Install
$ agentstack add skill-vaquarkhan-compliance-agent-skills-using-compliance-agent-skills ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Using Compliance Agent Skills
Overview
This skill is the routing and orchestration layer for the compliance-agent-skills repository. It teaches the agent how to discover, load, and chain specialized skills without inventing regulatory steps. The repository implements progressive disclosure via Pydantic AI SkillsCapability: only load skills whose scope matches the user's task.
The compliance agent enforces a mandatory PHI redaction gate (redaction.py / Presidio) before any user text reaches the LLM. Skills operate on redacted input; authorized outputs may be deanonymized via the deanonymize_response tool.
Lifecycle commands (user-facing or scripted):
| Command | Purpose | | --- | --- | | /scope | Define in-scope systems, data flows, frameworks, and exclusions | | /audit | Execute framework-specific control testing | | /evidence | Collect, hash, and package artifacts for auditors | | /remediate | Draft remediation plans with owners and deadlines | | /report | Produce executive and technical findings summaries |
When to Use
Use this skill when:
- The user asks a broad compliance question without naming a framework ("Are we compliant?")
- You need to select among framework skills (HIPAA, PCI-DSS, SOC 2, ISO 27001, NIST CSF, CCPA, FedRAMP, SOX, CMMC, GLBA)
- Configuring MCP servers (Playwright, Postgres, Slack, Presidio) for an audit run
- Starting a new engagement and defining scope before deep work
- Chaining skills (e.g., scope → PHI redaction → PCI script audit → evidence bundle)
- The user references presets or lifecycle commands (
/scope,/audit, etc.)
Do not use this skill when:
- The task maps cleanly to one specialized skill (load it directly)
- The user needs only PHI redaction configuration (use
hipaa-phi-redaction-pipeline) - The task is pure third-party vendor review (use
hipaa-baa-vendor-assessmentorvendor-third-party-risk)
Core Process
Execute the following steps in order for every new engagement.
Step 1: Intake and framework detection
- Parse the user request for:
- Framework signals: HIPAA (PHI, BAA), PCI-DSS (CDE, PAN, scripts), SOC 2 (TSC), ISO 27001 (Annex A, SoA), NIST CSF (Govern/Identify/Protect), CCPA/CPRA (DSAR, opt-out), FedRAMP (SSP, 800-53), SOX (ITGC, 404), CMMC (CUI, 800-171), GLBA (NPI, Safeguards)
- Artifact type: policy review, technical control test, incident, vendor assessment
- Environment: production vs staging, cloud provider, MCP availability
- If multiple frameworks apply, list them explicitly and propose a sequenced plan (scope first, then deepest-risk skill).
- Record engagement metadata: UTC timestamp, auditor/run ID, target systems, authorization to scan.
Step 2: Scope definition (/scope)
- Document in-scope:
- Systems, URLs, databases, MCP servers, identity providers
- Data classifications (ePHI, CHD/SAD, confidential processing data)
- Applicable regulations and TSC categories
- Document out-of-scope with rationale (reduces audit creep and false positives).
- Identify blocking dependencies: missing BAA, no scan authorization, Playwright MCP offline.
- Emit a scope artifact:
scope-{engagement-id}.jsonwith version and approver field.
Step 3: Skill routing matrix
Load exactly one primary skill per audit thread; add secondary skills only when scope requires:
| User intent | Primary skill | Common secondary skills | | --- | --- | --- | | Payment page / checkout scripts | pci-dss-script-audit | mcp-compliance-integration, soc2-evidence-collection | | CDE network / firewall | pci-dss-network-segmentation | access-control-identity-audit | | PHI in prompts / LLM pipeline | hipaa-phi-redaction-pipeline | hipaa-technical-safeguards | | Access controls, MFA, IAM | access-control-identity-audit | soc2-trust-services-criteria | | Log tampering / audit trails | audit-logging-integrity | hipaa-technical-safeguards | | SOC 2 control mapping | soc2-trust-services-criteria | soc2-evidence-collection | | Continuous monitoring | soc2-ccm-continuous-monitoring | compliance-as-code-governance | | LLM/cloud vendor legal | hipaa-baa-vendor-assessment | vendor-third-party-risk | | MCP server hardening | mcp-compliance-integration | access-control-identity-audit | | PCI encryption, PAN, key management | pci-dss-encryption-key-management | audit-logging-integrity | | HIPAA minimum necessary / de-id | hipaa-privacy-minimum-necessary | hipaa-phi-redaction-pipeline | | ISO 27001 Annex A / SoA | iso27001-annex-a-controls | soc2-trust-services-criteria | | NIST CSF 2.0 assessment | nist-csf-2-assessment | compliance-as-code-governance | | CCPA/CPRA consumer rights | ccpa-cpra-privacy-rights | hipaa-privacy-minimum-necessary | | FedRAMP cloud authorization | fedramp-moderate-baseline | nist-csf-2-assessment | | SOX ITGC / SOX 404 | sox-itgc-audit | access-control-identity-audit | | CMMC / CUI / defense | cmmc-nist-800-171 | fedramp-moderate-baseline | | GLBA / banking / fintech | glba-ffiec-financial-privacy | vendor-third-party-risk | | HITECH breach / OCR portal | hitech-breach-notification | breach-incident-response | | US state privacy (VCDPA, CPA, TX) | us-state-privacy-laws | ccpa-cpra-privacy-rights | | NIST AI RMF / AI governance | nist-ai-rmf-governance | nist-csf-2-assessment | | FERPA / EdTech / student records | ferpa-education-records | coppa-children-privacy | | COPPA / under-13 / child app | coppa-children-privacy | ferpa-education-records | | GDPR / EU transfers | gdpr-us-multinational | us-state-privacy-laws | | Breach / incident | breach-incident-response | audit-logging-integrity | | Policy-as-code / IaC | compliance-as-code-governance | soc2-evidence-collection |
- Call
load_skillfor the primary skill and follow its Core Process verbatim.
