Internal audit team — 2 agents (internal-audit-lead, audit-engagement-specialist) for the independent assurance & advisory function over ALL risk, anchored on the IIA Global Internal Audit Standards (2024 — 5 domains / 15 principles), COSO Internal Control & COSO ERM, and the Three Lines Model. Covers the risk-based audit universe → annual plan → engagement lifecycle (planning memo/scope, risk & control matrix, test of design + operating effectiveness, attribute sampling, workpapers & evidence), findings via the 5 C's, impact×likelihood issue rating, the audit-committee report & management action plans, follow-up/remediation validation, and the QAIP + external quality assessment. Independence discipline: IA assures/advises, never owns controls. 3 skills, a 2-doc knowledge bank (decision tree + 2026 patterns), and 2 templates. Distinct from cybersecurity-grc (security-control assurance), regulatory-compliance (AML/financial regs), and esg-sustainability-reporting (ESG assurance). Needs ravenclaude-core.
Use to EXECUTE an internal-audit engagement — planning memo & scope, risk & control matrix, walkthroughs, test of design + operating effectiveness, attribute sampling, workpapers, findings via the 5 C's, issue rating, and follow-up. NOT for the annual plan / audit universe → internal-audit-lead.
Use to run the internal-audit FUNCTION — risk-based audit universe & annual plan, IIA Global Standards (2024) conformance, independence & objectivity, the audit-committee reporting line, and the QAIP / external quality assessment. NOT for security-control assurance → cybersecurity-grc.
Build a risk-based internal-audit universe and annual plan by traversing the internal-audit decision tree (assurance-vs-advisory → risk-ranking the universe → coverage/cycle → resourcing), then return the scored audit universe, the resource-balanced annual plan (assurance/advisory mix, cycle coverage), the IIA-Standards/Three-Lines positioning, and the audit-committee residual-risk narrative. Reach for this when the user asks 'how do we rank our audit universe?', 'what should be on this year's audit plan?', 'how much of the universe can we cover?', or 'how do we stay IIA-conformant and independent?'. Used by internal-audit-lead (primary).
Plan and execute a single internal-audit engagement by traversing the internal-audit decision tree (assurance-vs-advisory → scope & criteria → sampling approach → evidence), then return the planning memo, the risk & control matrix (risk → control → type → tests), the walkthrough, the test of design + test of operating effectiveness with an attribute-sampling plan and sample size, and review-ready workpapers. Reach for this when the user asks 'draft the planning memo and RCM', 'how do we test this control?', 'what sample size?', or 'are our workpapers sufficient?'. Used by audit-engagement-specialist (primary).
Turn tested control gaps into well-formed internal-audit findings and report them by traversing the issue-rating branch of the internal-audit decision tree, then return each finding on the 5 C's (Criteria/Condition/Cause/Consequence/Corrective action), an impact×likelihood rating (high/medium/low), the agreed management action plan (owner + date), the audit-committee summary, and the follow-up / remediation-validation plan. Reach for this when the user asks 'write this control gap as a finding', 'how bad is this issue / what rating?', 'draft the audit report or committee summary', or 'how do we validate the fix closed?'. Used by audit-engagement-specialist (primary) and internal-audit-lead.
Uses power tools
Uses Bash, Write, or Edit tools
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
A private Claude Code plugin marketplace — bundled team rules, specialist agents, dispatch playbooks, and templates that travel with you across projects.
🚀 ▶ See what RavenClaude is (
pitch.html) — the one-page pitch: the value prop, the proof, and the plugin catalog at a glance. Start here. (Or view the raw HTML source, or download and open locally — no server, no build step.)🏠 ▶ Open the landing page (
index.html) rendered in your browser — the front door: a navigable home with the plugin catalog, the specialist roster, and a comfort-posture starter. Regenerated from the manifests on every release.(Or view the raw HTML source, or download and open locally — no server, no build step.)
🎛 ▶ Open the RavenClaude dashboard — point-and-click editor for your
.ravenclaude/comfort-posture.yaml: set per-tool file, network, shell, and package autonomy across three levels (deny → ask → allow) — per layer (user / local / project) and per individual permission — without editing YAML by hand. (That link is the published, read-only preview; to use it for real — where Save & apply writes your repo's config — runrc dashboardfrom your project, the one canonical launcher across Claude Code, Copilot CLI, and a bare terminal.)
🖥 Working on this repo? Launch the functional local dashboard (where Save & apply actually writes this repo's config) with one command:
bash scripts/open-dashboard.sh. It kills any running dashboard server, starts a fresh one, and opens it in your browser automatically. (VS Code users: a.vscode/tasks.jsonwired as the default build task — Ctrl/Cmd+Shift+B — runs the same script;.vscode/is gitignored, so add it locally if you want the keybinding.)
📖 ▶ Open the RavenClaude portal — one self-contained page: browse every plugin, agent, skill, hook, rule, and template in the Marketplace section (with an “I want to…” use-case lookup), tune the comfort-posture Dashboard, and more. Regenerated from the manifests on every release.
(Or view the raw HTML source, or download and open locally — no server, no build step.)
🚀 ▶ First Workflow in 10 Minutes — install → dashboard → one governed multi-agent dispatch →
/wrap. The canonical onboarding walkthrough. Start here if you've never used RavenClaude before.
🌐 ▶ Raven Power ↗ — the consulting front door behind RavenClaude. This marketplace is the proof-of-craft; the website is where the engagements live.
Today this marketplace ships 163 plugins:
ravenclaude-core — domain-neutral Team Lead + 14 specialists (architect, coders, reviewers, designer, documentarian, deep-researcher, project-manager, partner-success-manager, prompt-engineer, data-engineer, etc.), plus dispatch playbooks (with a Cross-plugin dispatch section), gates, 43 skills, 16 hooks, templates, and the cross-project contribution-staging loop.power-platform — 11 Microsoft Power Platform specialists (Power Fx, flows, Power BI, Dataverse, model-driven, PCF, Copilot Studio, Power Pages, admin, ALM, tester), 21 skills, an advisory house-opinions hook covering 8 checks, and the bundled pbix-mcp MCP server.finance — 7 corporate-finance & FP&A specialists (FP&A analyst, financial modeler, controller, treasury, valuation, audit-prep, board-pack composer), 9 skills, templates, advisory anti-pattern hook.regulatory-compliance — 12 financial-regulatory specialists (6 function: AML/KYC, regulatory reporting, risk-and-controls, policy & procedure writer, examination prep, Bermuda-insurance; plus 6 jurisdiction: BMA, CIMA Cayman, Bahamas, Channel Islands, UK PRA, US), 10 skills, templates, defensive PII-scrub hook.web-design — 7 web specialists (web architect, UX, visual, frontend implementer, content strategist, accessibility auditor, performance engineer) with WCAG 2.2 AA/AAA, Core Web Vitals, SEO/AEO, and Fluent + React discipline. 11 skills, templates, advisory web anti-pattern hook.edtech-partner-success — 6 K-12 EdTech partner-success specialists (partner-success manager, success-playbook designer, learning-analytics analyst, QBR composer, partner-profile curator, FERPA comms translator) with 16 skills and a knowledge bank of operating cadences.npx claudepluginhub mcorbett51090/ravenclaude --plugin internal-auditAI multimedia for brand & winery sites: a creative brief -> on-brand, web-optimized, license-clean images/video/3D/audio behind a mandatory human curation gate. 4 agents (generation-strategist, web-asset-pipeline-engineer, asset-provenance-guardian, brand-and-accessibility-reviewer) route a brief to the right generator (provider-neutral, Grok-lean for images where competitive; inpaint/outpaint/bg-removal/upscale first-class), turn raw output into AVIF/WebP responsive <picture> markup with LCP/CLS-safe embeds, pin commercial-use licenses (flags the FLUX-dev non-commercial trap; C2PA + a provenance ledger; EU AI Act Art.50 disclosure), and gate every asset on brand-hex/style conformance + WCAG alt text before ship. 6 skills, 4 knowledge docs (Mermaid decision trees; all prices [unverified]), 6 best-practices, 4 commands, 5 templates, 4 scripts. The shared foundation the brand-identity-studio plugin consumes. Declarative fal MCP binding (set FAL_KEY). Requires ravenclaude-core@>=0.7.0.
Corporate finance & FP&A specialist team — FP&A analyst, financial modeler, controller, treasury analyst, valuation analyst, audit-prep specialist, and board-pack composer. Ships 23 skills including the controller-autopilot: a governed close-to-report cycle (GAAP statements, COA mapping, reconciliation auto-match, review→approve→lock workflow, ELT staging, consolidation, per-entity dashboard, close schedules) plus its live-integration tier (multi-currency remeasurement + CTA, OAuth GL connectors + drill-through lineage, warehouse/RLS dashboard, IdP-backed segregation of duties) and a gold-standard NetSuite close (OAuth2 M2M + SuiteQL BS/IS trial balance, COA-draft, tie-out doctor, changed-after-sign-off drift, layperson runbook). 10 templates, a knowledge bank, and 2 advisory hooks (anti-patterns + secrets/PII scan). Inherits ravenclaude-core protocols (Grounding, Structured Output, Cited-Adjudicator).
Power Platform specialist team — 11 agents (incl. power-platform-tester, power-bi-engineer) and 23 skills, with strong ALM/git coverage for solutions, flows, and PBIP. A house-opinions hook flags 8 §3/§4 violations; the knowledge bank carries production decision trees (PA-flow recovery, Dataverse token-acquisition, PCF React surface, PBI deploy/refresh, custom-connector build-path, PBIR Enhanced infinite-spinner debug + full build reference, DAX silent-zero scoring via the `Domain` pattern, sempy.fabric notebook reference, Power BI Copilot report-readiness, Code Apps connector gotchas, PBIP deployment variables + #839, PBIR reference enrichment, PBIP report fast-solve triage router [MCP-optional]) plus a real-engagement scenarios bank. Bundles the community pbix-mcp server (d0nk3yhm/pbix-mcp, MIT) for .pbix/.pbit read/write/DAX-eval (`pip install pbix-mcp`); documents (not bundles) the official Microsoft Dataverse MCP (CLAUDE.md §9a). Extends ravenclaude-core.
Project & delivery management team — four specialists across the predictive (PMBOK/PMP) and agile (Scrum/Kanban) tracks and the hybrid between: delivery-lead (charter, schedule, scope/change control, earned value), scrum-master (backlog, sprints, ceremonies, velocity, impediments), risk-and-raid-analyst (scored qual+quant risk, RAID depth, mitigation/contingency, issue triage), and stakeholder-comms-lead (stakeholder register, comms plan, status/exec reporting, escalation memos, steering packs). Deepens — does NOT replace — ravenclaude-core's domain-neutral project-manager (the lightweight RAID/status-hygiene default every plugin routes to); this is the deep PM craft layer. Knowledge: a predictive-vs-agile-vs-hybrid decision tree + a best-practices library. Seams: prose polish → ravenclaude-core/documentarian; system design → architect. Requires ravenclaude-core@>=0.7.0.
AI/LLM red-teaming team — 2 agents (ai-redteam-lead, adversarial-testing-engineer) for the layer answering 'can this AI system be made to do harm, leak data, or exceed its authority — and how do we harden it?': threat modeling + rules of engagement, the attack taxonomy (OWASP LLM Top 10 2025 + MITRE ATLAS), direct vs indirect prompt injection, jailbreaks (roleplay/encoding/many-shot/crescendo), data exfiltration & training-data extraction, agentic tool-abuse / excessive agency, multimodal attacks, and defense-in-depth remediation. Fluent in automated red-team harnesses (PyRIT, Garak, Promptfoo red-team, Giskard) and likelihood×impact severity. 3 skills, a 2-doc knowledge bank (attack-taxonomy decision tree + 2026 patterns), and 2 templates. Distinct from llm-evaluation-engineering (quality-regression eval), trust-and-safety (content-moderation / T&S policy), and security-engineering (app/infra pentest) — the adversarial AI-security layer over model- and agent-based systems. Requires ravenclaude-core@>=0.7.0.
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Develop, test, build, and deploy Godot 4.x games with Claude Code. Includes GdUnit4 testing, web/desktop exports, CI/CD pipelines, and deployment to Vercel/GitHub Pages/itch.io.
A growing collection of Claude-compatible academic workflow bundles. Covers scientific figures, manuscript writing and polishing, reviewer assessment, citation retrieval, data availability, paper reading, literature search, response letters, paper-to-PPTX conversion, and evidence-grounded Chinese invention patent drafting. Rules are organized as reusable skill folders with explicit workflows and quality checks.
Comprehensive PR review agents specializing in comments, tests, error handling, type design, code quality, and code simplification
Comprehensive feature development workflow with specialized agents for codebase exploration, architecture design, and quality review
Harness-native ECC operator layer - 67 agents, 278 skills, 94 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses