GRC Agents. Copy and deploy.
Open-source Anthropic Managed Agent configs for GRC practitioners. Preview the YAML inline, download in one click, and run them against your own infrastructure with full file-system access. Inspired by the 21st.dev agent registry — built for compliance.
Security Auditor
Full security audit with Critical/High/Medium/Low findings and remediation roadmap.
Conducts comprehensive security audits, compliance assessments, and risk evaluations across systems, infrastructure, and processes. Reads your actual codebase and policy docs via file-system tools.
Incident Response Coordinator
Walks your team through IR playbook steps in real time during a live incident.
Acts as your incident commander during active security incidents. Follows NIST SP 800-61 methodology — detection, containment, eradication, recovery, and lessons learned. Generates timeline, stakeholder briefs, and post-incident reports.
Compliance Gap Analyzer
Maps your current controls to framework requirements. Shows exactly what is missing.
Reads your policies, SSP, and evidence directory, then maps each control against the target framework's requirements. Produces a gap register with severity, remediation effort estimate, and sequenced roadmap.
Evidence Reviewer
Grades every piece of evidence before your auditor sees it. Flags red flags.
Reviews screenshots, log excerpts, policy clips, and configuration exports against specific assessment objectives. Returns an adequacy verdict (Sufficient / Insufficient / Missing) with precise assessor-language gaps and what additional evidence is needed.
POA&M Advisor
Reviews POA&M items, scores remediation priority, flags certification blockers.
Reads your Plan of Action and Milestones, evaluates each open item against SPRS impact weights and framework POA&M eligibility rules, and produces a prioritized remediation schedule with milestone dates and owner assignments.
SSP Narrator
Generates present-tense SSP narratives in your system's voice. Assessment-grade.
Reads your system context, existing configurations, and policy docs to write SSP control narratives. Output matches the present-tense, objective-level style that CCAs and 3PAOs expect — not boilerplate, not paraphrased requirements.
Policy Drafter
Writes complete IS policies from a single prompt. AUP, IR Plan, Access Control, and more.
Generates complete information security policies tailored to your organization size, industry, and target frameworks. Output includes purpose, scope, definitions, policy statements, exceptions process, and review schedule. Ready for leadership sign-off.
Risk Register Builder
Builds a complete risk register with likelihood, impact, and treatment plans.
Reads your system inventory, threat landscape, and existing controls, then generates a structured risk register with qualitative and quantitative scoring. Each risk gets inherent and residual scores, treatment options, and an owner assignment.
Third-Party Risk Assessor
Reviews vendor questionnaires, SOC reports, and contracts for GRC risk exposure.
Analyzes vendor security questionnaires (SIG, CAIQ, custom), SOC 2 reports, penetration test summaries, and MSAs to produce a vendor risk score and gap list. Flags exceptions, subprocessors, and contractual gaps.
Threat Intel Analyst
Monitors CISA KEV, CVEs, and threat feeds. Translates exploits into GRC control gaps.
Fetches live threat intelligence from CISA KEV, NVD, and ISAC feeds. For each active threat, maps it to the controls that would prevent or detect it, scores your organization's exposure, and drafts a management-ready threat brief.
Regulatory Intel Agent
Monitors Federal Register, SEC, CISA, and global regulators for rule changes that affect your program.
Daily scan of regulatory sources — Federal Register final and proposed rules, SEC cybersecurity disclosures, CISA guidance, EU DORA/NIS2 updates, India DPDPA rulemaking. Summarizes what changed, who is affected, and what action is required by what deadline.
ConMon Agent
Runs your monthly continuous monitoring cycle. Scans, scores, and drafts the monthly report.
Automates the FedRAMP / CMMC continuous monitoring workflow — vulnerability scan triage, POA&M status updates, monthly reporting, significant change identification, and control effectiveness review. Produces the monthly ConMon package.
All agents above are open-source YAML configs — fork them, extend them, or contribute your own to the ZeroFinding registry.