All Skills

Security & Compliance AI Skills

Discover Security & Compliance AI skills designed for modern teams. Each skill is production-ready and governed with enterprise features including SSO, RBAC, and audit logs. Install once and distribute across your organization with full visibility into usage and compliance.

Security & Compliance

Search

AI Adoption Readiness Assessment

verified

A structured assessment framework that scores your organization across five critical dimensions of AI readiness. Produces an actionable scorecard with prioritized recommendations, a detailed gap analysis spreadsheet, and optional Jira tickets to track remediation efforts.

AI Governance Framework Generator

verified

Generates a complete AI governance framework tailored to your organization's structure and regulatory requirements. Defines a five-tier risk classification system, designs approval workflows with SLAs for each tier, establishes a governance board with RACI matrix, creates escalation paths, and produces all supporting artifacts including charter, decision tree, and meeting templates.

AI Tool Access Request Workflow

verified

Sets up a complete intake-to-approval pipeline for AI tool access requests. Creates a Jira issue type with structured fields, configures automation rules for risk-based tier assignment and reviewer routing, adds Slack notifications for transparency, and includes a security review runbook with decision templates.

AI Usage Policy Generator

verified

Produces a comprehensive, ready-to-review AI acceptable use policy document customized to your industry, regulatory requirements, and risk appetite. Covers data classification, approved tools, prohibited uses, IP ownership, incident response, and training requirements. Outputs a formatted Google Doc with table of contents and employee acknowledgment page.

Cloud Security Posture Review

verified

Performs a comprehensive cloud security posture review against CIS benchmarks for AWS, GCP, or Azure. Checks identity, networking, logging, encryption, and compute configurations, then produces a scored findings report with prioritized remediation steps in a Google Sheet.

Compliance Evidence Collector

verified

Automates the collection and organization of compliance evidence for SOC2, ISO 27001, or HIPAA audits. Pulls evidence from AWS configurations, Google Drive policies, and Jira tickets, then organizes findings into a structured evidence package with control mappings and gap identification.

Data Classification Scanner

verified

Scans GitHub repositories, S3 buckets, and Google Drive for personally identifiable information (PII), protected health information (PHI), financial data, and other sensitive content. Classifies findings by data type and sensitivity level, maps data flows, and generates a comprehensive data classification report with remediation recommendations.

IAM Policy Analyzer

verified

Reviews IAM policies across cloud providers to identify over-permissive access, unused roles, cross-account trust issues, and privilege escalation paths. Generates a risk-scored findings report with specific remediation recommendations for each policy violation.

Incident Response Playbook Generator

verified

Creates detailed incident response playbooks tailored to your cloud environment and team structure. Covers detection, containment, eradication, recovery, and post-incident review phases for common cloud security incidents including compromised credentials, data exposure, cryptomining, and unauthorized access.

MCP Server Security Review

verified

Performs a structured security audit of an MCP server by reviewing its source code for credential handling, data exposure risks, permission scope, transport security, code quality, and documentation. Scores each dimension, checks for common vulnerabilities (hardcoded secrets, eval injection, path traversal), and produces a review report with an approve/conditional/reject recommendation.

Secret Scanning & Rotation Planner

verified

Scans GitHub repositories for exposed secrets including API keys, tokens, passwords, and certificates. Classifies each finding by severity and exposure window, then generates a prioritized rotation plan with step-by-step remediation instructions and prevention recommendations.

Security Alert Triage

verified

Automatically triages security alerts from AWS GuardDuty, CloudTrail, and other cloud security services. Classifies each alert by severity and type, correlates related events, filters false positives, suggests response actions, and routes critical alerts to the appropriate team via Slack and PagerDuty.

1–12 of 15 skills

Security & Compliance Skills FAQ

What are Security & Compliance AI Skills?

Security & Compliance AI skills are pre-built capabilities that help teams automate tasks and workflows. They work across Claude, Cursor, ChatGPT, and other AI agents.

How do I deploy these skills to my team?

Install any skill in minutes using your MCP client (Claude Desktop, Cursor, VS Code, etc.). Each skill can be distributed across your organization with centralized management, usage tracking, and access controls.

Are these skills compatible with my tools?

Yes. Skills work with popular tools and environments including VS Code, Cursor, JetBrains IDEs, and any MCP-compatible agent. They integrate seamlessly with your existing workflows.

What security controls are available?

All skills include enterprise-grade security: Single Sign-On (SSO), Role-Based Access Control (RBAC), comprehensive audit logs, and data governance. Your data remains secure and compliant.

Security & Compliance AI Skills | Willow Marketplace