Agent skill

Ciso Advisor

by borghei in borghei/Claude-Skills

Security leadership for growth-stage companies. An agent skill from borghei/Claude-Skills.

MITAuto-check passedLegal & Compliance

Install Ciso Advisor

skills CLI
$ npx skills add borghei/Claude-Skills --skill ciso-advisor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills ciso-advisor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/c-level-advisor/ciso-advisor .claude/skills/ciso-advisor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ciso-advisor
GitHub stars
881
Token cost
~5.3k tokens
SKILL.md length
1,887 words
Files
4 (incl. scripts)
Skills in repo
349
Repo updated
First seen
Licence
MIT

At a glance

Security leadership for growth-stage companies. An agent skill from borghei/Claude-Skills.

  • Building security programs
  • SKILL.md covers Keywords, Risk Quantification Framework, Compliance Roadmap and Security Architecture Strategy, plus 5 more sections
  • Runs Python scripts from its folder; calls python
  • Selecting compliance frameworks (SOC 2

What it does

Ciso Advisor is an agent skill from borghei/Claude-Skills. Security leadership for growth-stage companies. Use when building security programs, selecting compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR), managing incidents, or assessing vendor risk.

Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `scripts/compliance_tracker.py`, `scripts/risk_register_manager.py` and `scripts/security_posture_scorer.py`).

It sits in Legal & Compliance, covering SOC 2 and security compliance, Privacy and GDPR and Healthcare and finance regulation. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Building security programs
  • Selecting compliance frameworks (SOC 2
  • Managing incidents
  • Assessing vendor risk

Example prompts

  • “/ciso-advisor”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ciso Advisor loads about 5.3k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 1,887 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 1,887 words, ~5,321 tokens.

Download SKILL.mdSave it as .claude/skills/ciso-advisor/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
ciso-advisor
description
Security leadership for growth-stage companies. Use when building security programs, selecting compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR), managing incidents, or assessing vendor risk.
license
MIT + Commons Clause
metadata.version
2.0.0
metadata.author
borghei
metadata.category
c-level
metadata.domain
ciso-leadership
metadata.updated
2026-03-09
metadata.frameworks
risk-based-security, zero-trust-architecture, defense-in-depth, compliance-sequencing, incident-response-leadership, vendor-risk-management
metadata.triggers
CISO, security strategy, risk quantification, compliance roadmap, SOC 2, ISO 27001, HIPAA, GDPR, zero trust, incident response, board security reporting…

CISO Advisor

Risk-based security frameworks for growth-stage companies. Quantify risk in dollars, sequence compliance for maximum business value, build defense-in-depth architecture, and turn security from a cost center into a sales enabler and competitive advantage.

Keywords

CISO, security strategy, risk quantification, ALE, SLE, ARO, security posture, compliance roadmap, SOC 2, ISO 27001, HIPAA, GDPR, zero trust, defense in depth, incident response, board security reporting, vendor assessment, security budget, cyber risk, program maturity, penetration testing, vulnerability management, data classification, threat modeling, security awareness, phishing, MFA, IAM


Risk Quantification Framework

Every security investment must be justified in business terms. "We need better security" is not a business case. "$800K expected annual loss from this unmitigated risk" is.

Core Formula
ALE = SLE x ARO

ALE  = Annual Loss Expectancy (expected cost per year)
SLE  = Single Loss Expectancy (cost if the event occurs once)
ARO  = Annual Rate of Occurrence (probability of occurrence per year)
Risk Register Template
Risk IDThreatAssetSLEAROALEMitigation CostROIPriority
R-001Data breach (customer PII)Customer database$2.5M0.15$375K$120K/yr3.1xCritical
R-002RansomwareProduction systems$1.8M0.10$180K$80K/yr2.3xHigh
R-003Insider threatSource code$500K0.05$25K$40K/yr0.6xMedium
R-004DDoSCustomer-facing app$200K0.20$40K$30K/yr1.3xMedium
R-005Third-party breachVendor with PII access$1.2M0.08$96K$25K/yr3.8xHigh
Risk Prioritization Decision Tree
START: New risk identified
  |
  v
[Calculate ALE]
  |
  +-- ALE > $200K/yr --> CRITICAL: Board-level reporting, immediate mitigation
  |
  +-- ALE $50K-$200K --> HIGH: Quarterly review, funded mitigation plan
  |
  +-- ALE $10K-$50K --> MEDIUM: Annual review, budget if ROI > 1.5x
  |
  +-- ALE < $10K --> LOW: Accept risk, document decision, monitor
SLE Component Breakdown
Cost ComponentDescriptionTypical Range
Direct costsForensics, remediation, legal$100K-$500K
Regulatory finesGDPR: up to 4% revenue; HIPAA: $100-$50K per recordVaries widely
Notification costs$5-$50 per affected individualScale with records
Business interruptionLost revenue during downtimeHours x hourly revenue
Reputation damageCustomer churn, brand impact2-5% annual revenue
Legal liabilityLawsuits, settlements$50K-$5M+

Compliance Roadmap

Sequencing for Maximum Business Value
Phase 1: Foundation (Months 1-3)
  Basic hygiene: MFA, endpoint protection, access controls, backups
  Cost: $20-50K   Impact: Blocks 80% of common attacks

Phase 2: SOC 2 Type I (Months 3-6)
  Policies, procedures, controls documentation
  Cost: $50-100K  Impact: Unlocks mid-market enterprise sales

Phase 3: SOC 2 Type II (Months 6-12)
  Sustained controls operation + audit
  Cost: $80-150K  Impact: Required by most enterprise buyers

Phase 4: Specialized (Months 12-18)
  ISO 27001, HIPAA, or GDPR based on market requirements
  Cost: $100-250K Impact: Market-specific requirement fulfillment
Compliance Framework Comparison
FrameworkTimelineCostBest ForCustomer Requirement
SOC 2 Type I3-6 months$50-100KB2B SaaS selling to US companiesMost common ask
SOC 2 Type II6-12 months$80-150KSustained enterprise salesRequired for large deals
ISO 270019-15 months$100-200KEuropean market, global companiesEU enterprise standard
HIPAA6-12 months$80-200KHealthcare data handlingHealthcare vertical
GDPR3-6 months$30-80KAny company with EU usersLegal requirement
PCI DSS6-12 months$100-300KPayment card processingPayment requirement
FedRAMP12-24 months$500K-2MUS federal government salesGovernment requirement
Framework Overlap Matrix
Control AreaSOC 2ISO 27001HIPAAGDPR
Access controlYesYesYesYes
EncryptionYesYesYesYes
Incident responseYesYesYesYes
Risk assessmentYesYesYesYes
Vendor managementYesYesYesYes
Data classificationPartialYesYesYes
Physical securityYesYesYesPartial
Business continuityYesYesPartialPartial
Privacy by designNoPartialPartialYes

Key insight: SOC 2 + ISO 27001 share approximately 70% of controls. Do SOC 2 first, then extend to ISO 27001 with ~30% incremental effort.


