research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Weekly 1-page executive summary for the CISO and direct leadership
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/exec-summaryContext preview
What this command does when you run it.
Weekly 1-page executive summary for the CISO and direct leadership
description: Weekly 1-page executive summary for the CISO and direct leadership allowed-tools: Read, Glob, Grep, Write, Bash
Draft a weekly 1-page update for the CISO or direct leadership. Every section is bulleted and scannable. An exec should get the full picture in 60 seconds. Lead with wins and business impact, not control IDs.
Before drafting, verify the toolkit has what it needs. Invoke the `context-bootstrap` skill. Look for:
If context is empty or partial, follow the `context-bootstrap` skill's setup path. Do not generate a hollow report.
When context is complete, load without asking:
Ask the user for what Claude cannot infer:
Skip questions the args already answered.
Apply the `so-what-translation` skill to translate findings into business impact. Apply `exec-narrative-patterns` for audience tone.
Every section is bulleted. No paragraphs. No hedging. Each bullet is one line, scannable at a glance.
Structure:
# Weekly Brief - <period> Audience: <audience> ## Headline - <One line. What changed this week that leadership should know.> ## Wins - <Automation shipped, control closed, audit passed. Who drove it. Business impact.> - <...> ## What Moved - <Business-impact framing of top changes. Control IDs in the appendix, not here.> - <...> ## Blockers - <Open issues that need a decision, budget, or access. Named owner, specific ask.> - <...> ## Asks - <Specific decision requested. Context in one line. Deadline.> - <...> ## Appendix - Findings run: `<run_id>` - Frameworks covered: `<list>` - Full gap report: `<path>`
Write to `./grc-reports/exec-summary-<period>.md`. Confirm path. Offer:
# Current week, default audience /report:exec-summary # Specific week /report:exec-summary 2026-W16 # Write for CEO weekly review /report:exec-summary 2026-W16 ceo-weekly
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.