Skills

Compliance Evidence Collector

verified
Last updatedUpdated May 27, 2026

What this skill does

Automates the collection and organization of compliance evidence for SOC2, ISO 27001, or HIPAA audits. Pulls evidence from AWS configurations, Google Drive policies, and Jira tickets, then organizes findings into a structured evidence package with control mappings and gap identification.

Example

InputPROMPT

Context: Preparing for SOC2 Type II audit Company: 200-person SaaS company, B2B product Environment: AWS (production, staging), Google Workspace, Jira/Confluence Timeline: Audit in 8 weeks, need evidence package by week 4 Controls in scope: CC6.1 (Logical access), CC6.6 (Change management), A1.2 (Risk assessment)

OutputOUTPUT
Compliance Evidence Collection Summary — SOC2 Type II FRAMEWORK: SOC2 Trust Services Criteria SCOPE: CC6 (Logical and Physical Access), A1 (Risk Assessment) EVIDENCE SOURCES: AWS, Google Drive, Jira COLLECTION DATE: 2026-02-12 CONTROLS MAPPED | Control | Description | Evidence Gathered | Status | |-----------|--------------------------|------------------------|----------| | CC6.1 | Logical access controls | IAM policies, MFA config | Complete | | CC6.6 | Change management | Jira change tickets | Complete | | A1.2 | Risk assessment | Risk register, findings | Partial | EVIDENCE GATHERED (by source) AWS: IAM user list (12), MFA status (100% enabled), S3 bucket policies (8), CloudTrail config G Drive: Access control matrix, sharing settings audit, DLP policy exports Jira: 45 change tickets (last 90 days), approval workflows, release process docs GAPS IDENTIFIED 1. A1.2 — Risk register missing 2 quarterly reviews (Q3, Q4 2025) 2. CC6.1 — 3 contractors have console access; recommend bastion + SSO 3. CC6.6 — 12% of changes lacked formal approval ticket REMEDIATION TICKETS CREATED Jira: COMP-101, COMP-102, COMP-103 with due dates and assignees

Required Tools

AWSAWS
Google DriveGoogle Drive
JiraJira

Compatible Agents

ClaudeClaude
CursorCursor
WindsurfWindsurf
ChatGPTChatGPT
GitHub CopilotGitHub Copilot
Any MCP-compatible agentAny MCP-compatible agent
Integration

Add to your agent

Download Skill

Or install via CLI:

$ npx skills add webrix-ai/agent-skills --skill compliance-evidence-collector

Enterprise

Deploy Org-wide

SSO readyProvision to teams via RBAC
SecurityIdentity-aware execution
ComplianceSigned & verified skills
AnalyticsFull audit trail
GovernanceAuto-bundled with required MCP servers
Use withwillow
Get started

Free for up to 5 users

Your agents are already in the wild.

Give them a Basecamp. Go from AI chaos to AI work, in minutes.

Compliance Evidence Collector | Willow Marketplace