Security Architecture Strategy

Zero Trust Maturity Model
LevelDescriptionKey ControlsTimeline
0: Ad-hocNo formal security architecture--Current state for most startups
1: IdentityMFA everywhere, SSO, role-based accessIAM + MFA + SSOMonths 1-3
2: NetworkNetwork segmentation, VPN/ZTNAMicro-segmentation, ZTNAMonths 3-6
3: DataData classification, encryption at rest/transit, DLPEncryption + classificationMonths 6-12
4: MonitoringSIEM, logging, anomaly detectionCentralized logging + alertingMonths 9-15
5: AutomatedAutomated response, continuous verificationSOAR + automated remediationMonths 12-24
Security Architecture Decision Tree
START: New system or feature being designed
  |
  v
[Does it handle sensitive data?]
  |
  +-- YES --> [What classification level?]
  |            |
  |            +-- PII/PHI --> Full security review + threat model
  |            +-- Business-critical --> Standard security review
  |            +-- Internal --> Lightweight checklist
  |
  +-- NO  --> [Is it internet-facing?]
              |
              +-- YES --> Standard security review + pen test
              +-- NO  --> Security checklist only
Defense-in-Depth Layers
LayerControlsInvestment Priority
IdentityMFA, SSO, RBAC, privileged access management1st (highest ROI)
EndpointEDR, device management, patching2nd
NetworkSegmentation, ZTNA, firewall, IDS/IPS3rd
ApplicationSAST, DAST, dependency scanning, WAF4th
DataEncryption, DLP, classification, backup5th
MonitoringSIEM, logging, alerting, threat detection6th

Incident Response Protocol

Severity Classification
SeverityDefinitionResponse TimeNotification
P0: CriticalActive breach, data exfiltration, ransomwareImmediate (< 15 min)CEO + Legal + Board
P1: HighVulnerability being exploited, service down< 1 hourCTO + CEO
P2: MediumVulnerability discovered, suspicious activity< 4 hoursCTO + Security team
P3: LowPolicy violation, minor misconfiguration< 24 hoursSecurity team only
Incident Response Workflow
DETECT --> CONTAIN --> ERADICATE --> RECOVER --> LEARN

Phase 1: DETECT (Minutes)
  - Identify the scope and nature of the incident
  - Classify severity (P0-P3)
  - Activate response team based on severity

Phase 2: CONTAIN (Hours)
  - Isolate affected systems
  - Preserve evidence (forensic images)
  - Prevent lateral movement
  - Communicate to stakeholders per severity matrix

Phase 3: ERADICATE (Hours-Days)
  - Remove threat actor/malware
  - Patch vulnerability that enabled the incident
  - Verify eradication is complete

Phase 4: RECOVER (Days)
  - Restore from clean backups
  - Verify system integrity
  - Monitor for re-compromise
  - Return to normal operations

Phase 5: LEARN (Days-Weeks)
  - Root cause analysis (blameless)
  - Timeline reconstruction
  - Control gap identification
  - Remediation plan with owners and deadlines
Regulatory Notification Timelines
RegulationNotification DeadlineTo Whom
GDPR72 hoursSupervisory authority + affected individuals
HIPAA60 daysHHS + affected individuals (+ media if > 500)
State breach laws (US)30-90 days (varies)State AG + affected individuals
SEC (public companies)4 business daysSEC + public disclosure
PCI DSSImmediatelyCard brands + acquiring bank

Vendor Security Assessment

Vendor Tiering
TierData AccessAssessment LevelFrequency
Tier 1: CriticalPII, PHI, financial data, source codeFull security assessment + pen test reviewAnnual
Tier 2: ImportantBusiness data, internal communicationsSecurity questionnaire + SOC 2 reviewAnnual
Tier 3: StandardNo sensitive data accessSelf-attestation + privacy policy reviewBiennial
Tier 4: MinimalNo data access, no system integrationContract review onlyAt contract renewal
Vendor Assessment Checklist (Tier 1)
DomainKey QuestionsPass/Fail Criteria
ComplianceSOC 2 Type II or ISO 27001?Must have at least one
EncryptionData encrypted at rest and in transit?AES-256 + TLS 1.2+
AccessMFA enforced? RBAC implemented?Both required
Incident responseDocumented IR plan? Notification timeline?Must have plan + 24hr notification
Business continuityDR plan tested? RTO/RPO defined?Must be tested within 12 months
Data handlingData classification? Retention policy?Must have both
SubprocessorsWho else handles our data?Must disclose all

Security Metrics Dashboard

Board-Level Metrics (Quarterly)
MetricTargetRed FlagBoard Language
ALE coverage> 80%< 60%"$X of $Y total risk is mitigated"
Mean time to detect (MTTD)< 24 hours> 72 hours"We find threats within X hours"
Mean time to respond (MTTR)< 4 hours> 24 hours"We contain threats within X hours"
Compliance statusAll currentAny lapsed"All certifications active" or "Gap in X"
Critical vulnerabilities open0Any > 30 days"Zero unpatched critical vulnerabilities"
Operational Metrics (Monthly)
MetricTargetAction Trigger
Phishing click rate< 5%> 10% = mandatory re-training
Critical patches within SLA100%< 95% = process review
Privileged accounts reviewed100% quarterlyAny unreviewed = immediate review
Tier 1 vendors assessed100% annuallyAny lapsed = assessment needed
Security training completion> 95%< 90% = escalate to managers

Security Budget Framework

Budget as Percentage of Revenue/IT Spend
Company StageSecurity Budget (% of Revenue)Security Budget (% of IT)
Seed/Series A2-4%8-12%
Series B3-5%10-15%
Series C+4-8%12-18%
Enterprise5-10%15-20%
Budget Allocation by Category
Category% of Security BudgetExamples
People40-50%Security team salaries, training
Tools25-35%SIEM, EDR, IAM, vulnerability scanner
Compliance10-15%Auditors, certifications, legal
Testing5-10%Pen testing, red team, bug bounty
Incident response5%Retainer, insurance, forensics
Budget Justification Formula

For each security investment:

Investment ROI = (ALE_before - ALE_after) / Investment_cost

If ROI > 1.5x --> Strong business case, approve
If ROI 1.0-1.5x --> Moderate case, consider alternatives
If ROI < 1.0x --> Weak case, re-evaluate or accept the risk

Red Flags

  • Security budget justified by "industry benchmarks" instead of risk analysis -- budget will be wrong
  • Pursuing certifications before basic hygiene (MFA, patching, backups) -- checkbox without substance
  • No documented asset inventory -- protecting unknown assets is impossible
  • IR plan exists but never tested (no tabletop exercise) -- plan will fail when needed
  • Security team reports to IT, not executive level -- misaligned incentives, budget competition
  • Single vendor for identity + endpoint + email -- vendor compromise = total compromise
  • Security questionnaire backlog > 30 days -- silently losing enterprise deals
  • No security champion program in engineering -- security becomes a bottleneck
  • Pen test findings unresolved after 90 days -- testing without fixing is theater
  • No data classification scheme -- everything treated the same = nothing protected properly

Show full SKILL.md (734 more words)Show less

Integration with C-Suite

When...CISO Works With...To...
Enterprise sales blockedCRO (cro-advisor)Complete security questionnaires, unblock deals
New product featuresCTO + CPO (cto-advisor, cpo-advisor)Threat modeling, security review
Compliance budgetCFO (cfo-advisor)Size program against quantified risk exposure
Vendor contractsCOO (coo-advisor)Security SLAs, right-to-audit clauses
M&A due diligenceCEO + CFOTarget security posture assessment
Incident occursCEO + LegalResponse coordination, regulatory notification
Board reportingCEO (ceo-advisor)Translate risk into business language
Hiring security teamCHRO (chro-advisor)Compensation, leveling, recruiting

Proactive Triggers

  • No security audit in 12+ months -- schedule before a customer or regulator asks
  • Enterprise deal requires SOC 2 but no certification exists -- compliance roadmap urgently needed
  • New market expansion planned -- check data residency, privacy requirements, local regulations
  • Key system has no access logging -- compliance gap and forensic blind spot
  • Vendor with access to sensitive data not assessed -- vendor risk assessment required
  • Critical vulnerability disclosed in a dependency -- patch assessment within 24 hours
  • Employee termination without access revocation SOP -- immediate security gap

Output Artifacts

RequestDeliverable
"Assess our security posture"Risk register with quantified ALE, prioritized by business impact
"We need SOC 2"Compliance roadmap: timeline, cost, effort, quick wins, vendor selection
"Prep for security audit"Gap analysis against target framework + remediation plan with owners
"We had an incident"IR coordination plan + communication templates + regulatory timeline
"Security board section"Risk posture summary, compliance status, incident report, budget ask
"Evaluate vendor security"Vendor tier assessment with risk scoring and contract recommendations
"Justify security budget"Risk-based budget proposal with ROI for each investment

Tool Reference

security_posture_scorer.py

Scores security posture across NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) and CISA Zero Trust Maturity Model pillars (Identity, Devices, Networks, Applications, Data). Produces board-ready security health reports.

bash
# Run with demo data (realistic Series B company)
python scripts/security_posture_scorer.py

# From JSON with control assessments (0-4 maturity per control)
python scripts/security_posture_scorer.py --input controls.json

# JSON output
python scripts/security_posture_scorer.py --json
risk_register_manager.py

Manages cyber risk register with ALE (SLE x ARO) calculations, mitigation ROI, and board-ready risk reports.

bash
# Run with demo risk register
python scripts/risk_register_manager.py

# From JSON risk register
python scripts/risk_register_manager.py --input risks.json

# Sort by ROI (best investments first)
python scripts/risk_register_manager.py --sort-by roi

# JSON output
python scripts/risk_register_manager.py --json
compliance_tracker.py

Tracks progress across SOC 2 Type I/II, ISO 27001, HIPAA, and GDPR. Calculates gap analysis, framework overlaps, and effort estimates.

bash
# Track SOC 2 readiness (default)
python scripts/compliance_tracker.py

# Track multiple frameworks
python scripts/compliance_tracker.py --frameworks soc2_type1 iso27001 gdpr

# List available frameworks
python scripts/compliance_tracker.py --list-frameworks

# From JSON
python scripts/compliance_tracker.py --input compliance.json

# JSON output
python scripts/compliance_tracker.py --json

Troubleshooting

ProblemLikely CauseFix
Security budget justified by "industry benchmarks" not risk dataNo risk quantification framework in placeImplement ALE-based risk register; justify every dollar against quantified risk reduction
Pursuing SOC 2 before basic hygiene (MFA, backups)Checkbox compliance without substancePhase 1 foundation first: MFA, endpoint protection, backups; then pursue certifications
Pen test findings unresolved after 90 daysTesting without fixing is theaterSet SLA: critical 7 days, high 30 days, medium 90 days; track in risk register
Security team reports to IT, not executive levelMisaligned incentives and budget competitionCISO should report to CEO or COO; separate budget from IT
Enterprise deals blocked by security questionnairesNo SOC 2 or questionnaire response backlog > 30 daysPrioritize SOC 2 Type I; create questionnaire response library; assign dedicated owner
Zero Trust initiative stalled at identity layerTrying to implement all pillars simultaneouslyFollow maturity model: Identity first (months 1-3), then Network, then Data

Success Criteria

  • Security posture score above 70/100 on NIST CSF assessment (measured annually via security_posture_scorer.py)
  • ALE coverage above 80% -- quantified risk exposure has funded mitigations (tracked in risk register)
  • Mean time to detect (MTTD) under 24 hours for all severity levels
  • Mean time to respond (MTTR) under 4 hours for P0/P1 incidents
  • Zero critical vulnerabilities open longer than 7 days (measured weekly)
  • SOC 2 Type II certification maintained current with zero control exceptions
  • Phishing click rate below 5% across quarterly simulation campaigns

Scope & Limitations

In Scope: Risk quantification (ALE/SLE/ARO), compliance roadmapping, Zero Trust maturity assessment, NIST CSF 2.0 scoring, incident response protocol, vendor security assessment, security budget justification, board-level security reporting.

Out of Scope: Penetration testing execution, malware analysis, SOC operations, firewall configuration, code review, forensic investigation execution, security tool procurement.

Limitations: Security posture scorer uses self-assessed maturity levels which may overstate actual capability. Risk register ALE calculations are estimates based on industry data -- actual losses vary significantly. Compliance tracker measures control implementation, not control effectiveness. Zero Trust scoring uses binary (implemented/not) which oversimplifies partial implementations.


Integration Points

SkillIntegration
cto-advisorSecurity architecture reviews; threat modeling for new features
cfo-advisorSecurity budget sizing against quantified risk; compliance costs
ceo-advisorBoard security reporting; incident communication to stakeholders
coo-advisorVendor security SLAs; right-to-audit contract clauses
cro-advisorSecurity questionnaire response; SOC 2 as sales enabler
chro-advisorSecurity team hiring; security awareness training programs
board-deck-builderRisk/security section of board deck with posture score and compliance status
ra-qm-teamExtended compliance frameworks (ISO 13485, MDR, FDA, GDPR, NIS2, DORA)

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts) in c-level-advisor/ciso-advisor of borghei/Claude-Skills.

  • SKILL.md
  • scripts/compliance_tracker.py
  • scripts/risk_register_manager.py
  • scripts/security_posture_scorer.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Ciso Advisor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ciso Advisor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ciso Advisor this skillborghei/Claude-Skills881—~5.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Security Compliancesangrokjung/claude-forge8502 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT
ComplianceRightNow-AI/openfang18k—~921Automated safety check: PassApache-2.0
Eks Securityaws-samples/appmod-blueprints113—~4.7kAutomated safety check: PassMIT-0

Similar skills

  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    850 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Compliance

    RightNow-AI/openfang

    Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

    18k GitHub stars~921 tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    113 GitHub stars~4.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 349 skills in this repo
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    881 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    881 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    881 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Brainstorm Okrs

    borghei/Claude-Skills

    OKR brainstorming and validation using the Radical Focus framework — outcome objectives, measurable key results, counter-metrics.

    881 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed

Questions about Ciso Advisor

What does Ciso Advisor do?

Security leadership for growth-stage companies. An agent skill from borghei/Claude-Skills. Ciso Advisor is an agent skill from borghei/Claude-Skills. Security leadership for growth-stage companies.

When should I use Ciso Advisor?

Ciso Advisor fits situations like: building security programs; selecting compliance frameworks (SOC 2; managing incidents; assessing vendor risk.

How do I install Ciso Advisor in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill ciso-advisor -a claude-code`. Or copy the skill folder (c-level-advisor/ciso-advisor in borghei/Claude-Skills) into .claude/skills/ciso-advisor in your project. Claude Code loads it when a task matches its description.

How do I install Ciso Advisor in Codex?

Run `npx skills add borghei/Claude-Skills --skill ciso-advisor -a codex`. Or copy the skill folder (c-level-advisor/ciso-advisor in borghei/Claude-Skills) into .agents/skills/ciso-advisor in your project. Codex loads it when a task matches its description.

Can I use Ciso Advisor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill ciso-advisor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ciso-advisor, .gemini/skills/ciso-advisor, .github/skills/ciso-advisor and .opencode/skills/ciso-advisor in your project.

What does Ciso Advisor need to run?

Going by SKILL.md and its folder, Ciso Advisor needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Ciso Advisor access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ciso Advisor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ciso Advisor use?

Ciso Advisor is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ciso Advisor use?

About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ciso Advisor?

Skills that share tags, products or a category with Ciso Advisor: Audit Report (harness/harness-skills, 115 stars), Security Compliance (sangrokjung/claude-forge, 850 stars), Ciso Advisor (alirezarezvani/claude-skills, 28k stars) and Compliance (RightNow-AI/openfang, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ciso Advisor?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 881 GitHub stars. The repository holds 349 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.