| name | evidence-generation |
| title | Enterprise Evidence Pack Generation |
| description | Use this skill when generating ISO 27001 or NIST SP 800-53 audit evidence packs, compliance reports, evidence narratives, reviewer-ready control matrices, or when the user asks about audit evidence, compliance evidence, evidence packages, audit documentation, or ISO/NIST evidence. |
| author | allsmog |
| author_url | https://github.com/allsmog/shinsa-plugin/tree/main/skills/evidence-generation |
| license | MIT |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | cybersecurity |
| language | en |
Enterprise Evidence Pack Generation
Purpose
Transform Shinsa assessment artifacts into an enterprise-grade evidence pack for Security and GRC reviewers. The pack must be defensible, reviewable, exportable, and honest about uncertainty. It supports an audit or control review; it does not replace a human auditor.
Inputs
Read persisted artifacts first:
assessment-plan.md
scope.md
applicability.json and applicability.md
domains/*.json and domains/*.md
reviews/round-*/*.json and reviews/round-*/*.md
synthesis/evidence-index.json
synthesis/control-matrix.json
shinsa-state.json when present
Do not rescan the repository during synthesis unless the orchestrator explicitly asks for a reconciliation pass. The evidence pack should explain what the persisted artifacts support.
Required Report Sections
The canonical report is shinsa-output/runs/<assessment_id>/synthesis/compliance-report.md. It must include these top-level sections:
## Assessment Metadata
## Executive Summary
## Control Matrix
## Findings
## Evidence Index
## Reviewer Notes
## Unresolved Risks
## Limitations
## What To Do Next
## Human Sign-Off
Assessment metadata must include:
- timestamp placeholder or ISO-8601 timestamp
- plugin version
- target path
- target commit placeholder or commit hash
- assessment mode
- standards assessed
- scope exclusions
- methodology
- raw artifact references
Per-Control Requirements
Every control row and narrative must include:
- control ID and title
- status
- confidence score
confidence_rationale
evidence_quality