Run comprehensive compliance audits and infrastructure hardening for HIPAA, GDPR, SOC2, PCI-DSS, covering incident response, secrets scanning, dependency vulnerabilities, access controls, and audit logging. Generates auditor-ready reports.
Audit data privacy across your entire system — PII detection, data flow mapping, third-party sharing, consent enforcement, anonymization, retention, and multi-jurisdictional compliance (GDPR, CCPA, HIPAA, FERPA, LGPD, PIPEDA).
Scan codebases for leaked secrets and credentials — API keys, database URLs, private keys, JWT secrets, OAuth tokens, webhook signing keys. Covers pre-commit hooks, CI integration, git history deep scan, secret rotation procedures, and incident response for compromised credentials.
Harden infrastructure — containers, orchestrators, OS, TLS, secrets, and patches. Reduce the attack surface to zero across Docker, Kubernetes/ECS, base images, certificates, and build pipelines. CIS benchmark enforcement, image scanning, runtime protection.
Audit network security — VPC architecture, security groups, NACLs, WAF, egress controls, flow logs, private connectivity, and zero-trust segmentation. Every port, every rule, every path.
Audit access controls across application and infrastructure — RBAC/ABAC models, permission enforcement, MFA, user lifecycle, service accounts, least privilege, and break-glass procedures. Maps findings to SOC 2 CC6, HIPAA §164.312(d), PCI-DSS Req 7-8. Use during quarterly access reviews, before compliance audits, or when onboarding new roles and services.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
105 structured skills for development teams — from planning to release.
Every skill comes with step-by-step guides, flow diagrams, checklists, templates, and anti-patterns.
This repo is a native Claude Code plugin. Install individual packs directly from within Claude Code:
/install-plugin and point it to this repo, or add to your settings.json:{
"plugins": [
{ "source": "https://github.com/heaptracetechnology/heaptrace-skills", "plugin": "heaptrace-dev" },
{ "source": "https://github.com/heaptracetechnology/heaptrace-skills", "plugin": "heaptrace-architect" }
]
}
Install only the packs your team needs. Each plugin is listed in .claude-plugin/marketplace.json.
Clone and copy individual plugin skills to your tool's skills directory.
git clone https://github.com/heaptracetechnology/heaptrace-skills.git
# Copy a specific plugin's skills (e.g. developer pack)
cp -r heaptrace-skills/plugins/heaptrace-dev/skills/* your-project/.claude/skills/
# Copy all plugins at once
for plugin in heaptrace-skills/plugins/*/; do
cp -r "$plugin/skills/"* your-project/.claude/skills/
done
Path: .claude/skills/<skill-name>/SKILL.md
# Copy a specific plugin's skills
cp -r heaptrace-skills/plugins/heaptrace-dev/skills/* your-project/.cursor/skills/
Path: .cursor/skills/<skill-name>/skill.md
Skills are personal tools — don't commit them to your project repo:
echo ".claude/skills/" >> .gitignore
echo ".cursor/skills/" >> .gitignore
Skills are structured instruction files that guide AI coding assistants through specific development tasks. Instead of writing prompts from scratch, skills give consistent, battle-tested processes your entire team can follow.
Client gives a task
→ /suggest (what's missing? what can we add?)
→ /feature-plan (break it down, plan it)
→ /feature-work (build it end-to-end)
→ /code-review (catch issues before PR)
→ /smart-commit (clean commit message)
→ /release-notes (client-ready changelog)
The daily toolkit for every developer.
| Skill | What It Does |
|---|---|
feature-plan | Break requirements into tasks, mockups, and flow diagrams |
feature-work | Build end-to-end: DB → API → UI → Test |
find-fix | Trace bugs: reproduce → isolate → root cause → fix → verify |
smart-commit | Generate semantic commit messages (WHY, not WHAT) |
suggest | Spot gaps and suggest improvements clients didn't ask for |
code-review | 8-pass review: logic, security, perf, naming, tests |
test-gen | Generate tests that catch real bugs, not just pass |
explain | Understand any code before you touch it |
sec-audit | OWASP Top 10, secrets scan, dependency check |
release-notes | Turn git history into client-ready changelogs |
quick-plan | Rapid planning for small, well-scoped tasks |
quick-work | Fast execution mode for clearly defined tasks |
code-standards | Enforce and document team coding standards |
For tech leads managing teams and making architectural decisions.
| Skill | What It Does |
|---|---|
sprint-plan | Break epics into sprints with estimates and assignments |
arch-review | Audit architecture for scalability, coupling, SPOFs |
tech-debt-audit | Find and prioritize tech debt across the codebase |
incident-response | Structured triage, root cause analysis, postmortem |
pr-strategy | Split large features into reviewable PRs |
onboard-dev | Generate onboarding guide for new team members |
perf-audit | Profile slow endpoints, N+1 queries, memory leaks |
decision-doc | Write Architecture Decision Records (ADRs) |
message-craft | Craft clear technical messages and stakeholder updates |
System design, API contracts, and infrastructure planning.
npx claudepluginhub heaptracetechnology/heaptrace-skills --plugin heaptrace-complianceMobile development skills for app releases, mobile APIs, authentication, CI/CD, debugging, offline support, performance, and state management.
UI/UX designer skills for wireframing, user flows, design systems, UX audits, responsive design, accessibility, and design handoff.
QA skills for test planning, E2E testing, API testing, regression checks, bug reporting, load testing, accessibility audits, and test data generation.
Core developer skills for feature planning, code review, testing, commits, and daily development workflows.
Automation QA skills for Cypress testing, CI test pipelines, contract testing, mock services, and visual regression.
Generate compliance reports
Compliance and governance including regulatory mapping, security policies, audit readiness, GDPR, SOC2, and PCI-DSS compliance.
A team of AI security specialists embedded in your coding workflow. 8 agents covering every phase of the Secure SDLC: requirements, threat modelling, code review, IaC security, compliance, and release gating. Works with Claude Code, Cursor, Windsurf, and any MCP-compatible tool.
Regulatory compliance verification for GDPR, SOC2, and HIPAA
Security agents — security, compliance, privacy specialists
DevsForge Enterprise Compliance Automation Architect delivering comprehensive compliance engineering methodologies, regulatory automation frameworks, and governance optimization strategies that transform compliance management from operational burden into strategic business value creation and trust catalyst