Agent skill

Fedramp Compliance

by sickn33 in sickn33/agentic-awesome-skills

Implement FedRAMP requirements for federal cloud services. An agent skill from sickn33/agentic-awesome-skills.

MITAuto-check passed

Install Fedramp Compliance

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill fedramp-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills fedramp-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/fedramp-compliance .claude/skills/fedramp-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fedramp-compliance
GitHub stars
47k
Used in
2 other repos
Token cost
~4.1k tokens
SKILL.md length
273 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Implement FedRAMP requirements for federal cloud services. An agent skill from sickn33/agentic-awesome-skills.

  • Providing cloud services to US federal agencies
  • SKILL.md covers When to Use, Impact Levels, NIST 800-53 Control Families and System Security Plan (SSP)…, plus 6 more sections
  • Calls openssl and aws; reaches s3-fips.us-east-1.amazonaws.com

What it does

Fedramp Compliance is an agent skill from sickn33/agentic-awesome-skills. Implement FedRAMP requirements for federal cloud services. Configure NIST 800-53 controls and continuous monitoring. Use when providing cloud services to US federal agencies.

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Checklist and framework guidance; no privileged tooling required. Apply controls through your own change process.

The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Providing cloud services to US federal agencies

Example prompts

  • “/fedramp-compliance”

Requirements

  • Compatibility (from SKILL.md): Checklist and framework guidance; no privileged tooling required. Apply controls through your own change process.

What it can do on your machine

Read from SKILL.md and the folder at commit 1c7bdea. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • openssl
    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • s3-fips.us-east-1.amazonaws.com

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Checklist and framework guidance; no privileged tooling required. Apply controls through your own change process.

    From compatibility in the SKILL.md frontmatter.

Context cost

Fedramp Compliance loads about 4.1k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 273 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 1c7bdea, republished under its MIT licence (© sickn33). 273 words, ~4,108 tokens.

Download SKILL.mdSave it as .claude/skills/fedramp-compliance/SKILL.md (or your agent's skills folder).
name
fedramp-compliance
description
Implement FedRAMP requirements for federal cloud services. Configure NIST 800-53 controls and continuous monitoring. Use when providing cloud services to US federal agencies.
compatibility
Checklist and framework guidance; no privileged tooling required. Apply controls through your own change process.
category
security
risk
safe
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

FedRAMP Compliance

Implement FedRAMP (Federal Risk and Authorization Management Program) requirements for cloud service providers serving US federal agencies.

When to Use

  • Pursuing FedRAMP authorization for a cloud service offering
  • Implementing NIST 800-53 security controls for federal workloads
  • Establishing continuous monitoring (ConMon) processes
  • Managing Plan of Action and Milestones (POA&M) tracking
  • Preparing for a Third-Party Assessment Organization (3PAO) audit
  • Operating a FedRAMP-authorized system and maintaining authorization

Impact Levels

yaml
impact_levels:
  low:
    control_count: ~125
    use_case: "Publicly available federal information"
    examples:
      - Public-facing websites with no sensitive data
      - Open data portals
      - Marketing and informational systems
    data_types: "No PII, no CUI, publicly releasable only"
    authorization_path: "FedRAMP Tailored (Li-SaaS) or standard Low"

  moderate:
    control_count: ~325
    use_case: "Most federal systems, including CUI"
    examples:
      - Email and collaboration platforms
      - Case management systems
      - Financial management systems
      - HR and personnel systems
    data_types: "CUI, PII, law enforcement sensitive (LES)"
    authorization_path: "Agency or JAB P-ATO"
    note: "~80% of FedRAMP authorizations are at Moderate"

  high:
    control_count: ~425
    use_case: "High-impact federal systems"
    examples:
      - Law enforcement and criminal justice systems
      - Emergency services and public safety
      - Financial systems with significant impact
      - Healthcare systems with PHI
    data_types: "Classified-adjacent, life-safety, critical infrastructure"
    authorization_path: "JAB P-ATO required"

NIST 800-53 Control Families

yaml
control_families:
  AC:
    name: "Access Control"
    key_controls:
      AC-2: "Account Management - manage system accounts lifecycle"
      AC-3: "Access Enforcement - enforce approved authorizations"
      AC-6: "Least Privilege - employ principle of least privilege"
      AC-17: "Remote Access - establish usage restrictions for remote access"
    implementation_notes: "Map to IAM policies, RBAC, MFA enforcement"

  AU:
    name: "Audit and Accountability"
    key_controls:
      AU-2: "Audit Events - define auditable events"
      AU-3: "Content of Audit Records - ensure records contain required info"
      AU-6: "Audit Review, Analysis, and Reporting"
      AU-12: "Audit Generation - generate audit records"
    implementation_notes: "Map to CloudTrail, CloudWatch Logs, SIEM"

  AT:
    name: "Awareness and Training"
    key_controls:
      AT-2: "Security Awareness Training - provide training to users"
      AT-3: "Role-Based Security Training - for personnel with security roles"
    implementation_notes: "Annual security training, role-specific training"

  CM:
    name: "Configuration Management"
    key_controls:
      CM-2: "Baseline Configuration - develop and maintain baseline"
      CM-6: "Configuration Settings - establish mandatory settings"
      CM-7: "Least Functionality - restrict to essential capabilities"
      CM-8: "Information System Component Inventory"
    implementation_notes: "Map to AWS Config, SSM, hardened AMIs"

  CP:
    name: "Contingency Planning"
    key_controls:
      CP-2: "Contingency Plan - develop and maintain plan"
      CP-4: "Contingency Plan Testing - test plan annually"
      CP-9: "Information System Backup"
      CP-10: "Information System Recovery and Reconstitution"
    implementation_notes: "Map to DR plan, backup strategy, failover testing"

  IA:
    name: "Identification and Authentication"
    key_controls:
      IA-2: "Identification and Authentication (Org Users)"
      IA-5: "Authenticator Management"
      IA-8: "Identification and Authentication (Non-Org Users)"
    implementation_notes: "Map to SSO, MFA, certificate-based auth, PIV/CAC"

  IR:
    name: "Incident Response"
    key_controls:
      IR-2: "Incident Response Training"
      IR-4: "Incident Handling - implement incident handling capability"
      IR-6: "Incident Reporting - report incidents to US-CERT"
      IR-8: "Incident Response Plan"
    implementation_notes: "US-CERT reporting within 1 hour for federal incidents"

  MA:
    name: "Maintenance"
    key_controls:
      MA-2: "Controlled Maintenance"
      MA-4: "Nonlocal Maintenance - authorize nonlocal maintenance"
    implementation_notes: "Patching procedures, remote maintenance controls"

  MP:
    name: "Media Protection"
    key_controls:
      MP-2: "Media Access - restrict access to media"
      MP-6: "Media Sanitization - sanitize media prior to disposal"
    implementation_notes: "Encryption at rest, secure disposal procedures"

  PE:
    name: "Physical and Environmental Protection"
    key_controls:
      PE-2: "Physical Access Authorizations"
      PE-3: "Physical Access Control"
      PE-6: "Monitoring Physical Access"
    implementation_notes: "Inherit from CSP for IaaS/PaaS, document inheritance"

  PL:
    name: "Planning"
    key_controls:
      PL-2: "System Security Plan (SSP)"
    implementation_notes: "SSP is the core FedRAMP deliverable"

  PS:
    name: "Personnel Security"
    key_controls:
      PS-3: "Personnel Screening"
      PS-4: "Personnel Termination"
      PS-5: "Personnel Transfer"
    implementation_notes: "Background checks, access revocation on termination"

  RA:
    name: "Risk Assessment"
    key_controls:
      RA-3: "Risk Assessment - conduct risk assessment"
      RA-5: "Vulnerability Scanning"
    implementation_notes: "Annual risk assessment, monthly vulnerability scans"

  CA:
    name: "Security Assessment and Authorization"
    key_controls:
      CA-2: "Security Assessments"
      CA-6: "Security Authorization"
      CA-7: "Continuous Monitoring"
    implementation_notes: "Annual assessment by 3PAO, ConMon program"

  SC:
    name: "System and Communications Protection"
    key_controls:
      SC-7: "Boundary Protection"
      SC-8: "Transmission Confidentiality and Integrity"
      SC-12: "Cryptographic Key Establishment and Management"
      SC-13: "Cryptographic Protection - FIPS 140-2 validated"
      SC-28: "Protection of Information at Rest"
    implementation_notes: "FIPS 140-2 validated modules required"

  SI:
    name: "System and Information Integrity"
    key_controls:
      SI-2: "Flaw Remediation"
      SI-3: "Malicious Code Protection"
      SI-4: "Information System Monitoring"
      SI-5: "Security Alerts, Advisories, and Directives"
    implementation_notes: "Patching SLAs, antimalware, IDS/IPS, SIEM"

  SA:
    name: "System and Services Acquisition"
    key_controls:
      SA-4: "Acquisition Process - security requirements in contracts"
      SA-9: "External Information System Services"
      SA-11: "Developer Security Testing"
    implementation_notes: "Supply chain risk management, SBOM"

  PM:
    name: "Program Management"
    key_controls:
      PM-1: "Information Security Program Plan"
      PM-9: "Risk Management Strategy"
    implementation_notes: "Organization-wide security program"

System Security Plan (SSP) Outline

yaml
ssp_sections:
  section_1: "Information System Name and Title"
  section_2: "Information System Categorization (FIPS 199)"
  section_3: "Information System Owner"
  section_4: "Authorizing Official"
  section_5: "Other Designated Contacts"
  section_6: "Assignment of Security Responsibility"
  section_7: "Information System Operational Status"
  section_8: "Information System Type (cloud service model)"
  section_9: "General System Description"
  section_10: "System Environment and Special Considerations"
  section_11: "System Interconnections"
  section_12: "Laws, Regulations, Policies Applicable"
  section_13: "Minimum Security Controls"

  key_attachments:
    - "Control Implementation Summary (CIS) workbook"
    - "Network architecture diagrams"
    - "Data flow diagrams"
    - "Interconnection security agreements (ISAs)"
    - "Incident response plan"
    - "Contingency plan"
    - "Configuration management plan"

POA&M (Plan of Action and Milestones) Tracking

yaml
# poam_template.yaml
poam_entry:
  - id: "POAM-2025-001"
    weakness: "AC-2(3) - Automated account disable after 90 days inactivity not implemented"
    control: "AC-2"
    risk_level: "moderate"
    finding_source: "3PAO Annual Assessment - 2025"
    date_identified: "2025-03-15"
    scheduled_completion: "2025-06-15"
    milestone_1:
      description: "Configure IdP inactivity policy"
      target_date: "2025-04-15"
      status: "complete"
    milestone_2:
      description: "Test automated disable in staging"
      target_date: "2025-05-01"
      status: "in_progress"
    milestone_3:
      description: "Deploy to production and validate"
      target_date: "2025-06-15"
      status: "not_started"
    responsible_party: "IAM Team"
    status: "open"
    vendor_dependency: false

  - id: "POAM-2025-002"
    weakness: "RA-5 - Vulnerability scan coverage does not include container images"
    control: "RA-5"
    risk_level: "high"
    finding_source: "3PAO Annual Assessment - 2025"
    date_identified: "2025-03-15"
    scheduled_completion: "2025-05-15"
    milestone_1:
      description: "Evaluate and select container scanning tool"
      target_date: "2025-04-01"
      status: "complete"
    milestone_2:
      description: "Integrate scanning into CI/CD pipeline"
      target_date: "2025-04-30"
      status: "in_progress"
    milestone_3:
      description: "Demonstrate full coverage to 3PAO"
      target_date: "2025-05-15"
      status: "not_started"
    responsible_party: "Security Engineering"
    status: "open"
    vendor_dependency: false

poam_aging_thresholds:
  high: "Must be resolved within 30 days"
  moderate: "Must be resolved within 90 days"
  low: "Must be resolved within 180 days"
  overdue_escalation: "Reported to authorizing official monthly"

Continuous Monitoring (ConMon) Procedures

yaml
continuous_monitoring:
  monthly:
    vulnerability_scanning:
      scope: "All operating systems, databases, web applications, and containers"
      tool: "Tenable.io, Qualys, or equivalent"
      deliverable: "Monthly scan report with remediation status"
      sla:
        critical_cvss_9_plus: "Remediate within 30 days"
        high_cvss_7_to_9: "Remediate within 30 days"
        moderate_cvss_4_to_7: "Remediate within 90 days"
        low_cvss_below_4: "Remediate within 180 days"

    poam_updates:
      action: "Update all open POA&M items with current status"
      deliverable: "Updated POA&M spreadsheet submitted to agency"
      content:
        - "Milestone completion updates"
        - "New POA&M items from scans"
        - "Closed POA&M items with evidence"

    inventory_updates:
      action: "Review and update system component inventory"
      deliverable: "Updated hardware and software inventory"

  quarterly:
    - "Review and update SSP with any system changes"
    - "Submit ConMon deliverables package to agency"
    - "Review access control lists and user accounts"
    - "Update network diagrams if changes occurred"

  annual:
    security_assessment:
      performed_by: "3PAO"
      scope: "Subset of controls (~1/3 each year, full coverage in 3 years)"
      deliverable: "Security Assessment Report (SAR)"

    penetration_testing:
      performed_by: "3PAO or qualified third party"
      scope: "External and internal network, web applications"
      deliverable: "Penetration test report with findings"

    contingency_plan_test:
      scope: "Full DR/BCP test including failover"
      deliverable: "Contingency plan test report"

    incident_response_test:
      scope: "Tabletop exercise or functional exercise"
      deliverable: "IR test report with lessons learned"

FedRAMP FIPS 140-2 Cryptography Requirements

bash
# Verify FIPS mode is enabled on Linux systems
cat /proc/sys/crypto/fips_enabled
# Output should be: 1

# Check OpenSSL FIPS module
openssl version
openssl list -providers  # Should show FIPS provider

# AWS: Use FIPS endpoints
# Example: Use FIPS endpoint for S3
aws s3 ls --endpoint-url https://s3-fips.us-east-1.amazonaws.com

# Configure AWS CLI for FIPS
# ~/.aws/config
# [default]
# use_fips_endpoint = true

# Verify TLS configuration meets FedRAMP requirements
openssl s_client -connect your-service.example.com:443 -tls1_2 < /dev/null 2>/dev/null | \
  grep -E "Protocol|Cipher"
# Must be TLS 1.2 or higher with FIPS-approved cipher suites

FedRAMP Authorization Checklist

yaml
authorization_checklist:
  pre_authorization:
    - [ ] Determine impact level (Low, Moderate, High)
    - [ ] Choose authorization path (Agency ATO or JAB P-ATO)
    - [ ] Engage FedRAMP PMO for readiness assessment
    - [ ] Select 3PAO from FedRAMP marketplace
    - [ ] Complete SSP with all control implementations documented
    - [ ] Develop required policies and procedures
    - [ ] Implement all applicable NIST 800-53 controls
    - [ ] Ensure FIPS 140-2 validated cryptographic modules in use

  assessment:
    - [ ] 3PAO conducts readiness assessment (optional but recommended)
    - [ ] 3PAO conducts full security assessment
    - [ ] 3PAO delivers Security Assessment Report (SAR)
    - [ ] Develop POA&M for all findings
    - [ ] Remediate critical and high findings before authorization

  authorization_package:
    - [ ] System Security Plan (SSP)
    - [ ] Security Assessment Report (SAR)
    - [ ] Plan of Action and Milestones (POA&M)
    - [ ] Continuous Monitoring Plan
    - [ ] Incident Response Plan
    - [ ] Contingency Plan
    - [ ] Configuration Management Plan
    - [ ] Control Implementation Summary (CIS)
    - [ ] Interconnection Security Agreements

  post_authorization:
    - [ ] Establish ConMon program with monthly deliverables
    - [ ] Monthly vulnerability scanning and POA&M updates
    - [ ] Annual 3PAO assessment of control subset
    - [ ] Annual penetration testing
    - [ ] Report significant changes to authorizing official
    - [ ] Report security incidents to US-CERT within 1 hour
    - [ ] Maintain authorization by meeting ConMon requirements

Best Practices

  • Start with a FedRAMP Readiness Assessment to identify gaps before the formal 3PAO assessment
  • Use the FedRAMP SSP template exactly as provided to avoid review delays
  • Inherit controls from your IaaS provider (AWS GovCloud, Azure Government) and document the inheritance clearly
  • Implement FIPS 140-2 validated cryptographic modules for all encryption (TLS, at-rest, key management)
  • Automate continuous monitoring deliverables to reduce manual effort and human error
  • Maintain POA&M items within aging thresholds; overdue items risk losing authorization
  • Report significant system changes to the authorizing official before implementation
  • Treat the SSP as a living document and update it with every change to the system boundary
  • Use US-CERT reporting procedures and maintain the 1-hour incident notification requirement
  • Engage the FedRAMP PMO early and often for guidance on the authorization process

Limitations

  • Guidance and checklists only; not legal advice and not a substitute for a qualified auditor.
  • Docs-only import: upstream templates and scripts not bundled.
Example
markdown
Map this skill's control checklist to our current evidence and list gaps.

Adapted from BagelHole/DevOps-Security-Agent-Skills (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/fedramp-compliance of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 1c7bdea

Used in 2 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Fedramp Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fedramp Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fedramp Compliance this skillsickn33/agentic-awesome-skills47k2 repos~4.1kAutomated safety check: PassMIT
Implementing Google Workspace Sso Configurationmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Implementcodewhale-hq/Codewhale41k—~190Automated safety check: PassMIT
Federation Initruvnet/ruflo74k—~221Automated safety check: PassMIT
Configure Channelopenclaw/openclaw392k—~946Automated safety check: PassMIT
Requirementsrizsotto/Bear6.5k—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • Implementing Google Workspace Sso Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Configures SAML 2.0 single sign-on for Google Workspace against a third-party identity provider (Okta, Azure AD/Entra ID, ADFS), with Workspace as the Service Provider, to centralize authentication…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Implement

    codewhale-hq/Codewhale

    Carry an authorized, defined request or approved plan through scoped edits and proportionate verification.

    41k GitHub stars~190 tokensUpdated today
    Auto-check passed
  • Federation Init

    ruvnet/ruflo

    Initialize federation on this node — generate keypair and configure peers

    74k GitHub stars~221 tokensUpdated yesterday
    Auto-check passed
  • Configure Channel

    openclaw/openclaw

    Configure and prove a chat channel with non-interactive one-liners; secrets only as SecretRefs.

    392k GitHub stars~946 tokensUpdated today
    Auto-check passed
  • Requirements

    rizsotto/Bear

    Write, modify, or review a requirement file under docs/requirements -- pick the single owning file, keep the text contract-only, name IDs so they need no explanation, and verify cross-references and…

    6.5k GitHub stars~2k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Incremental Implementation

    addyosmani/agent-skills

    Delivers a change in thin vertical slices, each implemented, tested, verified and committed before the next, using vertical, contract-first or risk-first slicing.

    105k GitHub starsUsed in 1 repo~2.3k tokens
    Agent WorkflowsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Fedramp Compliance

What does Fedramp Compliance do?

Implement FedRAMP requirements for federal cloud services. An agent skill from sickn33/agentic-awesome-skills. Fedramp Compliance is an agent skill from sickn33/agentic-awesome-skills. Implement FedRAMP requirements for federal cloud services.

When should I use Fedramp Compliance?

Fedramp Compliance fits situations like: providing cloud services to US federal agencies.

How do I install Fedramp Compliance in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill fedramp-compliance -a claude-code`. Or copy the skill folder (skills/fedramp-compliance in sickn33/agentic-awesome-skills) into .claude/skills/fedramp-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Fedramp Compliance in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill fedramp-compliance -a codex`. Or copy the skill folder (skills/fedramp-compliance in sickn33/agentic-awesome-skills) into .agents/skills/fedramp-compliance in your project. Codex loads it when a task matches its description.

Can I use Fedramp Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill fedramp-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fedramp-compliance, .gemini/skills/fedramp-compliance, .github/skills/fedramp-compliance and .opencode/skills/fedramp-compliance in your project.

What does Fedramp Compliance need to run?

Going by SKILL.md and its folder, Fedramp Compliance needs the command-line tools its instructions call (openssl and aws). Compatibility (from SKILL.md): Checklist and framework guidance; no privileged tooling required. Apply controls through your own change process..

Does Fedramp Compliance access the network?

SKILL.md names 2 domains. In commands or code: s3-fips.us-east-1.amazonaws.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Fedramp Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fedramp Compliance use?

Fedramp Compliance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fedramp Compliance use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fedramp Compliance?

Skills that share tags, products or a category with Fedramp Compliance: Implementing Google Workspace Sso Configuration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implement (codewhale-hq/Codewhale, 41k stars), Federation Init (ruvnet/ruflo, 74k stars) and Configure Channel (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fedramp Compliance?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,443 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 10, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.