Skill Scanner
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
NIS2 Directive (EU 2022/2555) compliance for critical infrastructure entities, covering the 10 minimum security measures.
$ npx skills add borghei/Claude-Skills --skill nis2-directive-specialist -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install borghei/Claude-Skills nis2-directive-specialist --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/nis2-directive-specialist .claude/skills/nis2-directive-specialist && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nis2-directive-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/nis2-directive-specialist into .claude/skills/nis2-directive-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2-directive-specialist", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/nis2-directive-specialistType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add borghei/Claude-Skills --skill nis2-directive-specialist -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install borghei/Claude-Skills nis2-directive-specialist --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ra-qm-team/nis2-directive-specialist .agents/skills/nis2-directive-specialist && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nis2-directive-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/nis2-directive-specialist into .agents/skills/nis2-directive-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2-directive-specialist", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add borghei/Claude-Skills --skill nis2-directive-specialist -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install borghei/Claude-Skills nis2-directive-specialist --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ra-qm-team/nis2-directive-specialist .cursor/skills/nis2-directive-specialist && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nis2-directive-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/nis2-directive-specialist into .cursor/skills/nis2-directive-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2-directive-specialist", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/borghei/Claude-Skills.git --path ra-qm-team/nis2-directive-specialist--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add borghei/Claude-Skills --skill nis2-directive-specialist -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install borghei/Claude-Skills nis2-directive-specialist --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ra-qm-team/nis2-directive-specialist .gemini/skills/nis2-directive-specialist && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nis2-directive-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/nis2-directive-specialist into .gemini/skills/nis2-directive-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2-directive-specialist", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install borghei/Claude-Skills nis2-directive-specialistInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add borghei/Claude-Skills --skill nis2-directive-specialist -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/ra-qm-team/nis2-directive-specialist .github/skills/nis2-directive-specialist && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nis2-directive-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/nis2-directive-specialist into .github/skills/nis2-directive-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2-directive-specialist", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add borghei/Claude-Skills --skill nis2-directive-specialist -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install borghei/Claude-Skills nis2-directive-specialist --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ra-qm-team/nis2-directive-specialist .opencode/skills/nis2-directive-specialist && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nis2-directive-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/nis2-directive-specialist into .opencode/skills/nis2-directive-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nis2-directive-specialist", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nis2-directive-specialistNIS2 Directive (EU 2022/2555) compliance for critical infrastructure entities, covering the 10 minimum security measures.
Nis2 Directive Specialist is an agent skill from borghei/Claude-Skills. NIS2 Directive (EU 2022/2555) compliance for critical infrastructure entities, covering the 10 minimum security measures. Use for NIS2 compliance assessments, entity scope analysis, supply chain security, and incident reporting readiness.
Its SKILL.md is about 8.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/nis2-implementation-playbook.md`, `references/nis2-requirements-guide.md` and `scripts/nis2_compliance_checker.py`).
It sits in Security, covering Supply chain security. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nis2 Directive Specialist loads about 8.1k tokens when it runs, and up to ~20k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 3,263 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 3,263 words, ~8,060 tokens.
.claude/skills/nis2-directive-specialist/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Tools and guidance for EU Directive 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive).
The NIS2 Directive (EU 2022/2555) is the EU's updated framework for cybersecurity, replacing the original NIS Directive (EU 2016/1148). It entered into force on January 16, 2023, with Member States required to transpose it into national law by October 17, 2024.
