Example AI Audit report: DoneThat SOC 2 Type 1.
An agent skill that runs an AI Audit modeled on a SOC 2 Type 1 or Type 2 examination: it pulls evidence from the client's compliance platform, tests every control against the Trust Services Criteria, and produces a PDF signed by the model that ran it. The report says it is an AI Audit, not an official SOC 2 audit.
It follows the open Agent Skills format, so the same soc2-audit/ folder works with Claude Code, Codex, Gemini CLI, Cursor, GitHub Copilot and other agents that read SKILL.md. All deterministic work runs in plain Python scripts, so nothing depends on one vendor's agent features.
init ──> ingest ──> check ──> plan ──> sample ──> test ──> validate ──> QA ──> opinion ──> signoff (model) ──> render + packet
│ │ │
connector writes agent writes one fresh context or
bundle/ (hashed) workpaper per control another model reviews
folder, probo, vanta, drata) turn a source into an evidence bundle. Every file is hashed at ingest.signoff --model with its own name. Until then every PDF is watermarked DRAFT. The signed PDF is an AI Audit, not an official SOC 2 audit. Any later change to the work clears the signature.git clone git@github.com:heychristoph/soc2-auditor.git
pip install -r soc2-auditor/soc2-audit/scripts/requirements.txt
Then make soc2-audit/ visible to your agent: copy or symlink it into the agent's skills directory (for Claude Code, ~/.claude/skills/soc2-audit), or tell the agent to read soc2-audit/SKILL.md.
python soc2-audit/scripts/soc2.py init ./acme-2026 --type 2 --start 2026-01-01 --end 2026-06-30 \
--org "Acme, Inc." --system "Acme Platform" \
--categories security,availability,confidentiality --connector probo --option organization_id=<id>
export PROBO_TOKEN=...
Then ask your agent: "Run the AI Audit in ./acme-2026." The agent signs the report with the model that ran it. soc2.py status ./acme-2026 shows progress and the next step at any time.
soc2-audit/assets/schemas/. Any step can be rerun or resumed by any agent.pull() function plus one reference page. Nothing downstream changes.assets/report/report-text.yaml plus the workpapers, so the PDF cannot disagree with the work. Firms replace the wording and the Typst layout without touching code.soc2-audit/ the skill (self-contained, spec-valid)
├── SKILL.md workflow and rules
├── references/ one page per step and per connector
├── scripts/ soc2.py CLI, connectors/
└── assets/ criteria, sampling table, schemas, report template and wording
evals/ fixtures, oracle, graders, agent runner, Probo mock
python evals/make_fixture.py # synthetic Type 1 and Type 2 engagements
python evals/run.py --case type2 --agent oracle # model-free regression test of the scripts
python evals/run.py --case type2 --agent 'claude -p --permission-mode bypassPermissions {prompt}'
python evals/test_probo_connector.py # Probo connector against a local mock
See evals/README.md.
This tool produces an AI Audit. It is not an official SOC 2 audit, not an AICPA attestation, and not a report a CPA firm can issue. The model that ran the work signs the PDF, and the report says so. The Trust Services Criteria in assets/criteria.yaml are paraphrased.
Python
97.2%
Typst
2.8%
Example AI Audit report: DoneThat SOC 2 Type 1.
An agent skill that runs an AI Audit modeled on a SOC 2 Type 1 or Type 2 examination: it pulls evidence from the client's compliance platform, tests every control against the Trust Services Criteria, and produces a PDF signed by the model that ran it. The report says it is an AI Audit, not an official SOC 2 audit.
It follows the open Agent Skills format, so the same soc2-audit/ folder works with Claude Code, Codex, Gemini CLI, Cursor, GitHub Copilot and other agents that read SKILL.md. All deterministic work runs in plain Python scripts, so nothing depends on one vendor's agent features.
init ──> ingest ──> check ──> plan ──> sample ──> test ──> validate ──> QA ──> opinion ──> signoff (model) ──> render + packet
│ │ │
connector writes agent writes one fresh context or
bundle/ (hashed) workpaper per control another model reviews
folder, probo, vanta, drata) turn a source into an evidence bundle. Every file is hashed at ingest.signoff --model with its own name. Until then every PDF is watermarked DRAFT. The signed PDF is an AI Audit, not an official SOC 2 audit. Any later change to the work clears the signature.git clone git@github.com:heychristoph/soc2-auditor.git
pip install -r soc2-auditor/soc2-audit/scripts/requirements.txt
Then make soc2-audit/ visible to your agent: copy or symlink it into the agent's skills directory (for Claude Code, ~/.claude/skills/soc2-audit), or tell the agent to read soc2-audit/SKILL.md.
python soc2-audit/scripts/soc2.py init ./acme-2026 --type 2 --start 2026-01-01 --end 2026-06-30 \
--org "Acme, Inc." --system "Acme Platform" \
--categories security,availability,confidentiality --connector probo --option organization_id=<id>
export PROBO_TOKEN=...
Then ask your agent: "Run the AI Audit in ./acme-2026." The agent signs the report with the model that ran it. soc2.py status ./acme-2026 shows progress and the next step at any time.
soc2-audit/assets/schemas/. Any step can be rerun or resumed by any agent.pull() function plus one reference page. Nothing downstream changes.assets/report/report-text.yaml plus the workpapers, so the PDF cannot disagree with the work. Firms replace the wording and the Typst layout without touching code.soc2-audit/ the skill (self-contained, spec-valid)
├── SKILL.md workflow and rules
├── references/ one page per step and per connector
├── scripts/ soc2.py CLI, connectors/
└── assets/ criteria, sampling table, schemas, report template and wording
evals/ fixtures, oracle, graders, agent runner, Probo mock
python evals/make_fixture.py # synthetic Type 1 and Type 2 engagements
python evals/run.py --case type2 --agent oracle # model-free regression test of the scripts
python evals/run.py --case type2 --agent 'claude -p --permission-mode bypassPermissions {prompt}'
python evals/test_probo_connector.py # Probo connector against a local mock
See evals/README.md.
This tool produces an AI Audit. It is not an official SOC 2 audit, not an AICPA attestation, and not a report a CPA firm can issue. The model that ran the work signs the PDF, and the report says so. The Trust Services Criteria in assets/criteria.yaml are paraphrased.
Python
97.2%
Typst
2.8%