GRC Agent Registry12 agents · Free to copyclaude-opus-4-6 · claude-sonnet-4-6

GRC Agents. Copy and deploy.

Open-source Anthropic Managed Agent configs for GRC practitioners. Preview the YAML inline, download in one click, and run them against your own infrastructure with full file-system access. Inspired by the 21st.dev agent registry — built for compliance.

2Security
3Assessment
2Documentation
2Risk
2Intelligence
1Workflow
SecurityOpus
live demo

Security Auditor

Full security audit with Critical/High/Medium/Low findings and remediation roadmap.

Conducts comprehensive security audits, compliance assessments, and risk evaluations across systems, infrastructure, and processes. Reads your actual codebase and policy docs via file-system tools.

readgrepglob
SOC 2ISO 27001CMMCHIPAA+2
Open agent →
SecuritySonnet

Incident Response Coordinator

Walks your team through IR playbook steps in real time during a live incident.

Acts as your incident commander during active security incidents. Follows NIST SP 800-61 methodology — detection, containment, eradication, recovery, and lessons learned. Generates timeline, stakeholder briefs, and post-incident reports.

bashweb_searchread
NIST SP 800-61ISO 27035SOC 2HIPAA Breach Rule
Open agent →
AssessmentOpus

Compliance Gap Analyzer

Maps your current controls to framework requirements. Shows exactly what is missing.

Reads your policies, SSP, and evidence directory, then maps each control against the target framework's requirements. Produces a gap register with severity, remediation effort estimate, and sequenced roadmap.

readgrepglob
CMMC L2SOC 2ISO 27001FedRAMP+2
Open agent →
AssessmentSonnet
live demo

Evidence Reviewer

Grades every piece of evidence before your auditor sees it. Flags red flags.

Reviews screenshots, log excerpts, policy clips, and configuration exports against specific assessment objectives. Returns an adequacy verdict (Sufficient / Insufficient / Missing) with precise assessor-language gaps and what additional evidence is needed.

readglob
CMMC L2SOC 2FedRAMPISO 27001+1
Open agent →
AssessmentSonnet

POA&M Advisor

Reviews POA&M items, scores remediation priority, flags certification blockers.

Reads your Plan of Action and Milestones, evaluates each open item against SPRS impact weights and framework POA&M eligibility rules, and produces a prioritized remediation schedule with milestone dates and owner assignments.

readgrep
CMMC L2FedRAMPNIST 800-171RMF
Open agent →
DocumentationSonnet
live demo

SSP Narrator

Generates present-tense SSP narratives in your system's voice. Assessment-grade.

Reads your system context, existing configurations, and policy docs to write SSP control narratives. Output matches the present-tense, objective-level style that CCAs and 3PAOs expect — not boilerplate, not paraphrased requirements.

readgrepglob
CMMC L2FedRAMP ModerateISO 27001NIST 800-171
Open agent →
DocumentationSonnet

Policy Drafter

Writes complete IS policies from a single prompt. AUP, IR Plan, Access Control, and more.

Generates complete information security policies tailored to your organization size, industry, and target frameworks. Output includes purpose, scope, definitions, policy statements, exceptions process, and review schedule. Ready for leadership sign-off.

readwrite
ISO 27001SOC 2CMMCHIPAA+1
Open agent →
RiskOpus

Risk Register Builder

Builds a complete risk register with likelihood, impact, and treatment plans.

Reads your system inventory, threat landscape, and existing controls, then generates a structured risk register with qualitative and quantitative scoring. Each risk gets inherent and residual scores, treatment options, and an owner assignment.

readgrepglob
ISO 27005NIST RMFSOC 2CMMC+1
Open agent →
RiskOpus

Third-Party Risk Assessor

Reviews vendor questionnaires, SOC reports, and contracts for GRC risk exposure.

Analyzes vendor security questionnaires (SIG, CAIQ, custom), SOC 2 reports, penetration test summaries, and MSAs to produce a vendor risk score and gap list. Flags exceptions, subprocessors, and contractual gaps.

readglob
SOC 2ISO 27001SIG LiteCAIQ+1
Open agent →
IntelligenceSonnet

Threat Intel Analyst

Monitors CISA KEV, CVEs, and threat feeds. Translates exploits into GRC control gaps.

Fetches live threat intelligence from CISA KEV, NVD, and ISAC feeds. For each active threat, maps it to the controls that would prevent or detect it, scores your organization's exposure, and drafts a management-ready threat brief.

web_searchweb_fetch
NIST CSFCIS ControlsCMMCISO 27001
Open agent →
IntelligenceSonnet

Regulatory Intel Agent

Monitors Federal Register, SEC, CISA, and global regulators for rule changes that affect your program.

Daily scan of regulatory sources — Federal Register final and proposed rules, SEC cybersecurity disclosures, CISA guidance, EU DORA/NIS2 updates, India DPDPA rulemaking. Summarizes what changed, who is affected, and what action is required by what deadline.

web_searchweb_fetch
FedRAMPCMMCDPDPANIS2+3
Open agent →
WorkflowOpus

ConMon Agent

Runs your monthly continuous monitoring cycle. Scans, scores, and drafts the monthly report.

Automates the FedRAMP / CMMC continuous monitoring workflow — vulnerability scan triage, POA&M status updates, monthly reporting, significant change identification, and control effectiveness review. Produces the monthly ConMon package.

readgrepglobbash
FedRAMPCMMC L2NIST RMFISO 27001
Open agent →
Want an agent built for your framework or workflow?

All agents above are open-source YAML configs — fork them, extend them, or contribute your own to the ZeroFinding registry.