identity-assurance

Assess identity assurance gaps across AAL/IAL/FAL, MFA, and OAuth/JWT controls.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill identity-assurance
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: identity-assurance
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/identity-assurance
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill identity-assurance

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Legacy identity and compliance frameworks (NIST 800-53, ISO 27001, SOC 2, etc.) were designed for pre-AI, network-centric environments and lack controls for AI agent-as-principal identity, phishing-resistant authentication requirements, and modern OAuth/JWT threat models. This skill fills that gap by providing a structured assessment process aligned with mid-2026 threat reality and current identity standards like NIST 800-63 rev4, FIDO2/WebAuthn, and RFC 9700.

Core Features & Use Cases

  • Full Identity Assurance Assessment: Generates a complete scorecard covering per-principal AAL/IAL/FAL posture, phishing-resistant MFA coverage, token lifetime audits, JWT validation checks, and federation surface mapping.
  • Compliance Gap Analysis: Maps identity control gaps to 20+ global regulatory frameworks (NIS2, DORA, UK CAF, AU ISM, ISO 27001, NY DFS, etc.) and MITRE ATT&CK/ATLAS TTPs to identify where paper compliance fails.
  • Actionable Remediation Roadmap: Prioritizes fixes for critical gaps like agent identity inheritance, non-phishing-resistant MFA deployment, and non-compliant OAuth token lifetimes, with clear ownership and target dates.
  • Use Case: A security team preparing for a SOC 2 audit can use this skill to run a full identity assessment, identify that 40% of privileged users are on TOTP instead of phishing-resistant MFA, and generate a prioritized roadmap to close the gap before the audit.

Quick Start

Use the identity-assurance skill to run a full identity assurance assessment for your organization, including principal inventory, phishing-resistant MFA coverage, and cross-jurisdictional compliance gap analysis.

Frequently Asked Questions about identity-assurance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess NIST 800-63 AAL/IAL/FAL compliance for AI agent identity workflows?▼

Identity assurance assessments evaluate per-principal AAL/IAL/FAL posture, mapping AI agent-as-principal identity and phishing-resistant MFA coverage to NIST 800-63 requirements. This generates a complete scorecard covering authentication strength and federation surfaces.

What is phishing-resistant MFA coverage and how does it impact SOC 2 audits?▼

Phishing-resistant MFA coverage measures the percentage of users on FIDO2/WebAuthn instead of vulnerable TOTP. For SOC 2 audits, insufficient coverage indicates paper compliance failure, requiring a prioritized remediation roadmap to close security gaps.

How do I map OAuth security gaps to MITRE ATT&CK and ATLAS TTPs?▼

Mapping OAuth security gaps to MITRE ATT&CK and ATLAS TTPs identifies where legacy token lifetimes and JWT validation failures expose threats. This aligns modern OAuth/JWT threat models with active adversary techniques for targeted remediation.

Does this identity assurance approach work with OIDC/SAML federation and cloud workload identity?▼

Identity assurance assessments support OIDC/SAML federation and cloud workload identity by mapping federation surfaces and token lifetimes. They evaluate zero trust architecture reviews and regulatory compliance for environments using MCP/agent workflows.

How to prepare for NIS2 and DORA compliance gap analysis for identity controls?▼

Compliance gap analysis maps identity control gaps to NIS2, DORA, and ISO 27001 requirements by auditing phishing-resistant MFA and agent identity inheritance. It generates cross-jurisdictional evidence and prioritizes fixes with clear ownership.

Why does legacy identity compliance fail for AI agent-as-principal authentication?▼

Legacy identity compliance fails for AI agent-as-principal authentication because pre-AI frameworks lack controls for modern OAuth/JWT threat models and MCP workflows. Updated assessments align with mid-2026 threat reality and RFC 9700 best practices.