basitalisandhu

Compliance Evidence Skills — DevOps skill for Claude Code

DevOps community

Claude Code skills for compliance evidence: a plugin with five skills that pack GitHub, AWS and Microsoft 365 exports with SHA-256 manifests, map them to ISO 27001 and SOC 2 control identifiers, and d.

How to install Compliance Evidence Skills

This entry records only its repository, not the path inside it, so there is no exact command to give. Open basitalisandhu/compliance-evidence-skills and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Compliance Evidence Skills does

Claude Code skills for compliance evidence: a plugin with five skills that pack GitHub, AWS and Microsoft 365 exports with SHA-256 manifests, map them to ISO 27001 and SOC 2 control identifiers, and draft auditor narratives that cite evidence or say not assessable. Tested standard-library scripts work offline.

Alternatives in DevOps

  • AWS Skills Pack — AWS cloud services skills 1.6k ★
  • Proxy — route Claude Code requests through multiple upstream providers (OpenCode Go, OpenCode Zen, and AWS Bedrock) wi 957 ★
  • Skill — Web extraction engine with antibot bypass 549 ★

README

Claude Code skills for compliance evidence

**Compliance evidence skills for Claude Code: build integrity-checked evidence packs from GitHub, AWS and Microsoft 365 exports, map them to ISO 27001 and SOC 2 control identifiers, and draft auditor narratives that cite evidence or say not assessable.**

compliance-evidence-skills is a Claude Code plugin marketplace with one plugin, `compliance-evidence`, holding five skills. Each skill is a fixed procedure plus a tested Python script (standard library only). The skills tell Claude which read-only exports to take and which permission each needs; the scripts then work on the saved files: hash them into a pack with a manifest, map them to control identifiers, and draft narratives in which every evidence statement cites a file and field.

It is written for the people who prepare an ISO 27001 or SOC 2 assessment in a small or mid-sized organisation: engineers and IT administrators who own GitHub, AWS and Microsoft 365, and the security or compliance lead who has to hand evidence to an assessor. It exists because evidence is still mostly screenshots and loose exports with no record of who took them, when, or with which command, and because tools that turn an API error into a control failure (or a missing file into a pass) cost hours of argument during fieldwork. These skills keep three result states only, `supported`, `contradicted` and `not assessable`, and never mark a control supported without a cited evidence file and field.

No network access from the scripts, no telemetry. All inputs are exports already on disk.

/plugin marketplace add basitalisandhu/compliance-evidence-skills
/plugin install compliance-evidence@compliance-evidence-skills

Demo

![Terminal output of compliance-evidence pack verify catching a changed file in the committed tampered test pack](docs/demo.svg)

Generated from the committed fixtures by [`scripts/render_demo.py`](scripts/render_demo.py); run `python3 scripts/render_demo.py` to