Key objectives:
Legal basis: Article 114 TFEU (internal market harmonization)
Relationship to other frameworks:
| Framework | Relationship |
|---|---|
| ISO 27001 | NIS2 measures map closely to ISO 27001 controls |
| GDPR | NIS2 complements GDPR for security of processing |
| CER Directive | Critical Entities Resilience — physical security complement |
| DORA | Lex specialis for financial sector entities |
| Cyber Resilience Act | Product security requirements for hardware/software |
| Sector | Sub-sectors |
|---|---|
| Energy | Electricity (DSOs, TSOs, producers, storage), oil (pipelines, production, refineries, storage), gas (DSOs, TSOs, LNG, storage), hydrogen, district heating/cooling |
| Transport | Air (carriers, airports, traffic management), rail (infrastructure managers, operators), water (inland, maritime, port operators), road (traffic management, ITS operators) |
| Banking | Credit institutions as defined in Regulation (EU) No 575/2013 |
| Financial market infrastructure | Trading venues, central counterparties |
| Health | Healthcare providers, EU reference laboratories, entities manufacturing pharmaceutical products, entities manufacturing medical devices considered critical during public health emergencies |
| Drinking water | Suppliers and distributors of water intended for human consumption |
| Waste water | Entities collecting, disposing, or treating urban waste water, domestic waste water, or industrial waste water |
| Digital infrastructure | IXPs, DNS providers, TLD registries, cloud computing providers, data center operators, CDN providers, trust service providers, public electronic communications networks, publicly available electronic communications services |
| ICT service management (B2B) | Managed service providers, managed security service providers |
| Public administration | Central government entities, regional government entities at NUTS level 1 and 2 |
| Space | Operators of ground-based infrastructure supporting space-based services |
| Sector | Sub-sectors |
|---|---|
| Postal and courier services | Providers of postal services including courier services |
| Waste management | Entities carrying out waste management (excluding those for whom waste management is not their principal economic activity) |
| Chemicals | Entities manufacturing, producing, or distributing chemical substances and mixtures |
| Food | Food businesses engaged in wholesale distribution, industrial production, and processing |
| Manufacturing | Medical devices and in vitro diagnostics, computer/electronic/optical products, electrical equipment, machinery and equipment, motor vehicles/trailers, other transport equipment |
| Digital providers | Online marketplaces, online search engines, social networking services platforms |
| Research | Research organizations |
| Category | Employees | Annual Turnover | Annual Balance Sheet |
|---|---|---|---|
| Medium enterprise | 50–249 | €10M–€50M | €10M–€43M |
| Large enterprise | 250+ | €50M+ | €43M+ |
Automatic inclusion regardless of size:
Exclusions:
All essential and important entities must implement appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risks. These measures must be based on an all-hazards approach and cover at minimum:
Establish and maintain comprehensive risk analysis processes and information security policies covering all information systems.
Requirements:
Implement procedures for detecting, managing, and responding to cybersecurity incidents.
Requirements:
Ensure service continuity during and after cybersecurity incidents.
Requirements:
Address security risks in relationships with direct suppliers and service providers.
Requirements:
Integrate security throughout the system lifecycle.
Requirements:
Evaluate whether cybersecurity risk management measures are effective.
Requirements:
Ensure all personnel have adequate cybersecurity awareness and skills.
Requirements:
Protect data confidentiality and integrity through cryptographic controls.
Requirements:
Manage people, access, and assets securely.
Requirements:
Deploy strong authentication and secure communication channels.
Requirements:
NIS2 introduces a multi-stage incident reporting regime for significant incidents. An incident is considered significant if it causes or is capable of causing:
| Stage | Deadline | Content |
|---|---|---|
| Early warning | Within 24 hours of becoming aware | Whether the incident is suspected of being caused by unlawful or malicious acts, whether it could have cross-border impact |
| Incident notification | Within 72 hours of becoming aware | Update of early warning, initial assessment of severity and impact, indicators of compromise where applicable |
| Intermediate report | Upon CSIRT/authority request | Status update on incident handling and response |
| Final report | Within 1 month of incident notification | Detailed description of the incident and its root cause, mitigation measures applied and ongoing, cross-border impact if applicable |
NIS2 introduces personal accountability for management bodies — a significant departure from NIS1.
Key requirements:
Consequences of non-compliance:
Supply chain security is one of the most impactful new requirements under NIS2.
Entities must take into account:
Tier 1 — Critical suppliers:
Tier 2 — Important suppliers:
Tier 3 — Standard suppliers:
The NIS Cooperation Group may carry out coordinated risk assessments of critical supply chains, considering:
| Entity Type | Maximum Fine |
|---|---|
| Essential entities | €10,000,000 or 2% of total worldwide annual turnover, whichever is higher |
| Important entities | €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher |
For essential entities (Article 32):
For important entities (Article 33):
| Aspect | Essential Entities | Important Entities |
|---|---|---|
| Supervision | Ex-ante (proactive) | Ex-post (reactive/complaint-based) |
| Audits | Regular security audits | Audits when justified |
| On-site inspections | Yes | Upon reasonable request |
| Management bans | Yes (temporary) | No |
| Aspect | NIS1 (2016/1148) | NIS2 (2022/2555) |
|---|---|---|
| Scope | 7 sectors, ~10K entities | 18 sectors, ~160K entities |
| Entity classification | OES and DSP | Essential and Important |
| Security measures | General requirements | 10 specific minimum measures |
| Incident reporting | No specific timeline | 24h / 72h / 1 month staged |
| Management accountability | Not specified | Mandatory training, personal liability |
| Supply chain | Not addressed | Explicit requirements |
| Penalties | Set by Member States | Harmonized: €10M/2% or €7M/1.4% |
| Supervision | Varied | Harmonized ex-ante/ex-post |
| Peer review | Limited | Enhanced peer review mechanism |
| Vulnerability disclosure | Not addressed | Coordinated vulnerability disclosure |
| Size threshold | Member State designation | Clear size-cap rules |
| Enforcement | Weak, inconsistent | Strong, harmonized |
Determines whether an organization falls within NIS2 scope and classifies it as Essential or Important.
# Analyze scope interactively
python scripts/nis2_scope_analyzer.py --sector energy --sub-sector electricity --employees 500 --turnover 100
# Full analysis with JSON output
python scripts/nis2_scope_analyzer.py --sector health --sub-sector healthcare_providers --employees 75 --turnover 15 --json
# Generate compliance checklist
python scripts/nis2_scope_analyzer.py --sector digital_infrastructure --sub-sector cloud_computing --employees 200 --turnover 50 --checklist
# Load from config file
python scripts/nis2_scope_analyzer.py --config organization.json --json --output scope_report.jsonFeatures:
Assesses compliance against all 10 minimum security measures with per-measure scoring.
# Run full compliance check
python scripts/nis2_compliance_checker.py --config assessment.json
# Generate assessment template
python scripts/nis2_compliance_checker.py --template > assessment.json
# Check specific measures only
python scripts/nis2_compliance_checker.py --config assessment.json --measures 1 2 4 --json
# Generate gap analysis report
python scripts/nis2_compliance_checker.py --config assessment.json --output gap_report.json --jsonFeatures:
Complete coverage of all 10 minimum security measures with implementation guidance, incident reporting procedures, management accountability requirements, supply chain security framework, and ISO 27001 control mapping.
12-month implementation roadmap with resource requirements, policy templates, technical controls checklist, training requirements, and cost estimation framework.
Before running the assessment, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the assessment.
1. Identify sector and sub-sector classification
→ Use NIS2 Scope Analyzer tool
2. Determine entity size (employees, turnover, balance sheet)
3. Check for automatic inclusion criteria
4. Classify as Essential or Important entity
5. Identify applicable Member State transposition requirements1. Document current security posture
2. Map existing controls to NIS2 10 minimum measures
→ Use NIS2 Compliance Checker tool
3. Assess incident reporting readiness
4. Evaluate supply chain security maturity
5. Review management accountability compliance
6. Generate gap analysis report1. Prioritize gaps by risk and regulatory impact
2. Develop remediation roadmap (see Implementation Playbook)
3. Allocate budget and resources
4. Define project milestones and ownership
5. Establish governance structure1. Implement technical controls
2. Develop and approve policies
3. Deploy monitoring and detection capabilities
4. Establish incident reporting procedures
5. Conduct supply chain security assessments
6. Train management body and staff1. Regular compliance assessments (quarterly minimum)
2. Annual management body training refresh
3. Incident response exercises (biannual)
4. Supply chain security reviews (annual)
5. Policy review and update cycles
6. Audit preparation and execution| Month | Phase | Key Activities |
|---|---|---|
| 1–2 | Assessment | Scope determination, gap analysis, current state documentation |
| 3–4 | Planning | Remediation roadmap, budget allocation, governance setup, quick wins |
| 5–6 | Foundation | Core policies, risk framework, asset inventory, management training |
| 7–8 | Implementation | Technical controls, monitoring deployment, incident response setup |
| 9–10 | Supply Chain | Supplier assessments, contractual updates, third-party risk program |
| 11 | Testing | Incident response exercises, penetration testing, compliance validation |
| 12 | Operationalize | Final audit, continuous monitoring, ongoing compliance program launch |
| Organization Size | FTE Requirement | Estimated Budget |
|---|---|---|
| Medium (50–249) | 1–2 dedicated + project team | €200K–€500K |
| Large (250–999) | 2–4 dedicated + project team | €500K–€1.5M |
| Enterprise (1000+) | 4–8 dedicated + project team | €1.5M–€5M+ |
| Problem | Likely Cause | Resolution |
|---|---|---|
| Scope Analyzer returns "out of scope" for an entity that should be in scope | Automatic inclusion criteria not triggered; size thresholds not met | Check for automatic inclusion flags (DNS providers, TLD registries, sole provider). Verify --turnover and --employees values. Use --checklist flag to review all criteria. |
| Compliance Checker scores are unexpectedly low | Assessment JSON has missing or null control responses | Run --template to regenerate a fresh assessment template. Ensure every control question has a boolean or score value. |
| Gap report does not cover all 10 measures | --measures flag is filtering output | Remove the --measures flag to assess all 10 Article 21 measures. Verify the config JSON includes all measure sections. |
| Entity classified as "Important" instead of "Essential" | Sector falls under Annex II rather than Annex I | Review sector/sub-sector classification. Annex I sectors produce Essential entities; Annex II sectors produce Important entities. Size also matters. |
| National transposition requirements unclear | Member State has not yet fully transposed NIS2 | As of early 2026, 13 of 27 EU Member States have incomplete transposition. Check the ECSO NIS2 Transposition Tracker for country-specific status. Apply the directive's baseline requirements. |
| Supply chain assessment section incomplete | Supplier tier classification not provided in config | Populate supplier data with tier levels (Critical/Important/Standard) and include contractual security requirements for each tier. |
| Incident reporting readiness score is zero | No incident handling controls documented in assessment | Complete Measure 2 (Incident Handling) controls in the assessment JSON, including detection capabilities, classification procedures, and CSIRT reporting integration. |
In Scope:
Out of Scope:
| Skill | Integration |
|---|---|
| information-security-manager-iso27001 | NIS2 measures map closely to ISO 27001 Annex A controls; use ISO 27001 ISMS as the implementation backbone for NIS2 compliance |
| infrastructure-compliance-auditor | Validate technical controls (DNS, TLS, MFA, encryption, monitoring) that satisfy NIS2 Article 21 requirements |
| dora-compliance-expert | DORA is lex specialis for financial sector entities; coordinate NIS2 and DORA assessments to avoid duplication |
| nist-csf-specialist | NIST CSF 2.0 functions map to NIS2 measures; use CSF maturity assessor to benchmark cybersecurity posture |
| soc2-compliance-expert | SOC 2 Trust Services Criteria overlap significantly with NIS2 measures; leverage existing SOC 2 evidence |
| isms-audit-expert | ISO 27001 audit evidence directly supports NIS2 compliance demonstrations |
Determines NIS2 applicability and entity classification.
| Flag | Required | Description |
|---|---|---|
--sector | Yes (or --config) | Sector identifier (e.g., energy, health, digital_infrastructure) |
--sub-sector | Yes (or --config) | Sub-sector identifier (e.g., electricity, healthcare_providers, cloud_computing) |
--employees | Yes (or --config) | Number of employees in the organization |
--turnover | Yes (or --config) | Annual turnover in millions of euros |
--config | No | Path to organization JSON config file (alternative to individual flags) |
--json | No | Output results in JSON format |
--checklist | No | Generate a compliance checklist based on entity classification |
--output | No | Path to write the output report file |
Assesses compliance against all 10 Article 21 minimum security measures.
| Flag | Required | Description |
|---|---|---|
--config | Yes (or --template) | Path to assessment JSON file with control responses |
--template | No | Generate a blank assessment template (pipe to file with >) |
--measures | No | Space-separated list of measure numbers to assess (e.g., 1 2 4). Omit for all 10. |
--json | No | Output results in JSON format |
--output | No | Path to write the gap analysis report |
Last Updated: March 2026 Directive Reference: EU 2022/2555 Applicable From: October 17, 2024 (Member State transposition deadline)
© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references) in ra-qm-team/nis2-directive-specialist of borghei/Claude-Skills.
Open the folder on GitHubat commit 4a698e8
Nis2 Directive Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nis2 Directive Specialist this skillborghei/Claude-Skills | 891 | — | ~8.1k | Automated safety check: Pass | MIT | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 481 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Eu CraSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~4k | Automated safety check: Pass | MIT | |
| Kesekit Checkcdppcorp/KESE-KIT | 360 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Bom Auditcdxgen/cdxgen | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 |
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
jdx/packslip
Configure signed release manifests with packslip: add the jdx/packslip action or packslip create to a release workflow, declare completions, man pages, CLI specs, skills, and SBOMs as resources, and…
borghei/Claude-Skills
Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.
borghei/Claude-Skills
Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.
borghei/Claude-Skills
Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.
borghei/Claude-Skills
Idea to AI-generated prototype to customer validation to engineering handoff.
borghei/Claude-Skills
Analytics engineering across data modeling, dbt, transformation, and semantic layers.
borghei/Claude-Skills
Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.
Categories
NIS2 Directive (EU 2022/2555) compliance for critical infrastructure entities, covering the 10 minimum security measures. Nis2 Directive Specialist is an agent skill from borghei/Claude-Skills. NIS2 Directive (EU 2022/2555) compliance for critical infrastructure entities, covering the 10 minimum security measures.
Nis2 Directive Specialist fits situations like: NIS2 compliance assessments; entity scope analysis; supply chain security; incident reporting readiness.
Run `npx skills add borghei/Claude-Skills --skill nis2-directive-specialist -a claude-code`. Or copy the skill folder (ra-qm-team/nis2-directive-specialist in borghei/Claude-Skills) into .claude/skills/nis2-directive-specialist in your project. Claude Code loads it when a task matches its description.
Run `npx skills add borghei/Claude-Skills --skill nis2-directive-specialist -a codex`. Or copy the skill folder (ra-qm-team/nis2-directive-specialist in borghei/Claude-Skills) into .agents/skills/nis2-directive-specialist in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill nis2-directive-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nis2-directive-specialist, .gemini/skills/nis2-directive-specialist, .github/skills/nis2-directive-specialist and .opencode/skills/nis2-directive-specialist in your project.
Going by SKILL.md and its folder, Nis2 Directive Specialist needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Nis2 Directive Specialist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 8.1k tokens (SKILL.md is roughly 32k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Nis2 Directive Specialist: Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars), Eu Cra (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and Kesekit Check (cdppcorp/KESE-KIT, 360 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 891 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.
Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.