Topic · Legal & Compliance
Best SOC 2 and security compliance skills for Claude Code, Codex and other agents.
- skills
- 128
- official
- 3
SOC 2 and security compliance skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Privacy and security compliance scanner for the Finance Guru repo. | AojdevStudio/ | 322 | — | ~2.6k | Automated safety check: Notes | Unknown | today |
| 2 | Run a pre-deployment security compliance checklist based on KISA guidelines. | cdppcorp/ | 359 | — | ~1.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 3 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 219 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 4 | Quality gate, audit evidence, live roots and cleanup boundaries for fastbrowse. | agent-labs-dev/ | 113 | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 5 | NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200… | Sushegaad/ | 939 | 1 repo | ~3.3k | Automated safety check: Pass | MIT | 2 days ago |
| 6 | A skill your agent uses to durably record a hard constraint or invariant that the work must respect. | harrylettering/ | 158 | — | ~793 | Automated safety check: Pass | No licence | 2 days ago |
| 7 | 7.Soc2 Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). | Sushegaad/ | 939 | 1 repo | ~2.7k | Automated safety check: Pass | MIT | 2 days ago |
| 8 | Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR… | mlunato47/ | 183 | — | ~6.1k | Automated safety check: Pass | MIT | today |
| 9 | Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies. | davila7/ | 32k | 1 repo | ~2.9k | Automated safety check: Pass | MIT | today |
| 10 | Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/. | cartography-cncf/ | 4.1k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | today |
| 11 | Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard. | GRCEngClub/ | 419 | — | ~2.6k | Automated safety check: Pass | Unknown | 3 days ago |
| 12 | Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills. | BagelHole/ | 1.1k | — | ~662 | Automated safety check: Notes | MIT | 4 mo ago |
| 13 | Senior ISMS Audit Expert for internal and external information security management system auditing. | davila7/ | 32k | 1 repo | ~3.1k | Automated safety check: Pass | MIT | today |
| 14 | 14.Audit Report Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools. | harness/ | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 15 | Build the deterministic evidence ledger (artifactmanifest.json + claims.json) that every other Anti-Autoresearch auditor reads. | wanshuiyin/ | 160 | — | ~11k | Automated safety check: Notes | MIT | yesterday |
| 16 | 16.Cis Controls Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection… | Sushegaad/ | 939 | 1 repo | ~4.2k | Automated safety check: Pass | MIT | 2 days ago |
| 17 | Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and… | sangrokjung/ | 849 | 2 repos | ~7.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 18 | 18.Iso27001 Expert ISO 27001 compliance assistant for security and compliance teams. | Sushegaad/ | 939 | 1 repo | ~2.2k | Automated safety check: Pass | MIT | 2 days ago |
| 19 | 19.Ciso Advisor Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills. | alirezarezvani/ | 28k | 1 repo | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 20 | ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. | alirezarezvani/ | 28k | 1 repo | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 21 | Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. | alirezarezvani/ | 28k | 1 repo | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 22 | Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. | alirezarezvani/ | 28k | 1 repo | ~4k | Automated safety check: Pass | MIT | 1 mo ago |
| 23 | Implement ISO 27001 Information Security Management System. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~4.2k | Automated safety check: Pass | MIT | yesterday |
| 24 | Implement SOC 2 Trust Services Criteria. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | yesterday |
| 25 | 安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust… | telagod/ | 244 | — | ~712 | Automated safety check: Pass | MIT | 2 mo ago |
| 26 | 26.Compliance Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks | RightNow-AI/ | 18k | — | ~921 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 27 | A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS… | aws-samples/ | 113 | — | ~4.7k | Automated safety check: Pass | MIT-0 | today |
| 28 | 28.Iso27701 Expert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. | Sushegaad/ | 939 | 1 repo | ~4.3k | Automated safety check: Pass | MIT | 2 days ago |
| 29 | 29.Nis2 EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities: entity classification, Art. | Sushegaad/ | 939 | 1 repo | ~4.4k | Automated safety check: Pass | MIT | 2 days ago |
| 30 | 30.Nist Csf Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. | Sushegaad/ | 939 | 1 repo | ~3.4k | Automated safety check: Pass | MIT | 2 days ago |
| 31 | Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export. | GRCEngClub/ | 419 | — | ~2.4k | Automated safety check: Notes | Unknown | 3 days ago |
| 32 | Review agentic workflow changes for correctness, security posture, and optimization opportunities with compile, validation, and audit evidence. | github/ | 5.3k | — | ~1k | Automated safety check: Pass | MIT | today |
| 33 | 33.Ads Create Create source-grounded paid-ad campaign concepts, messaging, copy, creative briefs, and production plans from a validated brand profile, campaign objective, platform requirements, and optional audit… | AgriciDaniel/ | 9.8k | — | ~462 | Automated safety check: Pass | MIT | 4 days ago |
| 34 | 34.Policy Opa Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA). | AgentSecOps/ | 219 | 1 repo | ~3.5k | Automated safety check: Pass | Unknown | 5 mo ago |
| 35 | Policy register: name, version, category, owner and approver, applies to, compliance framework, acknowledgement requirement, effective date and next review. | sickn33/ | 47k | 1 repo | ~3.5k | Automated safety check: Pass | MIT | yesterday |
| 36 | Build a vulnerability exception and risk acceptance tracking system covering approval workflows, compensating controls documentation, and automatic expiration for vulnerabilities that miss SLA… | mukul975/ | 34k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 37 | Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC 2, and HIPAA. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 38 | Turns kube-bench output into a finished CIS Kubernetes Benchmark audit: interpreting PASS/FAIL/WARN per control, judging which failures are genuine on a managed cluster, writing remediation, and… | mukul975/ | 34k | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 39 | Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 40 | Reviews pull requests for compliance regressions. An agent skill from GRCEngClub/claude-grc-engineering. | GRCEngClub/ | 419 | — | ~587 | Automated safety check: Notes | Unknown | 3 days ago |
| 41 | Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across… | alirezarezvani/ | 28k | — | ~3.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 42 | A skill your agent uses when an RFP, RFI, RFQ, security questionnaire, vendor questionnaire, or proposal request arrives and the team needs a structured response — parsing multi-section… | alirezarezvani/ | 28k | — | ~3.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 43 | Plan/create/audit evidence-led research decks for defenses, meetings and talks, with render QA. | huang-sir1/ | 1.9k | — | ~2.5k | Automated safety check: Pass | Unknown | 16 days ago |
| 44 | Designs and implements VLAN-based (802.1Q) network segmentation on managed switches to isolate zones such as corporate, servers, DMZ, guest, and IoT, and to limit lateral movement paths. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 45 | Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 46 | Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 47 | Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 48 | Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configuration to enforce identity-based access policies, posture assessment, and… | mukul975/ | 34k | — | ~3.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
Questions, answered from the data.
What is the best SOC 2 and security compliance skill?
Compliance Scan from AojdevStudio/Finance-Guru ranks first of the 128 SOC 2 and security compliance skills listed here, with the highest score: its repository has 322 GitHub stars, its SKILL.md loads about 2.6k tokens and it has informational notes only in the automated safety check. Next come Kesekit Check and DefectDojo Vulnerability Management.
Which SOC 2 and security compliance skills are official?
3 of the 128 SOC 2 and security compliance skills are official, published by the vendor's own GitHub organization: Eks Security, Review Agentic Workflows and Azure Enterprise Infra Planner.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.