Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Expertise on FedRAMP SSP authoring — what the DOCX templates contain, what OSCAL 1.2.0 SSP looks like for FedRAMP, how this plugin fits alongside Compliance Trestle and oscal-cli.
.claude/skills/grcengclub-fedramp-ssp-expert/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-03 | ✗→✓ | ▲ Improved | 3% | 0% |
| case-06 | ✗→✓ | ▲ Improved | -13% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 17% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 27% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 17% | 0% |
You are the guide for turning FedRAMP Rev 5 Word-template SSPs into machine-readable OSCAL 1.2.0.
FedRAMP publishes three Word-template documents that CSPs fill in:
The DOCX→OSCAL pipeline here consumes the main SSP + Appendix A and produces an OSCAL 1.2.0 SSP JSON covering the most-critical content.
metadata: system name, authorization path, version, last-modifiedsystem-characteristics: identification, authorization boundary, system information, data types (security objectives for confidentiality/integrity/availability)system-implementation: users, components, leveraged authorizations, inventory itemscontrol-implementation: 323 implemented-requirements, each with implementation status, control origination, responsible roles, and narrative by-component statementsback-matter: resources and referencesThe output uses FedRAMP-namespaced props (https://fedramp.gov/ns/oscal) for fields like implementation-status, control-origination, cloud deployment model.
/oscal:validate — pass --validate to this plugin, or run /oscal:validate manually on the output./oscal:convert — convert the JSON output to XML for Compliance Trestle or to YAML for human review./grc-engineer:gap-assessment --output=oscal-ar — produces OSCAL Assessment Results. A full FedRAMP package is SSP + AR + POA&M; this plugin provides the SSP side.[CSP-specific: ...] placeholders. If your team hasn't filled them in, the pipeline propagates placeholder text into the OSCAL narratives. Review before submission.sp-system, sp-corporate, customer-configured, customer-provided, inherited, shared. Values outside that set fail FedRAMP validation./oscal:validate bundles 1.1.3. These are schema-compatible for the SSP subset used, but if you need strict 1.1.3, set oscal-version: "1.1.3" in the output or update the oscal-cli schema bundle./grc-engineer:test-control + a 3PAO assessment.| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-15 | pass→pass | 11,161 | 11,330 | +2% | 1 | 1 | 0% | 2,029 | 3,041 | +50% | 0 | 0 | — |
case-16 | pass→pass | 15,766 | 12,422 | -21% | 1 | 1 | 0% | 2,515 | 3,250 | +29% | 0 | 0 | — |
case-03 | fail→pass | 18,593 | 11,031 | -41% | 1 | 1 | 0% | 2,800 | 2,897 | +3% | 0 | 0 | — |
case-13 | fail→fail | 11,242 | 7,656 | -32% | 1 | 1 | 0% | 1,824 | 2,440 | +34% | 0 | 0 | — |
case-01 | fail→fail | 20,417 | 25,814 | +26% | 1 | 1 | 0% | 3,231 | 4,344 | +34% | 0 | 0 | — |
case-02 | fail→fail | 24,542 | 21,070 | -14% | 1 | 1 | 0% | 4,129 | 5,171 | +25% | 0 | 0 | — |
case-04 | pass→pass | 14,525 | 4,453 | -69% | 1 | 1 | 0% | 2,261 | 1,788 | -21% | 0 | 0 | — |
case-05 | pass→pass | 15,868 | 7,560 | -52% | 1 | 1 | 0% | 2,239 | 2,081 | -7% | 0 | 0 | — |
case-06 | fail→pass | 14,627 | 5,442 | -63% | 1 | 1 | 0% | 2,121 | 1,853 | -13% | 0 | 0 | — |
case-07 | fail→pass | 17,358 | 11,438 | -34% | 1 | 1 | 0% | 2,594 | 3,025 | +17% | 0 | 0 | — |
case-08 | fail→pass | 12,040 | 8,330 | -31% | 1 | 1 | 0% | 1,954 | 2,480 | +27% | 0 | 0 | — |
case-14 | pass→pass | 9,021 | 7,577 | -16% | 1 | 1 | 0% | 1,668 | 2,440 | +46% | 0 | 0 | — |
case-09 | pass→pass | 10,772 | 4,462 | -59% | 1 | 1 | 0% | 1,870 | 1,790 | -4% | 0 | 0 | — |
case-10 | fail→pass | 12,876 | 9,107 | -29% | 1 | 1 | 0% | 2,555 | 2,989 | +17% | 0 | 0 | — |
case-11 | fail→pass | 8,584 | 2,971 | -65% | 1 | 1 | 0% | 1,443 | 1,517 | +5% | 0 | 0 | — |
case-12 | fail→pass | 12,764 | 3,028 | -76% | 1 | 1 | 0% | 1,978 | 1,539 | -22% | 0 | 0 | — |
case-17 | pass→pass | 13,536 | 11,483 | -15% | 1 | 1 | 0% | 2,337 | 3,069 | +31% | 0 | 0 | — |
case-18 | pass→pass | 15,988 | 11,206 | -30% | 1 | 1 | 0% | 2,379 | 2,755 | +16% | 0 | 0 | — |
case-19 | pass→pass | 16,755 | 11,041 | -34% | 1 | 1 | 0% | 2,448 | 2,810 | +15% | 0 | 0 | — |
case-20 | fail→pass | 18,498 | 11,715 | -37% | 1 | 1 | 0% | 3,022 | 2,913 | -4% | 0 | 0 | — |
case-21 | pass→pass | 15,713 | 7,081 | -55% | 1 | 1 | 0% | 2,420 | 2,277 | -6% | 0 | 0 | — |
case-22 | fail→pass | 19,083 | 11,999 | -37% | 1 | 1 | 0% | 3,011 | 2,926 | -3% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +41 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.