test-remediation

test-remediation is a skill for Claude Code from VantaInc/vanta-mcp-plugin. It costs 62 tokens per session (711 once invoked), scanned A, original, MIT.

Instructions for fixing failed Vanta compliance tests with code. Vanta is a service that checks whether a company follows security and privacy requirements such as SOC 2 or ISO 27001.

In plain words
What is it for?
Use them when a Vanta test fails, when you have a test ID or Vanta URL, or when addressing requirements for SOC 2, ISO 27001, or HIPAA.
Why use it?
They turn a failed compliance check into specific remediation work and require checking the relevant test and affected systems first. This helps avoid guessing at a fix.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the vanta-mcp-plugin plugin — 3 skills shipped together

Good fit Use them when a Vanta test fails, when you have a test ID or Vanta URL, or when addressing requirements for SOC 2, ISO 27001, or HIPAA.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/vantainc/vanta-mcp-plugin/test-remediation
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add VantaInc/vanta-mcp-plugin --skill test-remediation
Clone the repo
git clone --depth 1 https://github.com/VantaInc/vanta-mcp-plugin

Made for: Claude Code.

Or install vanta-mcp-plugin, the plugin that ships this one along with the rest of its 3 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for test-remediation

README.md
[![agentmods](https://agentmods.dev/badge/skills/vantainc/vanta-mcp-plugin/test-remediation.svg)](https://agentmods.dev/skills/vantainc/vanta-mcp-plugin/test-remediation)
Your own site
<a href="https://agentmods.dev/skills/vantainc/vanta-mcp-plugin/test-remediation"><img src="https://agentmods.dev/badge/skills/vantainc/vanta-mcp-plugin/test-remediation.svg" alt="Measured on agentmods" height="20"></a>
Per session 62 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 711 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00062 $0.00711
Opus 5 $0.00031 $0.00356
Sonnet 5 $0.00012 $0.00142
Haiku 4.5 $0.00006 $0.00071

Measured 8d ago against content hash 529a4db1a077, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

test-remediation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/test-remediation/SKILL.md · 36 lines

How it starts

The opening of the file, as written. The whole thing — 36 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Vanta Test Remediation

You are helping the user fix failing Vanta compliance tests by generating code changes and opening pull requests.

Key Tools

  • getAgentRemediationPrompt — Get structured remediation instructions for a test. Returns a system prompt, user message, and entity context. Always call this before attempting any fix.
  • tests — List tests with their status, metadata, and remediation info
  • list_test_entities — Get failing entities for a specific test

Response Principles

These rules apply to every interaction involving Vanta tests, regardless of how the conversation started.

  1. Never dead-end. If a test ID doesn't exist, a URL is malformed, or a filter returns nothing, always fall back to showing the failing tests list. Fuzzy-match against the user's input when possible. The user should always have a next step.
  2. Always call getAgentRemediationPrompt before suggesting a fix. Never rely on general LLM knowledge for remediation. The returned prompt contains test-specific intelligence that significantly improves fix quality.
  3. Be transparent about what you can and can't do. Don't generate code if you can't find matching code files. Tell the user directly when something requires manual action.
  4. Web search for non-code fixes. getAgentRemediationPrompt may return guidance instead of code. Existing remediation instructions are often stale. Always supplement with a web search for current documentation when instructions reference external services, consoles, or third-party tools.
  5. Suggest the next action. After every response, offer a clear next step: "Want me to fix it?", "Run /vanta:fix-test <id>", "Want to try the next test?"
  6. Show cost implications. Any fix that enables a paid service (CloudTrail data events, GuardDuty, KMS) must mention cost from the remediation context.
  7. Keep it scannable. Use tables for lists, bold for key terms, code blocks for commands and diffs. Users are scanning, not reading paragraphs.
  8. Never weaken security configurations. Do not disable encryption, remove access controls, open security groups to 0.0.0.0/0, or take any action that trades security for convenience. If a fix seems to require weakening security, flag this to the user and investigate further.

Read the full file on GitHub · 36 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 36 lines · 62 tokens per session scan A 529a4db1a077

Subscribe to this mod's changes

test-remediation is a skill published in the GitHub repository VantaInc/vanta-mcp-plugin (4 stars, last pushed 3mo ago), licensed MIT. It adds 62 tokens to every session and 711 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

specification-writing

A workflow for writing complete patent specifications from patent claims and an invention disclosure. It adapts the document to a chosen jurisdiction, such as the US, Europe, or China.

wanshuiyin/Auto-claude-code-research-in-sleep · 49 tokens

regulatory-research-fallback

Fallback workflow for regulatory research when web extraction tools fail on government PDFs.

HKUDS/OpenSpace · 20 tokens

x-scorecard

OpenSSF Scorecard for assessing open source project security. Check security best practices and compliance. Dependency: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.

x-cmd/x-cmd · 57 tokens

memstack-business-gdpr

Use this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR…

cwinvestments/memstack · 121 tokens

gesellschaftsrechtliche-satzungen-agb

Für Gesellschaftsrechtliche Satzungen AGB Abgrenzung: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt. Fachgebiet: AGB-Recht-Prüfer. Route: gesellschaftsrechtliche-satzungen-agb.

Klotzkette/claude-fuer-deutsches-recht · 69 tokens

nda-review

Use when the user uploads or pastes a non-disclosure agreement and asks for review, redline, risk assessment, or a recommendation on whether to sign. Identifies missing standard protections, one-sided or unusual provisions, and operational issues; produces a structured report with severity ratings and citations to…

LegalQuants/lq-ai · 79 tokens