Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By GRCEngClub
Set up oscal-cli and manage OSCAL compliance documents: validate JSON/XML/YAML files against NIST schemas, convert formats with round-trip fidelity, author SSPs/profiles/ARs/POA&Ms, fix validation errors, and integrate with FedRAMP/eMASS workflows.
npx claudepluginhub grcengclub/claude-grc-engineering --plugin oscalConvert OSCAL documents between JSON, XML, and YAML formats with round-trip fidelity.
Install the oscal-cli Go binary and register it with the plugin. Idempotent.
Validate an OSCAL document (catalog, profile, SSP, SAP, SAR, POA&M, component definition, assessment results) against the official JSON schemas.
Share bugs, ideas, or general feedback.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Convert FedRAMP Rev 5 Moderate SSP DOCX templates to validated OSCAL 1.2.0 JSON. Wraps ethanolivertroy/frdocx-to-froscal-ssp — ready for oscal-cli, Compliance Trestle, eMASS, and FedRAMP 20X workflows.
GRC (Governance, Risk, and Compliance) domain knowledge — frameworks, controls, audits, evidence, ConMon, cross-framework mappings, document review, and operational workflows. Cloud-agnostic.
End-to-end FedRAMP authorization guidance — readiness assessments, SSP narratives, POA&M management, NIST 800-53 Rev 5 control mapping, and ConMon support.
Check infrastructure compliance (SOC2, HIPAA, PCI-DSS)
Harness-native ECC plugin for engineering teams - 63 agents, 249 skills, 79 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Deploy a serverless trust center to publish your company's compliance posture. Supports AWS deployment with S3, CloudFront, Lambda, DynamoDB, Cognito, and WAF.
SOC 2 Compliance Plugin - Trust Service Criteria expertise, Type I/II assessment support, and control mapping
Essential 8 Plugin - Australian Cyber Security Centre mitigation strategies with 3 maturity levels
GRC connector for GitHub: evaluates repo protections, branch policies, Actions, secret scanning, Dependabot, and deploy keys. Emits findings conforming to schemas/finding.schema.json v1.
GRC Third-Party Risk Management Plugin - Vendor assessments, questionnaire analysis, and risk scoring
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claim