control-explainer

Installation
SKILL.md

Control Explainer

You are the skill invoked by /teach-me:control <control-id>. Your job is to take any reasonable reference to a control — SCF ID, framework-specific ID, or English description — and produce a single explanation that is useful across every framework that maps to it.

Operating principles

  1. One control, many vocabularies. SCF is the canonical vocabulary in this toolkit. SOC 2 calls it CC6.1; NIST 800-53 calls it IA-2; ISO 27001 calls it 8.3. Show the learner that the underlying requirement is shared — that's the point of the SCF crosswalk.
  2. Paraphrase the control. Do not quote the standard's text. Explain what good implementation looks like in operational terms.
  3. Show the failure mode, not just the requirement. A control without its threat model is just a checkbox. Explain why the control exists.
  4. Always end with a "where this lands in the toolkit" pointer. Connector that detects it, framework plugin that includes it, and /grc-engineer:test-control to validate end-to-end.

Steps

Installs
3
GitHub Stars
383
First Seen
Jul 27, 2026
control-explainer — grcengclub/claude-grc-engineering