Skip to content

Commit b264007

Browse files
committed
Launch release 0.2.0.
1 parent e342078 commit b264007

File tree

16 files changed

+133
-56
lines changed

16 files changed

+133
-56
lines changed

.claude-plugin/marketplace.json

Lines changed: 105 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"$schema": "https://anthropic.com/claude-code/marketplace.schema.json",
33
"name": "grc-skills",
4-
"description": "Claude Code skills for Governance, Risk & Compliance ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, and ISO 42001 AI Management System.",
4+
"description": "Claude Code skills for Governance, Risk & Compliance \u2014 ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, and ISO 42001 AI Management System.",
55
"owner": {
66
"name": "Hemant Naik",
77
"email": "[email protected]"
@@ -11,118 +11,195 @@
1111
"name": "iso27001",
1212
"source": "./plugins/iso27001",
1313
"description": "Expert ISO 27001 gap analysis, policy writing, Annex A control guidance, SoA generation, and risk register creation for both 2013 and 2022 versions.",
14-
"version": "0.1.0",
14+
"version": "0.2.0",
1515
"author": {
1616
"name": "Hemant Naik",
1717
"email": "[email protected]"
1818
},
1919
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
2020
"category": "compliance",
21-
"keywords": ["iso27001", "isms", "compliance", "security", "grc", "gap-analysis", "annex-a"]
21+
"keywords": [
22+
"iso27001",
23+
"isms",
24+
"compliance",
25+
"security",
26+
"grc",
27+
"gap-analysis",
28+
"annex-a"
29+
]
2230
},
2331
{
2432
"name": "soc2",
2533
"source": "./plugins/soc2",
26-
"description": "Expert SOC 2 compliance advisor covering all Trust Services Criteria gap analysis, policy drafting, control documentation, audit evidence, and vendor risk.",
27-
"version": "0.1.0",
34+
"description": "Expert SOC 2 compliance advisor covering all Trust Services Criteria \u2014 gap analysis, policy drafting, control documentation, audit evidence, and vendor risk.",
35+
"version": "0.2.0",
2836
"author": {
2937
"name": "Hemant Naik",
3038
"email": "[email protected]"
3139
},
3240
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
3341
"category": "compliance",
34-
"keywords": ["soc2", "aicpa", "trust-services", "audit", "compliance", "grc"]
42+
"keywords": [
43+
"soc2",
44+
"aicpa",
45+
"trust-services",
46+
"audit",
47+
"compliance",
48+
"grc"
49+
]
3550
},
3651
{
3752
"name": "fedramp",
3853
"source": "./plugins/fedramp",
39-
"description": "End-to-end FedRAMP authorization guidance readiness assessments, SSP narratives, POA&M management, NIST 800-53 Rev 5 control mapping, and ConMon support.",
40-
"version": "0.1.0",
54+
"description": "End-to-end FedRAMP authorization guidance \u2014 readiness assessments, SSP narratives, POA&M management, NIST 800-53 Rev 5 control mapping, and ConMon support.",
55+
"version": "0.2.0",
4156
"author": {
4257
"name": "Hemant Naik",
4358
"email": "[email protected]"
4459
},
4560
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
4661
"category": "compliance",
47-
"keywords": ["fedramp", "nist", "ato", "ssp", "poam", "federal", "cloud-security", "grc"]
62+
"keywords": [
63+
"fedramp",
64+
"nist",
65+
"ato",
66+
"ssp",
67+
"poam",
68+
"federal",
69+
"cloud-security",
70+
"grc"
71+
]
4872
},
4973
{
5074
"name": "gdpr-compliance",
5175
"source": "./plugins/gdpr-compliance",
52-
"description": "GDPR compliance assistant code and system audits, privacy notice drafting, DPAs, DPIAs, data flow reviews, and authoritative article-cited Q&A.",
53-
"version": "0.1.0",
76+
"description": "GDPR compliance assistant \u2014 code and system audits, privacy notice drafting, DPAs, DPIAs, data flow reviews, and authoritative article-cited Q&A.",
77+
"version": "0.2.0",
5478
"author": {
5579
"name": "Hemant Naik",
5680
"email": "[email protected]"
5781
},
5882
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
5983
"category": "compliance",
60-
"keywords": ["gdpr", "privacy", "data-protection", "dpa", "dpia", "eu", "grc"]
84+
"keywords": [
85+
"gdpr",
86+
"privacy",
87+
"data-protection",
88+
"dpa",
89+
"dpia",
90+
"eu",
91+
"grc"
92+
]
6193
},
6294
{
6395
"name": "hipaa-compliance",
6496
"source": "./plugins/hipaa-compliance",
65-
"description": "HIPAA compliance advisor covering Privacy Rule, Security Rule, and Breach Notification document generation, technical safeguards for cloud, and breach response.",
66-
"version": "0.1.0",
97+
"description": "HIPAA compliance advisor covering Privacy Rule, Security Rule, and Breach Notification \u2014 document generation, technical safeguards for cloud, and breach response.",
98+
"version": "0.2.0",
6799
"author": {
68100
"name": "Hemant Naik",
69101
"email": "[email protected]"
70102
