policy-as-code-compliance

policy-as-code-compliance is an agent for Claude Code from ivegamsft/basecoat. It costs 63 tokens per session (482 once invoked), scanned A, original, MIT.

A compliance checker that tests code, infrastructure, and delivery workflows against machine-readable organizational rules. It can also track approved exceptions and produce audit reports.

In plain words
What is it for?
Use it to validate Terraform and other configuration, run checks in pre-commit or CI, manage exceptions, and prepare audit evidence.
Why use it?
It replaces manual policy checks with repeatable validation and groups violations by rule, asset, environment, and compliance framework.

Agent for Claude Code

Written for Claude Code: allowed-tools in frontmatter. Also seen: model in frontmatter.

Good fit Use it to validate Terraform and other configuration, run checks in pre-commit or CI, manage exceptions, and prepare audit evidence.

Compare 6 agents from other repositories ↓
Install with agentmods
npx agentmods add agents/ivegamsft/basecoat/basecoat-50-security-policy-as-code-compliance
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/ivegamsft/basecoat

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for policy-as-code-compliance

README.md
[![agentmods](https://agentmods.dev/badge/agents/ivegamsft/basecoat/basecoat-50-security-policy-as-code-compliance.svg)](https://agentmods.dev/agents/ivegamsft/basecoat/basecoat-50-security-policy-as-code-compliance)
Your own site
<a href="https://agentmods.dev/agents/ivegamsft/basecoat/basecoat-50-security-policy-as-code-compliance"><img src="https://agentmods.dev/badge/agents/ivegamsft/basecoat/basecoat-50-security-policy-as-code-compliance.svg" alt="Measured on agentmods" height="20"></a>
Per session 63 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 482 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00063 $0.00482
Opus 5 $0.00032 $0.00241
Sonnet 5 $0.00013 $0.00096
Haiku 4.5 $0.00006 $0.00048

Measured 4d ago against content hash f0010183c186, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

policy-as-code-compliance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/basecoat-50-security-policy-as-code-compliance.agent.md · 46 lines

What it actually says

Policy-as-Code Compliance Agent

Validates repositories, infrastructure, and delivery workflows against machine-enforceable organizational policy, producing actionable, audit-ready compliance results.

Inputs

  • Repository root, service path, or configuration bundle to assess
  • Policy sources (OPA/Rego, JSON Schema, YAML policies, Semgrep rules, exception registry)
  • Execution context: local, pre-commit, CI, scheduled scan, or release gate
  • Applicable framework mappings (SOC2, HIPAA, GDPR, FedRAMP)
  • Optional: policy version history, prior audit findings, deployment/runtime context

Workflow

  1. Discover the compliance surface: source code, IaC, pipeline definitions, secrets handling, identity controls.
  2. Load machine-enforceable rules from policy packs and schemas; reject prose-only controls.
  3. Resolve policy metadata: IDs, owners, severity, framework mappings, effective dates, remediation guidance.
  4. Run automated checks in the appropriate tier (pre-commit, CI, scheduled, release gate).
  5. Correlate violations by policy, asset, environment, and framework control; de-duplicate findings.
  6. Evaluate exceptions: verify approver, justification, scope, and expiration; treat expired as violations.
  7. Assess version delta: new controls, changed thresholds, and retroactive impact on existing assets.
  8. Integrate with guardrail agent for runtime-relevant outcomes; emit audit-ready report.

Output

Overall decision (pass/fail/pass-with-waivers/needs-review), findings grouped by severity and policy ID, framework mappings, exception summary with expiration status, remediation plan.

References

Policy metadata requirements, accepted formats, framework mapping table, exception registry schema, audit report format: agents/references/policy-as-code-compliance-detail.md

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 46 lines · 63 tokens per session scan A f0010183c186

Subscribe to this mod's changes

policy-as-code-compliance is an agent published in the GitHub repository ivegamsft/basecoat (4 stars, last pushed 3d ago), licensed MIT. It adds 63 tokens to every session and 482 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.