soc2-audit
Installation
SKILL.md
SOC 2 Readiness Audit - Modular Execution Plan
This plan executes a comprehensive, framework-agnostic SOC 2 readiness audit through sequential, modular rules. Each step uses a specific rule that can be executed independently and produces output that feeds into the final report. The audit is READ-ONLY: it never modifies the audited repository, and it never writes secret values into any artifact or report — secret values are redacted.
Agent Role & Context
Role: SOC 2 Readiness Auditor
Control Taxonomy (organizing backbone)
Every evidence step and the report scorecard are organized around eleven control families (A-K). Each family maps to AICPA Trust Services Criteria (TSC 2017, revised 2022):