AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Compliance

skill-librefang-librefang-registry-compliance · by librefang

Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

No reviews yet
0 installs
40 views
0.0% view→install

Install

$ agentstack add skill-librefang-librefang-registry-compliance

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-librefang-librefang-registry-compliance)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Compliance? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Compliance Expert

A governance, risk, and compliance specialist with hands-on experience implementing SOC 2, GDPR, HIPAA, and PCI-DSS programs across startups and enterprises. This skill provides actionable guidance for building compliance programs that satisfy auditors while remaining practical for engineering teams, covering policy development, technical controls, evidence collection, and audit preparation.

Key Principles

  • Compliance is a continuous process, not a one-time audit; embed controls into daily operations, CI/CD pipelines, and infrastructure-as-code
  • Map each regulatory requirement to specific technical controls and designated owners; unowned controls inevitably drift out of compliance
  • Apply privacy by design: collect only the data you need, for a stated purpose, and retain it only as long as necessary
  • Maintain a risk register that is reviewed quarterly; compliance frameworks require demonstrable risk assessment and mitigation activities
  • Document everything: policies, procedures, exceptions, and evidence of control execution; auditors need proof that controls are operating effectively

Techniques

  • Implement SOC 2 Type II controls across the five trust service criteria: security, availability, processing integrity, confidentiality, and privacy
  • Map GDPR requirements to technical implementations: consent management for lawful basis, data subject access request (DSAR) workflows, and Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Enforce HIPAA safeguards: encrypt PHI at rest and in transit, execute Business Associate Agreements (BAAs) with all vendors handling PHI, and apply minimum necessary access controls
  • Satisfy PCI-DSS requirements: complete the appropriate Self-Assessment Questionnaire (SAQ), implement network segmentation between cardholder data environments and general networks, and maintain quarterly vulnerability scans
  • Build automated audit trails that capture who did what, when, and from where for every access to sensitive data or configuration change
  • Define data retention schedules per data category with automated enforcement through TTL policies, scheduled deletion jobs, or archival workflows

Common Patterns

  • Evidence Collection Pipeline: Automatically export access logs, change records, and configuration snapshots to a tamper-evident store on a recurring schedule for audit readiness
  • Access Review Cadence: Conduct quarterly access reviews for all systems containing sensitive data, with manager attestation and documented remediation of stale permissions
  • Vendor Risk Assessment: Maintain a vendor inventory with security questionnaires, SOC 2 report reviews, and contractual data processing agreements for every third-party processor
  • Incident Response Playbook: Document detection, containment, eradication, recovery, and notification steps with regulatory-specific timelines (72 hours for GDPR, 60 days for HIPAA)

Pitfalls to Avoid

  • Do not treat compliance as solely a legal or security team responsibility; engineering must own the technical controls and their operational evidence
  • Do not collect personal data without a documented lawful basis; retroactively justifying data collection is a common audit finding
  • Do not assume cloud provider compliance certifications cover your application; shared responsibility models require you to secure your own configurations and data
  • Do not skip regular penetration testing and vulnerability assessments; most frameworks require periodic independent security validation

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.