research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Validate an OSCAL document (catalog, profile, SSP, SAP, SAR, POA&M, component definition, assessment results) against the official JSON schemas.
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/validateContext preview
What this command does when you run it.
Validate an OSCAL document (catalog, profile, SSP, SAP, SAR, POA&M, component definition, assessment results) against the official JSON schemas.
name: OSCAL Validate description: Validate an OSCAL document (catalog, profile, SSP, SAP, SAR, POA&M, component definition, assessment results) against the official JSON schemas.
Validates an OSCAL document against the NIST JSON schemas bundled with `oscal-cli`. Supports JSON, XML, and YAML input (XML/YAML are auto-converted internally for validation).
bash plugins/oscal/scripts/validate.sh <file> [--quiet] [--json]
/oscal:validate gap-assessment-20260413/gap-report.oscal-ar
This checks that `/grc-engineer:gap-assessment`'s OSCAL Assessment Results output is well-formed before handing it to downstream tooling (Compliance Trestle, eMASS, FedRAMP 20X).
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.