research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Set up GitHub Actions CI/CD with OIDC for keyless AWS authentication — automatic deployment on every push to main.
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/cicdContext preview
What this command does when you run it.
Set up GitHub Actions CI/CD with OIDC for keyless AWS authentication — automatic deployment on every push to main.
description: Set up GitHub Actions CI/CD with OIDC for keyless AWS authentication — automatic deployment on every push to main.
Configures fully automated deployments using GitHub Actions and GitHub OIDC. No static AWS access keys stored anywhere — the workflow assumes a least-privilege IAM role via OIDC token.
1. Creates (or verifies) the GitHub OIDC provider in your AWS account 2. Creates an IAM role scoped to **only** your S3 bucket and CloudFront distribution 3. Generates `.github/workflows/deploy.yml` — triggers on push to `main` and `workflow_dispatch` 4. Commits and pushes the workflow file 5. Verifies the first run completes successfully
/grc-portfolio:cicd ~/Desktop/repos/my-grc-portfolio /grc-portfolio:cicd
After this, every `git push` to `main` automatically builds and deploys your portfolio.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.