heyGRC, compliance review for pull requests, from inside your coding agent.
One portable plugin, five agents. Install the setup skill and your agent walks the heyGRC GitHub App install and the frameworks-as-code configuration with you, step by step.
The plugin (better-isms/heygrc-plugin) teaches your coding agent the heyGRC flow: attach the GitHub App, claim the install, write the company profile and selected frameworks as code with one API call, and pick the review cadence.
Use the agent plugin when you want setup and configuration done in conversation, command by command. The review itself still runs server-side through the GitHub App; the plugin does not review code on your machine.
The review still runs in the GitHub App
The plugin is a setup skill, not a second reviewer. It ships as one portable repo that works across Claude Code, Codex CLI, GitHub Copilot CLI, Cursor, and Gemini CLI, plus any Agent Skills client via npx skills add. Your agent gives you the right install link for the tool it runs in.
It never blocks a merge and it does not review code locally. Public repos stay free; private repos use the same free monthly cap and a claim-only trial, exactly like a direct GitHub App install.
Control-relevant changes, named in the review.
A few of the control-relevant changes heyGRC is built to flag, each cited to the clause it touches.
An IAM role widens to a wildcard
SOC 2 CC6.1A privileged-action audit log is removed
ISO 27001:2022 A.8.15A new email or phone column lands with no retention plan
GDPR Art. 5(1)(e)
heyGRC flags control-relevant changes and cites the clause so the issue can be handled in the pull request. It does not certify you, run your audit, or replace your own judgment.