Audit Soc2 — Security skill for Claude Code
Audit SOC 2 Type II readiness across the codebase.
How to install Audit Soc2
Installs to ~/.claude/skills/macanderson-agent-harness-audit-soc2/SKILL.md
mkdir -p ~/.claude/skills/macanderson-agent-harness-audit-soc2 && curl -fsSL https://raw.githubusercontent.com/macanderson/agent-harness/HEAD/commands/audit-soc2.md -o ~/.claude/skills/macanderson-agent-harness-audit-soc2/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Audit Soc2 does
description: Audit SOC 2 Type II readiness across the codebase. Checks access controls, audit logging, secrets management, encryption, and change management. Outputs a scored HTML report. allowed-tools: Bash, Read, Grep, Glob, Agent, TodoWrite, ToolSearch, TaskCreate, TaskGet, TaskList, TaskOutput, TaskStop, TaskUpdate, mcp__claude_ai_Linear__list_issues, mcp__claude_ai_Linear__save_issue, mcp__claude_ai_Linear__list_issue_labels, mcp__claude_ai_Linear__list_projects, mcp__claude_ai_Linear__
Alternatives in Security
- Engage.Exploit — Execute Phase 4 - Exploitation and Access Establishment 348 ★
- Data Viz Audit — Audit a data visualization for chart type selection, accessible color palette, annotations, and anti-patterns 309 ★
- Migration Agent — Plans a token migration (format, tool, naming or tier): chains token-audit and naming-audit, builds the transf 194 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Audit Tenancy
Audit multi-tenancy enforcement — RLS policies, withTenantDb usage, query-time tenant filters, and cross-tenan
Vibe Audit
Security scanner for AI-built apps. Catches hardcoded secrets, injection vulnerabilities, missing rate limits,
Audit E2e
Audit end-to-end test coverage of critical Playwright paths. Identifies missing flows, flaky tests, slow suite
Observability Audit
Observability / instrumentation audit: structured logging quality, log levels & correlation IDs, secrets/PII i
MCP Intercepter
Transparent proxy + enterprise gateway for MCP: audit logging, tool allow/deny policy, secrets/PII redaction,
Content Audit Skill
Post-publication content maintenance skill for Claude Code — GEO compliance auditing, freshness decay detectio
Related Agents
SecOps Orchestrator
Orchestrates LibreSecOps Grok skills for defensive security — threat model, defaults, deps, secrets, access, l
06 Release Readiness.Agent
Release gate decision agent. Consumes all QA pipeline outputs (plan, execution results, defect triage, metrics
Compliance Mapper
Delegates to this agent when the user wants to map penetration-test findings to compliance frameworks — PCI DS