Skip to content

Repository files navigation

Protofire GRC Agent Skill Suite

Source framework: GRC-PF-001 v1.0 · CL-PHASE-001 v1.0 Policy corpus: Protofire GRC Policy Repository v2026-04-16 (POL-001–017 · STD-101–110 · PR-208–210 · REG-501–513 · PLAN-701–703 · GL-304–305 · DPA-001 · MSA-001) Phases covered: 1–12 · 42 checklist steps · Track A + Track B Deployment target: Claude.ai Projects Integrations: Google Drive · Slack · GitHub/GitLab · ClickUp Last synced: 2026-07-15 (v2.2 — 2026 H1 threat delta + reviewed PR #1; see kaizen-meta-agent/kaizen-changelog.md)


Skill index

Skill Role Gate authority Primary phases
am-agent/SKILL.md Account Manager Gate G1-A 1, 2, 3, 12
no-agent/SKILL.md Node Owner G1-A → G8 (all gates) All
vciso-agent/SKILL.md vCISO Gate G4 (mandatory) + G7 1, 5, 9, 10
tl-agent/SKILL.md Technical Lead G4, G5, G6, G7 5, 6, 8, 9, 11
pm-agent/SKILL.md Project Manager Gate G3 (co-sign) 4, 6, 7, 10
devops-agent/SKILL.md DevOps Engineer Gate G6 (co-sign) 4, 8, 9, 11
qa-agent/SKILL.md QA Engineer Signs audit/test reports 6, 8, 11
fin-agent/SKILL.md Finance / Billing HS-05 hard stop owner 3 + ongoing
grc-manager-agent/SKILL.md GRC Manager Programme operations Ongoing
dpo-agent/SKILL.md Data Protection Officer G4-A (DPIA input) 4, 8, 10, ongoing
kaizen-meta-agent/SKILL.md Kaizen Meta-Agent Improves all 10 above Post-session

Hard-wired non-negotiables

  1. Gate G4 — invalid without BOTH TL + vCISO signatures
  2. Irreversibility Gate Record — invalid without ALL THREE: NO + TL + vCISO
  3. Phase 4 blocked until Gate G2 signed (HS-02 enforcement)
  4. vCISO = Aleksey Lekontsev — never substituted
  5. HS-01 (OFAC) — non-waivable; immediate stop; no further client contact (POL-009 §3)
  6. HS-05 (arrears >60d) — FIN agent triggers; NO makes stop-work decision
  7. SoD: NO = PM → DoE co-sign mandatory at all T2+ gates
  8. Author ≠ reviewer on all smart contract PRs (POL-004 §2.4)
  9. DPIA mandatory for T2+ engagements with EU personal data (POL-011 §6.1 · CL-409)
  10. Breach to CISO within 4h; supervisory authority within 72h (POL-011 §8 · PR-208)
  11. Key Compromise response — PR-210 (separate from breach notification PR-208)
  12. HS-08 — undecodable/mismatched/stale authorization or unattested/mobile signer endpoint: do not sign; non-waivable except decoded emergency pause path
  13. HS-09 — unverified high-risk counterparty/token/collateral: block onboarding, listing and limit increase; non-waivable
  14. High-risk transaction — CL-414 + transaction-intent record + pending-authorization inventory required

Kaizen cadence

  • Every session → micro-review (10 min)
  • Every 5 sessions → full cycle (30 min)
  • Monthly → pattern analysis via kaizen-meta-agent/kaizen-changelog.md

Four optimization targets: A Triggering · B Decision logic · C Instructions · D Artifact templates


Policy corpus coverage (v2026-04-16)

Domain Documents
Policies POL-001–017, DAO-001
Standards STD-101–105, STD-110, S-109, S-115, OPS-001
Procedures L2-DEL-101, L2-RISK-102, L2-ASSURE-103, L2-INC-201, L2-VULN-202, L2-ACCESS-203, L2-CHANGE-205, PR-208, PR-209, PR-210
Guidelines GL-304, GL-305, L3-TEST-204
Plans PLAN-701 (Tabletop IR), PLAN-702 (BCP), PLAN-703 (DR)
Checklists CL-PHASE-001, CL-409, CL-411, CL-414
Registers REG-501–513
Legal templates DPA-001, MSA-001
Foundation L0-1, L0-2, L0-4, L0-5, GRC-MASTER-001, GRC-PF-001, L1-ERM-001, L1-SDLC-003, L1-KEY-005

About

No description, website, or topics provided.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors