GRCEngClub/claude-grc-engineering
Plugin Claude Code
GRC connector for Google Cloud: evaluates IAM, Cloud Storage, audit logs, KMS rotation, and Compute for compliance misconfigurations. Emits findings conforming to schemas/finding.schema.json v1.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
GRC connector for Google Cloud: evaluates IAM, Cloud Storage, audit logs, KMS rotation, and Compute for compliance misconfigurations. Emits findings conforming to schemas/finding.schema.json v1.
GRCEngClub/claude-grc-engineering
Skill Claude CodeCodex
Expertise in evaluating GCP projects for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret gcloud output.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
GRC connector for GitHub: evaluates repo protections, branch policies, Actions, secret scanning, Dependabot, and deploy keys. Emits findings conforming to schemas/finding.schema.json v1.
GRCEngClub/claude-grc-engineering
Skill Claude CodeCodex
Expertise in evaluating GitHub repositories for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret gh CLI output.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
GRC connector for Okta: evaluates authentication policies, MFA enrollment, password policy, session management, and admin/privileged accounts. Emits findings conforming to schemas/finding.schema.json v1.
GRCEngClub/claude-grc-engineering
Skill Claude CodeCodex
Expertise in evaluating Okta configurations for compliance — policies, MFA, session management, admin accounts, lifecycle. Maps to FedRAMP/NIST/SOC2/PCI identity controls.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
FedRAMP POA&M lifecycle management and VDR generation. Converts Nessus, Tenable, Qualys, and Wiz scanner exports into a FedRAMP-compliant POA&M, manages the full finding lifecycle, generates FedRAMP 20x VDR reports with live CISA KEV and EPSS enrichment, and produces per-release Product Vulnerability Disclosure…
GRCEngClub/claude-grc-engineering
Skill Claude CodeCodex
Expertise in FedRAMP POA&M lifecycle management, FedRAMP 20x VDR generation, and vulnerability classification using CISA KEV, EPSS, N-ratings, LEV/IRV, and NIST 800-53 control mappings.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
GRC connector for Slack: evaluates workspace 2FA, SSO/session posture, retention, app approvals, and DLP visibility. Emits findings conforming to schemas/finding.schema.json v1.
GRCEngClub/claude-grc-engineering
Skill Claude CodeCodex
Interpret slack-inspector findings, explain Slack API coverage limits, and turn Slack workspace posture results into control evidence or remediation.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
GRC connector for Snowflake ACCOUNTUSAGE: evaluates MFA, network policies, masking/row access policies, session timeout, and data retention. Emits findings conforming to schemas/finding.schema.json v1.
GRCEngClub/claude-grc-engineering
Skill Claude CodeCodex
Interpret Snowflake account usage findings for MFA, network policies, masking/row access policies, session timeout, and retention.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
GRC connector for Splunk: evaluates index retention, RBAC roles, audit-source coverage, saved-search ACLs, and user authentication signals. Emits findings conforming to schemas/finding.schema.json v1.
GRCEngClub/claude-grc-engineering
Skill Claude CodeCodex
Interpret splunk-inspector findings and translate Splunk retention, RBAC, audit, search ACL, and auth posture into compliance evidence and remediation.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
GRC connector for Tenable.io/Tenable.sc: evaluates scan coverage, credentialed scan signals, vulnerability age, and scan access visibility. Emits findings conforming to schemas/finding.schema.json v1.
GRCEngClub/claude-grc-engineering
Skill Claude CodeCodex
Interpret Tenable vulnerability-management findings for scan coverage, credentialed scans, vulnerability age, and scan access visibility.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
GRC connector wrapping testssl.sh. Scans HTTPS endpoints for protocol/cipher posture, certificate issues, and known TLS CVEs (Heartbleed, ROBOT, POODLE, FREAK, LOGJAM, SWEET32, ...). Emits findings conforming to schemas/finding.schema.json v1, anchored on SCF CRY-01/CRY-03/CRY-05/CRY-08/NET-09/VPM-01/VPM-06/WEB-03 and.
GRCEngClub/claude-grc-engineering
Command
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.
GRCEngClub/claude-grc-engineering
Skill Claude CodeCodex
Interpret testssl-inspector normalized findings, recommend remediations, and tie evidence back to SCF anchor controls plus SOC 2 / NIST 800-53 r5 / PCI DSS 4.0.1 / ISO 27002:2022 equivalents derived from SCF crosswalks.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
GRC connector for Wiz CNAPP: normalizes configuration findings, issues, vulnerabilities, and cloud resource inventory into v1 Findings.
GRCEngClub/claude-grc-engineering
Skill Claude CodeCodex
Use wiz-inspector when Wiz CNAPP is the source of cloud posture, vulnerability, toxic-combination, or inventory evidence.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
Localhost compliance posture dashboard for monitor-continuous JSON output. Reference implementation of the Dashboards category from RFC #38.
GRCEngClub/claude-grc-engineering
Command
Serve a localhost compliance posture dashboard from monitor-continuous JSON.
GRCEngClub/claude-grc-engineering
Plugin Claude Code
Convert FedRAMP Rev 5 Moderate SSP DOCX templates to validated OSCAL 1.2.0 JSON. Wraps ethanolivertroy/frdocx-to-froscal-ssp — ready for oscal-cli, Compliance Trestle, eMASS, and FedRAMP 20X workflows.