Skip to main content
Guide9 min read·Updated August 21, 2026
🧩

Best AI Agent Skills for SOC 2 Compliance in 2026

B

A. Frans

Published August 21, 2026

SOC 2ComplianceSecurityClaude CodeGRC

No auditor has ever accepted "Claude said we were compliant." That's worth stating before anything else, because the marketing around AI compliance tooling badly blurs the line between preparing for an audit and passing one.

What agent skills do change is the two things that eat a SOC 2 or ISO 27001 timeline: writing the policy and control documentation from scratch, and figuring out which of your 400 cloud misconfigurations map to a control your auditor will test. Both are enormous. Neither is evidence.

Here's what's real in this category right now, what each one installs as, and where the honest limits are.

The lineup

SkillWhat it doesStarsTrustInstalls as
GRC Skills Pack30 framework-specific skills: SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, FedRAMP, EU AI Act842CommunityClaude Code marketplace
Prowler639 AWS checks mapped to 47 compliance frameworks14,621VerifiedCLI + bundled skills + MCP server
Trail of Bits Skills40+ audit plugins: code review, malware analysis, property testing6,668VerifiedPlugin marketplace
SemgrepSAST across 30+ languages, custom rule patterns16,305VerifiedCLI the agent drives
Wazuh MCP Server55 SIEM tools: alert triage, vuln management, compliance reporting222CommunityMCP server
SAIL Skill91-risk catalog for AI/agent security gap assessments131CommunitySKILL.md, any agent
CordumPolicy enforcement + approval gates + audit trails for agents494CommunityMCP server
agentshPolicy-enforced shell with execution audit log375CommunitySkill + shell layer
Two clusters here, and mixing them up is the most common mistake. The first five help you assess and document your systems. The last three secure the agent itself, which is a control your auditor will start asking about but a different problem.

Documentation: the GRC skills pack

This is the one that maps most directly to "help me get through SOC 2." Thirty skills, one per framework, covering SOC 2 and ISO 27001 alongside GDPR, HIPAA, PCI DSS, FedRAMP, NIST CSF, CMMC 2.0, ISO 42001, DORA, EU NIS2, the EU AI Act, CCPA/CPRA, LGPD, and about fifteen more. MIT licensed, updated monthly, 842 stars and 173 forks.

The maintainer publishes a benchmark: 93% with skills against a 79% baseline across 150 test cases. Take that for what it is: a self-graded number from the person who built the thing, measured on a test set they also wrote. It's not nothing, and the direction is almost certainly right, since a skill that loads the actual control text beats a model recalling it from training. But it isn't independent evidence, and nobody should quote it to a security committee as though it were.

Installation goes through the Claude Code marketplace. Note that the repo organizes skills as [Framework Name] - Claude Skill/framework.skill rather than the conventional SKILL.md directory layout, so if you're used to dropping folders into ~/.claude/skills/ and expecting them to register, check the repo's own instructions first.

Where it helps most: control narratives, policy drafts, gap assessment questionnaires, and translating between frameworks when you're already ISO 27001 certified and going for SOC 2. Where it doesn't help at all: producing the log exports, access reviews, and ticket histories that constitute actual audit evidence.

Cloud posture: Prowler

Prowler is the heavyweight, at 14,621 stars and the most widely used open-source cloud security platform. 639 AWS checks mapped across 47 compliance frameworks including SOC 2, ISO 27001, PCI-DSS, HIPAA, GDPR, FedRAMP, NIST 800-53, NIST CSF, CIS, and MITRE ATT&CK.

pip install prowler
prowler -v

Python 3.10 to 3.12. The repo also ships Claude Code skills via ./skills/setup.sh, which writes into .claude/skills/, plus a Prowler MCP server for the Lighthouse assistant. That combination is the useful part: the scanner produces the findings, the skill teaches your agent how to read and prioritize them.

Prowler is the closest thing on this list to real audit input. A CIS or SOC 2 framework run produces per-check pass/fail output with resource identifiers, which is the kind of artifact an auditor will look at. It still isn't the control evidence itself, since nobody certifies you because a scanner passed — but it's the difference between "we think encryption at rest is on" and a dated report listing every bucket.

Budget a full day for the first run. On any real AWS account, output is in the hundreds of findings, and triaging that list is the actual work.

Code security: Trail of Bits and Semgrep

Trail of Bits Skills carries the strongest provenance of anything here. Trail of Bits is a top-tier security research firm, and this is 40+ plugins covering code auditing (c-review, rust-review, differential-review, semgrep-rule-creator), smart contract security, malware analysis via yara-authoring, property-based testing, mutation testing, constant-time analysis, and reverse engineering. 6,668 stars, 9,500 installs, CC-BY-SA-4.0.

/plugin marketplace add trailofbits/skills
/plugin menu

That second command opens the browser so you can install only what you need. Do that. Installing 40 plugins at once buys you a bloated context window and a lot of skills you'll never invoke.

Semgrep is a different shape. It's a SAST engine, not a skill package: you install the CLI and your agent runs it. 16,305 stars, LGPL-2.1, pattern-matching static analysis where rules look like the source code they match, across Go, Java, JavaScript, Python, Ruby, C, and more.

The pairing worth knowing: Trail of Bits' semgrep-rule-creator skill exists specifically to have an agent write Semgrep rules for you. Custom rules are where Semgrep gets powerful and where most teams stop, because writing them is fiddly. This is one of the clearest cases in the whole skills ecosystem where the skill layer does something the underlying tool can't do alone.

SIEM and monitoring: Wazuh MCP

55 tools for alert triage, threat hunting, vulnerability management, active response, and compliance reporting against PCI DSS, GDPR, HIPAA, NIST CSF, and ISO 27001. OAuth 2.1, RBAC, multi-cluster, air-gap ready. 222 stars, community tier, unreviewed.

That "unreviewed" flag deserves weight here more than anywhere else on this page. This connects an LLM to your SOC with active response capability, a category of access where a wrong tool call has operational consequences, not just a bad answer. The OAuth 2.1 and RBAC support is what makes it defensible: scope the credential tightly, start read-only, and read the source before it touches production. It's a small enough project that reading it is realistic.

Only relevant if you already run Wazuh. If you don't, this isn't a reason to adopt it.

Securing the agent itself

Here's the part most compliance content skips. If your engineers are running agents against production infrastructure, your auditor is going to ask how those actions are controlled and logged. "We trust the model" is not a control.

SAIL Skill ships the Secure AI Lifecycle V2 catalog of 91 risks as an agent skill for gap assessments, security roadmaps, and compliance checklists. Works on Claude Code, Codex, ChatGPT, Antigravity, and anything that reads SKILL.md. 131 stars, community, and the licence is non-standard, so check it before commercial use.

Cordum is an agent control plane: pre-execution policy enforcement, approval gates, and audit trails, working across LangChain, CrewAI, and MCP. agentsh takes a lower-level cut at the same problem — a policy-enforced shell that logs what the agent executed.

Neither is mature. Both are under 500 stars and unreviewed. But the audit trail question is real and arriving fast, and the teams thinking about it now are going to have a much easier conversation in twelve months than the ones who aren't.

What to install, by situation

Preparing for a first SOC 2 with an AWS footprint: Prowler plus the GRC skills pack. Scanner for posture, skills for documentation. That covers the two biggest time sinks.

Already certified, adding a framework: GRC skills pack alone. Cross-framework mapping is the specific thing it's good at, and you already have the evidence machinery.

Security engineering team, not compliance: Trail of Bits plus Semgrep. Skip everything else; you're solving code security, not certification.

Running agents in production: Add Cordum or agentsh, and read the SAIL catalog even if you never install it. The 91-risk list is useful as a checklist regardless of tooling.

The line you shouldn't cross

Never let an agent generate audit evidence. Control narratives, gap analyses, policy drafts, remediation plans are all fine, all reviewable, all things a human signs off on. But an access review, a change log, a vulnerability scan result, a training completion record: those have to come out of the system that produced them, unedited.

The failure mode is specific and it's already happened to people. An agent asked to "prepare the access review for Q3" produces a clean, formatted, plausible table. Nobody notices it was assembled from a summary rather than exported from the identity provider. That's not a compliance gap. Depending on what you signed, it's a misrepresentation.

Use these tools to get to the auditor faster. Don't use them to write what the auditor asked to see.

FAQ

Can an AI agent get us SOC 2 certified? No. Certification requires an independent CPA firm to test controls over an observation period. What these skills compress is preparation: policy documentation, gap assessment, and mapping cloud findings to control objectives. That is most of the calendar time before the audit window opens.

Is Prowler enough on its own for SOC 2? It covers cloud configuration posture, which is one input among many. SOC 2 also tests access management, vendor management, change management, incident response, and HR controls, none of which a cloud scanner sees. Prowler handles a meaningful slice, not the whole thing.

Which of these are safe to install without a security review? Prowler, Semgrep, and Trail of Bits are all verified tier with strong provenance and permissive licences. The GRC pack is MIT and reads as documentation rather than executable tooling. Wazuh MCP, Cordum, agentsh, and SAIL are community tier and unreviewed, so read the source first, especially anything you're pointing at production. Our guide on the risk of installing community skills covers the process.

Does the GRC pack cover the EU AI Act? Yes, along with ISO 42001 and the NIST AI Risk Management Framework. It's one of the few skill collections that has kept pace with AI governance frameworks specifically.

We're a small team with no compliance staff. Where do we start? Run Prowler against your cloud account and read the SOC 2 framework output. It costs nothing but time, and the findings list tells you honestly how far from ready you are before you spend money on an auditor or a compliance platform. See our full list for cybersecurity professionals for tooling beyond the agent-skill layer.

Do these work outside Claude Code? SAIL is explicitly multi-agent: Claude Code, Codex, ChatGPT, Antigravity, anything reading SKILL.md. Cordum and Wazuh are MCP servers, so any MCP-compatible client works. Trail of Bits and the GRC pack are distributed through the Claude Code marketplace. Prowler and Semgrep are plain CLIs, so any agent that can run a shell command can use them.

Share this article

📬

Get More AI Tool Guides

New comparisons and guides every week. Join thousands of professionals staying ahead of the AI curve.