vaquarkhan

193 mods across 7 repositories, 1.5k stars between them.

vaquarkhan/compliance-agent-skills

Agent

Simulates a FedRAMP Third Party Assessment Organization (3PAO) perspective for Moderate baseline authorization packages — not an official FedRAMP assessment or Agency ATO.

2 8d ago A 0 tokens original MIT

gdpr-dpo-advisor

99

vaquarkhan/compliance-agent-skills

Agent

Simulates Data Protection Officer advisory workflows for US multinationals processing EU/EEA/UK personal data—RoPA, DPIA, transfers, and 72-hour breach notification. Not a appointed DPO or EU legal counsel.

2 8d ago A 0 tokens original MIT

hipaa-privacy-officer

101

vaquarkhan/compliance-agent-skills

Agent

Simulates a HIPAA Privacy/Security Officer perspective for Security Rule technical reviews, minimum necessary assessments, and breach notification readiness — not legal counsel.

2 8d ago A 0 tokens original MIT

vaquarkhan/compliance-agent-skills

Agent

Coordinates HITECH Act breach notification workflows after initial incident containment—OCR portal submissions, unsecured PHI analysis, BA notification chains, and penalty-tier documentation. Not legal counsel or OCR representation.

2 8d ago A 0 tokens original MIT

pci-qsa-reviewer

104

vaquarkhan/compliance-agent-skills

Agent

Simulates a PCI Qualified Security Assessor review style for PCI-DSS v4.0 — focused on payment-page scripts (Req 6.4.3 / 11.6.1), CDE segmentation, and logging — not a formal ROC attestation.

2 8d ago A 0 tokens original MIT

soc2-auditor

105

vaquarkhan/compliance-agent-skills

Agent

Simulates a SOC 2 examination perspective for Trust Services Criteria mapping, control testing, and evidence packaging — not a CPA attestation.

2 8d ago A 0 tokens original MIT

sox-it-auditor

106

vaquarkhan/compliance-agent-skills

Agent

Simulates an IT general controls (ITGC) auditor perspective for Sarbanes-Oxley Section 404 financial reporting — not external audit opinion or PCAOB attestation.

2 8d ago A 0 tokens original MIT

state-privacy-analyst

107

vaquarkhan/compliance-agent-skills

Agent

Supports multi-state US comprehensive privacy law compliance—VCDPA, CPA, TDPSA, CTDPA, and harmonized consumer rights programs for agent/LLM data flows. Not licensed attorney.

2 8d ago A 0 tokens original MIT

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Audits identity and access management—least privilege, RBAC, MFA, privileged access, joiner-mover-leaver—for SOC 2 CC6.1–CC6.8, HIPAA §164.312(a), and PCI Req 7/8. Trigger when reviewing IAM policies, agent/MCP service accounts, access certifications, or admin console permissions. Do not use for network firewall…

2 8d ago A 114 tokens original MIT

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Designs and validates tamper-evident audit logging, SIEM integration, and log retention for HIPAA §164.312(b) audit controls, SOC 2 CC7.2/CC7.3, and PCI Req 10. Trigger when assessing agent/MCP audit trails, log tampering risks, centralized logging, or forensic readiness. Do not use for IAM permission reviews (use…

2 8d ago A 104 tokens original MIT

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Executes USA breach and security incident response—HIPAA Breach Notification Rule (45 CFR §164.400–414), HITECH 60-day notification, state breach laws, and SOC 2 CC7.4/CC7.5 incident management—for agent, MCP, and LLM-related events. Trigger when investigating suspected PHI/PII exposure, unauthorized MCP access, LLM…

2 8d ago A 114 tokens original MIT

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Implements California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)—Cal. Civ. Code §1798.100 et seq.—covering consumer rights to know, delete, correct, opt-out of sale/share, and limit use of sensitive personal information, plus DSAR workflows, privacy notices, and service provider…

2 8d ago A 173 tokens original MIT

cmmc-nist-800-171

112

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Implements CMMC 2.0 Level 2 assessments aligned to NIST SP 800-171 Revision 2 (110 security requirements across 14 families) for Controlled Unclassified Information (CUI) protection in the Defense Industrial Base (DIB), including SPRS score self-assessment, POA&M management, and government contract flow-down…

2 8d ago A 188 tokens original MIT

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Implements policy-as-code and infrastructure compliance scanning—OPA/Rego policies, Terraform static analysis, CI gates, and drift remediation—for SOC 2, HIPAA, and PCI control enforcement. Trigger when codifying security policies, integrating Checkov/tfsec/Sentinel, or automating guardrails for agent/MCP deployments.…

2 8d ago A 103 tokens original MIT

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Implements FTC COPPA (15 U.S.C. §6501–6506; 16 CFR Part 312) for operators of websites, apps, and AI agents directed to children under 13 or with actual knowledge of child users—verifiable parental consent, data minimization, retention, security, and third-party LLM/MCP subprocessors. Trigger when building consumer…

2 8d ago A 175 tokens original MIT

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Implements FedRAMP Moderate baseline assessments using NIST SP 800-53 Revision 5 controls—authorization boundary definition, System Security Plan (SSP), Plan of Action and Milestones (POA&M), and continuous monitoring (ConMon)—with Cloud Service Provider (CSP) and agency customer responsibility matrices. Trigger when…

2 8d ago A 179 tokens original MIT

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Implements FERPA (20 U.S.C. §1232g; 34 CFR Part 99) protections for student education records in EdTech, LMS integrations, and AI tutoring agents—school official exceptions, legitimate educational interest, directory information, parent/eligible student rights, and vendor DPAs. Trigger when K-12 or higher-ed systems…

2 8d ago A 162 tokens original MIT

gdpr-us-multinational

117

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Implements GDPR compliance workflows for US-headquartered multinationals—EU/EEA/UK data subjects, Articles 5-7 lawful basis, Article 30 records of processing, Article 32 security, Articles 33-34 breach notification (72 hours), Article 35 DPIA, Standard Contractual Clauses, EU-US Data Privacy Framework adequacy, and…

2 8d ago A 189 tokens original MIT

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Implements Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 CFR Part 314) and Privacy Rule (16 CFR Part 313) compliance aligned to FFIEC IT Examination Handbook modules for financial institutions—customer information protection, risk assessments, access controls, vendor oversight, and GLBA privacy notices (initial…

2 8d ago A 183 tokens original MIT

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Reviews Business Associate Agreements and subprocessors for LLM vendors, cloud providers, and MCP server operators under HIPAA (45 CFR §164.502(e), §164.504(e)). Trigger when onboarding OpenAI/Anthropic/Azure OpenAI, cloud hosts, observability tools, or MCP integrations that may access ePHI. Do not use for technical…

2 8d ago A 110 tokens original MIT

vaquarkhan/compliance-agent-skills

Skill Claude CodeCodex

Configures and validates the Presidio-based PHI redaction pipeline—DLP entity detection, reversible tokenization before LLM ingestion, and authorized deanonymization—integrated with redaction.py and the compliance agent. Trigger when ePHI may appear in prompts, implementing minimum-necessary LLM access, tuning entity…

2 8d ago A 117 tokens original MIT