By GRCEngClub
Audit GitHub repositories for security compliance by scanning branch protections, secret scanning, Dependabot alerts, code scanning, and deploy keys; emit standardized JSON findings mapped to SCF controls. Setup gh CLI auth, collect findings across repo scopes, check connector status and rate limits.
Query GitHub for compliance-relevant configuration and emit findings conforming to the v1 contract.
Verify the github-inspector connector's prerequisites and write its config. Idempotent.
Report configuration state, auth validity, and last-run freshness for the github-inspector connector.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Deploy a serverless trust center to publish your company's compliance posture. Supports AWS deployment with S3, CloudFront, Lambda, DynamoDB, Cognito, and WAF.
FedRAMP Rev 5 Plugin - Traditional authorization path with SSP/SAP/SAR/POA&M documentation and NIST 800-53 Rev 5 control mapping
SOC 2 Compliance Plugin - Trust Service Criteria expertise, Type I/II assessment support, and control mapping
NIST 800-53 Plugin - Control families, baseline selection (Low/Moderate/High), and FedRAMP alignment
DORA Plugin - EU Digital Operational Resilience Act for financial entities with ICT risk management (effective January 2025)
npx claudepluginhub grcengclub/claude-grc-engineering --plugin github-inspectorGRC Engineering Plugin - Maps IaC to compliance controls, generates policies, collects evidence, reviews PRs for compliance, and transforms risks to Jira tickets
Audit and harden your software supply chain - packages, containers, GitHub Actions, IaC, AI/ML models, and IDE extensions. Action commands fix issues directly; walkthrough commands guide you through advanced setup.
GRC (Governance, Risk, and Compliance) domain knowledge — frameworks, controls, audits, evidence, ConMon, cross-framework mappings, document review, and operational workflows. Cloud-agnostic.
Intercepts GitHub URL fetches and curl/wget commands, redirecting to the authenticated gh CLI.
Check infrastructure compliance (SOC2, HIPAA, PCI-DSS)
AI-powered cybersecurity code review with 8 specialist agents, OWASP Top 10:2021, CWE Top 25:2024, MITRE ATT&CK v15, and framework-aware false-positive suppression