/website-preflight
Validates AWS readiness for website deployment. Checks CLI tools, credentials, SES, Route 53, and ACM. Produces a report with pass/fail and action items.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill website-preflight --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/website-preflight
Context preview
The summary Claude sees to decide when to auto-load this skill.
Validates AWS readiness for website deployment. Checks CLI tools, credentials, SES, Route 53, and ACM. Produces a report with pass/fail and action items.
SKILL.md
website-preflight.SKILL.mdname: website-preflight
description: Validates AWS readiness for website deployment. Checks CLI tools, credentials, SES, Route 53, and ACM. Produces a report with pass/fail and action items.
allowed-tools: Bash, Read, Write, Edit, Glob
Website Preflight Skill
You are running the `/grc-portfolio:preflight` skill. Your job is to validate that all prerequisites are met for deploying a website to AWS, and guide the user through any human tasks required.
Step 1: Locate Config
Find `site-config.json`:
- Check `$ARGUMENTS` for a project directory path
- Check the current working directory
- Ask the user if not found
Read it to understand what features are enabled and what AWS configuration is needed.
Step 2: Automated Checks
Run each check and record the result as PASS or FAIL:
Required Checks (all deployments)
1. **AWS CLI installed**
aws --version
If missing: suggest running `$TOOLKIT_DIR/scripts/bootstrap.sh`
2. **Node.js installed (v18+)**
node --version
3. **npm installed**
npm --version
4. **AWS credentials configured**
aws sts get-caller-identity --profile <aws.profile>
Record the account ID and ARN for the report.
5. **AWS region set to us-east-1** Verify `aws.region` in config is `us-east-1` (required for CloudFront + ACM).
6. **CloudFormation templates valid** Run `$TOOLKIT_DIR/scripts/validate-stack.sh` against the appropriate template:
- If `features.customDomain`: validate `$TOOLKIT_DIR/cloudformation/website-infrastructure.yaml`
- Otherwise: validate `$TOOLKIT_DIR/cloudformation/website-infrastructure-no-domain.yaml`
Conditional Checks
7. **SES email verified** (if `features.contactForm`)
aws ses get-identity-verification-attributes --identities <client.email> --profile <aws.profile> --region us-east-1
Check that the status is "Success".
8. **Route 53 hosted zone exists** (if `features.customDomain`)
aws route53 list-hosted-zones-by-name --dns-name <aws.domain> --profile <aws.profile>
If found, save the hosted zone ID to `aws.hostedZoneId` in config.
9. **ACM certificate exists in us-east-1** (if `features.customDomain`)
aws acm list-certificates --region us-east-1 --profile <aws.profile> --query "CertificateSummaryList[?DomainName=='<aws.domain>']"
If found and status is "ISSUED", save the ARN to `aws.certArn` in config.
10. **gh CLI installed** (for future /grc-portfolio:repo and /grc-portfolio:cicd steps)
gh --version
Step 3: Produce Report
Output a formatted report with three sections:
PASS
List all checks that passed with a checkmark.
ACTION REQUIRED (Automated)
Things that can be fixed automatically -- offer to run the fix:
- Missing tools (run bootstrap.sh)
- Template validation (fix template issues)
ACTION REQUIRED (Human)
Things the user must do manually. For each, provide:
- **What to do** (clear instructions)
- **AWS Console URL** (direct link where possible)
- **Expected time** (rough estimate)
- **Verification command** (how to check it's done)
Common human tasks:
- **Create AWS account**: https://aws.amazon.com/ -- sign up, create IAM user with AdministratorAccess
- **Buy/transfer domain to Route 53**: https://console.aws.amazon.com/route53/home#/DomainRegistration
- **Request ACM certificate**: https://console.aws.amazon.com/acm/home?region=us-east-1#/certificates/request -- request for the domain + *.domain, use DNS validation
- **Verify email in SES**: https://console.aws.amazon.com/ses/home?region=us-east-1#/verified-identities -- add email, click verification link
- **Install gh CLI**: `brew install gh && gh auth login`
Step 4: Wait for Human Tasks
If there are human action items, tell the user to complete them and then say "ready" or "done" to re-run the checks.
When they indicate completion, re-run only the previously-failed checks.
Step 5: Update Config
Once all checks pass:
- Update `aws.hostedZoneId` if discovered
- Update `aws.certArn` if discovered
- Set `status.preflightComplete = true`
- Write the updated `site-config.json`
Step 6: Summary
Tell the user:
- All preflight checks passed
- Suggest running `/grc-portfolio:build` next (if not done) or `/grc-portfolio:infra` to deploy infrastructure
Variables
- `$TOOLKIT_DIR` = read from `site-config.json` `toolkitDir` field
- `$ARGUMENTS` = arguments passed after `/grc-portfolio:preflight` (expected: project directory path)
Read more
name: website-preflight description: Validates AWS readiness for website deployment. Checks CLI tools, credentials, SES, Route 53, and ACM. Produces a report with pass/fail and action items. allowed-tools: Bash, Read, Write, Edit, Glob
Website Preflight Skill
You are running the `/grc-portfolio:preflight` skill. Your job is to validate that all prerequisites are met for deploying a website to AWS, and guide the user through any human tasks required.
Step 1: Locate Config
Find `site-config.json`:
- Check `$ARGUMENTS` for a project directory path
- Check the current working directory
- Ask the user if not found
Read it to understand what features are enabled and what AWS configuration is needed.
Step 2: Automated Checks
Run each check and record the result as PASS or FAIL:
Required Checks (all deployments)
1. **AWS CLI installed**
aws --version
If missing: suggest running `$TOOLKIT_DIR/scripts/bootstrap.sh`
2. **Node.js installed (v18+)**
node --version
3. **npm installed**
npm --version
4. **AWS credentials configured**
aws sts get-caller-identity --profile <aws.profile>
Record the account ID and ARN for the report.
5. **AWS region set to us-east-1** Verify `aws.region` in config is `us-east-1` (required for CloudFront + ACM).
6. **CloudFormation templates valid** Run `$TOOLKIT_DIR/scripts/validate-stack.sh` against the appropriate template:
- If `features.customDomain`: validate `$TOOLKIT_DIR/cloudformation/website-infrastructure.yaml`
- Otherwise: validate `$TOOLKIT_DIR/cloudformation/website-infrastructure-no-domain.yaml`
Conditional Checks
7. **SES email verified** (if `features.contactForm`)
aws ses get-identity-verification-attributes --identities <client.email> --profile <aws.profile> --region us-east-1
Check that the status is "Success".
8. **Route 53 hosted zone exists** (if `features.customDomain`)
aws route53 list-hosted-zones-by-name --dns-name <aws.domain> --profile <aws.profile>
If found, save the hosted zone ID to `aws.hostedZoneId` in config.
9. **ACM certificate exists in us-east-1** (if `features.customDomain`)
aws acm list-certificates --region us-east-1 --profile <aws.profile> --query "CertificateSummaryList[?DomainName=='<aws.domain>']"
If found and status is "ISSUED", save the ARN to `aws.certArn` in config.
10. **gh CLI installed** (for future /grc-portfolio:repo and /grc-portfolio:cicd steps)
gh --version
Step 3: Produce Report
Output a formatted report with three sections:
PASS
List all checks that passed with a checkmark.
ACTION REQUIRED (Automated)
Things that can be fixed automatically -- offer to run the fix:
- Missing tools (run bootstrap.sh)
- Template validation (fix template issues)
ACTION REQUIRED (Human)
Things the user must do manually. For each, provide:
- **What to do** (clear instructions)
- **AWS Console URL** (direct link where possible)
- **Expected time** (rough estimate)
- **Verification command** (how to check it's done)
Common human tasks:
- **Create AWS account**: https://aws.amazon.com/ -- sign up, create IAM user with AdministratorAccess
- **Buy/transfer domain to Route 53**: https://console.aws.amazon.com/route53/home#/DomainRegistration
- **Request ACM certificate**: https://console.aws.amazon.com/acm/home?region=us-east-1#/certificates/request -- request for the domain + *.domain, use DNS validation
- **Verify email in SES**: https://console.aws.amazon.com/ses/home?region=us-east-1#/verified-identities -- add email, click verification link
- **Install gh CLI**: `brew install gh && gh auth login`
Step 4: Wait for Human Tasks
If there are human action items, tell the user to complete them and then say "ready" or "done" to re-run the checks.
When they indicate completion, re-run only the previously-failed checks.
Step 5: Update Config
Once all checks pass:
- Update `aws.hostedZoneId` if discovered
- Update `aws.certArn` if discovered
- Set `status.preflightComplete = true`
- Write the updated `site-config.json`
Step 6: Summary
Tell the user:
- All preflight checks passed
- Suggest running `/grc-portfolio:build` next (if not done) or `/grc-portfolio:infra` to deploy infrastructure
Variables
- `$TOOLKIT_DIR` = read from `site-config.json` `toolkitDir` field
- `$ARGUMENTS` = arguments passed after `/grc-portfolio:preflight` (expected: project directory path)
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

