prowler-compliance

Installation
SKILL.md

When to Use

Use this skill when:

  • Creating a new compliance framework for any provider — decide universal vs legacy first (see below)
  • Syncing an existing framework with an upstream source of truth (CIS, FINOS CCC, CSA CCM, NIST, ENS, etc.)
  • Adding requirements to existing frameworks, or extending a universal framework to a new provider
  • Mapping checks to compliance controls
  • Adding ConfigRequirements guardrails so configurable checks can't silently satisfy a requirement with a loosened config
  • Auditing existing check mappings as a cloud auditor ("are these mappings correct?", "which checks apply?", "review the mappings")
  • Adding a new legacy output formatter (table dispatcher + per-provider classes + CSV models)
  • Fixing JSON bugs: duplicate IDs, empty Version, wrong Section, stale check refs, inconsistent FamilyName, padded tangential check mappings
  • Investigating why a finding/check isn't showing under the expected compliance framework in the UI
  • Understanding compliance framework structures and attributes

The authoritative contributor doc is docs/developer-guide/security-compliance-framework.mdx — keep this skill and that doc consistent when either changes. For reviewing a compliance PR, use the sister skill prowler-compliance-review instead.

Installs
67
GitHub Stars
14.6K
First Seen
Jan 21, 2026
prowler-compliance — prowler-cloud/prowler