16 procédures général issues de ComplianceAsCode, chargées par les agents CompliForge. Chaque skill est un fichier lisible, versionné, retirable.

SkillCe qu'il fait
assess nist controlAssess a pending NIST 800-53 control with OSCAL enrichment, CIS reverse lookup, and Linux hardening prioritization. Guides authors through understanding, automatability analysis, rule mapping, and validation.
build productBuild a ComplianceAsCode product
create productCreate a new product in ComplianceAsCode project
create ruleCreate a new security rule with all required components
create templateCreate a template for checks and remediations
create test scenariosCreate Automatus test scenarios to test the given rule.
draft prOpen a pull request in the browser with prefilled title, description, and labels
find ruleSearch for existing rules that match a given requirement text. Identify rules that implement a specific control.
inspect controlInspect a control file showing requirement stats, mapping status, and cross-framework context. Use for triage before mapping.
manage profileCreate or update a versioned profile pair (versioned + unversioned extends pattern).
map controlsInteractive control-to-rule mapping session. Walk through unmapped requirements, suggest rules using cross-framework analysis, and write selections to control files.
map requirementMap rules to a single control file requirement using cross-framework analysis and rule search.
onboard controlOnboard a new security policy as a control file. Parse the document, create control file structure, and map existing rules to requirements.
resolve rule variablesResolve XCCDF variable selections for a set of rules. Looks up which variables each rule depends on, reads their .var files, and guides the author to select a value key for each variable. Returns a list of var_name=key selections ready to add to a control file
run testsRun ctest validation tests on a built product
test ruleRun Automatus tests for a security rule

Source : ComplianceAsCode (BSD). Hub Forge AI indexe et exécute ; il n'est pas l'auteur de ces skills.

Ces skills, exécutés par vos agents

CompliForge déployé sur votre infrastructure

Cette bibliothèque est ce que les agents CompliForge chargent quand ils travaillent chez vous : à jour chaque semaine, en lecture seule par défaut, avec validation humaine sur toute action sensible.