Install
openclaw skills install grc-agent-soc2-quality-reviewEvaluate SOC 2 report quality using the SOC 2 Quality Guild rubric (Structure, Substance, Source). Use when reviewing a vendor SOC 2 Type 1/Type 2 report, triaging report credibility, producing a risk memo, or preparing diligence follow-up questions and evidence requests.
openclaw skills install grc-agent-soc2-quality-reviewThis skill was built using the SOC 2 Quality Guild resources at s2guild.org as a baseline for quality-focused SOC 2 vendor attestation reviews.
This project was the first GRC agent I wanated to try creating with OpenClaw after setting up across multiple environments, including Raspberry Pi, Intel NUC, several LXC containers, and a cluster setup of 3 Mac Studios using EXO.
Big thanks to the SOC 2 Quality Guild community for sharing excellent, practical guidance that helped shape this agent.
Review SOC 2 quality before trusting conclusions.
Do not use this skill for:
Before scoring, capture these user-selectable settings:
Default to user-provided settings when available. If not provided, ask once before final verdict.
Capture:
If key sections are missing, stop and request a full report.
Read references/rubric.md and score each signal:
Use a strict standard for Section 4 testing detail and source credibility checks.
After S1–S11 scoring, run references/advanced-diligence.md and collect answers for the additional diligence set.
Rules:
Unknown and create a follow-up request.Treat these as high-severity findings by default:
If one or more hard fails exist, recommend compensating evidence even if the opinion is unqualified.
Always return three artifacts.
references/confidence-rubric.md)List S1–S11 with:
references/evidence-citation-format.md)Create a vendor-facing request list using references/vendor-request-templates.md:
Use references/decision-matrix.md with the selected risk posture and evidence strictness.
Baseline outcomes:
Use this exact section order:
For structure and quality calibration, mirror references/output-example.md.
Apply thresholds using selected profile:
Apply evidence strictness setting: