Memory

compliance-aiops

Try it

Generate compliance evidence from AIops audit trails — HIPAA, PCI-DSS, SOC 2, GDPR, and more.

What it does

Reads the local audit databases your governed AIops agents already write, maps infrastructure operations to specific compliance controls, and produces signed evidence bundles. Supports HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, GDPR, ISO/IEC 27001:2022, and 等保2.0. Generates change-approval reports, gap analyses, exceptions reports, and hash-chain-sealed bundles for auditors. Runs fully offline with no external network or platform credentials.

When to use it

  • SOC 2 auditor needs Q3 change-approval evidence by Friday
  • Identify which controls have no or weak audit evidence (gap analysis)
  • Seal and sign an evidence bundle; prove it wasn't altered later
  • Detect deleted or missing rows in a source audit trail

The skill document

Compliance AIops

Disclaimer: Community-maintained open-source project, not affiliated with, endorsed by, or sponsored by any framework body or GRC vendor. HIPAA, PCI-DSS, SOC 2, GDPR and OSCAL are referenced descriptively; trademarks belong to their owners. Source at github.com/AIops-tools/Compliance-AIops under the MIT license.

Governed compliance-evidence tooling — 19 MCP tools. It reads the audit trails your governed AIops agents already write (~/.-aiops/audit.db, one shared audit_log schema, discovered via ~/.*-aiops/audit.db) read-only, and turns that activity into framework-mapped, hash-chain-sealed compliance evidence. It does not scan infrastructure and does not replace a GRC platform.

Standalone: the governance harness is bundled (compliance_aiops.governance). Not a platform wrapper — no external API, no network, no platform credentials. Evidence, not certification; fully offline and deterministic.

What This Skill Does

GroupToolsCountRead/Write
Audit readslist_audit_sources, query_audit_events, activity_timeline3read
Framework mappinglist_frameworks, coverage_summary, control_evidence, gap_analysis4read
Assurance reportsapproval_report, exceptions_report2read
Integrityverify_source_chain, verify_bundle, list_bundles, bundle_schedule_hint, oscal_assessment_results5read
Artifactsgenerate_evidence_bundle (low), export_bundle (low), sign_bundle (medium)3write (no external mutation)
Undoundo_list, undo_apply2undo

Frameworks & sample controls

FrameworkSample controls (strength)
HIPAA §164.312164.312(b) Audit controls (strong), 164.312(a)(1) Access control (strong), 164.312(c)(1) Integrity (strong)
PCI-DSS v4.010.2 Audit log content (strong), 10.3 Protect audit logs (strong), 7-8 Least privilege / authn (partial)
SOC 2 TSCCC6.1 Logical access (strong), CC7.2 Monitoring (strong), CC8.1 Change management (strong)
GDPRArt.30 Records of processing (partial), Art.32 Security of processing (strong)
ISO/IEC 27001:2022 (Annex A)A.5.15 Access control (strong), A.5.16 Identity mgmt (strong), A.5.18 Access rights (partial), A.8.2 Privileged access (partial), A.8.15 Logging (strong), A.8.16 Monitoring (strong), A.8.32 Change management (strong)
等保2.0 (DJCP L3) GB/T 22239-2019 三级8.1.5.4 安全审计 (strong), 8.1.4.2 访问控制 (partial), 8.1.5 安全管理中心/集中审计 (strong)

Audit trails prove operating effectiveness strongly but control design / configuration only partially — each control is labelled strong or partial, and gap_analysis surfaces the caveat rather than overclaiming.

Quick Install

uv tool install compliance-aiops
compliance-aiops init       # discover sibling ~/.*-aiops/audit.db, set org name, optional signing key
compliance-aiops doctor     # which sibling audit DBs are present/readable

When to Use This Skill

  • Map AI-agent infra-ops activity to a framework's controls (coverage_summary)
  • Pull the evidence rows + population for one control (control_evidence)
  • Find controls with no or weak evidence, with the honest caveat (gap_analysis)
  • Produce a change-approval artifact — who approved which high-risk write and why (approval_report)
  • Produce enforcement / anomaly evidence — denied / errored / budget-tripped ops (exceptions_report)
  • Seal a tamper-evident evidence bundle (generate_evidence_bundle, sign_bundle) and later prove it wasn't altered (verify_bundle)
  • Detect deleted / missing audit rows in a source trail (verify_source_chain)

Do NOT use to scan or operate infrastructure, or as a GRC platform. It reads the audit DBs the other AIops-tools write; for platform operations use those other AIops-tools.

If the user wants…Use
Compliance evidence from existing AIops audit trailscompliance-aiops (this skill)
To actually operate a platform (VMs, storage, clusters, network, …)the relevant platform AIops-tools skill
OT / industrial edge (Modbus, OPC-UA, PLC)the industrial-aiops line
A full GRC platform / policy managementout of scope — this is evidence, not GRC

Common Workflows

1. "The SOC 2 auditor wants Q3 change-approval evidence by Friday"

  1. compliance-aiops doctor → confirm the source audit trails are discoverable and readable before you promise a delivery date
  2. compliance-aiops report sources (MCP: list_audit_sources) → which sibling audit trails were found, and the event count and date range in each. If a source you expected is missing, the bundle would be silently incomplete — fix discovery first
  3. compliance-aiops report coverage soc2 → confirm CC8.1 is actually covered by the evidence you have, before generating anything
  4. compliance-aiops report approvals → the high-risk write operations with their named approver and rationale — this is the population CC8.1 is asking about
  5. compliance-aiops bundle generate soc2 --since 2026-07-01 --until 2026-10-01 --sign → a hash-chain-sealed bundle under ~/.compliance-aiops/bundles/
  6. compliance-aiops bundle export --format markdown → the auditor-facing report (also json / csv)
  7. Failure branch: if report coverage shows CC8.1 thin, do not generate anyway and hope — run workflow 2 first and hand the auditor the honest gap statement. A bundle asserts what the audit trail contains; it cannot manufacture evidence that was never recorded.

2. "Which controls are we actually short on?" (gap analysis)

  1. compliance-aiops report sources → establish the evidence base and its date coverage; a gap caused by a missing source is a different problem from a gap caused by missing activity
  2. compliance-aiops report gaps hipaa (also pci_dss, soc2, gdpr) → controls with no or weak evidence, each with an honest caveat and a remediation suggestion
  3. compliance-aiops report exceptions → the operations that ran without an approver or rationale — usually the fastest-to-fix category of gap
  4. Drill into one control's population with control_evidence (MCP) to see the reproducible query behind the coverage number, so the figure can be defended rather than merely quoted
  5. compliance-aiops report coverage again after remediation to confirm the gap actually closed
  6. Failure branch: if list_frameworks does not carry the framework or control the auditor named, say so — this tool maps to HIPAA / PCI-DSS / SOC 2 / GDPR and does not silently substitute a near-miss control.

3. Prove a delivered bundle was not altered

  1. compliance-aiops bundle list → locate the bundle and its recorded chainHead
  2. compliance-aiops bundle verify → re-derives the hash chain, compares it to the seal's chainHead, and checks the optional signature
  3. Because the chain is computed over evidence records only, the same (framework, period, sources) reproduces the same chainHead — regenerate and compare to prove reproducibility
  4. Record the chainHead out-of-band (ticket, email to the auditor, WORM store) at delivery time; that out-of-band copy is what makes later verification meaningful
  5. verify_source_chain (MCP) on each source → returns the source chain head and flags row-id gaps, a sign that rows were deleted from that audit.db
  6. Failure branch: a chainHead mismatch or a row-id gap means the evidence is not trustworthy — escalate, and treat the source audit.db as the system of record. Do not re-seal a fresh bundle to make the mismatch go away; the tool is tamper-evident, not tamper-proof, and its whole value is that it reports this rather than papering over it.

4. 定期封存 — schedule periodic sealed bundles (no daemon)

This tool ships no scheduler; it emits a cron line for you to install.

  1. compliance-aiops report sources → confirm the sources you want sealed are discoverable from the account cron will run as (a common failure: cron sees a different $HOME)
  2. compliance-aiops bundle schedule soc2 --cron "0 2 * * 1" --period 7d --sign (MCP: bundle_schedule_hint) → returns a cronLine plus the exact non-interactive command. It writes nothing.
  3. Paste the cronLine into crontab -e, e.g. 0 2 * * 1 compliance-aiops bundle generate soc2 --period 7d --sign
  4. Export COMPLIANCE_AIOPS_MASTER_PASSWORD in the cron environment so the signing key unlocks non-interactively — never inline the real password in the crontab
  5. After the first scheduled run, compliance-aiops bundle list and bundle verify the newest bundle to confirm the unattended path really works
  6. Failure branch: if the cron run produces no bundle, the usual causes are an unset master password (signing cannot unlock) or COMPLIANCE_AIOPS_HOME not being set in cron's environment, so sources resolve elsewhere. Verify by running the emitted command by hand with a clean environment before trusting the schedule.

Governance & Safety

The skill reads audit trails and writes evidence bundles and records what it does; it does not decide whether producing or signing a bundle is permitted. That is your agent's judgement, or the filesystem permissions of the account it runs as. There is no read-only switch, policy file, or approval gate.

  • Audit is the guarantee, and it is not bypassable. Every operation — MCP and CLI alike — is logged to ~/.compliance-aiops/audit.db (relocatable via COMPLIANCE_AIOPS_HOME): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.
  • The source audit trails are opened read-only; the tool never mutates them. The only files written are bundles under ~/.compliance-aiops/bundles/.
  • COMPLIANCE_AUDIT_APPROVED_BY / COMPLIANCE_AUDIT_RATIONALE are optional annotations recorded on the audit row (who/why); they are never required and never block.
  • Tamper-EVIDENT, not tamper-PROOF — the source audit.db remains the system of record.

References

  • references/capabilities.md — full tool → inputs → returns reference
  • references/cli-reference.md — CLI command reference
  • references/setup-guide.md — source discovery, org name, optional signing key, integrity notes

Questions people ask

Which compliance frameworks does this support?
HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, GDPR, ISO/IEC 27001:2022 (Annex A), and 等保2.0 (DJCP L3). Each supported control is labeled 'strong' or 'partial' based on what the audit trail can prove.
How does the tamper-evident bundle work?
The bundle computes a hash chain over the evidence records. Later, `verify_bundle` re-derives the chain and compares it to the recorded chainHead. A mismatch means the bundle was altered after sealing.
Can this detect if someone deleted audit rows?
Yes. `verify_source_chain` checks each source audit.db for row-id gaps. A gap indicates deleted rows in that source trail — the tool flags this rather than silently proceeding.

Related skills

Operate Kubernetes clusters with 55 audited tools — list resources, diagnose pod health, scale workloads, and manage rollouts safely.

by zw0081 installs1 stars

Join video meetings as a voice bot, visual avatar, or avatar with live screen sharing.

by johnpatternai22 installs8 stars

Escape the scarcity trap — diagnose bandwidth consumption and design protected slack to restore strategic capacity.

by deciqai1 installs2 stars

Know whether you're qualified to make a decision before you make it

by deciqai1 installs3 stars

Measure whether a transformation changed your growth engine or just added a one-time bump.

by deciqai1 installs2 stars

Prioritize growth directions with a 2×2 risk framework — pick one bet and commit.

by deciqai2 installs2 stars

More from zw008

Browse all skills

Operate VMware VMs, deployments, clusters, guest tasks, and alarms with plan and rollback support.

by zw00878 installs1 stars

Inspect VMware health, inventory, alarms, events, and performance without changing infrastructure.

by zw00876 installs

Query Aria Operations metrics, alerts, capacity forecasts, anomalies, and reports from CLI or MCP.

by zw00853 installs

Manage AVI services and pools, and diagnose AKO ingress, sync, certificates, analytics, and health.

by zw00851 installs

Manage Supervisor Namespaces and TKC cluster lifecycles in vSphere Kubernetes Service.

by zw00851 installs

Manage NSX segments, gateways, routing, IP pools, health checks, and connectivity diagnostics.

by zw00850 installs