Audit Report
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
Security leadership for growth-stage companies. An agent skill from borghei/Claude-Skills.
$ npx skills add borghei/Claude-Skills --skill ciso-advisor -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install borghei/Claude-Skills ciso-advisor --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/c-level-advisor/ciso-advisor .claude/skills/ciso-advisor && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ciso-advisor" agent skill from https://github.com/borghei/Claude-Skills/tree/main/c-level-advisor/ciso-advisor into .claude/skills/ciso-advisor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ciso-advisor", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/borghei/Claude-Skills/tree/main/c-level-advisor/ciso-advisorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add borghei/Claude-Skills --skill ciso-advisor -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install borghei/Claude-Skills ciso-advisor --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/c-level-advisor/ciso-advisor .agents/skills/ciso-advisor && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ciso-advisor" agent skill from https://github.com/borghei/Claude-Skills/tree/main/c-level-advisor/ciso-advisor into .agents/skills/ciso-advisor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ciso-advisor", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add borghei/Claude-Skills --skill ciso-advisor -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install borghei/Claude-Skills ciso-advisor --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/c-level-advisor/ciso-advisor .cursor/skills/ciso-advisor && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ciso-advisor" agent skill from https://github.com/borghei/Claude-Skills/tree/main/c-level-advisor/ciso-advisor into .cursor/skills/ciso-advisor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ciso-advisor", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/borghei/Claude-Skills.git --path c-level-advisor/ciso-advisor--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add borghei/Claude-Skills --skill ciso-advisor -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install borghei/Claude-Skills ciso-advisor --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/c-level-advisor/ciso-advisor .gemini/skills/ciso-advisor && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ciso-advisor" agent skill from https://github.com/borghei/Claude-Skills/tree/main/c-level-advisor/ciso-advisor into .gemini/skills/ciso-advisor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ciso-advisor", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install borghei/Claude-Skills ciso-advisorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add borghei/Claude-Skills --skill ciso-advisor -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/c-level-advisor/ciso-advisor .github/skills/ciso-advisor && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ciso-advisor" agent skill from https://github.com/borghei/Claude-Skills/tree/main/c-level-advisor/ciso-advisor into .github/skills/ciso-advisor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ciso-advisor", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add borghei/Claude-Skills --skill ciso-advisor -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install borghei/Claude-Skills ciso-advisor --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/c-level-advisor/ciso-advisor .opencode/skills/ciso-advisor && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ciso-advisor" agent skill from https://github.com/borghei/Claude-Skills/tree/main/c-level-advisor/ciso-advisor into .opencode/skills/ciso-advisor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ciso-advisor", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ciso-advisorSecurity leadership for growth-stage companies. An agent skill from borghei/Claude-Skills.
Ciso Advisor is an agent skill from borghei/Claude-Skills. Security leadership for growth-stage companies. Use when building security programs, selecting compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR), managing incidents, or assessing vendor risk.
Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `scripts/compliance_tracker.py`, `scripts/risk_register_manager.py` and `scripts/security_posture_scorer.py`).
It sits in Legal & Compliance, covering SOC 2 and security compliance, Privacy and GDPR and Healthcare and finance regulation. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.
Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ciso Advisor loads about 5.3k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 1,887 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 1,887 words, ~5,321 tokens.
.claude/skills/ciso-advisor/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Risk-based security frameworks for growth-stage companies. Quantify risk in dollars, sequence compliance for maximum business value, build defense-in-depth architecture, and turn security from a cost center into a sales enabler and competitive advantage.
CISO, security strategy, risk quantification, ALE, SLE, ARO, security posture, compliance roadmap, SOC 2, ISO 27001, HIPAA, GDPR, zero trust, defense in depth, incident response, board security reporting, vendor assessment, security budget, cyber risk, program maturity, penetration testing, vulnerability management, data classification, threat modeling, security awareness, phishing, MFA, IAM
Every security investment must be justified in business terms. "We need better security" is not a business case. "$800K expected annual loss from this unmitigated risk" is.
ALE = SLE x ARO
ALE = Annual Loss Expectancy (expected cost per year)
SLE = Single Loss Expectancy (cost if the event occurs once)
ARO = Annual Rate of Occurrence (probability of occurrence per year)| Risk ID | Threat | Asset | SLE | ARO | ALE | Mitigation Cost | ROI | Priority |
|---|---|---|---|---|---|---|---|---|
| R-001 | Data breach (customer PII) | Customer database | $2.5M | 0.15 | $375K | $120K/yr | 3.1x | Critical |
| R-002 | Ransomware | Production systems | $1.8M | 0.10 | $180K | $80K/yr | 2.3x | High |
| R-003 | Insider threat | Source code | $500K | 0.05 | $25K | $40K/yr | 0.6x | Medium |
| R-004 | DDoS | Customer-facing app | $200K | 0.20 | $40K | $30K/yr | 1.3x | Medium |
| R-005 | Third-party breach | Vendor with PII access | $1.2M | 0.08 | $96K | $25K/yr | 3.8x | High |
START: New risk identified
|
v
[Calculate ALE]
|
+-- ALE > $200K/yr --> CRITICAL: Board-level reporting, immediate mitigation
|
+-- ALE $50K-$200K --> HIGH: Quarterly review, funded mitigation plan
|
+-- ALE $10K-$50K --> MEDIUM: Annual review, budget if ROI > 1.5x
|
+-- ALE < $10K --> LOW: Accept risk, document decision, monitor| Cost Component | Description | Typical Range |
|---|---|---|
| Direct costs | Forensics, remediation, legal | $100K-$500K |
| Regulatory fines | GDPR: up to 4% revenue; HIPAA: $100-$50K per record | Varies widely |
| Notification costs | $5-$50 per affected individual | Scale with records |
| Business interruption | Lost revenue during downtime | Hours x hourly revenue |
| Reputation damage | Customer churn, brand impact | 2-5% annual revenue |
| Legal liability | Lawsuits, settlements | $50K-$5M+ |
Phase 1: Foundation (Months 1-3)
Basic hygiene: MFA, endpoint protection, access controls, backups
Cost: $20-50K Impact: Blocks 80% of common attacks
Phase 2: SOC 2 Type I (Months 3-6)
Policies, procedures, controls documentation
Cost: $50-100K Impact: Unlocks mid-market enterprise sales
Phase 3: SOC 2 Type II (Months 6-12)
Sustained controls operation + audit
Cost: $80-150K Impact: Required by most enterprise buyers
Phase 4: Specialized (Months 12-18)
ISO 27001, HIPAA, or GDPR based on market requirements
Cost: $100-250K Impact: Market-specific requirement fulfillment| Framework | Timeline | Cost | Best For | Customer Requirement |
|---|---|---|---|---|
| SOC 2 Type I | 3-6 months | $50-100K | B2B SaaS selling to US companies | Most common ask |
| SOC 2 Type II | 6-12 months | $80-150K | Sustained enterprise sales | Required for large deals |
| ISO 27001 | 9-15 months | $100-200K | European market, global companies | EU enterprise standard |
| HIPAA | 6-12 months | $80-200K | Healthcare data handling | Healthcare vertical |
| GDPR | 3-6 months | $30-80K | Any company with EU users | Legal requirement |
| PCI DSS | 6-12 months | $100-300K | Payment card processing | Payment requirement |
| FedRAMP | 12-24 months | $500K-2M | US federal government sales | Government requirement |
| Control Area | SOC 2 | ISO 27001 | HIPAA | GDPR |
|---|---|---|---|---|
| Access control | Yes | Yes | Yes | Yes |
| Encryption | Yes | Yes | Yes | Yes |
| Incident response | Yes | Yes | Yes | Yes |
| Risk assessment | Yes | Yes | Yes | Yes |
| Vendor management | Yes | Yes | Yes | Yes |
| Data classification | Partial | Yes | Yes | Yes |
| Physical security | Yes | Yes | Yes | Partial |
| Business continuity | Yes | Yes | Partial | Partial |
| Privacy by design | No | Partial | Partial | Yes |
Key insight: SOC 2 + ISO 27001 share approximately 70% of controls. Do SOC 2 first, then extend to ISO 27001 with ~30% incremental effort.
| Level | Description | Key Controls | Timeline |
|---|---|---|---|
| 0: Ad-hoc | No formal security architecture | -- | Current state for most startups |
| 1: Identity | MFA everywhere, SSO, role-based access | IAM + MFA + SSO | Months 1-3 |
| 2: Network | Network segmentation, VPN/ZTNA | Micro-segmentation, ZTNA | Months 3-6 |
| 3: Data | Data classification, encryption at rest/transit, DLP | Encryption + classification | Months 6-12 |
| 4: Monitoring | SIEM, logging, anomaly detection | Centralized logging + alerting | Months 9-15 |
| 5: Automated | Automated response, continuous verification | SOAR + automated remediation | Months 12-24 |
START: New system or feature being designed
|
v
[Does it handle sensitive data?]
|
+-- YES --> [What classification level?]
| |
| +-- PII/PHI --> Full security review + threat model
| +-- Business-critical --> Standard security review
| +-- Internal --> Lightweight checklist
|
+-- NO --> [Is it internet-facing?]
|
+-- YES --> Standard security review + pen test
+-- NO --> Security checklist only| Layer | Controls | Investment Priority |
|---|---|---|
| Identity | MFA, SSO, RBAC, privileged access management | 1st (highest ROI) |
| Endpoint | EDR, device management, patching | 2nd |
| Network | Segmentation, ZTNA, firewall, IDS/IPS | 3rd |
| Application | SAST, DAST, dependency scanning, WAF | 4th |
| Data | Encryption, DLP, classification, backup | 5th |
| Monitoring | SIEM, logging, alerting, threat detection | 6th |
| Severity | Definition | Response Time | Notification |
|---|---|---|---|
| P0: Critical | Active breach, data exfiltration, ransomware | Immediate (< 15 min) | CEO + Legal + Board |
| P1: High | Vulnerability being exploited, service down | < 1 hour | CTO + CEO |
| P2: Medium | Vulnerability discovered, suspicious activity | < 4 hours | CTO + Security team |
| P3: Low | Policy violation, minor misconfiguration | < 24 hours | Security team only |
DETECT --> CONTAIN --> ERADICATE --> RECOVER --> LEARN
Phase 1: DETECT (Minutes)
- Identify the scope and nature of the incident
- Classify severity (P0-P3)
- Activate response team based on severity
Phase 2: CONTAIN (Hours)
- Isolate affected systems
- Preserve evidence (forensic images)
- Prevent lateral movement
- Communicate to stakeholders per severity matrix
Phase 3: ERADICATE (Hours-Days)
- Remove threat actor/malware
- Patch vulnerability that enabled the incident
- Verify eradication is complete
Phase 4: RECOVER (Days)
- Restore from clean backups
- Verify system integrity
- Monitor for re-compromise
- Return to normal operations
Phase 5: LEARN (Days-Weeks)
- Root cause analysis (blameless)
- Timeline reconstruction
- Control gap identification
- Remediation plan with owners and deadlines| Regulation | Notification Deadline | To Whom |
|---|---|---|
| GDPR | 72 hours | Supervisory authority + affected individuals |
| HIPAA | 60 days | HHS + affected individuals (+ media if > 500) |
| State breach laws (US) | 30-90 days (varies) | State AG + affected individuals |
| SEC (public companies) | 4 business days | SEC + public disclosure |
| PCI DSS | Immediately | Card brands + acquiring bank |
| Tier | Data Access | Assessment Level | Frequency |
|---|---|---|---|
| Tier 1: Critical | PII, PHI, financial data, source code | Full security assessment + pen test review | Annual |
| Tier 2: Important | Business data, internal communications | Security questionnaire + SOC 2 review | Annual |
| Tier 3: Standard | No sensitive data access | Self-attestation + privacy policy review | Biennial |
| Tier 4: Minimal | No data access, no system integration | Contract review only | At contract renewal |
| Domain | Key Questions | Pass/Fail Criteria |
|---|---|---|
| Compliance | SOC 2 Type II or ISO 27001? | Must have at least one |
| Encryption | Data encrypted at rest and in transit? | AES-256 + TLS 1.2+ |
| Access | MFA enforced? RBAC implemented? | Both required |
| Incident response | Documented IR plan? Notification timeline? | Must have plan + 24hr notification |
| Business continuity | DR plan tested? RTO/RPO defined? | Must be tested within 12 months |
| Data handling | Data classification? Retention policy? | Must have both |
| Subprocessors | Who else handles our data? | Must disclose all |
| Metric | Target | Red Flag | Board Language |
|---|---|---|---|
| ALE coverage | > 80% | < 60% | "$X of $Y total risk is mitigated" |
| Mean time to detect (MTTD) | < 24 hours | > 72 hours | "We find threats within X hours" |
| Mean time to respond (MTTR) | < 4 hours | > 24 hours | "We contain threats within X hours" |
| Compliance status | All current | Any lapsed | "All certifications active" or "Gap in X" |
| Critical vulnerabilities open | 0 | Any > 30 days | "Zero unpatched critical vulnerabilities" |
| Metric | Target | Action Trigger |
|---|---|---|
| Phishing click rate | < 5% | > 10% = mandatory re-training |
| Critical patches within SLA | 100% | < 95% = process review |
| Privileged accounts reviewed | 100% quarterly | Any unreviewed = immediate review |
| Tier 1 vendors assessed | 100% annually | Any lapsed = assessment needed |
| Security training completion | > 95% | < 90% = escalate to managers |
| Company Stage | Security Budget (% of Revenue) | Security Budget (% of IT) |
|---|---|---|
| Seed/Series A | 2-4% | 8-12% |
| Series B | 3-5% | 10-15% |
| Series C+ | 4-8% | 12-18% |
| Enterprise | 5-10% | 15-20% |
| Category | % of Security Budget | Examples |
|---|---|---|
| People | 40-50% | Security team salaries, training |
| Tools | 25-35% | SIEM, EDR, IAM, vulnerability scanner |
| Compliance | 10-15% | Auditors, certifications, legal |
| Testing | 5-10% | Pen testing, red team, bug bounty |
| Incident response | 5% | Retainer, insurance, forensics |
For each security investment:
Investment ROI = (ALE_before - ALE_after) / Investment_cost
If ROI > 1.5x --> Strong business case, approve
If ROI 1.0-1.5x --> Moderate case, consider alternatives
If ROI < 1.0x --> Weak case, re-evaluate or accept the risk| When... | CISO Works With... | To... |
|---|---|---|
| Enterprise sales blocked | CRO (cro-advisor) | Complete security questionnaires, unblock deals |
| New product features | CTO + CPO (cto-advisor, cpo-advisor) | Threat modeling, security review |
| Compliance budget | CFO (cfo-advisor) | Size program against quantified risk exposure |
| Vendor contracts | COO (coo-advisor) | Security SLAs, right-to-audit clauses |
| M&A due diligence | CEO + CFO | Target security posture assessment |
| Incident occurs | CEO + Legal | Response coordination, regulatory notification |
| Board reporting | CEO (ceo-advisor) | Translate risk into business language |
| Hiring security team | CHRO (chro-advisor) | Compensation, leveling, recruiting |
| Request | Deliverable |
|---|---|
| "Assess our security posture" | Risk register with quantified ALE, prioritized by business impact |
| "We need SOC 2" | Compliance roadmap: timeline, cost, effort, quick wins, vendor selection |
| "Prep for security audit" | Gap analysis against target framework + remediation plan with owners |
| "We had an incident" | IR coordination plan + communication templates + regulatory timeline |
| "Security board section" | Risk posture summary, compliance status, incident report, budget ask |
| "Evaluate vendor security" | Vendor tier assessment with risk scoring and contract recommendations |
| "Justify security budget" | Risk-based budget proposal with ROI for each investment |
Scores security posture across NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) and CISA Zero Trust Maturity Model pillars (Identity, Devices, Networks, Applications, Data). Produces board-ready security health reports.
# Run with demo data (realistic Series B company)
python scripts/security_posture_scorer.py
# From JSON with control assessments (0-4 maturity per control)
python scripts/security_posture_scorer.py --input controls.json
# JSON output
python scripts/security_posture_scorer.py --jsonManages cyber risk register with ALE (SLE x ARO) calculations, mitigation ROI, and board-ready risk reports.
# Run with demo risk register
python scripts/risk_register_manager.py
# From JSON risk register
python scripts/risk_register_manager.py --input risks.json
# Sort by ROI (best investments first)
python scripts/risk_register_manager.py --sort-by roi
# JSON output
python scripts/risk_register_manager.py --jsonTracks progress across SOC 2 Type I/II, ISO 27001, HIPAA, and GDPR. Calculates gap analysis, framework overlaps, and effort estimates.
# Track SOC 2 readiness (default)
python scripts/compliance_tracker.py
# Track multiple frameworks
python scripts/compliance_tracker.py --frameworks soc2_type1 iso27001 gdpr
# List available frameworks
python scripts/compliance_tracker.py --list-frameworks
# From JSON
python scripts/compliance_tracker.py --input compliance.json
# JSON output
python scripts/compliance_tracker.py --json| Problem | Likely Cause | Fix |
|---|---|---|
| Security budget justified by "industry benchmarks" not risk data | No risk quantification framework in place | Implement ALE-based risk register; justify every dollar against quantified risk reduction |
| Pursuing SOC 2 before basic hygiene (MFA, backups) | Checkbox compliance without substance | Phase 1 foundation first: MFA, endpoint protection, backups; then pursue certifications |
| Pen test findings unresolved after 90 days | Testing without fixing is theater | Set SLA: critical 7 days, high 30 days, medium 90 days; track in risk register |
| Security team reports to IT, not executive level | Misaligned incentives and budget competition | CISO should report to CEO or COO; separate budget from IT |
| Enterprise deals blocked by security questionnaires | No SOC 2 or questionnaire response backlog > 30 days | Prioritize SOC 2 Type I; create questionnaire response library; assign dedicated owner |
| Zero Trust initiative stalled at identity layer | Trying to implement all pillars simultaneously | Follow maturity model: Identity first (months 1-3), then Network, then Data |
In Scope: Risk quantification (ALE/SLE/ARO), compliance roadmapping, Zero Trust maturity assessment, NIST CSF 2.0 scoring, incident response protocol, vendor security assessment, security budget justification, board-level security reporting.
Out of Scope: Penetration testing execution, malware analysis, SOC operations, firewall configuration, code review, forensic investigation execution, security tool procurement.
Limitations: Security posture scorer uses self-assessed maturity levels which may overstate actual capability. Risk register ALE calculations are estimates based on industry data -- actual losses vary significantly. Compliance tracker measures control implementation, not control effectiveness. Zero Trust scoring uses binary (implemented/not) which oversimplifies partial implementations.
| Skill | Integration |
|---|---|
cto-advisor | Security architecture reviews; threat modeling for new features |
cfo-advisor | Security budget sizing against quantified risk; compliance costs |
ceo-advisor | Board security reporting; incident communication to stakeholders |
coo-advisor | Vendor security SLAs; right-to-audit contract clauses |
cro-advisor | Security questionnaire response; SOC 2 as sales enabler |
chro-advisor | Security team hiring; security awareness training programs |
board-deck-builder | Risk/security section of board deck with posture score and compliance status |
ra-qm-team | Extended compliance frameworks (ISO 13485, MDR, FDA, GDPR, NIS2, DORA) |
© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts) in c-level-advisor/ciso-advisor of borghei/Claude-Skills.
Open the folder on GitHubat commit 4a698e8
Ciso Advisor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ciso Advisor this skillborghei/Claude-Skills | 881 | — | ~5.3k | Automated safety check: Pass | MIT | |
| Audit Reportharness/harness-skills | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Security Compliancesangrokjung/claude-forge | 850 | 2 repos | ~7.2k | Automated safety check: Pass | MIT | |
| Ciso Advisoralirezarezvani/claude-skills | 28k | 1 repos | ~1.8k | Automated safety check: Pass | MIT | |
| ComplianceRightNow-AI/openfang | 18k | — | ~921 | Automated safety check: Pass | Apache-2.0 | |
| Eks Securityaws-samples/appmod-blueprints | 113 | — | ~4.7k | Automated safety check: Pass | MIT-0 |
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
sangrokjung/claude-forge
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…
alirezarezvani/claude-skills
Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.
RightNow-AI/openfang
Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks
aws-samples/appmod-blueprints
A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…
AgentSecOps/SecOpsAgentKit
Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).
borghei/Claude-Skills
Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.
borghei/Claude-Skills
Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.
borghei/Claude-Skills
Idea to AI-generated prototype to customer validation to engineering handoff.
borghei/Claude-Skills
Analytics engineering across data modeling, dbt, transformation, and semantic layers.
borghei/Claude-Skills
Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.
borghei/Claude-Skills
OKR brainstorming and validation using the Radical Focus framework — outcome objectives, measurable key results, counter-metrics.
Categories
Security leadership for growth-stage companies. An agent skill from borghei/Claude-Skills. Ciso Advisor is an agent skill from borghei/Claude-Skills. Security leadership for growth-stage companies.
Ciso Advisor fits situations like: building security programs; selecting compliance frameworks (SOC 2; managing incidents; assessing vendor risk.
Run `npx skills add borghei/Claude-Skills --skill ciso-advisor -a claude-code`. Or copy the skill folder (c-level-advisor/ciso-advisor in borghei/Claude-Skills) into .claude/skills/ciso-advisor in your project. Claude Code loads it when a task matches its description.
Run `npx skills add borghei/Claude-Skills --skill ciso-advisor -a codex`. Or copy the skill folder (c-level-advisor/ciso-advisor in borghei/Claude-Skills) into .agents/skills/ciso-advisor in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill ciso-advisor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ciso-advisor, .gemini/skills/ciso-advisor, .github/skills/ciso-advisor and .opencode/skills/ciso-advisor in your project.
Going by SKILL.md and its folder, Ciso Advisor needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Ciso Advisor is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ciso Advisor: Audit Report (harness/harness-skills, 115 stars), Security Compliance (sangrokjung/claude-forge, 850 stars), Ciso Advisor (alirezarezvani/claude-skills, 28k stars) and Compliance (RightNow-AI/openfang, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 881 GitHub stars. The repository holds 349 skills in this directory. The repository was last updated on October 7, 2026.
Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.