Compliance Evidence Skills — DevOps skill for Claude Code
Claude Code skills for compliance evidence: a plugin with five skills that pack GitHub, AWS and Microsoft 365 exports with SHA-256 manifests, map them to ISO 27001 and SOC 2 control identifiers, and d.
How to install Compliance Evidence Skills
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open basitalisandhu/compliance-evidence-skills and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Compliance Evidence Skills does
Claude Code skills for compliance evidence: a plugin with five skills that pack GitHub, AWS and Microsoft 365 exports with SHA-256 manifests, map them to ISO 27001 and SOC 2 control identifiers, and draft auditor narratives that cite evidence or say not assessable. Tested standard-library scripts work offline.
Alternatives in DevOps
- AWS Skills Pack — AWS cloud services skills 1.6k ★
- Proxy — route Claude Code requests through multiple upstream providers (OpenCode Go, OpenCode Zen, and AWS Bedrock) wi 957 ★
- Skill — Web extraction engine with antibot bypass 549 ★
README
Claude Code skills for compliance evidence
**Compliance evidence skills for Claude Code: build integrity-checked evidence packs from GitHub, AWS and Microsoft 365 exports, map them to ISO 27001 and SOC 2 control identifiers, and draft auditor narratives that cite evidence or say not assessable.**
compliance-evidence-skills is a Claude Code plugin marketplace with one plugin, `compliance-evidence`, holding five skills. Each skill is a fixed procedure plus a tested Python script (standard library only). The skills tell Claude which read-only exports to take and which permission each needs; the scripts then work on the saved files: hash them into a pack with a manifest, map them to control identifiers, and draft narratives in which every evidence statement cites a file and field.
It is written for the people who prepare an ISO 27001 or SOC 2 assessment in a small or mid-sized organisation: engineers and IT administrators who own GitHub, AWS and Microsoft 365, and the security or compliance lead who has to hand evidence to an assessor. It exists because evidence is still mostly screenshots and loose exports with no record of who took them, when, or with which command, and because tools that turn an API error into a control failure (or a missing file into a pass) cost hours of argument during fieldwork. These skills keep three result states only, `supported`, `contradicted` and `not assessable`, and never mark a control supported without a cited evidence file and field.
No network access from the scripts, no telemetry. All inputs are exports already on disk.
/plugin marketplace add basitalisandhu/compliance-evidence-skills
/plugin install compliance-evidence@compliance-evidence-skills
Demo

Generated from the committed fixtures by [`scripts/render_demo.py`](scripts/render_demo.py); run `python3 scripts/render_demo.py` to
Related Skills
Reliability Review
Read-only AWS reliability & resilience review; doubles as SOC 2 Availability evidence.
SOC Investigation Toolkit
SOC/IR toolkit for Microsoft Sentinel, Defender XDR, Entra and Purview, with CrowdStrike, Slack and Azure DevO
Transilience Mdr Rainer
Claude Code skills for AWS MDR workflows: CloudTrail collection, evidence packaging, baselining, detection eng
Incident Triage Agent
An AI-powered agent built with AWS Bedrock, Claude, and Strands Agents SDK that monitors system alerts, connec
Certification Mock Exam
Claude skill that builds timed, offline HTML mock exams for professional IT certifications (Databricks, Micros
PR Visual Impact
Given an uncommitted diff / branch / PR, produce a user-facing impact map — what WILL change visually on Bazod
Related Agents
Compliance Mapper
Delegates to this agent when the user wants to map penetration-test findings to compliance frameworks — PCI DS
Compliance Automation Specialist
Use this agent when you need to automate compliance processes for SOC 2, ISO 27001, GDPR, HIPAA, and other ent
Agency Compliance Auditor
Technical compliance auditor — SOC 2, ISO 27001, GDPR, ČNB ECSP, AML. Use pro OneFlow internal compliance post