一键导入
compliance-agent-skills
compliance-agent-skills 收录了来自 vaquarkhan 的 30 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。
这个仓库中的 skills
Implements FTC COPPA (15 U.S.C. §6501–6506; 16 CFR Part 312) for operators of websites, apps, and AI agents directed to children under 13 or with actual knowledge of child users—verifiable parental consent, data minimization, retention, security, and third-party LLM/MCP subprocessors. Trigger when building consumer apps, chatbots, or agents used by children, auditing EdTech with under-13 users outside school official context, or reviewing parental consent flows and vendor DPAs. Do not use for FERPA school official deployments (use ferpa-education-records), HIPAA pediatric clinical data (use hipaa-technical-safeguards), or general teen users 13+ (use us-state-privacy-laws / ccpa-cpra-privacy-rights).
Implements FERPA (20 U.S.C. §1232g; 34 CFR Part 99) protections for student education records in EdTech, LMS integrations, and AI tutoring agents—school official exceptions, legitimate educational interest, directory information, parent/eligible student rights, and vendor DPAs. Trigger when K-12 or higher-ed systems process student records, deploying AI agents in classrooms, auditing EdTech subprocessors, or assessing LLM use with FERPA-regulated data. Do not use for HIPAA PHI in clinical settings (use hipaa-technical-safeguards), COPPA under-13 consumer apps without school context (use coppa-children-privacy), or general PII without education record nexus (use us-state-privacy-laws).
Implements NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1)—GOVERN, MAP, MEASURE, and MANAGE functions—for trustworthy AI systems including LLM agents, MCP toolchains, and automated compliance workflows. Trigger when assessing AI governance, model risk, agent trustworthiness, GenAI deployment controls, or harmonizing AI RMF with NIST CSF 2.0 and ISO 42001 concepts. Do not use for general cybersecurity without AI scope (use nist-csf-2-assessment), HIPAA PHI controls alone (use hipaa-technical-safeguards), or EU AI Act (out of scope—use gdpr-us-multinational for privacy overlap only).
Meta entry skill for the USA compliance agent repository. Routes tasks to HIPAA, HITECH, PCI-DSS, SOC 2, ISO 27001, NIST CSF 2.0, CCPA/CPRA, US state privacy, GDPR, FedRAMP, SOX, CMMC, and GLBA skills; configures presets, MCP servers, and the audit lifecycle (/scope, /audit, /evidence, /remediate, /report). Trigger when starting any compliance engagement, choosing which skill to load, onboarding a new auditor, or orchestrating multi-framework workflows. Do not use when a specific framework skill already matches the task (load that skill directly instead).
Implements GDPR compliance workflows for US-headquartered multinationals—EU/EEA/UK data subjects, Articles 5-7 lawful basis, Article 30 records of processing, Article 32 security, Articles 33-34 breach notification (72 hours), Article 35 DPIA, Standard Contractual Clauses, EU-US Data Privacy Framework adequacy, and DPA/subprocessor governance for agent/LLM cross-border transfers. Trigger when US companies process EU residents' data, deploying agents in EU regions, assessing LLM vendor international transfers, or preparing RoPA/DPIA for multinational privacy programs. Do not use for US state laws only (use us-state-privacy-laws or ccpa-cpra-privacy-rights), HIPAA PHI (use hipaa-technical-safeguards), or UK-only post-Brexit without EU scope (note UK GDPR parallels in references).
Implements HITECH Act breach notification depth beyond baseline HIPAA—42 U.S.C. §17921–17923, ARRA Title XIII Subtitle D, OCR breach reporting portal workflows, 500+ individual media/HHS rules, business associate direct liability, encryption/unsecured PHI safe harbor analysis, and accounting of disclosures for breaches involving agent/LLM/MCP systems. Trigger when conducting HITECH-specific breach determinations, preparing OCR portal submissions, analyzing BA liability for LLM vendors, or auditing breach accounting and penalty exposure. Do not use for general incident containment (use breach-incident-response first), routine HIPAA Security Rule controls (use hipaa-technical-safeguards), or California CPRA consumer rights (use ccpa-cpra-privacy-rights).
