Agent Plugins Marketplace
← All plugins

pm-compliance

v1.0.0

Compliance & trust skills for regulated and enterprise teams: SOC 2 Readiness, GDPR Compliance, HIPAA Safeguards, ISO 27001 ISMS, Vendor Security Review, and Data Retention Policy. Each ships a stdlib scoring/validation script.

Claude Code7 Skills

By Mohit AggarwalLicense: MIT1.4k GitHub starsUpdated yesterday

Directory evidence

Runtimes
Claude Code
Parsed components
7 skill or MCP entries
Source updated
Oct 4, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install pm-compliance for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install pm-compliance@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/mohitagw15856/pm-claude-skills

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/pm-compliance/.

Plugin files

plugins/pm-compliance/
├── .claude-plugin/plugin.json
├── skills/data-retention-policy/SKILL.md
├── skills/gdpr-compliance/SKILL.md
├── skills/hipaa-safeguards/SKILL.md
├── skills/iso-27001-isms/SKILL.md
├── skills/security-questionnaire-autofill/SKILL.md
├── skills/soc2-readiness/SKILL.md
└── skills/vendor-security-review/SKILL.md

Included Skills7

data-retention-policyskills/data-retention-policy/SKILL.md

Build a data retention and deletion schedule grounded in legal basis. Use when asked to create a data retention policy, set retention periods, plan data deletion/minimisation, or answer 'how long can we keep this data?'. Produces a retention schedule — data categories with their retention period, legal/business basis, deletion trigger and method, plus flags for data kept with no basis or no defined period.

gdpr-complianceskills/gdpr-compliance/SKILL.md

Assess GDPR compliance and build the core records (ROPA, lawful basis, DSAR, DPIA triggers). Use when asked to get GDPR-compliant, build a Record of Processing Activities, decide a lawful basis, handle data-subject requests, or check whether a DPIA is needed. Produces a GDPR assessment — a ROPA, lawful-basis mapping per activity, DSAR workflow, DPIA-trigger screen, and a prioritised gap list.

hipaa-safeguardsskills/hipaa-safeguards/SKILL.md

Map HIPAA Security Rule safeguards and run a risk analysis for systems handling PHI. Use when asked to become HIPAA-compliant, assess HIPAA safeguards, prepare for handling PHI/ePHI, or scope a BAA. Produces a HIPAA assessment — the administrative/physical/technical safeguards with required-vs-addressable status, a risk analysis, BAA scope, and a prioritised remediation plan.

iso-27001-ismsskills/iso-27001-isms/SKILL.md

Scope an ISO 27001 ISMS and build the Statement of Applicability across Annex A controls. Use when asked to implement ISO 27001, scope an ISMS, build a Statement of Applicability (SoA), or prepare for ISO 27001 certification. Produces an ISMS plan — scope & context, risk-treatment approach, an Annex A control applicability table (the SoA), and a prioritised implementation roadmap.

security-questionnaire-autofillskills/security-questionnaire-autofill/SKILL.md

Draft answers to a vendor security questionnaire (SIG, CAIQ, or a custom sheet) from your real controls — fast, consistent, and honest about gaps. Use when asked to fill out a security questionnaire, answer a SIG/CAIQ, respond to a customer's security review, or complete a vendor risk assessment. Produces drafted answers grounded in your stated controls, a gap list of questions you can't truthfully answer yet, and reusable answer snippets for next time — never fabricated compliance.

soc2-readinessskills/soc2-readiness/SKILL.md

Assess SOC 2 readiness across the Trust Services Criteria and produce a gap remediation plan. Use when asked to prepare for a SOC 2 audit, run a SOC 2 readiness/gap assessment, scope controls, or get audit-ready. Produces a readiness report — scope & criteria, a control-by-control status, a weighted readiness score, prioritised gaps with owners, and the evidence each control needs.

vendor-security-reviewskills/vendor-security-review/SKILL.md

Run a third-party / vendor security review and assign a risk tier with required controls. Use when asked to assess a vendor's security, run a third-party risk assessment, complete a security questionnaire about a vendor, or decide what due diligence a new tool needs. Produces a vendor risk assessment — a data/access-driven risk tier, the questionnaire focus, required evidence (SOC 2, pen test, DPA), residual risk, and an approve/conditional/reject recommendation.

Plugin manifests1

plugins/pm-compliance/.claude-plugin/plugin.json
{
  "$schema": "https://anthropic.com/claude-code/plugin.schema.json",
  "name": "pm-compliance",
  "version": "1.0.0",
  "description": "Compliance & trust skills for regulated and enterprise teams: SOC 2 Readiness, GDPR Compliance, HIPAA Safeguards, ISO 27001 ISMS, Vendor Security Review, and Data Retention Policy. Each ships a stdlib scoring/validation script.",
  "author": {
    "name": "Mohit Aggarwal",
    "email": "[email protected]"
  },
  "homepage": "https://github.com/mohitagw15856/pm-claude-skills",
  "license": "MIT",
  "keywords": [
    "compliance",
    "soc2",
    "gdpr",
    "hipaa",
    "iso-27001",
    "security",
    "privacy",
    "vendor-risk",
    "governance",
    "trust"
  ]
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[pm-compliance on Agent Plugins Marketplace](https://pluginsmp.com/plugins/pm-compliance)