๐งช Community โ Claude Code โ Claude Desktop Standalone โข Compliance-pack
Compliance Pack
Compliance โ evidence collection and control drift against CIS/SOC 2/HIPAA and cyber-insurance questionnaires.
Installation
Install this plugin individually:
/plugin marketplace add wyre-technology/msp-claude-plugins --plugin compliance-pack Or install all MSP plugins at once:
/plugin marketplace add wyre-technology/msp-claude-plugins Features
- Evidence Mapping
- Insurance Questionnaires
- Standards Drift
Skills
This plugin provides 3 skills that teach Claude about Compliance Pack:
| Skill | Description |
|---|---|
evidence-mapping | Tracing a compliance control (CIS, SOC 2, HIPAA, or a cyber-insurance questionnaire line item) to concrete, retrievable tool evidence: which vendor family can observe what โ CIPP for live M365/Entra configuration, Liongard for point-in-time infrastructure state, IT Glue/Hudu for documentation โ a representative control-to-tool-call map, and the evidentiary weights that separate Configured from Documented, Contradicted, and Unable to Verify. |
insurance-questionnaires | Drafting tool-verified answers to cyber-insurance renewal, new-business, and underwriter security questionnaires: the standard recurring question set (MFA everywhere including privileged accounts, EDR coverage ratio, tested and immutable backups, documented and tested IR plan, security awareness training), which connected tools actually answer each one, and the evidence-backed / documented-only / unable-to-verify labeling discipline that keeps an answer defensible during a claim investigation. |
standards-drift | Detecting configuration drift against an established baseline: CIPP standards checks and Best Practice Analyser results, Liongard change detections and inspection timelines, the three conditions that make a diff real drift rather than noise, the signals that separate intentional or authorized change from unauthorized weakening (ticket correlation, reversion pattern, direction of change), and the priority order for ranking several drift findings at once. |
Agents
This plugin provides 3 agents for autonomous task execution:
| Agent | Description |
|---|---|
control-drift-reporter | Use this agent when an MSP needs to know what has changed in a client's compliance posture since the last known-good baseline, prioritized by how much each change actually matters. |
evidence-packager | Use this agent when an MSP needs to gather and assemble compliance evidence for a client against a named framework or control set, producing a source-cited package an auditor or client can review. |
questionnaire-autofiller | Use this agent when a client needs its cyber-insurance renewal or new-business questionnaire drafted using live tool evidence rather than best-guess answers. |
Commands
Available slash commands:
| Command | Description |
|---|---|
/drift-report | Report control and configuration drift since the last known-good baseline for a client or the whole portfolio |
/evidence-pack | Build a source-cited compliance evidence package for a client against a named framework |
/questionnaire | Draft evidence-backed answers to the standard cyber-insurance questionnaire for a client |
API Reference
| Base URL | |
| Authentication | |
| Rate Limit | |
| Documentation |
Example Usage
Report control and configuration drift since the last known-good baseline for a client or the whole portfolio
/drift-report Build a source-cited compliance evidence package for a client against a named framework
/evidence-pack Draft evidence-backed answers to the standard cyber-insurance questionnaire for a client
/questionnaire Using Skills
/skill compliance-pack:evidence-mapping
Tracing a compliance control (CIS, SOC 2, HIPAA, or a cyber-insurance questionnaire line item) to concrete, retrievable tool evidence: which vendor family can observe what โ CIPP for live M365/Entra configuration, Liongard for point-in-time infrastructure state, IT Glue/Hudu for documentation โ a representative control-to-tool-call map, and the evidentiary weights that separate Configured from Documented, Contradicted, and Unable to Verify.