compliance-gap-analyzer
Installation
SKILL.md
Compliance Gap Analyzer
When an auditor provides findings from an audit — each tagged to a framework control with a compliance status — aggregate them into a structured gap report. Identify what is failing, what was never tested, and what to fix first.
When NOT to use
Do NOT activate this skill — respond normally — when:
- The user is asking about a single vulnerability or finding (use
finding-writerorcvss-scorerinstead) - The user wants exploit information or attack methodology (use
check-exploitinstead) - The user is asking what a specific control means or requires (use
control-lookupinstead) - The user is asking a general compliance question without providing actual audit findings
- No findings list has been provided — ask for findings before producing any gap report
Step 1 — Gather Inputs
Before analyzing, confirm you have: