Commit graph

5 commits

Author SHA1 Message Date
Alireza Rezvani
4570768781
Merge pull request #936 from benrfairless/fix/frontmatter-yaml-validation
fix(frontmatter): repair 14 unloadable YAML blocks + add gate G10
2026-08-21 10:43:35 +02:00
Claude
7405298b4b
fix: resolve the actionable reported issues (#954, #949, #933, #931, #969, #968, #924, #885)
- #954: strip non-spec source/attribution keys from all 39 plugin.json
  manifests so Claude Code's validator accepts them; metadata preserved in
  new .claude-plugin/authoring-notes.json sidecars; check_plugin_json.py now
  hard-fails manifests carrying those keys and sanity-checks the sidecar;
  CLAUDE.md ClawHub schema section updated to the new rule.
- #949: move the c-level-agents plugin out of c-level-advisor/ to a
  top-level directory so the two marketplace sources no longer overlap;
  updated marketplace.json source, homepage, descriptions, all
  cross-references, docs, harness manifest, mirror-tree symlinks/indexes,
  and rebased the moved files' relative links; domain counters trued up
  (18 -> 19 domains).
- #933: replace dead links to the gitignored maintainer-local megaprompts/
  tree with annotated plain-text references (44 files: SKILL.md, READMEs,
  agents, commands).
- #931: DynamoDB on-demand pricing updated to post-Nov-2024 rates
  ($0.625/M writes, $0.125/M strongly consistent reads).
- #969: skill_security_auditor.py and the three dossier scripts reconfigure
  stdout/stderr to UTF-8 (errors=replace) so legacy Windows codepages no
  longer crash at print time; PYTHONUTF8=1 documented.
- #968: Windows Notes section in INSTALLATION.md + README pointer for the
  core.symlinks mirror-tree checkout caveat.
- #924/#885 residuals: hook commands quote "${CLAUDE_PLUGIN_ROOT}" paths in
  all plugin hooks.json/settings.json (space-safe roots); removed the stale
  pre-rename status/review mirror symlinks and index entries left over from
  the memory-status/memory-review rename.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qgc6RYXWJPr5oW9DHU7zR4
2026-08-21 05:47:37 +00:00
Ben Fairless
02c04e3d32
fix(frontmatter): repair 14 unloadable YAML blocks
Twelve files had frontmatter that yaml.safe_load rejects, all from the same
cause: an unquoted plain scalar containing ": " inside description. Claude Code
responds by loading the body with empty metadata, so the skill keeps working
via /name but has no description for the model to match against, and the seven
affected agents (where name and description are required) may not load at all.

Eleven are fixed by quoting the existing scalar, leaving the text
byte-identical. design-system carries both ' and " so quoting would defeat the
repo's regex extractors in generate-docs.py and sync-codex-skills.py; its one
colon-space is reworded instead ("Precedence:" -> "Precedence is").

Two agents had no frontmatter at all and were being listed with a placeholder
description; both now declare name and description. tools is deliberately
omitted so they keep inheriting the full set, as before.

Assisted-by: Claude Code:claude-opus-5
2026-08-03 08:55:36 +08:00
Claude
c934707999
feat(compliance-os): Phase 2 — per-framework audit playbooks + personas + commands
Stream A Phase 2 expansion of the multi-framework compliance OS.

5 new audit playbook references (each citing 10-11 authoritative sources):
- ra-qm-team/skills/isms-audit-expert/references/iso27001_audit_playbook.md
  (7-phase audit workflow + Annex A scope prioritization + common findings)
- ra-qm-team/skills/qms-audit-expert/references/iso13485_audit_playbook.md
  (Design Controls + CAPA + Process Validation focus; MDR + FDA QSR cross-walk)
- ra-qm-team/skills/gdpr-dsgvo-expert/references/gdpr_audit_playbook.md
  (Article-cited audit; Article 5/6/9/30/32/33-34/35 + Schrems II transfers)
- ra-qm-team/skills/soc2-compliance/references/soc2_audit_playbook.md
  (Type II observation-period discipline + AICPA TSC + 75% ISO 27001 reuse)
- compliance-os/skills/compliance-os/references/multi_framework_audit_playbook.md
  (Integrated audit programme + cross-framework finding impact + integrated mgmt review)

5 new cs-* persona agents:
- cs-ciso-iso27001: sample-driven ISMS auditor; rejects curated audit demos
- cs-cqm-iso13485: traceability-obsessed QMS auditor; DHF + CAPA + post-market focused
- cs-dpo-gdpr: Article-cited DPO; lawful-basis + DPIA + Schrems II discipline
- cs-soc2-auditor: observation-period operator; 75% ISO 27001 reuse coordinator
- cs-fda-qsr-auditor: FDA-specific overlay on ISO 13485 (substantially harmonized
  post-Feb 2026); complaint files + MDR reporting + Form 483 response

5 new /cs:* slash commands (sub-skill pattern):
- /cs:iso27001-audit-prep: 6Q forcing interrogation (audit programme + risk + sampling)
- /cs:iso13485-audit-prep: 6Q forcing interrogation (DHFs + CAPA + post-market)
- /cs:gdpr-audit-prep: 6Q Article-cited interrogation (RoPA + DPIA + DSAR + Schrems II)
- /cs:soc2-audit-prep: 6Q observation-period interrogation (TSC + cycle skips + exceptions)
- /cs:fda-qsr-audit-prep: 6Q FDA-discipline interrogation (complaints + MDR + DHRs + Form 483)

Plugin.json updated to v1.1.0 with 5 new sub-skill references.

Builds on Phase 1 (compliance OS MVP merged in #639). Reuses existing 14 ra-qm-team
skills via cross-references; no duplication of operational depth. Each persona +
command + playbook trio routes to the existing skill's Python tools for operational
work; the new artefacts add audit-readiness discipline + cross-framework impact
tracking.

Total: 16 files, ~2,459 insertions. No Python tools added in this phase (docs +
agents + commands only). All 5 references cite 10-11 authoritative sources each
(ISO 19011, IIA IPPF, AICPA AT-C, AICPA TSC, regulation text, EDPB, NIST, ISACA,
industry retrospectives).

https://claude.ai/code/session_01VFreMf7XLBqMgjsrG4wSYe
2026-05-13 19:09:19 +00:00
Claude
4463dc1752
feat(compliance-os): multi-framework meta-orchestrator for compliance teams
Stream A Phase 1 — Plugin 3 of 3 (compliance OS MVP).

Top-level peer of ra-qm-team/ that orchestrates the 14 ra-qm-team skills
plus the two new compliance-team-* plugins (iso42001 + eu-ai-act).

Four stdlib Python tools:
- framework_selector.py: company profile -> applicable frameworks across all 9
  (ISO 27001, 13485, 42001, 14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR)
  with binding-vs-certifiable priority + dependency graph
- cross_framework_mapper.py: 19 merged control themes covering access, asset,
  risk, supplier, incident, logging, change, BCP, training, data, audit, mgmt
  review, crypto, secure SDLC, vuln, physical, privacy, document control, CAPA;
  HIGH/MED/LOW confidence per framework; >= 30 atomic 27001<->SOC 2 mappings
- audit_simulator.py: 10 finding scenarios per scope with IIA-target severity
  distribution (60% observation, 0% critical for embedded sample = healthy);
  3-5 interview questions per scoped control + document-review requests
- evidence_pool_generator.py: 15 curated artefacts with reuse-leverage scoring
  (100 total (framework, control) satisfactions in embedded sample)

Four references each citing 5+ authoritative sources:
- compliance_os_pattern.md: meta-framework architecture + IMS pattern
- cross_framework_overlap.md: 9-framework control-family overlap matrix
- audit_simulation_methodology.md: ISO 19011 + IIA IPPF + AICPA AT-C principles
- evidence_management.md: reuse-leverage + retention + freshness + storage

Three cs-* persona agents:
- cs-compliance-officer: multi-framework orchestrator
- cs-aims-iso42001: ISO 42001 AIMS implementation operator
- cs-ai-act-compliance: EU AI Act Article-cited compliance operator

Three /cs:* slash commands (sub-skill pattern):
- /cs:compliance-readiness: 6-question multi-framework forcing interrogation
- /cs:aims-audit: 6-question ISO 42001 internal-audit interrogation
- /cs:ai-act-readiness: 6-question EU AI Act readiness interrogation

Two JSON asset templates for tool inputs.

Karpathy gate: complexity_checker 100/100 (0 findings).

Phase 1 success criteria all met:
- framework_selector: AI SaaS profile -> 5 frameworks (GDPR/AI Act binding + 27001/SOC2/42001 cert)
- cross_framework_mapper: 19 merged controls, 16 HIGH-confidence 27001+SOC2 pair themes, 51 atomic 27001 + 34 atomic SOC2 citations
- audit_simulator: 10 findings, 60% observation, 0% critical = healthy distribution
- evidence_pool: 15 artefacts, 100 total satisfactions, 11 high-leverage (>= 5 mappings)

https://claude.ai/code/session_01VFreMf7XLBqMgjsrG4wSYe
2026-05-13 17:48:33 +00:00