SQ
Security Questionnaire Autofill
🔵 Stable
🔷 SkillSpec L3
pm-compliance
Draft answers to a vendor security questionnaire (SIG, CAIQ, or a custom sheet) from your real controls — fast, consistent, and honest about gaps. Use when asked to fill out a security questionnaire, answer a SIG/CAIQ, respond to a customer's security review, or complete a vendor risk assessment. Produces drafted answers grounded in your stated controls, a gap list of questions you can't truthfully answer yet, and reusable answer snippets for next time — never fabricated compliance.
🗣 Say this to your agent
“Fill out this security questionnaire from our controls.”“Answer this SIG/CAIQ for a customer security review.”“Respond to the vendor risk assessment — flag anything we can't truthfully claim.”“Draft answers to this security review and list our gaps.”
What to give it
▸The questionnaire — the questions (SIG, CAIQ, or custom), pasted or attached
▸Your controls — your security posture: policies, certifications (SOC 2, ISO 27001), encryption, access control, MFA, backups, incident process — whatever's real
▸Your posture doc / prior answers — if you have a security whitepaper or past questionnaire, feed it for consistency
▸Honesty stance — confirm: flag gaps rather than best-case them (default: yes)
✅ The bar it holds itself to
Every skill in this library self-verifies — these are this skill's own quality checks, straight from its definition.
✓Every "yes" traces to a real, named control — none inferred or invented
✓Gaps are flagged explicitly, not softened into misleading answers
✓Repeated questions get consistent answers
✓Scope is honest where a control is partial
✓Anything requiring a business/legal decision is escalated, not guessed
⚠️ What it refuses to do
**Fabricating a "yes"** to speed the deal — the single thing this skill must never do.
**Inconsistent answers** to the same control across the sheet — reviewers notice.
**Vague answers with no evidence** — "we take security seriously" fails a review.
**Hiding a partial scope** behind a blanket claim.
Install
npx pm-claude-skills add --agent claude # or codex · cursor · gemini · hermes
# or one-line MCP (every skill, any client):
claude mcp add pm-skills -- npx -y pm-claude-skills-mcp
Related skills
🔌 Embed this skill
Drop this on your blog, docs, or site — it renders a "Run this skill" card:
<div data-pm-skill="security-questionnaire-autofill"></div>
<script src="https://mohitagw15856.github.io/pm-claude-skills/embed.js" async></script>
💬 Discussion
Security Questionnaire Autofill is one of 832 open-source professional AI agent skills — all SkillSpec L3.
Try them all in the browser · ⭐ Star on GitHub · Browse the full catalog