soc2-compliance
soc2-compliance is an code AI skill with a core value of Implement SOC 2 Trust Services Criteria. It
helps developers solve real-world problems in the code domain, boosting
efficiency, automating repetitive tasks, and optimizing workflows.
Implement SOC 2 Trust Services Criteria. Configure security, availability, and processing integrity controls. Use when achieving SOC 2 certification.
Quick Facts
mkdir -p ./skills/soc2-compliance && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/soc2-compliance/SKILL.md -o ./skills/soc2-compliance/SKILL.md Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).
Skill Content
# SOC 2 Compliance
Implement SOC 2 Trust Services Criteria controls, evidence collection, and continuous compliance monitoring for Type I and Type II audits.
When to Use
- Preparing for a SOC 2 Type I or Type II audit
- Mapping existing controls to Trust Services Criteria
- Automating evidence collection for auditor requests
- Building continuous compliance monitoring into CI/CD
- Onboarding new services and ensuring SOC 2 control coverage
Trust Services Criteria Detailed Checklist
security_common_criteria:
CC1_control_environment:
CC1.1: "Management demonstrates commitment to integrity and ethical values"
CC1.2: "Board exercises oversight of internal controls"
CC1.3: "Management establishes structure, authority, and responsibility"
CC1.4: "Commitment to competence - hire and retain qualified personnel"
CC1.5: "Individuals are held accountable for internal control responsibilities"
evidence:
- Code of conduct document
- Organizational chart
- Job descriptions with security responsibilities
- Board meeting minutes discussing security
- Background check policy and records
CC2_communication:
CC2.1: "Entity obtains or generates relevant quality information"
CC2.2: "Entity internally communicates information including objectives and responsibilities"
CC2.3: "Entity communicates with external parties"
evidence:
- Security awareness training records
- Internal security newsletters or updates
- Customer-facing security documentation
- Status page and incident communication records
CC3_risk_assessment:
CC3.1: "Entity specifies objectives clearly to identify and assess risks"
CC3.2: "Entity identifies risks to achievement of objectives"
CC3.3: "Entity considers potential for fraud"
CC3.4: "Entity identifies and assesses significant changes"
evidence:
- Annual risk assessment report
- Risk register with ratings and treatment plans
- Fraud risk assessment documentation
- Change management records
CC4_monitoring:
CC4.1: "Entity selects, develops, and performs ongoing/separate evaluations"
CC4.2: "Entity evaluates and communicates internal control deficiencies"
evidence:
- Continuous monitoring dashboard screenshots
- Internal audit reports
- Vulnerability scan results
- Penetration test reports
CC5_control_activities:
CC5.1: "Entity selects and develops control activities to mitigate risks"
CC5.2: "Entity selects and develops technology-based controls"
CC5.3: "Entity deploys control activities through policies and procedures"
evidence:
- Information security policy
- Access control procedures
- Change management procedures
- Encryption standards documentation
CC6_logical_access:
CC6.1: "Logical access security over protected information assets"
CC6.2: "Prior to access, users are registered and authorized"
CC6.3: "Access to data, software, functions, and other IT resources is authorized and modified"
CC6.6: "Logical access security measures against threats from outside system boundaries"
CC6.7: "Transmission of data between parties is protected"
CC6.8: "Controls to prevent or detect unauthorized or malicious software"
evidence:
- IAM credential report
- MFA enforcement configuration
- Access review completion records
- Firewall and WAF configurations
- TLS/encryption configurations
- Endpoint protection deployment records
CC7_system_operations:
CC7.1: "Detect anomalies and potential security incidents"
CC7.2: "Monitor system components for anomalies"
CC7.3: "Evaluate detected events and determine incidents"
CC7.4: "Respond to identified security incidents"
CC7.5: "Identify and remediate security incidents"
evidence:
- SIEM alert rules and dashboards
- Monitoring configuration (CloudWatch, Datad🎯 Best For
- Security auditors
- DevSecOps teams
- Compliance officers
- Claude users
- Software engineers
💡 Use Cases
- Auditing dependencies for known CVEs
- Scanning API endpoints for auth gaps
- Code quality improvement
- Best practice enforcement
📖 How to Use This Skill
- 1
Install the Skill
Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.
- 2
Load into Your AI Assistant
Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.
- 3
Apply soc2-compliance to Your Work
Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.
- 4
Review and Refine
Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.
❓ Frequently Asked Questions
Can this replace a dedicated SAST tool?
AI-based security review is complementary to SAST tools. Use it as a first-pass filter, not a replacement.
Is soc2-compliance compatible with Cursor and VS Code?
Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.
Do I need specific dependencies for soc2-compliance?
Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.
How do I install soc2-compliance?
Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/soc2-compliance/SKILL.md, ready to use.
Can I customize this skill for my team?
Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.
⚠️ Common Mistakes to Avoid
Only scanning surface-level issues
Deep security review requires understanding your app architecture, not just regex patterns.
Skipping validation
Always test AI-generated code changes, even for simple refactors.
Missing dependency updates
Check if the skill requires updated dependencies or new packages.