claude-grc-engineering — security grade SAFE, quality 70/100

Security audit verdict: SAFE · quality 70/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by GRCEngClub · Agent Tool · ★ 405

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is claude-grc-engineering safe to install? View the security audit →

About claude-grc-engineering

claude-grc-engineering https://github.com/user-attachments/assets/a83aa297-9fba-4a7d-b56c-06f962d1ec6b Open-source GRC Engineering resource for Claude. turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows. It is built for the Claude ecosystem: Claude Code plugin installs first, with Claude Desktop and Claude Cowork usage supported through the same Markdown skills, command runbooks, schemas, and repository files. It is maintained by the [GRC Engineerin

agentic-aiauditingclaude-codeclaude-code-plugincmmccompliancefedrampgap-analysisgrchitrust

Quick Facts

Stars405
Forks92
LanguageJavaScript
CategoryAgent Tool
Quality Score70.0344457652407/100
Open Issues29
Last Updated2026-09-20
Created2025-12-26
Platformsclaude-code, node
Est. Tokens~15k

Compatible Skills

These tools work well together with claude-grc-engineering for enhanced workflows:

  • claude-plugins — semantic(0.24)+complementary+same_lang+similar_pop+shared_platform (58%)
  • wozcode-plugin — semantic(0.23)+complementary+same_lang+similar_pop+shared_platform (53%)

claude-grc-engineering alternative? Top 6 similar tools

Looking for a claude-grc-engineering alternative? If you're comparing claude-grc-engineering with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • Claude-Skills-Governance-Risk-and-Compliance by Sushegaad · ⭐ 894

    Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2,

  • claude-code-safety-net by kenryu42 · ⭐ 1.3k

    A coding agent hook that acts as a safety net, catching destructive git and filesystem commands before they ex

  • code-on-incus by mensfeld · ⭐ 726

    Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops t

  • claude-code-hooks by karanb192 · ⭐ 519

    🪝 Claude Code hooks + an installable plugin marketplace: safety, cost, observability, productivity.

  • orchestkit by yonatangross · ⭐ 278

    The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stabl

  • agentjail by LuD1161 · ⭐ 91

    Policy guardrails for coding agents (Claude Code, Codex, Cursor) — every tool call is checked locally, before

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is claude-grc-engineering?

claude-grc-engineering is Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.. It is categorized as a Agent Tool with 405 GitHub stars.

What programming language is claude-grc-engineering written in?

claude-grc-engineering is primarily written in JavaScript. It covers topics such as agentic-ai, auditing, claude-code.

How do I install or use claude-grc-engineering?

You can find installation instructions and usage details in the claude-grc-engineering GitHub repository at github.com/GRCEngClub/claude-grc-engineering. The project has 405 stars and 92 forks, indicating an active community.

What are the best alternatives to claude-grc-engineering?

The top alternatives to claude-grc-engineering on Agent Skills Hub include Claude-Skills-Governance-Risk-and-Compliance, claude-code-safety-net, code-on-incus. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools