Works with the AI tools you already use
SOC 2 Evidence Collector
Collect timestamped AWS and GitHub evidence, map it to your control matrix, redact likely secrets, and package an auditor-reviewable evidence bundle.
$5
SOC 2 Evidence Collector
Example session with this skill installed
Collect this month's technical evidence for our SOC 2 control matrix in controls.json.
Use AWS profile audit-readonly in us-east-1 and the GitHub repositories already listed in the matrix.
Run a preflight first, then collect only allowlisted read-only evidence.
Package each artifact under its control ID, timestamp everything in UTC, redact any likely credential patterns, and produce a manifest with SHA-256 hashes.
Do not change any AWS resources or GitHub settings.
If a collector lacks permission, record the evidence gap instead of requesting administrator credentials.
- Read your context and instructions
- Compiled the soc 2 evidence
- Generated the document
Evidence snapshot complete
A timestamped evidence package was created from the approved control matrix using allowlisted AWS and GitHub read operations.
No infrastructure or repository settings were modified.
Collection Summary
| Metric | Result |
|---|---|
| Controls in matrix | 14 |
| Collectors planned | 31 |
| Evidence artifacts collected | 27 |
| Failed permission checks | 2 |
| Skipped collectors | 2 |
| Secret-pattern redactions | 1 |
Evidence Package
evidence/2026-09-12T173000Z/
The package contains
manifest.json— artifact paths, control IDs, statuses, timestamps and SHA-256 hashescollection-summary.json— collection totals and unresolved evidence gapsredaction-report.json— credential-like patterns removed during packagingcontrols/<CONTROL_ID>/— technical evidence grouped by control
Example Coverage
CC6.1
- AWS IAM account summary — COLLECTED
- Existing IAM credential report — COLLECTED
- GitHub main branch protection — COLLECTED
CC7.2
- CloudTrail configuration — COLLECTED
- AWS Config recorders — COLLECTED
- Security Hub enabled standards — FAILED: insufficient read permission
CC8.1
- Repository configuration — COLLECTED
- Branch protection — COLLECTED
- GitHub Actions permissions — COLLECTED
Security Checks
One credential-like pattern was detected during processing and automatically redacted.
The redaction report records the affected artifact and pattern type without preserving the sensitive value.
Two evidence collectors could not be completed using the current read-only identity. These failures were preserved in the package instead of bypassing permission controls.
Important Limitation
This package contains technical evidence and does not constitute a SOC 2 compliance determination.
For a Type II examination, retain recurring dated evidence according to your approved control cadence and confirm evidence sufficiency with your service auditor.
soc-2-evidence-collector.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
SOC 2 evidence collection can consume days of engineering time. Teams repeatedly capture cloud settings, repository controls, timestamps, and supporting artifacts, then manually map them back to audit controls.
What it does
SOC 2 Evidence Collector turns an approved local control matrix into a repeatable technical evidence snapshot across AWS and GitHub.
- Executes only allowlisted, read-oriented AWS CLI and GitHub CLI collectors
- Maps every artifact to the control ID supplied by your team
- Creates timestamped evidence runs instead of overwriting previous evidence
- Records UTC timestamps, execution status, and SHA-256 hashes
- Redacts common credential patterns before packaging evidence
- Surfaces permission failures and evidence gaps instead of hiding them
- Produces an evidence manifest and collection summary for auditor review
Why this beats prompting it yourself
A normal AI prompt can tell you what evidence might be useful. This skill actually runs deterministic collectors against the AWS and GitHub environments you authorize, while blocking arbitrary shell commands and maintaining a structured evidence trail.
Security by design
The collector does not intentionally retrieve secret-manager values, private keys, GitHub tokens, AWS secret access keys, password vault contents, or environment-variable dumps.
Infrastructure and repository settings are never modified by the bundled collectors.
Designed for evidence collection — not fake compliance
This skill does not certify SOC 2 compliance and does not replace a CPA or service auditor. Evidence sufficiency depends on your system, controls, examination period, and auditor requirements.
For SOC 2 Type II work, each run is a point-in-time evidence snapshot designed to be repeated at your approved evidence cadence.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 17 days ago
- Passed all security checks, Safe to install
Needs access to