-skills soc2-prep --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/soc2-prep .claude/skills/soc2-prep && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "soc2-prep" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/soc2-prep into .claude/skills/soc2-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "soc2-prep", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/shawnpang/startup-founder-skills/tree/main/skills/soc2-prepType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install shawnpang/startup-founder-skills soc2-prep --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/soc2-prep .agents/skills/soc2-prep && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "soc2-prep" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/soc2-prep into .agents/skills/soc2-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "soc2-prep", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install shawnpang/startup-founder-skills soc2-prep --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/soc2-prep .cursor/skills/soc2-prep && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "soc2-prep" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/soc2-prep into .cursor/skills/soc2-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "soc2-prep", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/shawnpang/startup-founder-skills.git --path skills/soc2-prep--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install shawnpang/startup-founder-skills soc2-prep --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/soc2-prep .gemini/skills/soc2-prep && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "soc2-prep" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/soc2-prep into .gemini/skills/soc2-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "soc2-prep", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install shawnpang/startup-founder-skills soc2-prepInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/soc2-prep .github/skills/soc2-prep && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "soc2-prep" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/soc2-prep into .github/skills/soc2-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "soc2-prep", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install shawnpang/startup-founder-skills soc2-prep --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/shawnpang/startup-founder-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/soc2-prep .opencode/skills/soc2-prep && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "soc2-prep" agent skill from https://github.com/shawnpang/startup-founder-skills/tree/main/skills/soc2-prep into .opencode/skills/soc2-prep/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "soc2-prep", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
soc2-prepWhen the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer…
Soc2 Prep is an agent skill from shawnpang/startup-founder-skills. When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer wants SOC 2", "CISO advice".
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering SOC 2 and security compliance and Security review. The repository describes itself as: AI agent skills for tech startup founders — fundraising, sales, product, recruiting, engineering, legal, ops, and growth. Works with Claude Code, Cursor, Codex, and any Agent… The licence is MIT.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4ad31b4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Soc2 Prep loads about 2.5k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 1,204 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from shawnpang/startup-founder-skills at commit 4ad31b4, republished under its MIT licence (© shawnpang). 1,204 words, ~2,513 tokens.
.claude/skills/soc2-prep/SKILL.md (or your agent's skills folder).Activate when a founder is preparing for SOC 2 certification, has been asked by a customer or prospect for a SOC 2 report, needs to quantify security risk for board or budget discussions, wants to build a compliance roadmap sequenced for business value, or needs to assess overall security posture. Also activate when the user mentions "SOC 2," "compliance audit," "trust service criteria," "security budget," "we need SOC 2 to close this deal," or "CISO."
# Security & Compliance Assessment: [Company Name]
## Risk Quantification — top risks with ALE, mitigation cost, expected value
## Gap Analysis Matrix — TSC criterion, requirement, current state, gap, priority, remediation
## Compliance Roadmap — sequenced timeline: SOC 2 Type I > Type II > ISO 27001/HIPAA
## Policy Documents — generated as needed, each with purpose/scope/roles/statements/procedures
## Implementation Timeline — phased checklist with milestones
## Evidence Collection Checklist — per-control artifacts, storage location, refresh cadence
## Security Metrics Dashboard — table of key metrics with current values and targetsTranslate technical risks into business impact: revenue loss, regulatory fines, reputational damage. Use ALE to prioritize.
Formula: ALE = SLE x ARO (Single Loss Expectancy x Annual Rate of Occurrence)
Board language: "A $200K security program preventing a $2M breach at 40% annual probability has $800K expected value. The program pays for itself 4x over."
Frame security spend as risk transfer cost, not overhead.
| Category | Metric | Target |
|---|---|---|
| Risk | ALE coverage (mitigated / total) | > 80% |
| Detection | Mean Time to Detect (MTTD) | < 24 hours |
| Response | Mean Time to Respond (MTTR) | < 4 hours |
| Compliance | Controls passing audit | > 95% |
| Hygiene | Critical patches within SLA | > 99% |
| Access | Privileged accounts reviewed quarterly | 100% |
| Vendor | Tier 1 vendors assessed annually | 100% |
| Training | Phishing simulation click rate | < 5% |
Security (Common Criteria -- always in scope): CC1-CC2 (control environment, communication), CC3 (risk assessment), CC4-CC5 (monitoring, control activities), CC6 (logical/physical access, encryption), CC7-CC8 (system ops, vulnerability mgmt, incident response, change mgmt), CC9 (vendor management, business continuity).
Optional: Availability (A1), Processing Integrity (PI1), Confidentiality (C1), Privacy (P1-P8).
Information Security, Access Control (MFA, least privilege, access reviews), Change Management (code review, rollback), Incident Response (detection through post-mortem), Risk Assessment (annual, with register), Vendor Management, Data Classification, Business Continuity/DR (RTO/RPO, backup testing), Acceptable Use, HR Security (background checks, onboarding/offboarding).
| Tier | Data Access | Assessment Level |
|---|---|---|
| Tier 1 | PII/PHI access | Full assessment annually |
| Tier 2 | Business data | Questionnaire + review |
| Tier 3 | No sensitive data | Self-attestation |
Type I vs Type II: Type I examines control design at a point in time (3-6 months, good for closing the first enterprise deal). Type II examines control operation over 3-12 months (what sophisticated buyers want, plan 12 months total). Start Type I immediately; begin Type II observation once controls are in place.
Right-Sizing by Stage: Seed (5-15): foundational controls, automation-heavy, concise policies, one part-time owner. Series A (15-50): dedicated compliance owner or fractional CISO, formal access reviews. Series B+ (50+): full-time security team, internal audit, GRC platform.
Cost-Effective Tooling: Compliance automation (Vanta, Drata, Secureframe — significantly reduces manual effort), SSO (Google Workspace or Okta), MDM (Kandji or Jamf), monitoring (Datadog, PagerDuty), vulnerability scanning (Dependabot, Snyk, Trivy).
All findings tagged before reaching decision-makers: Verified (confirmed against evidence), Medium (reported but not independently verified), Assumed (inferred, needs validation).
privacy-policy — SOC 2 Privacy criteria (P1-P8) align directly with privacy policy commitments. Ensure consistency.security-review — Technical security controls from security-review map to SOC 2 Common Criteria (CC6, CC7, CC8). Use findings to inform gap analysis.User: "A prospect wants SOC 2 before signing a $200K contract. We have nothing."
Good output excerpt:
Business case: This $200K deal justifies a $30-50K compliance investment. At your stage, every enterprise deal blocked by missing SOC 2 has an opportunity cost.
Area Status Key Gaps Access Control Partial MFA not enforced on AWS root, no SSO, no formal reviews Change Management Partial GitHub PRs used but no documented policy Incident Response Missing No documented plan, no on-call rotation Risk Assessment Missing No formal risk assessment conducted Recommended approach: Type I in 3 months, then begin Type II observation. Immediate actions: (1) Sign up for compliance automation. (2) Enforce MFA everywhere. (3) Select an auditor with startup experience. Interim response to prospect: Share security questionnaire response, SOC 2 Type I commitment timeline, and a signed mutual NDA with security addendum.
User: "We already use Okta for SSO and do code reviews. Where are we relative to SOC 2?"
Good output excerpt:
Gap Analysis Summary: 55% ready
Compliant: CC6.1 Okta SSO with MFA, CC8.1 code reviews via PRs. Partial: CC6.2 no quarterly access reviews documented, CC7.2 IRP never tested, CC6.3 no formal offboarding checklist. Missing: CC3.1 no annual risk assessment, CC2.1 no security training, CC9.2 no vendor management, CC4.1 no control monitoring, all 10 required policies need drafting.
Disclaimer: This skill provides SOC 2 preparation guidance for planning purposes only. It does not constitute legal, audit, or professional compliance advice. SOC 2 reports can only be issued by a licensed CPA firm. Engage a qualified auditor to confirm readiness before scheduling an audit.
© shawnpang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/soc2-prep of shawnpang/startup-founder-skills.
Open the folder on GitHubat commit 4ad31b4
Soc2 Prep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Soc2 Prep this skillshawnpang/startup-founder-skills | 341 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Infrastructure Compliance Auditorborghei/Claude-Skills | 881 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Cursor Compliance Auditjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.3k | Automated safety check: Notes | MIT | |
| Isms Audit Expertdavila7/claude-code-templates | 32k | 1 repos | ~3.1k | Automated safety check: Pass | MIT | |
| Senior Secopsalirezarezvani/claude-skills | 28k | 1 repos | ~4k | Automated safety check: Pass | MIT | |
| Vendor Security Reviewmohitagw15856/pm-claude-skills | 1.4k | — | ~1.1k | Automated safety check: Pass | MIT |
borghei/Claude-Skills
Cross-framework infrastructure security audit across cloud, network, and CI/CD.
jeremylongshore/tons-of-skills-marketplace
Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.
davila7/claude-code-templates
Senior ISMS Audit Expert for internal and external information security management system auditing.
alirezarezvani/claude-skills
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.
mohitagw15856/pm-claude-skills
Run a third-party / vendor security review and assign a risk tier with required controls.
jeremylongshore/tons-of-skills-marketplace
Apply security best practices for Fondo including OAuth token management, financial data protection, SOC 2 compliance, and access control.
shawnpang/startup-founder-skills
When the user wants to apply to startup accelerators, incubators, or fellowship programs.
shawnpang/startup-founder-skills
When the user needs to design or evaluate system architecture — service boundaries, data models, API contracts, infrastructure topology, database selection, or dependency analysis.
shawnpang/startup-founder-skills
When the user needs to write a monthly or quarterly investor update, prepare a board deck, or communicate company progress to stakeholders.
shawnpang/startup-founder-skills
When the user needs to identify at-risk accounts, understand why customers are leaving, reduce churn rate, build health scores, design save plays, or create win-back campaigns.
shawnpang/startup-founder-skills
When the user needs to set up or improve CI/CD pipelines — GitHub Actions, GitLab CI, deployment automation, or says "set up CI", "automate deployment", "add tests to pipeline", "fix my build".
shawnpang/startup-founder-skills
When the user asks for a code review, shares code for feedback, or says "review this", "check my code", "what's wrong with this".
Categories
When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer…. Soc2 Prep is an agent skill from shawnpang/startup-founder-skills. When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer wants SOC 2", "CISO advice".
Soc2 Prep fits situations like: needs to prepare for SOC 2; build a compliance roadmap; assess security posture; quantify security risk.
Run `npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a claude-code`. Or copy the skill folder (skills/soc2-prep in shawnpang/startup-founder-skills) into .claude/skills/soc2-prep in your project. Claude Code loads it when a task matches its description.
Run `npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a codex`. Or copy the skill folder (skills/soc2-prep in shawnpang/startup-founder-skills) into .agents/skills/soc2-prep in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shawnpang/startup-founder-skills --skill soc2-prep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/soc2-prep, .gemini/skills/soc2-prep, .github/skills/soc2-prep and .opencode/skills/soc2-prep in your project.
SKILL.md names no scripts, command-line tools or credentials: Soc2 Prep is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Soc2 Prep is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Soc2 Prep: Infrastructure Compliance Auditor (borghei/Claude-Skills, 881 stars), Cursor Compliance Audit (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Isms Audit Expert (davila7/claude-code-templates, 32k stars) and Senior Secops (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
shawnpang (a GitHub user) maintains it in shawnpang/startup-founder-skills, which has 341 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on March 16, 2026.
Source: shawnpang/startup-founder-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.