Claude Skill

compliance-mapper

Map the codebase and controls against security standards - OWASP ASVS, CIS Benchmarks, SOC 2, ISO 27001, PCI-DSS - producing a gap analysis with evidence and remediation. Use for /comply, audit prep, or "are we compliant with X?" questions.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download navinspire-ia-navin-navin_skills_compliance-mapper-e9c73a3.zip · 1 KB
Part of navinspire-ia/navin — 182 skills

Install

skills CLI npx skills add https://github.com/Navinspire-ia/navin/tree/main/navin/skills/compliance-mapper
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install navinspire-ia-navin@llmmart
Git git clone https://github.com/Navinspire-ia/navin.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole navinspire-ia/navin collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Compliance Mapper

Overview

Translate security findings into the language of a standard. For a chosen framework, go control by control, mark each met / partial / gap / not-applicable with concrete evidence from the codebase, and give the work needed to close each gap. This is a readiness assessment, not a certification.

Supported frameworks

  • OWASP ASVS - application-level verification (L1/L2), best default for a codebase.
  • CIS Benchmarks - OS/container/cloud hardening baselines.
  • SOC 2 (Trust Services Criteria) - security, availability, confidentiality controls.
  • ISO 27001 Annex A - ISMS control set.
  • PCI-DSS - if cardholder data is handled.
  • GDPR - pair with the data-privacy-auditor for data-protection articles.

Workflow

  1. Confirm the target framework and scope (whole product, a service, or infra). If unclear, default to OWASP ASVS L2.
  2. Pull evidence from prior audits (/fortify, /probe, /perimeter, /bastion, /vault) and the code itself - do not re-audit from scratch; synthesize.
  3. For each control: ID | requirement | status | evidence (file/config) | gap | remediation | effort.
  4. Roll up a compliance scorecard per domain (authentication, access control, crypto, logging, config, data protection…).
  5. Produce a prioritized remediation roadmap: quick wins first, then structural gaps, with an owner suggestion per item.
  6. Save the report as a file in the workspace when substantial.

Anti-patterns

  • Marking a control "met" without pointing to concrete evidence
  • Claiming the system is "certified/compliant" - this is a gap assessment only
  • Copying the full standard text instead of mapping it to this system
  • Ignoring not-applicable controls (mark and justify them)
Files (navin)
  • SKILL.md 2.1 KB
    ---
    name: compliance-mapper
    description: Map the codebase and controls against security standards - OWASP ASVS, CIS Benchmarks, SOC 2, ISO 27001, PCI-DSS - producing a gap analysis with evidence and remediation. Use for /comply, audit prep, or "are we compliant with X?" questions.
    metadata: {"navin":{"emoji":"📋","category":"security"}}
    ---
    
    # Compliance Mapper
    
    ## Overview
    
    Translate security findings into the language of a standard. For a chosen framework, go control by control, mark each **met / partial / gap / not-applicable** with concrete evidence from the codebase, and give the work needed to close each gap. This is a readiness assessment, not a certification.
    
    ## Supported frameworks
    
    - **OWASP ASVS** - application-level verification (L1/L2), best default for a codebase.
    - **CIS Benchmarks** - OS/container/cloud hardening baselines.
    - **SOC 2** (Trust Services Criteria) - security, availability, confidentiality controls.
    - **ISO 27001 Annex A** - ISMS control set.
    - **PCI-DSS** - if cardholder data is handled.
    - **GDPR** - pair with the data-privacy-auditor for data-protection articles.
    
    ## Workflow
    
    1. Confirm the target framework and scope (whole product, a service, or infra). If unclear, default to OWASP ASVS L2.
    2. Pull evidence from prior audits (`/fortify`, `/probe`, `/perimeter`, `/bastion`, `/vault`) and the code itself - do not re-audit from scratch; synthesize.
    3. For each control: `ID | requirement | status | evidence (file/config) | gap | remediation | effort`.
    4. Roll up a compliance scorecard per domain (authentication, access control, crypto, logging, config, data protection…).
    5. Produce a prioritized remediation roadmap: quick wins first, then structural gaps, with an owner suggestion per item.
    6. Save the report as a file in the workspace when substantial.
    
    ## Anti-patterns
    
    - Marking a control "met" without pointing to concrete evidence
    - Claiming the system is "certified/compliant" - this is a gap assessment only
    - Copying the full standard text instead of mapping it to this system
    - Ignoring not-applicable controls (mark and justify them)
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related