Implements comprehensive US state comprehensive privacy law assessments—Virginia VCDPA (Va. Code §59.1-575), Colorado CPA (C.R.S. §6-1-1301), Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, Iowa ICDPA, Delaware DPDPA, New Jersey, and harmonized multi-state consumer rights programs—for agent/LLM data flows, opt-out, DSAR, and data protection assessments. Trigger when operating nationally beyond California CPRA, mapping state-by-state obligations, building unified US privacy programs, or auditing agent systems for VCDPA/CPA-style rights. Do not use for California-only CPRA (use ccpa-cpra-privacy-rights), HIPAA PHI (use hipaa-privacy-minimum-necessary), or EU GDPR (use gdpr-us-multinational).
Configures and validates the Presidio-based PHI redaction pipeline—DLP entity detection, reversible tokenization before LLM ingestion, and authorized deanonymization—integrated with redaction.py and the compliance agent. Trigger when ePHI may appear in prompts, implementing minimum-necessary LLM access, tuning entity types, or auditing redaction effectiveness. Do not use for HIPAA access control design (use hipaa-technical-safeguards) or legal BAA review (use hipaa-baa-vendor-assessment).
Implements CMMC 2.0 Level 2 assessments aligned to NIST SP 800-171 Revision 2 (110 security requirements across 14 families) for Controlled Unclassified Information (CUI) protection in the Defense Industrial Base (DIB), including SPRS score self-assessment, POA&M management, and government contract flow-down obligations under DFARS 252.204-7012/7019/7020. Trigger when preparing for CMMC Level 2 certification, calculating SPRS scores, auditing CUI enclaves, or mapping 800-171 practices to cloud and on-prem implementations. Do not use for FedRAMP Moderate federal cloud authorization (use fedramp-moderate-baseline), SOX financial ITGCs (use sox-itgc-audit), or HIPAA PHI workflows (use hipaa-technical-safeguards).
Implements FedRAMP Moderate baseline assessments using NIST SP 800-53 Revision 5 controls—authorization boundary definition, System Security Plan (SSP), Plan of Action and Milestones (POA&M), and continuous monitoring (ConMon)—with Cloud Service Provider (CSP) and agency customer responsibility matrices. Trigger when preparing FedRAMP authorization packages, assessing cloud offerings for federal customers, mapping 800-53 Rev 5 controls to CSF outcomes, or auditing ConMon deliverables (monthly POA&M, annual assessments). Do not use for CMMC/CUI defense contractor assessments (use cmmc-nist-800-171), SOX ITGC financial reporting controls (use sox-itgc-audit), or generic CSF gap analysis without FedRAMP artifacts (use nist-csf-2-assessment).
Implements Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 CFR Part 314) and Privacy Rule (16 CFR Part 313) compliance aligned to FFIEC IT Examination Handbook modules for financial institutions—customer information protection, risk assessments, access controls, vendor oversight, and GLBA privacy notices (initial, annual, opt-out). Trigger when auditing banks, credit unions, fintech lenders, or insurance entities for GLBA Safeguards, preparing FFIEC cybersecurity examinations, reviewing customer information security programs, or harmonizing GLBA with state privacy laws. Do not use for California CPRA consumer rights alone (use ccpa-cpra-privacy-rights), PCI cardholder data controls (use pci-dss-encryption-key-management), or SOX 404 ITGC without GLBA customer information scope (use sox-itgc-audit).
Performs Sarbanes-Oxley Act (SOX) IT General Controls (ITGC) audits aligned to COSO Internal Control—Integrated Framework and PCAOB AS 2201—covering access to programs and data, program change management, program development, and computer operations relevant to financial reporting systems. Trigger when preparing SOX 404 management assessment, supporting external auditor ITGC reliance, testing change tickets for financially relevant applications, or auditing segregation of duties in ERP and cloud financial systems. Do not use for FedRAMP authorization packages (use fedramp-moderate-baseline), PCI cardholder environments (use pci-dss-network-segmentation), or HIPAA ePHI controls without financial reporting scope (use hipaa-technical-safeguards).
Audits identity and access management—least privilege, RBAC, MFA, privileged access, joiner-mover-leaver—for SOC 2 CC6.1–CC6.8, HIPAA §164.312(a), and PCI Req 7/8. Trigger when reviewing IAM policies, agent/MCP service accounts, access certifications, or admin console permissions. Do not use for network firewall segmentation (use pci-dss-network-segmentation) or tamper-evident logging design (use audit-logging-integrity).
