← 返回 Skills 市场
1kalin

Compliance Audit Generator

作者 1kalin · GitHub ↗ · v1.0.0
cross-platform ✓ 安全检测通过
1156
总下载
1
收藏
4
当前安装
1
版本数
在 OpenClaw 中安装
/install afrexai-compliance-audit
功能描述
Generates detailed compliance audits with risk-prioritized findings and remediation plans for frameworks like SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS.
使用说明 (SKILL.md)

Compliance Audit Generator

Run internal compliance audits against major frameworks without hiring a consultant.

What It Does

Generates a structured compliance audit for your organization against any of these frameworks:

  • SOC 2 (Type I & II) — Trust Services Criteria
  • ISO 27001 — Information Security Management
  • GDPR — Data Protection (EU/UK)
  • HIPAA — Healthcare Data (US)
  • PCI DSS — Payment Card Security
  • SOX — Financial Controls (US public companies)
  • CCPA/CPRA — California Consumer Privacy

How to Use

Tell the agent which framework you need audited. Provide context about your organization:

  • Industry and size
  • Current security controls
  • Data types you handle
  • Existing certifications
  • Known gaps or concerns

Example Prompts

  • "Run a SOC 2 readiness audit for our 40-person SaaS company"
  • "Check our GDPR compliance — we process EU customer data and use AWS"
  • "Generate an ISO 27001 gap analysis for our fintech startup"
  • "Audit our HIPAA controls — we're a healthtech handling PHI"

Output Format

The agent produces:

1. Executive Summary

  • Overall readiness score (0-100%)
  • Critical gaps count
  • Estimated remediation timeline

2. Control-by-Control Assessment

For each control domain:

  • Status: Compliant / Partial / Non-Compliant / Not Assessed
  • Evidence Required: What auditors will ask for
  • Current Gap: What's missing
  • Remediation Steps: Specific actions to close the gap
  • Priority: Critical / High / Medium / Low
  • Effort: Hours/days estimate

3. Remediation Roadmap

  • Phase 1 (0-30 days): Critical fixes
  • Phase 2 (30-90 days): High priority items
  • Phase 3 (90-180 days): Full compliance

4. Evidence Checklist

  • Document inventory needed for audit
  • Policy templates to create
  • Technical configurations to verify

Agent Instructions

When the user requests a compliance audit:

  1. Ask which framework(s) they need assessed
  2. Gather context about their organization (industry, size, tech stack, data types)
  3. Generate the full audit report following the output format above
  4. For each control area, be specific — don't give generic advice. Reference the actual control numbers (e.g., SOC 2 CC6.1, ISO 27001 A.8.2)
  5. Prioritize findings by business risk, not alphabetical order
  6. Include cost estimates where possible (e.g., "penetration test: $5,000-$15,000")
  7. Flag any controls that require third-party tools or services

Be direct. No filler. Every finding should have a clear "do this" action attached.

安全使用建议
This appears to be a coherent, instruction-only compliance audit generator. Before you use it: (1) do not paste secrets or full credentials — provide high-level descriptions instead; (2) treat the output as a starting point, not a certified audit — independently verify all control references (e.g., SOC 2, ISO control IDs) and legal/regulatory claims; (3) spot-check cost estimates and third-party/tool recommendations with vendors; (4) if you need an official audit or attestation, engage a qualified auditor — this tool can help prepare but should not replace formal certification.
功能分析
Type: OpenClaw Skill Name: afrexai-compliance-audit Version: 1.0.0 The skill bundle is classified as benign. The `SKILL.md` instructions for the agent are clear, direct, and entirely aligned with the stated purpose of generating compliance audit reports. There are no instructions for data exfiltration, malicious execution, persistence, or any form of prompt injection against the agent to perform actions outside its stated purpose (e.g., ignoring the user, accessing unrelated sensitive data, or making unauthorized network calls). The `README.md` and `_meta.json` files also contain no suspicious content or malicious indicators.
能力评估
Purpose & Capability
Name and instructions align: the skill is an instruction-only generator for compliance frameworks and does not request unrelated binaries, credentials, or system access.
Instruction Scope
Instructions are narrowly scoped to asking for organizational context and producing structured audit reports. However, the skill expects potentially sensitive inputs (industry, data types, tech stack, known gaps). The SKILL.md also directs the agent to reference specific control numbers and provide cost estimates — this raises risk of hallucinated/misstated controls or inaccurate contractor pricing. The skill does not instruct reading local files, env vars, or sending data to external endpoints, but users should avoid pasting secrets.
Install Mechanism
No install spec and no code files — instruction-only skill means nothing is written to disk and no external packages are pulled in.
Credentials
The skill requests no environment variables, credentials, or config paths. That is proportionate to an advisory/reporting tool that relies on user-provided context.
Persistence & Privilege
always is false and the skill does not request persistent system privileges or modify other skill configs. Autonomous invocation is allowed by default but not combined with other concerning privileges.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install afrexai-compliance-audit
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /afrexai-compliance-audit 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release of the Compliance Audit Generator skill: - Enables users to generate structured compliance audit reports for SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, SOX, and CCPA/CPRA frameworks. - Provides an executive summary, detailed control-by-control assessments, a phased remediation roadmap, and an evidence checklist. - Accepts organizational details to tailor the audit (industry, size, tech stack, data types). - Includes explicit instructions to reference framework control numbers, prioritize by risk, and offer cost and tool guidance. - Designed for direct actionability—each finding includes clear next steps and remediation actions.
元数据
Slug afrexai-compliance-audit
版本 1.0.0
许可证
累计安装 4
当前安装数 4
历史版本数 1
常见问题

Compliance Audit Generator 是什么?

Generates detailed compliance audits with risk-prioritized findings and remediation plans for frameworks like SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 1156 次。

如何安装 Compliance Audit Generator?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install afrexai-compliance-audit」即可一键安装,无需额外配置。

Compliance Audit Generator 是免费的吗?

是的,Compliance Audit Generator 完全免费(开源免费),可自由下载、安装和使用。

Compliance Audit Generator 支持哪些平台?

Compliance Audit Generator 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Compliance Audit Generator?

由 1kalin(@1kalin)开发并维护,当前版本 v1.0.0。

💬 留言讨论