ワンクリックで
gap-analysis
Run a full SOC 2 gap analysis against the connected AWS account and present findings with remediation guidance.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Run a full SOC 2 gap analysis against the connected AWS account and present findings with remediation guidance.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
Deep code scan for AI security issues — prompt injection, PII in prompts, hardcoded keys, unguarded agents.
Run AI governance checks across cloud accounts and code repos — ISO 42001, EU AI Act, NIST AI RMF compliance.
Scan cloud accounts and GitHub repos to discover AI/ML services and build an AI system inventory.
Walk staged changes against the engineering principles checklist and report pass/fail per principle. Run before any non-trivial commit. Catches doc drift, stub functions, single-region defaults, missing framework mappings, and other regressions before they ship.
Generate a public-facing security trust page from scan data. Produces a single deployable index.html that shows compliance framework scores, security policies, infrastructure overview, and data protection posture. Deployable to S3, Vercel, Netlify, or GitHub Pages.
Paste a vendor's domain. Get a security risk assessment in 60 seconds.
| name | gap-analysis |
| description | Run a full SOC 2 gap analysis against the connected AWS account and present findings with remediation guidance. |
| user-invocable | true |
You are performing a SOC 2 gap analysis for a semi-technical founder.
Read shasta.config.json for python_cmd. Use that for all commands (shown as <PYTHON_CMD>).
<PYTHON_CMD> -c "
from shasta.db.schema import ShastaDB
db = ShastaDB(); db.initialize()
scan = db.get_recent_scan(max_age_minutes=60)
if scan:
print(f'RECENT_SCAN|{scan.id}|{scan.completed_at}|{len(scan.findings)} findings')
else:
print('NO_RECENT_SCAN')
"
If recent scan exists, tell the user and ask if they want to reuse it. If reusing:
<PYTHON_CMD> -c "
from shasta.db.schema import ShastaDB
from shasta.reports.generator import save_markdown_report, save_html_report
db = ShastaDB(); db.initialize()
scan = db.get_latest_scan()
md = save_markdown_report(scan)
html = save_html_report(scan)
print(f'Markdown: {md}')
print(f'HTML: {html}')
print(f'Based on scan from {scan.completed_at}')
"
If running fresh:
<PYTHON_CMD> -c "
from shasta.config import get_aws_client
from shasta.scanner import run_full_scan
from shasta.reports.generator import save_markdown_report, save_html_report
from shasta.db.schema import ShastaDB
client = get_aws_client(); client.validate_credentials()
print('Running full compliance scan...')
scan = run_full_scan(client)
db = ShastaDB(); db.initialize(); db.save_scan(scan)
md = save_markdown_report(scan)
html = save_html_report(scan)
print(f'Markdown: {md}')
print(f'HTML: {html}')
print(f'Scan completed at {scan.completed_at}')
"
/remediate for specific findings