Agent skill

Ciso Review

by alirezarezvani in alirezarezvani/claude-skills

/cs:ciso-review <plan — Risk-paranoid interrogation of any plan that touches data, compliance, or production access.

MITAuto-check passedLegal & Compliance

Install Ciso Review

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill ciso-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills ciso-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/c-level-agents/skills/ciso-review .claude/skills/ciso-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ciso-review
GitHub stars
28k
Token cost
~809 tokens
SKILL.md length
264 words
Files
1
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

/cs:ciso-review <plan — Risk-paranoid interrogation of any plan that touches data, compliance, or production access.

  • Works in 6 steps: Threat Model → Blast Radius → Detection → …
  • Launching features that handle customer data
  • SKILL.md covers When to Run, The Six CISO Questions, Workflow and Output Format, plus 2 more sections
  • Calls python

What it does

Ciso Review is an agent skill from alirezarezvani/claude-skills. /cs:ciso-review <plan — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit, or after any incident or near-miss.

Its SKILL.md is about 810 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering SOC 2 and security compliance. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • Launching features that handle customer data
  • Before a SOC 2 / ISO audit
  • After any incident

Example prompts

  • “/ciso-review”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Threat Model
  2. Blast Radius
  3. Detection
  4. Response
  5. Regulatory Window
  6. Vendor & Supply Chain

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ciso Review loads about 809 tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 264 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~809

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 264 words, ~809 tokens.

Download SKILL.mdSave it as .claude/skills/ciso-review/SKILL.md (or your agent's skills folder).
name
ciso-review
description
/cs:ciso-review <plan> — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit, or after any incident or near-miss.

/cs:ciso-review — CISO Forcing Questions

Command: /cs:ciso-review <plan>

The risk-paranoid threat-modeler. Six questions before any production change that touches customer data or compliance scope.

When to Run

  • Before deploying any system that touches PII / PHI / cardholder data
  • Before signing a new vendor with data access
  • Before a compliance audit (SOC 2, ISO 27001, HIPAA, GDPR)
  • Before any architecture decision crossing trust boundaries
  • After any near-miss incident

The Six CISO Questions

1. Threat Model

What's the STRIDE threat model for this system, and which threat is most likely?

  • Spoofing, Tampering, Repudiation, Info Disclosure, DoS, Elevation of Privilege.
  • Pick the top 3 by likelihood × impact.
2. Blast Radius

If this is fully compromised, what data is exposed and how many users are affected?

  • Worst case in plain English.
  • Quantify in dollars via FAIR-based ALE.
3. Detection

What signals indicate compromise, and how long until they're triggered (MTTD)?

  • Logs alone are not detection.
  • Define the detection rule, the alert, and the on-call.
4. Response

Is there an IR runbook for this scenario, and has it been tabletop-tested?

  • If no runbook: build one before ship.
  • If untested: tabletop before ship.
5. Regulatory Window

What's the regulator notification window if this scenario occurs?

  • GDPR: 72h. HIPAA: 60d. State breach laws vary.
  • Pre-write the customer comms template.
6. Vendor & Supply Chain

Which third-party vendors are in scope, and what's their security posture?

  • Subprocessor list current?
  • DPAs in place?
  • Last security review per vendor?

Workflow

bash
python ../../../c-level-advisor/skills/ciso-advisor/scripts/risk_quantifier.py
python ../../../c-level-advisor/skills/ciso-advisor/scripts/compliance_tracker.py

Output Format

markdown
# CISO Review: <plan>
**Date:** YYYY-MM-DD

## Threat Model
- Top threat: <STRIDE category> — <description>
- Likelihood: H/M/L | Impact: H/M/L
- ALE: $X / year

## Blast Radius
- Data exposed (worst case): <description>
- Users affected: N
- Estimated cost: $X

## Detection
- MTTD target: X hours
- Current MTTD: X hours
- Detection rule: <name>

## Response
- IR runbook: ✅ / ❌
- Last tabletop: <date>

## Regulatory
- Frameworks in scope: SOC 2 / ISO 27001 / HIPAA / GDPR
- Notification window: X hours/days

## Vendors
- New vendors added: N
- DPAs signed: N / N
- Security reviews complete: N / N

## Verdict
🟢 SHIP | 🟡 MITIGATE THEN SHIP | 🔴 BLOCK

Routing

  • /cs:cto-review — architecture alignment
  • /cs:gc-review — DPA, regulatory implications
  • /cs:decide — log risk acceptance
  • /cs:boardroom — for CRITICAL risks

Version: 1.0.0

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in c-level-agents/skills/ciso-review of alirezarezvani/claude-skills.

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Ciso Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ciso Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ciso Review this skillalirezarezvani/claude-skills28k—~809Automated safety check: PassMIT
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.3kAutomated safety check: PassMIT
Soc2Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.7kAutomated safety check: PassMIT
Grc Knowledgemlunato47/claude-grc-plugin184—~6.1kAutomated safety check: PassMIT
Information Security Manager Iso27001davila7/claude-code-templates33k1 repos~2.9kAutomated safety check: PassMIT
Audit Frameworkscartography-cncf/cartography4.1k—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    946 GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Information Security Manager Iso27001

    davila7/claude-code-templates

    Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies.

    33k GitHub starsUsed in 1 repo~2.9k tokens
    Legal & ComplianceAuto-check passed
  • Audit Frameworks

    cartography-cncf/cartography

    Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/.

    4.1k GitHub stars~2.8k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 6 days ago
    Legal & ComplianceAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Questions about Ciso Review

What does Ciso Review do?

/cs:ciso-review <plan — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Ciso Review is an agent skill from alirezarezvani/claude-skills. /cs:ciso-review <plan — Risk-paranoid interrogation of any plan that touches data, compliance, or production access.

When should I use Ciso Review?

Ciso Review fits situations like: launching features that handle customer data; before a SOC 2 / ISO audit; after any incident.

How do I install Ciso Review in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill ciso-review -a claude-code`. Or copy the skill folder (c-level-agents/skills/ciso-review in alirezarezvani/claude-skills) into .claude/skills/ciso-review in your project. Claude Code loads it when a task matches its description.

How do I install Ciso Review in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill ciso-review -a codex`. Or copy the skill folder (c-level-agents/skills/ciso-review in alirezarezvani/claude-skills) into .agents/skills/ciso-review in your project. Codex loads it when a task matches its description.

Can I use Ciso Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill ciso-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ciso-review, .gemini/skills/ciso-review, .github/skills/ciso-review and .opencode/skills/ciso-review in your project.

What does Ciso Review need to run?

Going by SKILL.md and its folder, Ciso Review needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Ciso Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ciso Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ciso Review use?

Ciso Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ciso Review use?

About 809 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ciso Review?

Skills that share tags, products or a category with Ciso Review: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Soc2 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Grc Knowledge (mlunato47/claude-grc-plugin, 184 stars) and Information Security Manager Iso27001 (davila7/claude-code-templates, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ciso Review?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,938 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.