Designs and validates tamper-evident audit logging, SIEM integration, and log retention for HIPAA §164.312(b) audit controls, SOC 2 CC7.2/CC7.3, and PCI Req 10. Trigger when assessing agent/MCP audit trails, log tampering risks, centralized logging, or forensic readiness. Do not use for IAM permission reviews (use access-control-identity-audit) or breach notification workflows (use breach-incident-response).
Executes USA breach and security incident response—HIPAA Breach Notification Rule (45 CFR §164.400–414), HITECH 60-day notification, state breach laws, and SOC 2 CC7.4/CC7.5 incident management—for agent, MCP, and LLM-related events. Trigger when investigating suspected PHI/PII exposure, unauthorized MCP access, LLM data leakage, or preparing breach notifications. Do not use for preventive logging design (use audit-logging-integrity) or routine vulnerability scanning.
Implements California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)—Cal. Civ. Code §1798.100 et seq.—covering consumer rights to know, delete, correct, opt-out of sale/share, and limit use of sensitive personal information, plus DSAR workflows, privacy notices, and service provider contracts for AI/agent data handling. Trigger when processing California residents' personal information, operating DSAR programs, reviewing agent/LLM data flows for CPRA compliance, or auditing privacy notices and vendor agreements. Do not use for HIPAA-covered PHI workflows (use hipaa-privacy-minimum-necessary), PCI cardholder encryption (use pci-dss-encryption-key-management), or general vendor SOC reports without CPRA scope (use vendor-third-party-risk).
Implements policy-as-code and infrastructure compliance scanning—OPA/Rego policies, Terraform static analysis, CI gates, and drift remediation—for SOC 2, HIPAA, and PCI control enforcement. Trigger when codifying security policies, integrating Checkov/tfsec/Sentinel, or automating guardrails for agent/MCP deployments. Do not use for one-time manual audits (use framework-specific skills) or vendor BAA review (use hipaa-baa-vendor-assessment).
Reviews Business Associate Agreements and subprocessors for LLM vendors, cloud providers, and MCP server operators under HIPAA (45 CFR §164.502(e), §164.504(e)). Trigger when onboarding OpenAI/Anthropic/Azure OpenAI, cloud hosts, observability tools, or MCP integrations that may access ePHI. Do not use for technical encryption testing (use hipaa-technical-safeguards) or general vendor SOC reports without BAA focus (use vendor-third-party-risk).
Implements HIPAA Privacy Rule minimum necessary standard—45 CFR §164.502(b)—plus §164.514 de-identification, Limited Data Sets, and patient rights to access and amend records, with agent prompt minimization, role-based PHI exposure, and integration with the Presidio redaction pipeline. Trigger when designing LLM/agent PHI access policies, auditing disclosure practices, implementing patient rights workflows, or validating that agent prompts contain only minimum necessary ePHI. Do not use for Presidio entity tuning alone (use hipaa-phi-redaction-pipeline), Security Rule technical controls (use hipaa-technical-safeguards), or BAA legal review (use hipaa-baa-vendor-assessment).
Implements HIPAA Security Rule technical safeguards (45 CFR §164.312)—access control, audit controls, integrity, person/entity authentication, and transmission security—for AI agents, MCP servers, and LLM pipelines. Trigger when assessing ePHI handling in agent architectures, MCP tool authorization, encryption in transit/at rest, or mapping HIPAA controls to technical implementations. Do not use for BAA legal review (use hipaa-baa-vendor-assessment) or Presidio tokenization setup (use hipaa-phi-redaction-pipeline).
Implements ISO/IEC 27001:2022 Annex A control assessment—93 controls across Organizational, People, Physical, and Technological themes—covering Statement of Applicability (SoA), risk treatment, and implementation evidence. Trigger when building or auditing an ISMS, mapping Annex A to existing controls, preparing ISO 27001 certification, or assessing agent/MCP systems against ISO 27002:2022 guidance. Do not use for SOC 2 TSC mapping alone (use soc2-trust-services-criteria), IAM-only reviews (use access-control-identity-audit), or vendor SOC report review without ISO scope (use vendor-third-party-risk).
Hardens Model Context Protocol (MCP) server integrations for compliance—OAuth 2.1, PKCE, scoped tool sets, transport security, and patterns for Playwright, Postgres, Slack, and Presidio MCP servers in audit workflows. Trigger when deploying, configuring, or auditing MCP servers for HIPAA, PCI, or SOC 2 agent architectures. Do not use for general IAM reviews without MCP focus (use access-control-identity-audit) or PCI script DOM audits (use pci-dss-script-audit).
Performs NIST Cybersecurity Framework 2.0 gap assessments across six Functions—Govern, Identify, Protect, Detect, Respond, Recover—using CSF 2.0 categories, subcategories, Implementation Tiers, and Organizational Profiles. Trigger when benchmarking security posture, preparing executive risk reporting, assessing AI/agent system controls against NIST CSF, or harmonizing CSF with ISO 27001 or SOC 2 programs. Do not use for ISO 27001 SoA certification work (use iso27001-annex-a-controls), PCI CDE scoping (use pci-dss-network-segmentation), or HIPAA Privacy Rule minimum necessary (use hipaa-privacy-minimum-necessary).
Audits PCI-DSS v4.0 Requirement 3 (protect stored account data) and Requirement 4 (protect cardholder data with strong cryptography during transmission)—covering key management lifecycle, HSM usage, PAN masking, tokenization, and TLS 1.2+ enforcement with Terraform/Vault MCP patterns for evidence collection. Trigger when assessing encryption of CHD/SAD at rest or in transit, reviewing key rotation and split knowledge, validating tokenization scope reduction, or scanning IaC for crypto misconfigurations. Do not use for network segmentation (use pci-dss-network-segmentation), payment-page script inventory (use pci-dss-script-audit), or general IAM without crypto focus (use access-control-identity-audit).
Validates PCI-DSS v4.0 network segmentation and scope reduction—Requirement 1.x (firewalls, network security controls) and 2.x (secure configurations)—for Cardholder Data Environment (CDE) isolation. Trigger when scoping PCI environments, reviewing firewall rules, VLAN segmentation, agent/MCP access to CDE, or reducing assessment scope. Do not use for payment-page script audits (use pci-dss-script-audit) or general IAM reviews without CDE focus (use access-control-identity-audit).
Automates PCI-DSS v4.0 Requirements 6.4.3 (payment-page script authorization, inventory, integrity hashes, and business justification) and 11.6.1 (weekly change/tamper detection for HTTP security headers and DOM scripts). Trigger when auditing ecommerce checkout or payment pages, validating third-party JavaScript governance, detecting unauthorized script or CSP changes, or producing PCI script inventory evidence. Do not use for backend server patching, network firewall rules, cardholder data storage encryption, or non-payment marketing pages.
Implements Continuous Control Monitoring (CCM) for SOC 2—automated control testing, configuration drift detection, predictive risk scoring, and alerting—for agent platforms, MCP servers, and cloud infrastructure. Trigger when building always-on compliance dashboards, detecting TSC control drift between audits, or operationalizing CC4/CC7 monitoring. Do not use for one-time evidence binders (use soc2-evidence-collection) or initial TSC mapping (use soc2-trust-services-criteria).
Automates SOC 2 evidence gathering—screenshots, configuration exports, access reviews, log samples, and audit-trail packaging with integrity hashes—for AICPA TSC examinations. Trigger when preparing audit binders, populating Vanta/Drata-style evidence requests, or packaging agent/MCP compliance artifacts. Do not use for control mapping (use soc2-trust-services-criteria) or continuous drift monitoring (use soc2-ccm-continuous-monitoring).
Maps organizational controls and evidence to AICPA SOC 2 Trust Services Criteria (2017 TSC with 2022 revisions)—Security (CC), Availability (A), Confidentiality (C), Processing Integrity (PI), and Privacy (P). Trigger when scoping SOC 2 audits, gap assessments, control design reviews, or mapping agent/MCP architecture to TSC. Do not use for evidence collection mechanics (use soc2-evidence-collection) or continuous monitoring dashboards (use soc2-ccm-continuous-monitoring).
Performs third-party and vendor risk assessments for compliance programs—security questionnaires, SOC 2 report review, control inheritance, and ongoing monitoring—for LLM, cloud, MCP, and GRC tool vendors (Vanta/Drata alternative operational mindset). Trigger when onboarding vendors, annual vendor reviews, or assessing subprocessor risk for HIPAA, PCI, and SOC 2. Do not use for BAA clause legal analysis (use hipaa-baa-vendor-assessment) or MCP technical hardening (use mcp-compliance-integration).