grc
01Plugin Claude Code
GRC (Governance, Risk, and Compliance) domain knowledge — frameworks, controls, audits, evidence, ConMon, cross-framework mappings, document review, and operational workflows. Cloud-agnostic.
A Claude Code plugin that turns Claude into a senior GRC (Governance, Risk, and Compliance) analyst. 72+ reference files covering 15 frameworks, 24 slash commands, and deep domain knowledge for federal and commercial compliance work.
Plugin Claude Code
GRC (Governance, Risk, and Compliance) domain knowledge — frameworks, controls, audits, evidence, ConMon, cross-framework mappings, document review, and operational workflows. Cloud-agnostic.
Agent
A read-only research agent for deep GRC reference lookups across frameworks, mappings, and audit procedures.
Command
Audit preparation checklists and guidance by audit type.
Command
Authorization boundary definition guidance.
Command
Generate a recurring compliance activity calendar by framework.
Command
Continuous monitoring guidance by topic.
Command
Look up controls by framework and ID or keyword.
Command
Draft deviation requests, risk acceptances, or false positive justifications.
Command
Generate an evidence preparation checklist for audits or assessments.
Command
Perform a structured gap analysis against a compliance framework.
Command
Model control inheritance based on service model and provider stack.
Command
Map controls between compliance frameworks using NIST 800-53 as the universal hub.
Command
Analyze overlap and gaps across multiple compliance frameworks.
Command
OSCAL structure, readiness, and conversion guidance.
Command
POA&M management help and templates.
Command
NIST 800-53 Rev 4 to Rev 5 transition guidance.
Command
Review a CRM for coverage, clarity, and completeness.
Command
Review a control implementation narrative for completeness and quality.
Command
Review POA&M entries or structure for completeness.
Command
Review a policy document for structure, coverage, and language quality.
Command
Validate SSP structure and completeness against FedRAMP template standards.
Command
Draft structured responses to SAR findings.
Command
Score control implementation maturity 0-5 with next-level guidance.
Command
Analyze whether a system change qualifies as significant and determine required actions.
At most 3 mods per repository are shown here — the rest are on their repository pages: