security-auditor

Guides security audit planning, control testing, evidence collection, and compliance framework comparison.

Updated Jun 5, 2026
One-click install
npx skills add https://github.com/yogiex/opencode-cyber-security-skills --skill security-auditor-yogiex
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-auditor
Source: https://github.com/yogiex/opencode-cyber-security-skills/tree/main/skills/security-auditor
Command: npx skills add https://github.com/yogiex/opencode-cyber-security-skills --skill security-auditor-yogiex

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Security auditors and GRC analysts often lack a structured methodology when planning audits, testing controls, or choosing between compliance frameworks like SOC 2, ISO 27001, PCI DSS, and HIPAA. This Skill provides a complete audit lifecycle reference so findings are evidence-based, risk-prioritized, and aligned with the right standard. ## Core Features & Use Cases - Audit Lifecycle Guidance: Covers planning, scoping, fieldwork, control testing, reporting, remediation tracking, and follow-up audits with concrete techniques like walkthroughs, re-performance, and CAATs. - Framework Comparison & Mapping: Compares SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, SOX, and HITRUST with control overlap tables and a decision tree for selecting the right framework. - Certification & Career Path: Details CISA, CISSP, ISO 27001 Lead Auditor, CRISC, and CISM with costs, prerequisites, and career progression. - Use Case: A GRC analyst preparing a SOC 2 Type II audit can use this Skill to scope control objectives, design sampling strategies, structure workpapers, and map findings to Trust Services Criteria. ## Quick Start Ask the agent to help plan a SOC 2 Type II audit for a B2B SaaS company, including scope, control testing approach, and evidence collection strategy.

Frequently Asked Questions about security-auditor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a security audit from start to finish?▼

Follow the audit lifecycle: planning (understand business context and regulations), scoping (define in-scope systems and control objectives), fieldwork (collect evidence via inquiry, observation, inspection, and re-performance), reporting, remediation tracking, and follow-up audits.

SOC 2 vs ISO 27001: which framework should I choose?▼

SOC 2 is a US-focused attestation ideal for B2B SaaS selling to enterprises, while ISO 27001 is a global certification better for international operations. The two frameworks share roughly 80% control overlap, so many organizations pursue both.

What is the difference between design and operating effectiveness in control testing?▼

Design effectiveness asks whether a control could theoretically prevent or detect a risk if executed properly. Operating effectiveness asks whether the control actually ran consistently throughout the audit period, typically verified through sampling and walkthroughs.

CISA vs ISO 27001 Lead Auditor certification: which is better for auditors?▼

CISA covers broad IT audit, governance, and security domains and is widely recognized in enterprise and government. ISO 27001 Lead Auditor is specialized for ISMS audits and suits consultants working in ISO-certified environments.

When should I not use an audit methodology skill?▼

This guidance is not suited for technical penetration testing, detailed threat modeling, or incident response execution. Those tasks require dedicated offensive security, threat modeling, or incident response playbooks instead.