1kalin/afrexai-soc2-compliance/SKILL.md
# SOC 2 Compliance Accelerator Your agent for achieving and maintaining SOC 2 Type I and Type II compliance — from readiness assessment through audit completion. ## What This Does Guides organizations through the full SOC 2 lifecycle: gap analysis, control implementation, evidence collection, audit prep, and continuous monitoring. Covers all 5 Trust Service Criteria with practical implementation steps. ## How to Use Tell your agent what stage you're at: - **"Run SOC 2 readiness assessment"
npx skillsauth add openclaw/skills 1kalin/afrexai-soc2-complianceInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Your agent for achieving and maintaining SOC 2 Type I and Type II compliance — from readiness assessment through audit completion.
Guides organizations through the full SOC 2 lifecycle: gap analysis, control implementation, evidence collection, audit prep, and continuous monitoring. Covers all 5 Trust Service Criteria with practical implementation steps.
Tell your agent what stage you're at:
System Description Checklist:
□ Infrastructure components (cloud, on-prem, hybrid)
□ Software stack (applications, databases, middleware)
□ People (roles, responsibilities, third parties)
□ Procedures (operational, security, change management)
□ Data flows (ingress, processing, storage, egress)
□ Trust Service Criteria selection (Security + which optional?)
□ Subservice organizations (cloud providers, SaaS tools)
□ Carve-out vs inclusive method for subservice orgs
Score each control area 1-5:
Priority Matrix: | Gap Score | Action | Timeline | |-----------|--------|----------| | 1-2 | Critical — implement immediately | 2-4 weeks | | 3 | Important — formalize and document | 1-2 weeks | | 4 | Minor — fill evidence gaps | 3-5 days | | 5 | Maintain — continue monitoring | Ongoing |
For each gap:
1. Assign control owner (by name, not role)
2. Define implementation steps
3. Set evidence collection method (automated preferred)
4. Establish testing cadence
5. Document exception handling process
| Control | Evidence Source | Tool Examples | |---------|---------------|---------------| | Access Reviews | IAM exports | Okta, Azure AD, AWS IAM | | Encryption | Config snapshots | AWS Config, CloudTrail | | Logging | Log aggregation | Datadog, Splunk, ELK | | Vulnerability Scans | Scan reports | Qualys, Nessus, Snyk | | Change Management | PR/deploy history | GitHub, GitLab, Jira | | Uptime | Monitoring dashboards | Datadog, PagerDuty |
| Control | Evidence Type | Frequency | |---------|--------------|-----------| | Background Checks | HR records | Per hire | | Security Training | Completion certificates | Annual | | Risk Assessment | Assessment document | Annual | | Pen Testing | Report | Annual | | DR Testing | Test results | Semi-annual | | Board/Mgmt Review | Meeting minutes | Quarterly | | Vendor Reviews | Assessment records | Annual | | Policy Reviews | Version history | Annual |
Week 1-2: Auditor selection + engagement letter
Week 2-4: System description draft
Week 4-6: Control documentation + evidence prep
Week 6-8: Fieldwork (auditor testing)
Week 8-10: Draft report review
Week 10-12: Final report issued
Month 1: Observation period begins (minimum 3 months, recommend 6-12)
Ongoing: Evidence collection, control operation
Month 3-12: Observation period ends
+Week 1-2: Fieldwork scheduling
+Week 2-4: Fieldwork (testing over observation period)
+Week 4-6: Draft report + final report
| Company Size | Type I | Type II | Annual Maintenance | |-------------|--------|---------|-------------------| | Startup (<50) | $20K-$50K | $30K-$80K | $15K-$40K | | Mid-Market (50-500) | $40K-$100K | $60K-$150K | $30K-$80K | | Enterprise (500+) | $80K-$200K | $120K-$300K | $60K-$150K |
Includes: auditor fees, tooling, personnel time, remediation costs.
Hidden costs to budget:
When deploying AI agents in SOC 2 environments:
| Industry | Extra Criteria | Key Controls | |----------|---------------|-------------| | Fintech | All 5 TSC typical | SOX mapping, encryption everywhere, PCI if payments | | Healthcare | Privacy, Confidentiality | HIPAA crosswalk, BAAs, PHI handling | | SaaS | Availability, Confidentiality | Multi-tenant isolation, SLA compliance | | Legal | Confidentiality, Privacy | Privilege protection, matter isolation | | Construction | Security, Availability | Field data protection, offline capability | | E-commerce | All 5 TSC typical | PCI DSS alignment, transaction integrity |
This skill gives you the framework. For industry-specific compliance playbooks with regulatory crosswalks, cost models, and vendor selection guides:
🔗 AfrexAI Context Packs — $47 per industry vertical
Available packs: Fintech, Healthcare, Legal, Construction, E-commerce, SaaS, Real Estate, Recruitment, Manufacturing, Professional Services
🔗 AI Revenue Leak Calculator — Find where compliance gaps cost you money
🔗 Agent Setup Wizard — Deploy compliance monitoring agents in minutes
Bundle pricing:
tools
Use when the user wants to connect to, test, or use the McDonalds service at mcp.mcd.cn, including checking authentication, probing MCP endpoints, listing tools, or calling McDonalds MCP tools through a reusable local CLI.
development
Web scraping platform — Twitter/X data, Vinted marketplace, and general web scraping API
development
SlowMist AI Agent Security Review — comprehensive security framework for skills, repositories, URLs, on-chain addresses, and products (Claude Code version)
data-ai
去除中文文本中的 AI 写作痕迹,使其读起来自然。基于维基百科 AI 写作特征指南,检测 24 种 AI 模式。触发词:humanizer-cn、去除 AI 痕迹、去除 AI 写作痕迹、中文文本人性化。