From splunk-inspector
Interpret splunk-inspector findings and translate Splunk retention, RBAC, audit, search ACL, and auth posture into compliance evidence and remediation.
How this skill is triggered — by the user, by Claude, or both
Slash command
/splunk-inspector:splunk-inspector-expertThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Use this skill when reviewing `splunk-inspector` output or planning Splunk logging and access-control remediation.
Use this skill when reviewing splunk-inspector output or planning Splunk logging and access-control remediation.
Findings are written to:
~/.cache/claude-grc/findings/splunk-inspector/<run_id>.json
Resource types:
splunk_deploymentsplunk_indexsplunk_roleLOG-05: log retentionLOG-08: audit event coverageIAC-07: role and saved-search access controlIAC-04: SSO / authentication method visibilityadmin_all_objects, edit_roles, and indexes_edit require owner review._audit data and export it where long-term retention is required.npx claudepluginhub shipstuff/claude-grc-engineering --plugin splunk-inspectorGuides creation and editing of skills using test-driven development with pressure scenarios and subagents to verify agent compliance.
Orchestrates altering an existing, working feature to new desired behavior by updating tests first, then implementation, with review and gated commit.
6plugins reuse this skill
First indexed Jul 18, 2026