Atlas / Skills / jeremylongshore / Checking Infrastructure Compliance

Checking Infrastructure ComplianceSAFE

skills/jeremylongshore/checking-infrastructure-compliance

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.26.0
Hosts
1 documented
License
MIT
Stars
2,823
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Bundled resources for compliance-checker skill

  • [ ] compliancereporttemplate.md: Markdown template for generating compliance reports.
  • [ ] exampleinfrastructureconfig.yaml: Example infrastructure configuration file for demonstration purposes.
  • [ ] compliance_rules.json: JSON file containing compliance rules and checks.
Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: checking-infrastructure-compliance
description: 'Execute use when you need to work with compliance checking.

  This skill provides compliance monitoring and validation with comprehensive guidance
  and automation.

  Trigger with phrases like "check compliance", "validate policies",

  or "audit compliance".

  '
allowed-tools: Read, Write, Edit, Grep, Glob, Bash(cmd:*)
version: 1.26.0
author: Jeremy Longshore <[email protected]>
license: MIT
tags:
- devops
- monitoring
- compliance
- audit
compatibility: Designed for Claude Code
---
# Checking Infrastructure Compliance

## Overview

Audit infrastructure configurations against compliance frameworks (CIS Benchmarks, SOC 2, HIPAA, PCI-DSS, GDPR) using policy-as-code tools like Open Policy Agent (OPA), Checkov, and tfsec. Generate compliance reports, identify violations, and produce remediation plans for Terraform, Kubernetes, and cloud provider configurations.

## Prerequisites

- Policy-as-code tool installed: `checkov`, `tfsec`, `opa`, or `kube-bench`
- Infrastructure-as-code files (Terraform, CloudFormation, Kubernetes manifests) in the project
- Cloud provider CLI authenticated with read access to resources
- Compliance framework requirements documented (CIS, SOC 2, HIPAA, PCI-DSS)
- `jq` for parsing JSON policy outputs

## Instructions

1. Identify the applicable compliance framework(s) based on industry and data classification
2. Scan Terraform files with `checkov -d .` or `tfsec .` to detect misconfigurations
3. Scan Kubernetes manifests for security issues: missing resource limits, privileged containers, missing network policies
4. Validate IAM policies for least-privilege violations using cloud-native tools (`aws iam access-analyzer`)
5. Check encryption at rest and in transit: verify S3 bucket encryption, database TLS, and EBS volume encryption
6. Audit logging configurations: confirm CloudTrail/Cloud Audit Logs are enabled and sent to immutable storage
7. Generate a compliance report mapping each finding to the relevant control (e.g., CIS AWS 2.1.1)
8. Produce remediation Terraform/YAML patches for each violation with severity ranking (Critical, High, Medium, Low)
9. Set up CI/CD integration so compliance checks block merges on Critical/High violations

## Output

- Compliance scan results in JSON/SARIF format for CI integration
- Markdown compliance report with control mappings and pass/fail status
- Remediation code patches (Terraform diffs, Kubernetes manifest updates)
- OPA/Rego policy files for custom organizational rules
- CI/CD pipeline step configuration for automated compliance gating

## Error Handling

| Error | Cause | Solution |
|-------|-------|---------|
| `checkov: no Terraform files found` | Scanner run from wrong directory | Specify path explicitly with `-d path/to/terraform/` |
| `tfsec: failed to parse HCL` | Syntax error in Terraform files | Run `terraform validate` first to fix HCL syntax before compliance scan |
| `False positive on compliance check` | Rule too broad for the specific use case | Add inline skip comments (`#checkov:skip=CKV_AWS_18:Reason`) or create a `.checkov.yml` skip list |
| `OPA policy evaluation error` | Rego syntax error or missing input data | Test policies with `opa eval -d policy.rego -i input.json` and validate Rego syntax |
| `Scan timeout on large codebase` | Too many files or complex module references | Use `--compact` mode, scan directories individually, or increase timeout limits |

## Examples

- "Run a CIS Benchmark compliance check against all Terraform files and generate a report with remediation steps for Critical findings."
- "Create OPA policies that enforce: all S3 buckets must have encryption, all EC2 instances must have IMDSv2, and all security groups must not allow 0.0.0.0/0 ingress."
- "Scan Kubernetes manifests for PCI-DSS compliance: verify no privileged containers, all pods have resource limits, and network policies exist for every namespace."

## Resources

- Checkov: https://www.checkov.io/
- tfsec: https://aquasecurity.github.io/tfsec/
- Open Policy Agent: https://www.openpolicyagent.org/docs/latest/
- CIS Benchmarks: https://www.cisecurity.org/cis-benchmarks
- kube-bench (CIS for Kubernetes): https://github.com/aquasecurity/kube-bench
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__checking-infrastructure-compliance.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aSAFEB89first audit
06

Questions

What does the Checking Infrastructure Compliance skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Checking Infrastructure Compliance safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Checking Infrastructure Compliance access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Checking Infrastructure Compliance work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement