with one click
shasta
shasta contains 23 collected skills from kkmookhey, with repository-level occupation coverage and site-owned skill detail pages.
Skills in this repository
Deep code scan for AI security issues — prompt injection, PII in prompts, hardcoded keys, unguarded agents.
Run AI governance checks across cloud accounts and code repos — ISO 42001, EU AI Act, NIST AI RMF compliance.
Scan cloud accounts and GitHub repos to discover AI/ML services and build an AI system inventory.
Walk staged changes against the engineering principles checklist and report pass/fail per principle. Run before any non-trivial commit. Catches doc drift, stub functions, single-region defaults, missing framework mappings, and other regressions before they ship.
Generate a public-facing security trust page from scan data. Produces a single deployable index.html that shows compliance framework scores, security policies, infrastructure overview, and data protection posture. Deployable to S3, Vercel, Netlify, or GitHub Pages.
Paste a vendor's domain. Get a security risk assessment in 60 seconds.
Launch the Shasta web dashboard to view compliance posture, findings, controls, and risk register in a browser.
Run a HIPAA Security Rule gap analysis against your cloud environment.
Auto-fill security questionnaires (SIG Lite, CAIQ, Enterprise) using scan data and policy documents.
Connect to an Azure subscription, validate credentials, and discover what services are in use.
Run SOC 2 compliance checks against connected cloud accounts (AWS and/or Azure) and display findings.
Run an ISO 27001:2022 Annex A gap analysis against your AWS environment.
Create and manage a SOC 2 risk register — auto-seeds from scan findings, tracks treatment, produces audit evidence.
Run a full SOC 2 gap analysis against the connected AWS account and present findings with remediation guidance.
Get interactive remediation guidance for compliance findings, including Terraform code and step-by-step instructions.
Generate professional compliance reports (Markdown, HTML, PDF) from the latest scan data.
Connect to an AWS account, validate credentials, and discover what services are in use.
Collect and store point-in-time compliance evidence snapshots for audit trail.
Run an automated security assessment — find internet-exposed resources, attack paths, and network vulnerabilities.
Generate SOC 2 compliance policy documents tailored to your company.
Run a periodic IAM access review — lists all users, permissions, activity, and flags issues. Required quarterly for SOC 2.
Generate a Software Bill of Materials (SBOM) from your AWS environment and scan for vulnerable/compromised packages.
Generate a personalized threat advisory based on your tech stack — what CVEs, breaches, and supply chain attacks matter to YOU.