Source profileQuality 93/100

datadog-labs/agent-skills/dd-audit/compliance-report/SKILL.md

dd-audit-compliance-report

Generate auditor-ready compliance evidence from Datadog Audit Trail for SOC 2 and PCI DSS. Maps framework controls to specific query patterns and produces formatted output.

Source repository stars
158
Declared platforms
0
Static risk flags
0
Last source update
2026-08-21
Source checked
2026-08-25

Decision brief

What it does: where it fits

Generate auditor-ready evidence from Datadog Audit Trail for SOC 2 and PCI DSS control requirements.

Best for

    Not for

    • Tasks that require unconfirmed production actions or broad system permissions.
    • Environments where the pinned source and install steps cannot be inspected.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/datadog-labs/agent-skills --skill "dd-audit/compliance-report"
    Safe inspection promptEditorial

    Inspect the Agent Skill "dd-audit-compliance-report" from https://github.com/datadog-labs/agent-skills/blob/47d0cf5096fed4e7191e1f8eb2b2dc69cc135f10/dd-audit/compliance-report/SKILL.md at commit 47d0cf5096fed4e7191e1f8eb2b2dc69cc135f10. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      Workflow

      1. Confirm: framework (SOC 2 / PCI DSS), time window, org scope 2. Run retention check 3. Run each relevant control query 4. Format output using the Evidence Report template

      Confirm: framework (SOC 2 / PCI DSS), time window, org scopeRun retention checkRun each relevant control query
    2. 02

      Prerequisites

      bash pup auth login OAuth2 (recommended)

      bash pup auth login OAuth2 (recommended)
    3. 03

      or set DDAPIKEY + DDAPPKEY with auditlogsread scope

      bash pup audit-logs search --query "@evt.name:\"Audit Trail\" @action:modified" --from 90d -o json \ | jq '[.data[] | { timestamp: .attributes.timestamp, user: .attributes.attributes.usr.email, action: .attributes.attributes.action, resource: .attributes.attributes.asset.type }]…

      bash pup audit-logs search --query "@evt.name:\"Audit Trail\" @action:modified" --from 90d -o json \ | jq '[.data[] | { timestamp: .attributes.timestamp, user: .attributes.attributes.usr.email, action: .attributes.attri…
    4. 04

      Read First

      See references/control-mapping.md for the full control → query mapping table and retention requirements by framework.

      See references/control-mapping.md for the full control → query mapping table and retention requirements by framework.
    5. 05

      Retention Check (Run First)

      PCI requires 12 months. Datadog default retention is 90 days. Check whether archive is configured:

      PCI requires 12 months. Datadog default retention is 90 days. Check whether archive is configured:If the requested time window exceeds 90 days and no archive is confirmed, surface this gap in the report header.

    Permission review

    Static risk signals and limitations

    No configured static risk pattern was detected

    This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score93/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars158SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    datadog-labs/agent-skills
    Skill path
    dd-audit/compliance-report/SKILL.md
    Commit
    47d0cf5096fed4e7191e1f8eb2b2dc69cc135f10
    License
    MIT
    Collected
    2026-08-25
    Default branch
    main
    View the original SKILL.md

    Audit Trail: Compliance Evidence Report

    Generate auditor-ready evidence from Datadog Audit Trail for SOC 2 and PCI DSS control requirements.

    Prerequisites

    pup auth login   # OAuth2 (recommended)
    # or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope
    

    Read First

    See references/control-mapping.md for the full control → query mapping table and retention requirements by framework.

    Retention Check (Run First)

    PCI requires 12 months. Datadog default retention is 90 days. Check whether archive is configured:

    pup audit-logs search --query "@evt.name:\"Audit Trail\" @action:modified" --from 90d -o json \
      | jq '[.data[] | {
          timestamp: .attributes.timestamp,
          user: .attributes.attributes.usr.email,
          action: .attributes.attributes.action,
          resource: .attributes.attributes.asset.type
        }]'
    

    If the requested time window exceeds 90 days and no archive is confirmed, surface this gap in the report header.

    Workflow

    1. Confirm: framework (SOC 2 / PCI DSS), time window, org scope
    2. Run retention check
    3. Run each relevant control query
    4. Format output using the Evidence Report template

    SOC 2 Queries

    CC6.2 — User Provisioning / Deprovisioning

    pup audit-logs search \
      --query "@evt.name:\"Access Management\" @asset.type:user @action:(created OR deleted OR modified)" \
      --from PERIOD_START --to PERIOD_END --limit 500 -o json \
      | jq '[.data[] | {
          timestamp: .attributes.timestamp,
          actor: .attributes.attributes.usr.email,
          action: .attributes.attributes.action,
          affected_user: .attributes.attributes.asset.id
        }]'
    

    CC6.3 — Role and Permission Changes

    pup audit-logs search \
      --query "@evt.name:\"Access Management\" @asset.type:role" \
      --from PERIOD_START --to PERIOD_END --limit 500 -o json \
      | jq '[.data[] | {
          timestamp: .attributes.timestamp,
          actor: .attributes.attributes.usr.email,
          action: .attributes.attributes.action,
          role_id: .attributes.attributes.asset.id
        }]'
    

    CC6.6 — Failed Logins and Suspicious Access

    pup audit-logs search \
      --query "@evt.name:Authentication @action:login @status:error" \
      --from PERIOD_START --to PERIOD_END --limit 500 -o json \
      | jq '[.data[] | {
          timestamp: .attributes.timestamp,
          user: .attributes.attributes.usr.email,
          ip: .attributes.attributes.network.client.ip,
          country: .attributes.attributes.network.client.geoip.country.name
        }]'
    

    CC7.2 — Privileged / Support User Actions

    pup audit-logs search \
      --query "@evt.actor.type:SUPPORT_USER" \
      --from PERIOD_START --to PERIOD_END --limit 500 -o json \
      | jq '[.data[] | {
          timestamp: .attributes.timestamp,
          support_actor: .attributes.attributes.usr.email,
          action: .attributes.attributes.action,
          resource_type: .attributes.attributes.asset.type,
          resource_id: .attributes.attributes.asset.id
        }]'
    

    PCI DSS Queries

    PCI 10.2.2 — Actions by Privileged Users

    Same as CC7.2 above. Also include org-level admin actions:

    pup audit-logs search \
      --query "@evt.name:\"Organization Management\"" \
      --from PERIOD_START --to PERIOD_END --limit 200 -o json \
      | jq '[.data[] | {
          timestamp: .attributes.timestamp,
          actor: .attributes.attributes.usr.email,
          action: .attributes.attributes.action,
          resource_type: .attributes.attributes.asset.type
        }]'
    

    PCI 10.2.3 — Access to Audit Trail Itself

    pup audit-logs search \
      --query "@evt.name:\"Audit Trail\"" \
      --from PERIOD_START --to PERIOD_END --limit 200 -o json \
      | jq '[.data[] | {
          timestamp: .attributes.timestamp,
          actor: .attributes.attributes.usr.email,
          action: .attributes.attributes.action,
          resource_type: .attributes.attributes.asset.type
        }]'
    

    PCI 10.2.4 — Invalid Access Attempts

    Same as CC6.6 failed logins above.

    PCI 10.2.5 — All Authentication Events

    pup audit-logs search \
      --query "@evt.name:Authentication @action:login" \
      --from PERIOD_START --to PERIOD_END --limit 1000 -o json \
      | jq '[.data[] | {
          timestamp: .attributes.timestamp,
          user: .attributes.attributes.usr.email,
          auth_method: .attributes.attributes.auth_method,
          result: .attributes.attributes.status,
          ip: .attributes.attributes.network.client.ip,
          country: .attributes.attributes.network.client.geoip.country.name
        }]'
    

    PCI 10.2.7 — Object Creation and Deletion

    pup audit-logs search \
      --query "@action:(created OR deleted)" \
      --from PERIOD_START --to PERIOD_END --limit 1000 -o json \
      | jq '[.data[] | {
          timestamp: .attributes.timestamp,
          user: .attributes.attributes.usr.email,
          action: .attributes.attributes.action,
          resource_type: .attributes.attributes.asset.type,
          resource_id: .attributes.attributes.asset.id,
          ip: .attributes.attributes.network.client.ip
        }]'
    

    Evidence Report Template

    # Datadog Audit Trail — Compliance Evidence Report
    Framework: [SOC 2 / PCI DSS]
    Organization: [org name]
    Period: [start] to [end]
    Generated: [date]
    
    ## Scope Boundary
    This report covers administrative actions within the Datadog platform.
    It does not cover actions taken within systems that Datadog monitors.
    
    ## Retention Status
    [✓ Full period covered by Audit Trail retention]
    [⚠ Requested period exceeds 90-day default. Archive config required for complete coverage.]
    
    ---
    
    ## [Control ID] — [Control Name]
    Events found: [N]
    
    | Timestamp | Actor | Action | Resource Type | Resource ID | IP | Country |
    |-----------|-------|--------|---------------|-------------|-----|---------|
    | ...       | ...   | ...    | ...           | ...         | ... | ...     |
    
    [Repeat per control]
    
    ---
    
    ## Gaps
    [List any controls where data was unavailable or incomplete, and why]
    

    Scope Caveat

    Datadog Audit Trail covers the Datadog platform as the system being audited. For PCI purposes, this is evidence that the monitoring platform's access controls are functioning — not direct evidence about the cardholder data environment (CDE) itself. Auditors should understand this scope boundary.

    References

    Frequently asked questions

    What to verify before installation and use

    What does the dd-audit-compliance-report source document cover?

    Generate auditor-ready evidence from Datadog Audit Trail for SOC 2 and PCI DSS control requirements.

    How do I install dd-audit-compliance-report?

    The source record exposes this install command: npx skills add https://github.com/datadog-labs/agent-skills --skill "dd-audit/compliance-report". Inspect the command and pinned source before running it.

    Alternatives

    Compare before choosing

    Computed 10024,921

    alirezarezvani/claude-skills

    app-store-optimization

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist

    Computed 10015,122

    wanshuiyin/Auto-claude-code-research-in-sleep

    citation-audit

    Use it for operations and research tasks; the detail page covers purpose, installation, and practical steps.

    Computed 10014,671

    prowler-cloud/prowler

    postgresql-indexing

    PostgreSQL indexing best practices for Prowler: index design, partial indexes, partitioned table indexing, EXPLAIN ANALYZE validation, concurrent operations, monitoring, and maintenance. Trigger: When creating or modifying PostgreSQL indexes, analyzing query performance with EXPLAIN, debugging slow queries, reviewing index usage statistics, reindexing, dropping indexes, or working with partitioned table indexes. Also trigger when discussing index strategies, partial indexes, or index maintenance

    Computed 9965

    brucesongs/kali-claw

    insecure-design

    Insecure Design (OWASP A06:2025) focuses on security flaws in system architecture and design phases, rather than code implementation-level bugs.