Skip to content

Create dedicated CMMC skill / plugin #174

Description

@ethanolivertroy

Overview

Build a standalone CMMC skill for the Hermes agent to provide CMMC 2.0-specific guidance beyond the existing SCF crosswalk.

Background

Currently CMMC is only handled via the scf-reference skill as a framework crosswalk (cmmc level 1/2/3 aliases). There is no dedicated skill for:

  • CMMC 2.0 Level 2 practitioner assessment workflows
  • C3PAO artifact generation (assessment plans, assessment reports)
  • DFARS 7012 / 7021 compliance guidance
  • CMMC domain scoring and gap analysis
  • CMMC-specific evidence templates

Scope

  1. Define CMMC 2.0 Level 1, 2, and 3 control domains and requirements
  2. Build assessment artifact templates (CAP, SAR, POA&M) aligned with CMMC Assessment Guide
  3. Integrate with the SCF API for control mappings where overlap exists
  4. Provide CLI helpers or document generation for C3PAO / OSC assessors

Acceptance Criteria

  • skill_view('cmmc') loads a complete SKILL.md with CMMC 2.0 guidance
  • Supports cmmc level 2 queries with domain breakdowns (e.g., AC, AM, AU, CM, IA, IR, MA, MP, PS, PE, RE, RM, SA, SC, SI, SR)
  • Includes CMMC assessment plan and report templates
  • Links to official DoD / CMMC-AB sources

Linked Linear Issue

Linear: GRC-62 — https://linear.app/grc-engineering-club/issue/GRC-62/create-dedicated-cmmc-skill-plugin

Metadata

Metadata

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions