⏳ This skill is pending AI review.
Scores will appear once the review pipeline completes.
trust-portal
Let AI agents drive SOC 2 Type 2 compliance end-to-end. Use when the user wants to get SOC 2 compliant, start a compliance program, manage controls, view or submit evidence, check compliance scores, generate policies, review systems/vendors/risks, query the audit log, upload decision logs, manage portal settings, or configure and run automated evidence collectors (AWS, Git/CodeCommit, Platform, Policy, Vendor). TRIGGER on any of these phrases — "get me SOC 2 compliant", "set up compliance", "start our compliance program", "check compliance", "what evidence is missing", "show the audit log", "set up evidence collection", "configure collectors", "run the collectors", or any mention of SOC 2 controls, tests, evidence, policies, or evidence collectors. For end-to-end SOC 2 journey guidance, read references/soc2-playbook.md which contains the complete 8-phase workflow with exact API calls, decision trees, and conversational scripts.
Choose how to use this skill
You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.
1. Native installer
This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.
Do not guess an installer command or replace an existing version without reviewing the diff.
2. Complete package recommended
Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.
No complete ProSkills package is published for this listing yet.3. Prompt-only
Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.
Need only the instruction file?
Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.
No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.
// RATINGS
Not yet listed on ClawHub or SkillsMP
// README
AI Agent-First Trust Portal — Claude Code Skill
A Claude Code agent skill for managing SOC 2 compliance data through the AI Agent-First Trust Portal API.
Features
- Compliance status: Overall and per-category scores, evidence gaps
- Full CRUD: Controls, tests, policies, systems, vendors, evidence, risks
- Audit log: Query change history with filters
- Decision logs: Upload session transcripts for compliance audit trail
- Portal settings: View and update portal configuration
- Pentest findings: View security assessment results
- Evidence collectors: Configure, test, run, and inspect the portal's five evidence collectors (AWS, Git/CodeCommit, Platform, Policy, Vendor)
Installation
-
Clone this repo into your development directory:
git clone https://github.com/MaxGood-AI/ai-agent-first-trust-portal-skill.git -
Create a symlink in your Claude Code skills directory:
ln -sf /path/to/ai-agent-first-trust-portal-skill ~/.claude/skills/trust-portal -
Add your trust portal credentials to
.envin your workspace:TRUST_PORTAL_API_URL=http://localhost:5100 TRUST_PORTAL_API_KEY=your-api-key-here
Usage
# Check compliance
python3 scripts/trust_portal_api.py compliance-score
# Find evidence gaps
python3 scripts/trust_portal_api.py evidence-gaps
# List controls
python3 scripts/trust_portal_api.py controls
# Query audit log
python3 scripts/trust_portal_api.py audit-log --table controls --limit 5
# Configure and run an evidence collector (credentials via data file only)
cat > /tmp/policy-config.json <<'EOF'
{"credential_mode": "none", "schedule_cron": "0 6 * * 1", "enabled": true}
EOF
python3 scripts/trust_portal_api.py configure-collector --name policy --data-file /tmp/policy-config.json
python3 scripts/trust_portal_api.py run-collector --name policy
See SKILL.md for the complete command reference.
Requirements
- Python 3.8+ (stdlib only — no pip install needed)
- A running AI Agent-First Trust Portal instance
- API key from the trust portal admin (
/admin/team)
License
MIT — see LICENSE.txt
// HOW IT'S BUILT
KEY FILES