vaquarkhan/compliance-agent-skills
Agent
Simulates a FedRAMP Third Party Assessment Organization (3PAO) perspective for Moderate baseline authorization packages — not an official FedRAMP assessment or Agency ATO.
vaquarkhan/compliance-agent-skills
Agent
Simulates a FedRAMP Third Party Assessment Organization (3PAO) perspective for Moderate baseline authorization packages — not an official FedRAMP assessment or Agency ATO.
vaquarkhan/compliance-agent-skills
Agent
Supports FERPA compliance for EdTech and school AI agents—school officials, LEI, directory information, §99.32 logging. Not legal counsel.
vaquarkhan/compliance-agent-skills
Agent
Simulates Data Protection Officer advisory workflows for US multinationals processing EU/EEA/UK personal data—RoPA, DPIA, transfers, and 72-hour breach notification. Not a appointed DPO or EU legal counsel.
vaquarkhan/compliance-agent-skills
Agent
Simulates a GLBA Safeguards and Privacy Rule compliance perspective for financial institutions and fintech — not legal counsel or FFIEC examination.
vaquarkhan/compliance-agent-skills
Agent
Simulates a HIPAA Privacy/Security Officer perspective for Security Rule technical reviews, minimum necessary assessments, and breach notification readiness — not legal counsel.
vaquarkhan/compliance-agent-skills
Agent
Coordinates HITECH Act breach notification workflows after initial incident containment—OCR portal submissions, unsecured PHI analysis, BA notification chains, and penalty-tier documentation. Not legal counsel or OCR representation.
vaquarkhan/compliance-agent-skills
Agent
Advises on NIST AI RMF 1.0 GOVERN/MAP/MEASURE/MANAGE for LLM agents and MCP systems. Not a certifying body.
vaquarkhan/compliance-agent-skills
Agent
Simulates a PCI Qualified Security Assessor review style for PCI-DSS v4.0 — focused on payment-page scripts (Req 6.4.3 / 11.6.1), CDE segmentation, and logging — not a formal ROC attestation.
vaquarkhan/compliance-agent-skills
Agent
Simulates a SOC 2 examination perspective for Trust Services Criteria mapping, control testing, and evidence packaging — not a CPA attestation.
vaquarkhan/compliance-agent-skills
Agent
Simulates an IT general controls (ITGC) auditor perspective for Sarbanes-Oxley Section 404 financial reporting — not external audit opinion or PCAOB attestation.
vaquarkhan/compliance-agent-skills
Agent
Supports multi-state US comprehensive privacy law compliance—VCDPA, CPA, TDPSA, CTDPA, and harmonized consumer rights programs for agent/LLM data flows. Not licensed attorney.
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Audits identity and access management—least privilege, RBAC, MFA, privileged access, joiner-mover-leaver—for SOC 2 CC6.1–CC6.8, HIPAA §164.312(a), and PCI Req 7/8. Trigger when reviewing IAM policies, agent/MCP service accounts, access certifications, or admin console permissions. Do not use for network firewall…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Designs and validates tamper-evident audit logging, SIEM integration, and log retention for HIPAA §164.312(b) audit controls, SOC 2 CC7.2/CC7.3, and PCI Req 10. Trigger when assessing agent/MCP audit trails, log tampering risks, centralized logging, or forensic readiness. Do not use for IAM permission reviews (use…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Executes USA breach and security incident response—HIPAA Breach Notification Rule (45 CFR §164.400–414), HITECH 60-day notification, state breach laws, and SOC 2 CC7.4/CC7.5 incident management—for agent, MCP, and LLM-related events. Trigger when investigating suspected PHI/PII exposure, unauthorized MCP access, LLM…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Implements California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)—Cal. Civ. Code §1798.100 et seq.—covering consumer rights to know, delete, correct, opt-out of sale/share, and limit use of sensitive personal information, plus DSAR workflows, privacy notices, and service provider…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Implements CMMC 2.0 Level 2 assessments aligned to NIST SP 800-171 Revision 2 (110 security requirements across 14 families) for Controlled Unclassified Information (CUI) protection in the Defense Industrial Base (DIB), including SPRS score self-assessment, POA&M management, and government contract flow-down…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Implements policy-as-code and infrastructure compliance scanning—OPA/Rego policies, Terraform static analysis, CI gates, and drift remediation—for SOC 2, HIPAA, and PCI control enforcement. Trigger when codifying security policies, integrating Checkov/tfsec/Sentinel, or automating guardrails for agent/MCP deployments.…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Implements FTC COPPA (15 U.S.C. §6501–6506; 16 CFR Part 312) for operators of websites, apps, and AI agents directed to children under 13 or with actual knowledge of child users—verifiable parental consent, data minimization, retention, security, and third-party LLM/MCP subprocessors. Trigger when building consumer…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Implements FedRAMP Moderate baseline assessments using NIST SP 800-53 Revision 5 controls—authorization boundary definition, System Security Plan (SSP), Plan of Action and Milestones (POA&M), and continuous monitoring (ConMon)—with Cloud Service Provider (CSP) and agency customer responsibility matrices. Trigger when…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Implements FERPA (20 U.S.C. §1232g; 34 CFR Part 99) protections for student education records in EdTech, LMS integrations, and AI tutoring agents—school official exceptions, legitimate educational interest, directory information, parent/eligible student rights, and vendor DPAs. Trigger when K-12 or higher-ed systems…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Implements GDPR compliance workflows for US-headquartered multinationals—EU/EEA/UK data subjects, Articles 5-7 lawful basis, Article 30 records of processing, Article 32 security, Articles 33-34 breach notification (72 hours), Article 35 DPIA, Standard Contractual Clauses, EU-US Data Privacy Framework adequacy, and…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Implements Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 CFR Part 314) and Privacy Rule (16 CFR Part 313) compliance aligned to FFIEC IT Examination Handbook modules for financial institutions—customer information protection, risk assessments, access controls, vendor oversight, and GLBA privacy notices (initial…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Reviews Business Associate Agreements and subprocessors for LLM vendors, cloud providers, and MCP server operators under HIPAA (45 CFR §164.502(e), §164.504(e)). Trigger when onboarding OpenAI/Anthropic/Azure OpenAI, cloud hosts, observability tools, or MCP integrations that may access ePHI. Do not use for technical…
vaquarkhan/compliance-agent-skills
Skill Claude CodeCodex
Configures and validates the Presidio-based PHI redaction pipeline—DLP entity detection, reversible tokenization before LLM ingestion, and authorized deanonymization—integrated with redaction.py and the compliance agent. Trigger when ePHI may appear in prompts, implementing minimum-necessary LLM access, tuning entity…