Skip to main content
amurthygithub
GitHub creator profile

amurthygithub

Repository-level view of 19 collected skills across 2 GitHub repositories.

skills collected
19
repositories
2
updated
2026-06-12
repository explorer

Repositories and representative skills

nist-800-53-rmf
compliance-officers-131041

Perform NIST SP 800-53 Rev 5 control selection, implementation, assessment, and continuous monitoring using the NIST Risk Management Framework (SP 800-37 Rev 2 RMF). Covers FIPS 199 categorization, baseline selection (Low/Moderate/High), 800-53A assessment procedures, control inheritance (FedRAMP/shared services/cloud), SAR/POA&M and ATO determination. Activate when performing RMF Step 2 (categorize), Step 3 (select), Step 4 (implement), Step 5 (assess), Step 6 (authorize), or Step 7 (monitor); when mapping SOC 2 / ISO 27001 / PCI / HIPAA to 800-53; when planning or executing a FedRAMP authorization; or when responding to a federal/DoD assessment.

2026-06-12
audit-category-pointer
compliance-officers-131041

Pointer to a library of 10 specialized audit/compliance skills — ISACA, COSO, AICPA SOC, Audit Workpapers, NIST 800-53/RMF, NIST CSF 2.0, HIPAA Security Rule, PCI DSS, SOX §302 disclosure controls, and FedRAMP cloud authorization. Use when working on IT audit, internal controls, SOC reporting, audit documentation, federal control baselines, cybersecurity maturity, HIPAA security, PCI DSS payment-security, SOX §302 disclosure-controls certification, or FedRAMP cloud-authorization tasks.

2026-06-12
fedramp-authorization
compliance-officers-131041

FedRAMP cloud-authorization program (Rev 5) — the FedRAMP Authorization Act of 2022 (44 U.S.C. 3607-3616), OMB M-24-15, the Rev 5 baselines (Low 156 / Moderate 323 / High 410 / LI-SaaS 156, tailored from NIST SP 800-53 Rev 5), the SSP/SAP/SAR/POA&M package, the 3PAO assessment, monthly Continuous Monitoring, and the FedRAMP 20x direction. Two load-bearing facts: FedRAMP baselines ARE tailored 800-53 controls (not a separate catalog — that is nist-800-53-rmf), and the current authorizer is the statutory FedRAMP Board, NOT the retired JAB. Use to categorize a system (FIPS 199 high-water mark) and select a baseline, scope an authorization package, plan a 3PAO assessment, run monthly ConMon and POA&M, or determine LI-SaaS eligibility. Activate when the user says 'FedRAMP', 'cloud authorization', 'ATO', 'P-ATO', 'agency authorization', '3PAO', 'SSP', 'SAR', 'POA&M', 'ConMon', 'continuous monitoring', 'Li-SaaS', 'FedRAMP baseline', 'FedRAMP Moderate/High', 'FedRAMP 20x', 'authorization to operate', or 'cloud servic

2026-06-11
audit-workpapers
accountants-and-auditors-132011

Create, organize, evaluate, and review audit workpapers per PCAOB AS 1215, AS 2315, AS 1105, and AS 3105, AICPA AU-C 230, ISA 230, COSO ICIF-2013, and ISACA ITAF. Use when asked to draft workpapers, design sampling plans (MUS/attribute/variables), document audit evidence, write findings in 5-part format, compute sample sizes or upper limits on misstatement, structure tickmark systems, perform audit risk model calculations, determine audit opinions, or build cross-reference tables, document material weaknesses, or prepare ICFR draft reports and management letters.

2026-06-11
sox-302-disclosure-controls
accountants-and-auditors-132011

SOX §302 Disclosure Controls & Procedures (DC&P) certification — 15 U.S.C. 7241; SEC Rules 17 CFR 240.13a-14 / 240.13a-15; Reg S-K Items 307, 308. The 6-element officer certification (PEO + PFO), quarterly DC&P evaluation, and the load-bearing DC&P-vs-ICFR and §302-vs-§404 boundaries. Use to draft or review a §302 certification, conclude on DC&P effectiveness after a material weakness, determine a newly-public filer's certification obligations, design a multi-entity sub-certification cascade, or scope the non-financial disclosure universe (risk factors, legal, MD&A, cyber 8-K). Activate when the user says 'SOX 302', 'Section 302', 'disclosure controls and procedures', 'DC&P', 'officer certification', '13a-14', '13a-15', 'Item 307', 'Item 308', 'disclosure committee', 'sub-certification', or 'PEO/PFO certification'.

2026-06-11
coso-internal-controls
accountants-and-auditors-132011

Perform COSO 2013 ICIF-based internal control assessments including SOX 404 ICFR evaluation, PCAOB AS 2201 top-down audit, deficiency classification, walkthrough procedures, Risk and Control Matrix documentation, entity-level and process-level control assessment, COSO 2017 ERM integration, and emerging technology controls. Activate for COSO framework application, ICFR assessment, SOX 404 compliance, internal control deficiency evaluation, or PCAOB AS 2201 audit procedures.

2026-06-11
pci-dss-assessment
compliance-officers-131041

PCI DSS v4.0.1 (Payment Card Industry Data Security Standard, Requirements and Testing Procedures): 6 goals, 12 principal requirements, 63 sections, 249 main-body defined requirements, plus appendices A-G. Serves BOTH an auditee path (merchant/service-provider scoping, SAQ selection, self-assessment) and an assessor path (QSA/ISA workflow, ROC vs AOC, customized-approach and compensating-control validation). Use to scope a cardholder data environment (CDE), select among the 10 SAQ types, walk Requirements 1-12, distinguish the defined vs customized approach, build a compensating-control worksheet, or confirm v4.0.1 currency. Activate when the user says 'PCI DSS', 'PCI compliance', 'cardholder data', 'CDE', 'SAQ', 'ROC', 'AOC', 'QSA', 'network security controls', 'account data', 'segmentation', 'customized approach', or 'compensating control'.

2026-06-11
hipaa-security-rule
compliance-officers-131041

HIPAA Security Rule (45 CFR Part 164, Subpart C): 22 standards across administrative (9), physical (4), technical (5), organizational (2), and policies/documentation (2) families, with Required vs Addressable implementation specifications. Serves BOTH auditor and auditee personas. Use to run a §164.308(a)(1)(ii)(A) risk analysis, work addressable-specification dispositions per §164.306(d)(3), check a BAA against §164.314(a)(2)(i), build an OCR-readiness matrix across all 22 standards, or right-size safeguards via the §164.306(b)(2) flexibility factors. Activate when the user says 'HIPAA Security Rule', 'ePHI', '45 CFR 164', 'addressable specification', 'business associate agreement', 'BAA', 'OCR audit', 'security risk analysis', 'HIPAA safeguards', or 'recognized security practices'.

2026-06-11
Showing top 8 of 12 collected skills in this repository.
agentreview
software-quality-assurance-analysts-and-testers

Four-agent consensus review of a PR (correctness / security / observability / style). 3-of-4 APPROVE = ship. Posts a single structured comment. Orchestrator on a larger model, sub-agents on a smaller model.

2026-06-01
handoff
software-developers

Snapshot the active ticket session (done / tried-and-failed / next step + git state) into a gitignored .claude/handoff-notes.md so a fresh agent resumes without re-walking dead ends.

2026-06-01
linear
software-developers

CLI for <TRACKER> ticket operations (create epic / story / task, update status, show, list) — no committed secrets, reads $<TRACKER>_API_KEY from env. The most-replaceable skill in this template — swap the API layer for any tracker.

2026-06-01
promote
software-developers

Promote <STAGING_BRANCH> → <DEFAULT_BRANCH> (production). USER-INVOKED ONLY. Opens a promote PR, posts a "promotion ready" digest, and waits for the user's explicit confirmation before merging. Tags + drafts a release on merge.

2026-06-01
ship
software-developers

Ship the current feature branch to <STAGING_BRANCH> — commit any uncommitted changes, push (triggers pre-push hook + agent review), open PR if missing, wait for consensus, merge to <STAGING_BRANCH> unless blockers or danger-zone hits.

2026-06-01
triage-review
software-quality-assurance-analysts-and-testers

Classify the latest /agentreview consensus comment via a 3-agent council (Cost / Correctness / Risk lenses). Prints a report sorting each finding into fix / skip / false-positive / human-required. Read-only — no Edit, no push, no tracker write.

2026-06-01
work-on
software-developers

Start work on a <TRACKER> ticket — fetch its details, branch off <STAGING_BRANCH> with a conventional name, acquire a per-branch lock, set status to In Progress, and load context into a file the user's session can read.

2026-06-01
Showing 2 of 2 repositories
All repositories loaded
amurthygithub Agent Skills | SkillsMP