No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by GRCEngClub · Agent Tool · ★ 405
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is claude-grc-engineering safe to install? View the security audit →
claude-grc-engineering https://github.com/user-attachments/assets/a83aa297-9fba-4a7d-b56c-06f962d1ec6b Open-source GRC Engineering resource for Claude. turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows. It is built for the Claude ecosystem: Claude Code plugin installs first, with Claude Desktop and Claude Cowork usage supported through the same Markdown skills, command runbooks, schemas, and repository files. It is maintained by the [GRC Engineerin
| Stars | 405 |
| Forks | 92 |
| Language | JavaScript |
| Category | Agent Tool |
| Quality Score | 70.0344457652407/100 |
| Open Issues | 29 |
| Last Updated | 2026-09-20 |
| Created | 2025-12-26 |
| Platforms | claude-code, node |
| Est. Tokens | ~15k |
These tools work well together with claude-grc-engineering for enhanced workflows:
Looking for a claude-grc-engineering alternative? If you're comparing claude-grc-engineering with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2,
A coding agent hook that acts as a safety net, catching destructive git and filesystem commands before they ex
Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops t
🪝 Claude Code hooks + an installable plugin marketplace: safety, cost, observability, productivity.
The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stabl
Policy guardrails for coding agents (Claude Code, Codex, Cursor) — every tool call is checked locally, before
Explore other popular agent tool tools:
claude-grc-engineering is Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.. It is categorized as a Agent Tool with 405 GitHub stars.
claude-grc-engineering is primarily written in JavaScript. It covers topics such as agentic-ai, auditing, claude-code.
You can find installation instructions and usage details in the claude-grc-engineering GitHub repository at github.com/GRCEngClub/claude-grc-engineering. The project has 405 stars and 92 forks, indicating an active community.
The top alternatives to claude-grc-engineering on Agent Skills Hub include Claude-Skills-Governance-Risk-and-Compliance, claude-code-safety-net, code-on-incus. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: