grcwarlock/compliance-as-code

Open-source agent skills, agents, and reference connectors for compliance engineers. SOC 2, ISO 27001, NIST 800-53.

2Stars on the repository
3Mods indexed here, across every type
4mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

iso-27001

01

grcwarlock/compliance-as-code

Skill Claude CodeCodex

Use when the user asks about ISO/IEC 27001:2022 from an engineering perspective — building an ISMS that runs on systems and code rather than spreadsheets, instrumenting Annex A controls, designing risk registers as data, and producing evidence pipelines that hold up to a certification audit. Engineer-voice, not…

2 4mo ago A 72 tokens original MIT

nist-800-53

02

grcwarlock/compliance-as-code

Skill Claude CodeCodex

Use when the user asks about NIST SP 800-53 Rev. 5 from an engineering perspective — selecting baselines, tailoring controls, modeling control inheritance from cloud providers and shared services, emitting OSCAL artifacts, or implementing controls in IaC and code rather than running them as a documentation exercise.…

2 4mo ago A 76 tokens original MIT

soc-2

03

grcwarlock/compliance-as-code

Skill Claude CodeCodex

Use when the user asks about SOC 2 from an engineering perspective — Trust Services Criteria (TSC) implementation, evidence-as-code, continuous monitoring patterns, instrumenting controls, or designing systems that produce audit-ready evidence by default. Engineer-voice, not auditor-voice.

2 4mo ago A 59 tokens original MIT