Topic · Legal & Compliance
Best SOC 2 and security compliance skills, page 2
SOC 2 and security compliance skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Provides step-by-step procedures for remediating Amazon S3 bucket misconfigurations that expose sensitive data: enabling S3 Block Public Access, auditing bucket policies and ACLs, enforcing… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 50 | A skill your agent uses when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs… | alirezarezvani/ | 28k | — | ~4.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 51 | Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify vulnerabilities and… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 52 | Guides implementation of an ISO/IEC 27001:2022 Information Security Management System (ISMS) end to end: gap analysis and scoping, risk assessment methodology, Annex A control selection, Statement… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 53 | Build and run a third-party/vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM: inventory and tier vendors, issue SIG/CAIQ questionnaires, review SOC 2/ISO 27001 evidence, set… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 54 | Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber… | Sushegaad/ | 943 | — | ~2k | Automated safety check: Pass | MIT | 4 days ago |
| 55 | 55.Tprm Expert third-party risk management (TPRM) advisor — a vendor risk analyst for the full lifecycle: risk-based vendor tiering, tailored due-diligence questionnaires (SIG-style or mapped to ISO 27001… | Sushegaad/ | 943 | — | ~2.3k | Automated safety check: Pass | MIT | 4 days ago |
| 56 | 56.Uae Grc United Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router. | Sushegaad/ | 943 | — | ~2.3k | Automated safety check: Pass | MIT | 4 days ago |
| 57 | Architect and provision enterprise Azure infrastructure from workload descriptions. | microsoft/ | 255 | 1 repo | ~1.6k | Automated safety check: Pass | MIT | today |
| 58 | Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection. | ancoleman/ | 526 | — | ~4k | Automated safety check: Pass | MIT | 10 mo ago |
| 59 | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. | aiskillstore/ | 430 | 6 repos | ~2.6k | Automated safety check: Pass | No licence | today |
| 60 | Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output. | GRCEngClub/ | 420 | — | ~1.4k | Automated safety check: Pass | Unknown | 5 days ago |
| 61 | AWS compliance commands in Atmos: atmos aws compliance report, Security Hub standards, CIS AWS, PCI DSS, SOC2, HIPAA, NIST, report formats, AI summaries | cloudposse/ | 1.4k | — | ~679 | Automated safety check: Pass | Apache-2.0 | today |
| 62 | Secure change control: RFC process, testing requirements, rollback procedures per ISO 27001 A.8.9, A.8.32 | Hack23/ | 239 | — | ~3k | Automated safety check: Pass | Apache-2.0 | today |
| 63 | You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. | aiskillstore/ | 430 | 8 repos | ~600 | Automated safety check: Pass | No licence | today |
| 64 | 64.Ciso Review /cs:ciso-review <plan — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. | alirezarezvani/ | 28k | — | ~809 | Automated safety check: Pass | MIT | 1 mo ago |
| 65 | 65.Ra Qm Skills Router/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document control, ISO… | alirezarezvani/ | 28k | — | ~833 | Automated safety check: Pass | MIT | 1 mo ago |
| 66 | Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001). | ancoleman/ | 526 | — | ~6.3k | Automated safety check: Pass | MIT | 10 mo ago |
| 67 | 67.Soc2 Prep When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer… | shawnpang/ | 342 | — | ~2.5k | Automated safety check: Pass | MIT | 6 mo ago |
| 68 | [omh] Pull request or changes to vet: bug-first review with evidence. | rlaope/ | 3.2k | — | ~2.3k | Automated safety check: Pass | MIT | today |
| 69 | Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks | aiskillstore/ | 430 | 4 repos | ~3.7k | Automated safety check: Pass | No licence | today |
| 70 | Audit numeric, artifact, log, citation, and cross-report claims against inspectable evidence. | NeuroAIHub/ | 1.1k | — | ~474 | Automated safety check: Pass | AGPL-3.0 | 7 days ago |
| 71 | Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification. | jeremylongshore/ | 2.8k | — | ~1.6k | Automated safety check: Pass | MIT | today |
| 72 | Execute use when you need to work with compliance checking. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 73 | Generate comprehensive compliance reports for security standards. | jeremylongshore/ | 2.8k | — | ~1.6k | Automated safety check: Pass | MIT | today |
| 74 | Analyze a target's TLS configuration — negotiated protocol version, cipher suite, certificate chain, expiry, and downgrade vectors. | jeremylongshore/ | 2.8k | — | ~2k | Automated safety check: Pass | MIT | today |
| 75 | Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema. | jeremylongshore/ | 2.8k | — | ~2.5k | Automated safety check: Notes | MIT | today |
| 76 | Audit a Python project's installed dependencies for known CVEs by wrapping pip-audit (PyPA's official vulnerability auditor) and emitting findings in the canonical penetration-tester schema. | jeremylongshore/ | 2.8k | — | ~2.3k | Automated safety check: Notes | MIT | today |
| 77 | Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin… | jeremylongshore/ | 2.8k | — | ~2k | Automated safety check: Pass | MIT | today |
| 78 | Probe a target for directories that return auto-generated index listings instead of denying or serving a specific file — exposes the full file tree under any reachable directory, including files the… | jeremylongshore/ | 2.8k | — | ~1.8k | Automated safety check: Notes | MIT | today |
| 79 | Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards. | jeremylongshore/ | 2.8k | — | ~1.7k | Automated safety check: Pass | MIT | today |
| 80 | Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE identifier when present. | jeremylongshore/ | 2.8k | — | ~2.1k | Automated safety check: Notes | MIT | today |
| 81 | Scan a source-code tree for hardcoded credentials embedded in source files: AWS access keys, GitHub tokens, Stripe keys, Slack tokens, Anthropic API keys, OpenAI keys, JWT signing secrets, generic… | jeremylongshore/ | 2.8k | — | ~2.1k | Automated safety check: Notes | MIT | today |
| 82 | Cross-framework compliance readiness orchestrator. An agent skill from borghei/Claude-Skills. | borghei/ | 886 | — | ~2.3k | Automated safety check: Pass | MIT | 2 days ago |
| 83 | ISO 27001:2022 ISMS implementation and cybersecurity governance for HealthTech and MedTech. | borghei/ | 886 | — | ~1.9k | Automated safety check: Pass | MIT | 2 days ago |
| 84 | Cross-framework infrastructure security audit across cloud, network, and CI/CD. | borghei/ | 886 | — | ~2.1k | Automated safety check: Pass | MIT | 2 days ago |
| 85 | ISMS auditing for ISO 27001 compliance, control assessment, and certification support. | borghei/ | 886 | — | ~4.9k | Automated safety check: Pass | MIT | 2 days ago |
| 86 | PCI DSS v4.0 payment card data security compliance, assessment, and implementation. | borghei/ | 886 | — | ~1.9k | Automated safety check: Pass | MIT | 2 days ago |
| 87 | SOC 2 audit-prep playbook: the 4/8/12-week sprint to audit-ready for a Type I or Type II observation. | borghei/ | 886 | — | ~2.1k | Automated safety check: Pass | MIT | 2 days ago |
| 88 | /cs:iso27001-audit-prep <scope — ISO 27001 ISMS audit readiness 6-question forcing interrogation. | alirezarezvani/ | 28k | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 89 | /cs:soc2-audit-prep <scope — SOC 2 Type II readiness 6-question forcing interrogation. | alirezarezvani/ | 28k | — | ~1.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 90 | Monitor and investigate EU DORA compliance posture using Dynatrace Compliance Assistant. | Dynatrace/ | 162 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 91 | Design marketing automation programs — end-to-end workflow architecture, lead scoring models with MQL/SQL thresholds, nurture and drip sequences, behavioral triggers, lifecycle stage frameworks… | indranilbanerjee/ | 859 | 1 repo | ~4.7k | Automated safety check: Pass | MIT | 5 days ago |
| 92 | Generate auditor-ready compliance evidence from Datadog Audit Trail for SOC 2 and PCI DSS. | datadog-labs/ | 177 | — | ~1.7k | Automated safety check: Pass | MIT | today |
| 93 | Implement Kubernetes security contexts, Pod Security Standards, and network policies. | BagelHole/ | 1.1k | — | ~632 | Automated safety check: Pass | MIT | 4 mo ago |
| 94 | SOC 2 Type I and Type II compliance management against the Trust Services Criteria. | borghei/ | 886 | — | ~5.3k | Automated safety check: Pass | MIT | 2 days ago |
| 95 | Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for… | forcedotcom/ | 1.1k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 96 | Regulatory compliance testing for GDPR, CCPA, HIPAA, SOC2, PCI-DSS and industry-specific regulations. | proffesor-for-testing/ | 495 | — | ~1.8k | Automated safety check: Pass | MIT | 5 days ago |