},
71103
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
72104
"category": "compliance",
73-
"keywords": ["hipaa", "phi", "healthcare", "baa", "privacy-rule", "security-rule", "grc"]
105+
"keywords": [
106+
"hipaa",
107+
"phi",
108+
"healthcare",
109+
"baa",
110+
"privacy-rule",
111+
"security-rule",
112+
"grc"
113+
]
74114
},
75115
{
76116
"name": "nist-csf",
77117
"source": "./plugins/nist-csf",
78-
"description": "NIST Cybersecurity Framework (CSF 2.0 and 1.1) advisor gap assessments, organisational profiles, implementation tiers, roadmaps, cross-framework mapping, and cybersecurity policy generation.",
79-
"version": "0.1.0",
118+
"description": "NIST Cybersecurity Framework (CSF 2.0 and 1.1) advisor \u2014 gap assessments, organisational profiles, implementation tiers, roadmaps, cross-framework mapping, and cybersecurity policy generation.",
119+
"version": "0.2.0",
80120
"author": {
81121
"name": "Hemant Naik",
82122
"email": "[email protected]"
83123
},
84124
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
85125
"category": "compliance",
86-
"keywords": ["nist-csf", "cybersecurity-framework", "csf20", "risk-management", "cybersecurity", "grc", "gap-assessment", "profiles", "tiers"]
126+
"keywords": [
127+
"nist-csf",
128+
"cybersecurity-framework",
129+
"csf20",
130+
"risk-management",
131+
"cybersecurity",
132+
"grc",
133+
"gap-assessment",
134+
"profiles",
135+
"tiers"
136+
]
87137
},
88138
{
89139
"name": "pci-compliance",
90140
"source": "./plugins/pci-compliance",
91-
"description": "PCI DSS v4.0.1 compliance advisor CDE scoping, SAQ selection, gap assessments, control implementation guidance, QSA audit preparation, and remediation planning.",
92-
"version": "0.1.0",
141+
"description": "PCI DSS v4.0.1 compliance advisor \u2014 CDE scoping, SAQ selection, gap assessments, control implementation guidance, QSA audit preparation, and remediation planning.",
142+
"version": "0.2.0",
93143
"author": {
94144
"name": "Hemant Naik",
95145
"email": "[email protected]"
96146
},
97147
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
98148
"category": "compliance",
99-
"keywords": ["pci-dss", "pci-compliance", "payment-security", "cardholder-data", "cde", "saq", "qsa", "grc"]
149+
"keywords": [
150+
"pci-dss",
151+
"pci-compliance",
152+
"payment-security",
153+
"cardholder-data",
154+
"cde",
155+
"saq",
156+
"qsa",
157+
"grc"
158+
]
100159
},
101160
{
102161
"name": "tsa-compliance",
103162
"source": "./plugins/tsa-compliance",
104-
"description": "TSA cybersecurity compliance advisor for critical infrastructure pipeline, freight rail, and transit Security Directive requirements including CIP/COIP, IRP, ADR, CAP, incident reporting, and OT/ICS security.",
105-
"version": "0.1.0",
163+
"description": "TSA cybersecurity compliance advisor for critical infrastructure \u2014 pipeline, freight rail, and transit Security Directive requirements including CIP/COIP, IRP, ADR, CAP, incident reporting, and OT/ICS security.",
164+
"version": "0.2.0",
106165
"author": {
107166
"name": "Hemant Naik",
108167
"email": "[email protected]"
109168
},
110169
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
111170
"category": "compliance",
112-
"keywords": ["tsa", "transportation-security", "critical-infrastructure", "pipeline-security", "rail-security", "ot-security", "ics-security", "grc"]
171+
"keywords": [
172+
"tsa",
173+
"transportation-security",
174+
"critical-infrastructure",
175+
"pipeline-security",
176+
"rail-security",
177+
"ot-security",
178+
"ics-security",
179+
"grc"
180+
]
113181
},
114182
{
115183
"name": "iso42001",
116184
"source": "./plugins/iso42001",
117-
"description": "ISO 42001 AI Management System (AIMS) advisor gap analysis, AI risk assessment, AI system impact assessment (AISIA), Annex A control guidance, SoA generation, policy writing, and certification readiness for ISO/IEC 42001:2023.",
118-
"version": "0.1.0",
185+
"description": "ISO 42001 AI Management System (AIMS) advisor \u2014 gap analysis, AI risk assessment, AI system impact assessment (AISIA), Annex A control guidance, SoA generation, policy writing, and certification readiness for ISO/IEC 42001:2023.",
186+
"version": "0.2.0",
119187
"author": {
120188
"name": "Hemant Naik",
121189
"email": "[email protected]"
122190
},
123191
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
124192
"category": "compliance",
125-
"keywords": ["iso42001", "ai-management-system", "aims", "responsible-ai", "ai-governance", "ai-risk", "aisia", "grc"]
193+
"keywords": [
194+
"iso42001",
195+
"ai-management-system",
196+
"aims",
197+
"responsible-ai",
198+
"ai-governance",
199+
"ai-risk",
200+
"aisia",
201+
"grc"
202+
]
126203
}
127204
]
128-
}
205+
}

GDPR - Claude Skill/GDPR-compliance-readme.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -184,7 +184,7 @@ The skill covers the full regulation across these key areas:
184184

185185
**Hemant Naik**
186186
[LinkedIn](https://www.linkedin.com/in/tanaji-naik/) · [[email protected]](mailto:[email protected])
187-
Skill version: 0.1.0 — March 2026.
187+
Skill version: 0.2.0 — March 2026.
188188

189189
> ⚠️ **Disclaimer**: This skill provides informational guidance based on the GDPR text and
190190
> established regulatory guidance (EDPB/ICO). It does not constitute legal advice. For matters

ISO 27001 - Claude Skill/ISO27001-README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -137,5 +137,5 @@ The skill activates on any of the following topics (non-exhaustive):
137137
[LinkedIn](https://www.linkedin.com/in/tanaji-naik/) · [[email protected]](mailto:[email protected])
138138
**Built with:** Claude (Anthropic) using the Claude Skills framework
139139
**Date:** March 2026
140-
**Skill version:** 0.1.0
140+
**Skill version:** 0.2.0
141141
**Standard coverage:** ISO/IEC 27001:2013 and ISO/IEC 27001:2022

NIST Cybersecurity framework - Claude Skill/NIST-Cybersecurity-README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -138,5 +138,5 @@ The skill activates on any of the following topics (non-exhaustive):
138138
[LinkedIn](https://www.linkedin.com/in/tanaji-naik/) · [[email protected]](mailto:[email protected])
139139
**Built with:** Claude (Anthropic) using the Claude Skills framework
140140
**Date:** March 2026
141-
**Skill version:** 0.1.0
141+
**Skill version:** 0.2.0
142142
**Standard coverage:** NIST Cybersecurity Framework 2.0 (February 2024) and NIST CSF 1.1 (April 2018)

PCI Compliance - Claude Skill/PCI-Compliance-README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -128,5 +128,5 @@ pci-compliance/
128128
[LinkedIn](https://www.linkedin.com/in/tanaji-naik/) · [[email protected]](mailto:[email protected])
129129
**Built with:** Claude (Anthropic) using the Claude Skills framework
130130
**Date:** March 2026
131-
**Skill version:** 0.1.0
131+
**Skill version:** 0.2.0
132132
**Standard coverage:** PCI DSS v4.0.1 (June 2024) and PCI DSS v4.0 (March 2022)

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIS
33

44
Benchmarked across 18 test cases (2 per framework) using the eval framework — each graded against 4–5 verifiable assertions by independent agents. Skills scored **94% ± 10%** vs a baseline of 72% ± 28%.
55

6-
[![Release: v0.1.0](https://img.shields.io/badge/Release-v0.1.0-brightgreen.svg)](../../releases/tag/v0.1.0)
6+
[![Release: v0.2.0](https://img.shields.io/badge/Release-v0.2.0-brightgreen.svg)](../../releases/tag/v0.2.0)
77
[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)
88
[![Skills: 9](https://img.shields.io/badge/Skills-9-green.svg)](#the-skills)
99
[![Built with Claude](https://img.shields.io/badge/Built%20with-Claude-orange.svg)](https://claude.ai)

TSA Compliance - Claude Skill/TSA-Compliance-README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -142,5 +142,5 @@ TSA Security Directives are classified as **Sensitive Security Information (SSI)
142142
[LinkedIn](https://www.linkedin.com/in/tanaji-naik/) · [[email protected]](mailto:[email protected])
143143
**Built with:** Claude (Anthropic) using the Claude Skills framework
144144
**Date:** March 2026
145-
**Skill version:** 0.1.0
145+
**Skill version:** 0.2.0
146146
**Standard coverage:** TSA SD Pipeline-2021-01G, SD Pipeline-2021-02F, SD 1580-21-01E, SD 1582-21-01E, November 2024 NPRM

plugins/fedramp/.claude-plugin/plugin.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"name": "fedramp",
33
"description": "End-to-end FedRAMP authorization guidance \u2014 readiness assessments, SSP narratives, POA&M management, NIST 800-53 Rev 5 control mapping, and ConMon support.",
4-
"version": "0.1.0",
4+
"version": "0.2.0",
55
"author": {
66
"name": "Hemant Naik",
77
"email": "[email protected]"
@@ -19,4 +19,4 @@
1919
"cloud-security",
2020
"grc"
2121
]
22-
}
22+
}

plugins/gdpr-compliance/.claude-plugin/plugin.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"name": "gdpr-compliance",
33
"description": "GDPR compliance assistant \u2014 code and system audits, privacy notice drafting, DPAs, DPIAs, data flow reviews, and authoritative article-cited Q&A.",
4-
"version": "0.1.0",
4+
"version": "0.2.0",
55
"author": {
66
"name": "Hemant Naik",
77
"email": "[email protected]"
@@ -18,4 +18,4 @@
1818
"eu",
1919
"grc"
2020
]
21-
}
21+
}

plugins/hipaa-compliance/.claude-plugin/plugin.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"name": "hipaa-compliance",
33
"description": "HIPAA compliance advisor covering Privacy Rule, Security Rule, and Breach Notification \u2014 document generation, technical safeguards for cloud, and breach response.",
4-
"version": "0.1.0",
4+
"version": "0.2.0",
55
"author": {
66
"name": "Hemant Naik",
77
"email": "[email protected]"
@@ -18,4 +18,4 @@
1818
"security-rule",
1919
"grc"
2020
]
21-
}
21+
}

0 commit comments

Comments
 (0)