Step 4: MCP preset configuration
Before /audit, confirm MCP servers required by the loaded skill:
| MCP server | Typical use | Compliance relevance | | --- | --- | --- | | Playwright (@playwright/mcp) | DOM, headers, screenshots | PCI 6.4.3, 11.6.1; SOC 2 CC7.x | | Postgres | Baselines, inventory, evidence store | Script hashes, control status | | Slack | SOC alerts, approval workflows | Incident notification | | Presidio (custom or REST) | DLP entity detection | HIPAA §164.312(e), minimum necessary |
If a required MCP is unavailable, stop and document a blocking finding—do not substitute undocumented tools.
Step 5: Execute audit (/audit)
- Ensure upstream PHI redaction ran (agent default in
agent.py). - Execute the loaded skill's Core Process without skipping steps.
- Log each step completion with artifact IDs in UTC.
Step 6: Evidence packaging (/evidence)
- Collect artifacts from all executed skills.
- Apply SHA-256 to each file; record in manifest.
- Store with immutable audit ID suitable for QSA or SOC 2 auditor review.
- Cross-reference controls to evidence items (control ID → artifact path → hash).
Step 7: Remediation (/remediate)
- For each FAIL or UNKNOWN finding, draft:
- Root cause, compensating controls (if any), remediation owner, target date
- Residual risk if deferred
- Prioritize by regulatory severity (e.g., PCI IOC, HIPAA transmission gap, SOC 2 CC6.1 MFA gap).
Step 8: Report (/report)
- Produce:
- Executive summary: scope, frameworks, pass/fail counts, top risks
- Technical appendix: control-by-control status with evidence links
- Open items: remediation backlog with owners
- Deanonymize only for authorized recipients via
deanonymize_response; never include raw PHI in reports sent to unapproved channels.
Common Rationalizations
| Excuse the agent might generate | Required rebuttal | | --- | --- | | "I'll answer from general compliance knowledge without loading a skill." | Skills contain mandatory sequences and exit criteria. General knowledge bypasses verifiable evidence requirements. | | "Scope can be implied; no need for /scope." | Undefined scope causes false positives and audit failures. Scope artifacts are required for multi-framework engagements. | | "I'll load multiple primary skills in parallel without sequencing." | Parallel primary skills duplicate work and conflict on MCP usage. One primary skill per thread; secondaries only when scoped. | | "MCP is optional if I can curl the URL." | Specialized skills (e.g., PCI script audit) require documented MCP tools for rendered DOM and baselines. | | "Evidence can be summarized without hashes." | Auditors require integrity-verified artifacts (SHA-256 manifest). Summaries alone are insufficient. | | "Remediation can wait until after the report." | /report must include open findings and remediation owners for FAIL items. | | "I'll deanonymize tokens to make the report readable." | Deanonymization is authorization-gated. Redacted tokens in LLM context must not be reconstructed without approval. |
Red Flags
- Engagement proceeds without documented scope or scan authorization
- User text bypasses PHI redaction before reaching the model
- Agent invents control IDs or regulatory citations not in loaded skills
- Primary skill skipped in favor of generic advice
- Evidence bundle missing hashes or UTC timestamps
- Deanonymized PHI appears in Slack or unencrypted channels
- PCI IOC or breach indicators routed to
/reportwithout/remediateand incident skills
Verification
Do not mark this skill complete until all exit criteria are confirmed:
- [ ] Framework(s) identified and documented in scope artifact
- [ ]
/scopecompleted with in-scope/out-of-scope systems and data classifications - [ ] Primary skill selected via routing matrix and loaded successfully
- [ ] Required MCP servers confirmed available or blocking finding recorded
- [ ] PHI redaction gate confirmed active for all user-provided text
- [ ] Loaded skill's Core Process executed (not abbreviated)
- [ ]
/evidencemanifest includes SHA-256 for every artifact - [ ] FAIL/UNKNOWN findings have remediation entries with owners and dates
- [ ]
/reportdelivered with executive summary and evidence cross-reference - [ ] Deanonymization applied only where authorization is documented
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: vaquarkhan
- Source: vaquarkhan/compliance-agent-skills
- License: MIT
- Homepage: https://github.com/vaquarkhan/compliance-agent-skills#readme
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.