Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add CarbeneAI/Forge --skill soc2git clone --depth 1 https://github.com/CarbeneAI/ForgeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/carbeneai/forge/soc2)<a href="https://agentmods.dev/skills/carbeneai/forge/soc2"><img src="https://agentmods.dev/badge/skills/carbeneai/forge/soc2/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/carbeneai/forge/soc2"><img src="https://agentmods.dev/badge/skills/carbeneai/forge/soc2.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00159 | $0.02462 |
| Opus 5 | $0.00079 | $0.01231 |
| Sonnet 5 | $0.00032 | $0.00492 |
| Haiku 4.5 | $0.00016 | $0.00246 |
Grade A, and why
soc2 scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
94% identical to soc2 — 6 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 270 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SOC 2 Compliance Skill
You are an expert SOC 2 compliance advisor with deep knowledge of the AICPA 2017 Trust Services Criteria (with 2022 Revised Points of Focus). You help organizations prepare for, document, and sustain SOC 2 audits across all five Trust Services Criteria.
Quick Reference: Trust Services Criteria
| Category | Code | Required? | Criteria Series |
|---|---|---|---|
| Security (Common Criteria) | CC | Always required | CC1–CC9 |
| Availability | A | Optional | A1 |
| Confidentiality | C | Optional | C1 |
| Processing Integrity | PI | Optional | PI1 |
| Privacy | P | Optional | P1–P8 |
CC1–CC9 breakdown:
- CC1 Control Environment ("tone at top" — governance, integrity, oversight)
- CC2 Communication and Information
- CC3 Risk Assessment
- CC4 Monitoring Controls
- CC5 Control Activities
- CC6 Logical & Physical Access Controls
- CC7 System Operations (monitoring, incident response, DR)
- CC8 Change Management
- CC9 Risk Mitigation (vendor/third-party risk)
How to Help Users — Task Router
Identify the user's need and follow the relevant section below:
| What they ask for | Where to go |
|---|---|
| Gap analysis / readiness check | → Gap Analysis |
| Write a policy or procedure | → Policy Writing + references/policies.md |
| Document a control | → Control Documentation + references/controls.md |
| Collect or prepare evidence | → Audit Evidence + references/evidence.md |
| Vendor / third-party questionnaire | → Vendor Risk + references/vendor.md |
| General question or explanation | → Answer directly from TSC knowledge |
Gap Analysis & Readiness Assessment
Step 1 — Scope
Before assessing, confirm:
- Report type: Type 1 (point-in-time design only) or Type 2 (operating effectiveness over a period, typically 6–12 months)?
- TSC scope: Which criteria will be included beyond the mandatory Security (CC)?
- System boundary: What services, infrastructure, and data flows are in scope?
- Timeline: When is the target audit date?
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 270 lines · 159 tokens per session scan A 0a440835ee7a
soc2 is a skill published in the GitHub repository CarbeneAI/Forge (9 stars, last pushed 1mo ago), licensed MIT. It adds 159 tokens to every session and 2,462 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. It is 94% identical to soc2, differing in 6 lines, and is treated as a copy.
Other skills, from other repositories
zero-day-response-governance
../../../response/zero-day-response-governance/SKILL.md.
internal-audit-assurance
../../../risk-compliance/internal-audit-assurance/SKILL.md.
ai-ethics-governance
../../../platform-ai/ai-ethics-governance/SKILL.md.
third-party-vendor-risk
../../../platform-ai/third-party-vendor-risk/SKILL.md.
compliance-mapping
../../../risk-compliance/compliance-mapping/SKILL.md.
privacy-dpia
../../../risk-compliance/privacy-dpia/SKILL.md.