Agent Skillsmohitagw15856/pm-claude-skills › security-questionnaire-autofill

security-questionnaire-autofill

GitHub

根据企业实际安全控制措施,自动起草SIG/CAIQ等供应商安全问卷的回答。生成基于事实的答案、差距列表及可复用片段,严禁伪造合规信息,确保回答真实一致并明确标识需人工决策的缺口。

skills/security-questionnaire-autofill/SKILL.md mohitagw15856/pm-claude-skills

触发场景

填写供应商安全问卷 回答SIG或CAIQ问卷 响应客户安全审查 完成供应商风险评估

安装

npx skills add mohitagw15856/pm-claude-skills --skill security-questionnaire-autofill -g -y
更多选项

不安装直接使用

npx skills use mohitagw15856/pm-claude-skills@security-questionnaire-autofill

指定 Agent (Claude Code)

npx skills add mohitagw15856/pm-claude-skills --skill security-questionnaire-autofill -a claude-code -g -y

安装 repo 全部 skill

npx skills add mohitagw15856/pm-claude-skills --all -g -y

预览 repo 内 skill

npx skills add mohitagw15856/pm-claude-skills --list

SKILL.md

Frontmatter
{
    "name": "security-questionnaire-autofill",
    "description": "Draft answers to a vendor security questionnaire (SIG, CAIQ, or a custom sheet) from your real controls — fast, consistent, and honest about gaps. Use when asked to fill out a security questionnaire, answer a SIG\/CAIQ, respond to a customer's security review, or complete a vendor risk assessment. Produces drafted answers grounded in your stated controls, a gap list of questions you can't truthfully answer yet, and reusable answer snippets for next time — never fabricated compliance."
}

Security Questionnaire Autofill

A single enterprise deal can arrive with a 300-question security questionnaire, and answering it by hand is a week no one has. This drafts the answers from your actual security posture, keeps the wording consistent across questions, and — critically — refuses to invent a control you don't have. What it can't answer truthfully, it flags, so you close the real gap instead of papering over it.

Answers must reflect reality. A fabricated "yes" on a security questionnaire is a misrepresentation that can void a contract — this skill flags gaps, it does not invent controls.

What This Skill Produces

  • Drafted answers — one per question, grounded in your stated controls, in consistent language
  • The gap list — questions you can't currently answer "yes" to, with what closing them would take
  • Reusable snippets — a growing answer library so the next questionnaire is faster
  • Evidence pointers — which policy/doc backs each answer (so reviewers can verify)

Required Inputs

Ask for these if not provided:

  • The questionnaire — the questions (SIG, CAIQ, or custom), pasted or attached
  • Your controls — your security posture: policies, certifications (SOC 2, ISO 27001), encryption, access control, MFA, backups, incident process — whatever's real
  • Your posture doc / prior answers — if you have a security whitepaper or past questionnaire, feed it for consistency
  • Honesty stance — confirm: flag gaps rather than best-case them (default: yes)

Framework: Answer From Truth

  1. Map question → control. Each question is answered from a real control or marked a gap. No control, no "yes."
  2. Consistent voice. The same control answered the same way every time it's asked (questionnaires repeat).
  3. Evidence-anchored. Every substantive answer names the policy/doc/cert that proves it.
  4. Gaps are findings, not failures. A flagged gap is an action item; a fabricated answer is a liability.
  5. Scope honestly. "Yes, for production; not yet for the sandbox" beats a misleading blanket yes.

Output Format

Security Questionnaire — [customer] · [framework]

Summary: [N answered · G gaps · C need a human decision]

Answers

# Question Answer Evidence Confidence
1 Yes — [detail] [policy/cert] High
2 GAP — not in place; would require [x]

Gaps to close (ranked)

  • [control] — effort to close, and whether it blocks this deal

Snippets saved for reuse

  • [control] → [reusable answer text]

Quality Checks

  • Every "yes" traces to a real, named control — none inferred or invented
  • Gaps are flagged explicitly, not softened into misleading answers
  • Repeated questions get consistent answers
  • Scope is honest where a control is partial
  • Anything requiring a business/legal decision is escalated, not guessed

Anti-Patterns

  • Fabricating a "yes" to speed the deal — the single thing this skill must never do.
  • Inconsistent answers to the same control across the sheet — reviewers notice.
  • Vague answers with no evidence — "we take security seriously" fails a review.
  • Hiding a partial scope behind a blanket claim.

Example Trigger Phrases

  • "Fill out this security questionnaire from our controls."
  • "Answer this SIG/CAIQ for a customer security review."
  • "Respond to the vendor risk assessment — flag anything we can't truthfully claim."
  • "Draft answers to this security review and list our gaps."

版本历史

  • f53846d 当前 2026-08-05 01:14

同 Skill 集合

exports/openclaw/360-feedback-template/SKILL.md
exports/openclaw/401k-plan-decoder/SKILL.md
exports/openclaw/ab-test-planner/SKILL.md
exports/openclaw/ab-test-readout/SKILL.md
exports/openclaw/accessibility-audit/SKILL.md
exports/openclaw/account-plan/SKILL.md
exports/openclaw/acquirer-red-team/SKILL.md
exports/openclaw/ad-copy/SKILL.md
exports/openclaw/aeo-optimizer/SKILL.md
exports/openclaw/agenda-or-cancel/SKILL.md
exports/openclaw/agent-design-review/SKILL.md
exports/openclaw/agent-hiring-panel/SKILL.md
exports/openclaw/agent-observability-spec/SKILL.md
exports/openclaw/agent-severance/SKILL.md
exports/openclaw/agent-spec/SKILL.md
exports/openclaw/agm-in-a-box/SKILL.md
exports/openclaw/ai-ethics-review/SKILL.md
exports/openclaw/ai-eval-plan/SKILL.md
exports/openclaw/ai-feature-prd/SKILL.md
exports/openclaw/ai-product-canvas/SKILL.md
exports/openclaw/air-quality/SKILL.md
exports/openclaw/altitude-shifter/SKILL.md
exports/openclaw/ambiguity-resolver/SKILL.md
exports/openclaw/analyst-relations-brief/SKILL.md
exports/openclaw/announcement-card/SKILL.md
exports/openclaw/api-docs-writer/SKILL.md
exports/openclaw/api-test-plan/SKILL.md
exports/openclaw/api-versioning-strategy/SKILL.md
exports/openclaw/apology-letter/SKILL.md
exports/openclaw/architecture-decision-record/SKILL.md
exports/openclaw/architecture-diagram/SKILL.md
exports/openclaw/archive-strategy/SKILL.md
exports/openclaw/assumption-bounty/SKILL.md
exports/openclaw/assumption-mapper/SKILL.md
exports/openclaw/async-update-format/SKILL.md
exports/openclaw/auto-repair-estimate-decoder/SKILL.md
exports/openclaw/autopilot-charter/SKILL.md
exports/openclaw/awkward-message-helper/SKILL.md
exports/openclaw/behavior-intervention-plan/SKILL.md
exports/openclaw/benefits-decoder/SKILL.md
exports/openclaw/bennett-time-audit/SKILL.md
exports/openclaw/bid-tender-review/SKILL.md
exports/openclaw/board-deck-narrative/SKILL.md
exports/openclaw/board-game-designer/SKILL.md
exports/openclaw/board-game-night-planner/SKILL.md
exports/openclaw/board-minutes/SKILL.md
exports/openclaw/board-pre-read/SKILL.md
exports/openclaw/bom-cost-review/SKILL.md
exports/openclaw/bookkeeping-categorization/SKILL.md
exports/openclaw/boolean-search-builder/SKILL.md

元信息

文件数
0
版本
c3bc7df
Hash
468ff69d
收录时间
2026-08-05 01:14

首页 - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-06 21:28
浙ICP备14020137号-1 $访客地图$