Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Setup guidance for users running a /report:* command before their toolkit has enough context. Use when a report command detects missing findings, frameworks, or history. Walks the user through installation and first collection rather than generating a hollow report.
.claude/skills/grcengclub-context-bootstrap/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 27% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 11% | 0% |
| case-02 | ✗→✓ | ▲ Improved | -23% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 2% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 71% | 0% |
Hollow reports are worse than no reports. When a user runs /report:exec-summary with an empty findings cache, the right move is to teach them the setup, not to make up a report.
Before any report command generates, verify:
/plugin list or inspect the marketplace. Need at least:grc-engineer (the pipeline hub)github-inspector, aws-inspector, okta-inspector)soc2, fedramp-rev5, iso27001)~/.cache/claude-grc/findings/<source>/*.json. Timestamps within the last 30 days mean the pipeline is active.plugin.json should have a framework_metadata block. Without it, coverage math fails silently./report:automation-coverage needs at least 2 metric snapshots in ./grc-data/metrics/ that are 7+ days apart. Verify snapshot dates there rather than inferring movement from the findings cache../grc-data/risks/*, ./grc-data/metrics/*, ./grc-data/incidents/*.md. The JSON contracts live in docs/GRC-DATA.md. Missing is fine; present is better./report:exec-summary: one connector, one framework, recent findings. Risks and metrics improve it but are not mandatory./report:program-health: two framework plugins plus one successful gap-assessment run per framework. A single-framework setup is not enough./report:board-brief: quarter-spanning findings history plus a real risk register if you want residual-risk sections to be grounded./report:automation-coverage: two metric snapshots in ./grc-data/metrics/ at least 7 days apart. Findings cache alone is not enough to claim week-over-week automation movement.Auto-discover everything. Ask at most one or two narrative questions (audience, material asks). Generate.
Name what's missing. Auto-discover what exists. Offer to proceed with interview mode where the user fills the gaps conversationally. Example:
> I see findings from github-inspector across the last 14 days, SOC 2 framework installed. No risk register at ./grc-data/risks/. I can still write the report using findings and metrics only, or you can set up a risk register first. docs/GRC-DATA.md shows the file shape. Which do you want?
Walk through the setup. Do not generate.
Deliver these steps in plain conversational form. Do not dump all commands at once; confirm each step before moving to the next.
/plugin marketplace add GRCEngClub/claude-grc-engineering
/plugin install grc-engineer@grc-engineering-suite /plugin install github-inspector@grc-engineering-suite /plugin install soc2@grc-engineering-suite
github-inspector is the lowest-setup connector (uses the gh CLI you probably already have authenticated). soc2 is the most common first framework.
/github-inspector:setup
Confirms gh auth status and writes a default config.
/github-inspector:collect --scope=@me
For a first run, @me scopes to the user's own repos. For org-wide scans, use --scope=<org-name> with a token that has admin:org.
/grc-engineer:gap-assessment SOC2 --sources=github-inspector
Not strictly required for /report:* commands, but produces the crosswalked finding structure report commands read.
/report:program-health, add a second framework now. /plugin install fedramp-rev5@grc-engineering-suite /grc-engineer:gap-assessment SOC2,FedRAMP-Moderate --sources=github-inspector
program-health needs more than one framework in scope or it is not a portfolio view.
/report:automation-coverage specificallyThis command needs history. If the user just finished a first-time setup, tell them:
> You have one baseline from today. Automation coverage needs at least two metric snapshots 7+ days apart so there's a delta to report. Two options: > > 1. Schedule regular collection with /grc-engineer:monitor-continuous SOC2 daily --sources=github-inspector. Come back in 7-14 days. > 2. Run /grc-engineer:record-automation-metrics <framework> --controls-total=<n> --controls-automated=<n> --window-label=<period> once per week so ./grc-data/metrics/ builds a real history, then rerun the report after you have two snapshots.
