{"id":25066,"plugin_id":"plugins_6a886769f0fc8191a0d42669abca1f98","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:19:09.740Z","digest":"7e48d2d3ac9e30c705d2a1060fd120798b71ad6bdf3b681472821deb3ba06967","against":null,"payload":{"description":"Set up and run heyGRC compliance review on a repository's pull requests. Use when the user wants GRC or security compliance review of their code changes against ISO 27001, SOC 2, GDPR, DORA, NIS 2, or the EU AI Act, including installing the heyGRC GitHub App, configuring the company profile and frameworks as code, and choosing how often reviews run.","included_files":[],"name":"heyGRC Compliance Review","skill_md_contents":"---\nname: heyGRC Compliance Review\ndescription: >\n  Set up and run heyGRC compliance review on a repository's pull requests.\n  Use when the user wants GRC or security compliance review of their code\n  changes against ISO 27001, SOC 2, GDPR, DORA, NIS 2, or the EU AI Act,\n  including installing the heyGRC GitHub App, configuring the company\n  profile and frameworks as code, and choosing how often reviews run.\n---\n\n# heyGRC compliance review\n\nheyGRC reviews every pull request for governance, risk, and compliance, grounded in your company\nprofile and the frameworks you must comply with (ISO 27001, SOC 2, GDPR, the EU AI Act, DORA, NIS 2,\nand more). Think of it as a code reviewer, but for compliance obligations instead of bugs.\n\nOn each review it posts three things:\n\n- **Inline findings** on the exact lines that touch an obligation, each with a control reference and\n  a short reason, as resolvable review threads.\n- **A neutral check run.** heyGRC never fails a check or blocks a merge; it informs, it does not gate.\n- **One sticky summary comment per PR**, updated in place instead of piling up new comments.\n\nPublic repositories are always free. Private repos are free up to 25 reviews per month; claiming your\ninstall starts a 14-day unlimited-private trial, after which on-demand private reviews are billed\n$0.49 each.\n\n## Important: heyGRC runs as a GitHub App, not from this machine\n\nThis plugin does not review code locally. The review runs server-side once the heyGRC GitHub App is\ninstalled on the repository. Your job (and this skill's job) is to get it installed and configured.\nThe one-click install is an account-owner action that no agent or API can do for the user, so hand\nthem the install link and let them click it.\n\nFull step-by-step instructions live in [SETUP.md](../../SETUP.md).\n\n## Setup flow\n\n**1. Install the GitHub App (the user clicks this once).**\nSend them to:\n\n```\nhttps://github.com/apps/heygrc/installations/new?via=claude-plugin\n```\n\nChoose the org or account, select the specific repositories, and Install. heyGRC asks only for\nread-only Contents and metadata, plus read + write on Checks and Pull requests. A bare install already\nreviews PRs with default frameworks under the Free-plan limits, before any account exists.\n\n**2. Get a review.**\nOpen a pull request, or comment `/heygrc` on an existing one (the commenter must be an Owner, Member,\nor Collaborator on the repo). heyGRC posts its findings, check run, and sticky summary.\n\n**3. Claim and configure (optional, sharpens every review).**\nHave the user sign in at https://app.heygrc.com to claim the install (starts the trial) and create an\nAPI key under Settings → API keys. The key is a `hgrc_…` token shown once; store it as\n`HEYGRC_API_KEY` and send it only in the `Authorization` header.\n\nThen configure the company context and frameworks as code with a single call. The `profile` is\nfree-form JSON: the more relevant it is (what they build, the data they handle, hosting, obligations),\nthe sharper the reviews.\n\n```bash\ncurl -X PUT https://api.heygrc.com/v1/config \\\n  -H \"Authorization: Bearer $HEYGRC_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"profile\": {\n      \"company\": \"Acme Inc\",\n      \"product\": \"B2B SaaS for invoice automation\",\n      \"data_handled\": \"customer PII, payment metadata, uploaded documents\",\n      \"hosting\": \"EU, AWS eu-central-1\",\n      \"compliance_posture\": \"pursuing SOC 2 and ISO 27001; ships an AI feature\"\n    },\n    \"frameworks\": [\"ISO_27001\", \"SOC_2\", \"GDPR\", \"EU_AI_ACT\"]\n  }'\n```\n\nA `200 {\"ok\": true, …}` means it is configured. Read it back any time with\n`GET https://api.heygrc.com/v1/config`.\n\n**4. Choose the review cadence** (default is `auto`). Set it in the console, per org or per repo:\n\n| Mode | Behavior |\n|------|----------|\n| `auto` | Reviews every PR when it is opened, reopened, or pushed to. |\n| `auto_once` | Reviews on open / reopen only, not on every new commit. |\n| `mention_only` | Stays silent until someone comments `/heygrc` on a PR. |\n\n## Reference\n\n- Setup guide: https://docs.heygrc.com/docs/setup-with-an-agent\n- GitHub App permissions: https://docs.heygrc.com/docs/github-app-permissions\n- Pricing and plans: https://docs.heygrc.com/docs/pricing-and-plans\n- API reference and framework catalog: https://docs.heygrc.com/docs/api-reference\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}