Do not fabricate a week-over-week comparison from Findings alone.
Never. A fake report is worse than no report because it teaches the user to trust numbers that aren't real. If the user explicitly asks for a template rendering with placeholder data for demo purposes, that is a different ask and gets a clearly-labeled DEMO DATA output.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 18,120 | 39,582 | +118% | 1 | 1 | 0% | 2,337 | 2,959 | +27% | 0 | 0 | — |
case-07 | fail→pass | 11,627 | 4,297 | -63% | 1 | 1 | 0% | 1,826 | 2,025 | +11% | 0 | 0 | — |
case-02 | fail→pass | 19,231 | 5,819 | -70% | 1 | 1 | 0% | 2,954 | 2,263 | -23% | 0 | 0 | — |
case-03 | fail→pass | 16,816 | 8,442 | -50% | 1 | 1 | 0% | 2,636 | 2,677 | +2% | 0 | 0 | — |
case-04 | fail→pass | 10,086 | 6,517 | -35% | 1 | 1 | 0% | 1,439 | 2,460 | +71% | 0 | 0 | — |
case-05 | pass→pass | 15,340 | 8,353 | -46% | 1 | 1 | 0% | 2,208 | 2,518 | +14% | 0 | 0 | — |
case-06 | pass→pass | 11,087 | 5,479 | -51% | 1 | 1 | 0% | 1,736 | 2,276 | +31% | 0 | 0 | — |
case-08 | fail→pass | 11,907 | 12,611 | +6% | 1 | 1 | 0% | 1,738 | 3,459 | +99% | 0 | 0 | — |
case-09 | fail→fail | 9,575 | 7,108 | -26% | 1 | 1 | 0% | 1,529 | 2,474 | +62% | 0 | 0 | — |
case-10 | pass→pass | 4,990 | 3,943 | -21% | 1 | 1 | 0% | 795 | 2,046 | +157% | 0 | 0 | — |
case-11 | fail→pass | 13,435 | 10,196 | -24% | 1 | 1 | 0% | 2,005 | 3,043 | +52% | 0 | 0 | — |
case-21 | fail→pass | 13,145 | 4,684 | -64% | 1 | 1 | 0% | 1,831 | 2,059 | +12% | 0 | 0 | — |
case-12 | fail→pass | 4,919 | 3,456 | -30% | 1 | 1 | 0% | 758 | 1,844 | +143% | 0 | 0 | — |
case-13 | pass→pass | 13,879 | 4,963 | -64% | 1 | 1 | 0% | 1,962 | 2,102 | +7% | 0 | 0 | — |
case-14 | fail→pass | 15,409 | 2,860 | -81% | 1 | 1 | 0% | 2,307 | 1,831 | -21% | 0 | 0 | — |
case-15 | fail→pass | 10,493 | 5,299 | -49% | 1 | 1 | 0% | 1,569 | 2,314 | +47% | 0 | 0 | — |
case-16 | fail→pass | 8,637 | 1,979 | -77% | 1 | 1 | 0% | 1,341 | 1,636 | +22% | 0 | 0 | — |
case-17 | fail→pass | 21,218 | 2,457 | -88% | 1 | 1 | 0% | 1,704 | 1,755 | +3% | 0 | 0 | — |
case-18 | fail→pass | 9,008 | 4,011 | -55% | 1 | 1 | 0% | 1,684 | 2,060 | +22% | 0 | 0 | — |
case-19 | fail→pass | 6,938 | 2,040 | -71% | 1 | 1 | 0% | 1,033 | 1,697 | +64% | 0 | 0 | — |
case-20 | pass→pass | 11,551 | 7,915 | -31% | 1 | 1 | 0% | 2,021 | 2,813 | +39% | 0 | 0 | — |
case-22 | pass→pass | 3,976 | 3,670 | -8% | 1 | 1 | 0% | 706 | 2,076 | +194% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +68 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.