Agent skill

Pci Dss Specialist

by borghei in borghei/Claude-Skills

PCI DSS v4.0 payment card data security compliance, assessment, and implementation.

MITAuto-check passedLegal & Compliance

Install Pci Dss Specialist

skills CLI
$ npx skills add borghei/Claude-Skills --skill pci-dss-specialist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills pci-dss-specialist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/pci-dss-specialist .claude/skills/pci-dss-specialist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pci-dss-specialist
GitHub stars
891
Token cost
~1.9k tokens
SKILL.md length
709 words
Files
9 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

PCI DSS v4.0 payment card data security compliance, assessment, and implementation.

  • PCI DSS scoping
  • SKILL.md covers Core Capabilities, When to Use, Clarify First and Quick Start, plus 3 more sections
  • Runs Python scripts from its folder; calls python
  • Cardholder data environment (CDE) security

What it does

Pci Dss Specialist is an agent skill from borghei/Claude-Skills. PCI DSS v4.0 payment card data security compliance, assessment, and implementation. Use for PCI DSS scoping, cardholder data environment (CDE) security, SAQ and ROC preparation, QSA engagement, tokenization, and merchant compliance.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `references/infrastructure-controls-and-roadmap.md`, `references/pci-dss-requirements-guide.md` and `references/pci-infrastructure-security.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation, Natural language processing and SOC 2 and security compliance. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • PCI DSS scoping
  • Cardholder data environment (CDE) security
  • SAQ and ROC preparation
  • Merchant compliance

Example prompts

  • “/pci-dss-specialist”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pci Dss Specialist loads about 1.9k tokens when it runs, and up to ~24k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 709 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~24k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 709 words, ~1,875 tokens.

Download SKILL.mdSave it as .claude/skills/pci-dss-specialist/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
pci-dss-specialist
description
PCI DSS v4.0 payment card data security compliance, assessment, and implementation. Use for PCI DSS scoping, cardholder data environment (CDE) security, SAQ and ROC preparation, QSA engagement, tokenization, and merchant compliance.
license
MIT + Commons Clause
metadata.version
1.1.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
payment-security
metadata.updated
2026-06-15
metadata.tags
pci-dss, payment-security, tokenization, cardholder-data

PCI-DSS v4.0 Specialist

Implement, assess, and maintain compliance with the Payment Card Industry Data Security Standard version 4.0 — the global standard for protecting cardholder data in payment processing environments. Covers CDE scoping, SAQ/ROC selection, gap assessment against all 12 requirements, scope reduction (tokenization, P2PE, segmentation), and the future-dated v4.0 controls that became mandatory March 31, 2025.

Core Capabilities

  • Compliance assessment — score against all 12 PCI DSS v4.0 requirements, identify gaps, and prioritize remediation (pci_compliance_checker.py)
  • Scoping & SAQ selection — map the cardholder data environment, classify connected and security-impacting systems, and determine the correct SAQ type or ROC requirement (pci_scope_analyzer.py)
  • Scope reduction — tokenization, P2PE, network segmentation, and outsourced/iFrame processing to remove systems from scope
  • v4.0 readiness — MFA for all CDE access, 12-char passwords, payment-page script controls (6.4.3/11.6.1), anti-phishing, automated log review, targeted risk analysis
  • Infrastructure controls — network segmentation, TLS/DNS, endpoint/POS, cloud (AWS/Azure/GCP), container, and API security; encryption key lifecycle and DUKPT

When to Use

Trigger on: "PCI DSS", "payment card security", "cardholder data", "PCI compliance", "payment security", "PCI assessment", "SAQ", "ROC", "QSA", "credit card security", "payment processing security", "tokenization", "CDE scoping", or "merchant level compliance".

Clarify First

Before running the assessment or scoping, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Business model / payment flow — how cards are accepted (e-commerce, terminal, P2PE, fully outsourced/iFrame) (determines the CDE scope and correct SAQ type)
  • Merchant / service-provider level — annual transaction volume (sets the validation path: SAQ vs ROC)
  • CDE scope — which systems store, process, or transmit cardholder data plus connected systems (drives which of the 12 requirements are in scope)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the report.

Quick Start

bash
# Check PCI compliance status (JSON report)
python scripts/pci_compliance_checker.py --input controls.json --output compliance_report.json

# Compliance gap report for stakeholders (Markdown)
python scripts/pci_compliance_checker.py --input controls.json --format markdown --output gap_report.md

# Determine SAQ type / analyze CDE scope
python scripts/pci_scope_analyzer.py --input business_model.json --output scope_report.json
python scripts/pci_scope_analyzer.py --input business_model.json --format markdown --output scope_analysis.md

Run --requirements 3,4,7,8 to scope the checker to specific requirements. Full tool detail, input JSON formats, and flag reference live in the tools reference below.

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • references/requirements-and-changes.md — PCI DSS overview, the 12 requirements deep-dive (objective + key sub-requirements + implementation guidance each), and the v4.0 changes / future-dated requirements summary. Read when implementing or explaining a requirement.
  • references/pci-dss-requirements-guide.md — tabular reference: every sub-requirement with testing procedures and v4.0 change status. Read when you need exact sub-requirement IDs or auditor testing procedures.
  • references/scoping-and-assessment.md — CDE definition and system classification, scope reduction strategies, SAQ types + selection decision tree, assessment types (SAQ/ROC/AOC), and merchant/service-provider levels. Read when scoping or choosing a validation path.
  • references/infrastructure-controls-and-roadmap.md — technical controls (segmentation, DNS/TLS, endpoint/POS, cloud, container, API, tokenization architecture, key management) and the 5-phase 12-month compliance roadmap. Read when building or planning the program.
  • references/pci-infrastructure-security.md — deep architecture: reference network diagrams, per-cloud build-outs, mPOS, e-commerce script controls, and Kubernetes manifests. Read when designing CDE infrastructure in detail.
  • references/tools-validation-troubleshooting.md — full tool capabilities, input JSON formats, CLI flag tables, validation checkpoints, troubleshooting table, and success criteria. Read when running the tools or validating an engagement.
Show full SKILL.md (224 more words)Show less

Scope & Limitations

In Scope:

  • PCI DSS v4.0/v4.0.1 compliance assessment against all 12 requirements
  • SAQ type determination based on business model and payment processing architecture
  • CDE scoping with connected system and security-impacting system identification
  • Technical control validation (encryption, access control, logging, network segmentation)
  • Compliance scoring with per-requirement gap analysis and remediation priorities
  • Scope reduction strategy recommendations (tokenization, segmentation, P2PE)

Out of Scope:

  • Approved Scanning Vendor (ASV) vulnerability scans (requires PCI SSC-approved ASV vendor)
  • Qualified Security Assessor (QSA) on-site assessment or Report on Compliance (ROC) generation
  • Payment application security validation (PA-DSS / PCI SSF scope)
  • PIN Transaction Security (PTS) device certification
  • Card brand-specific program requirements (Visa, Mastercard, Amex each have additional program rules)
  • Legal advice on contractual obligations with acquiring banks or card brands
  • Real-time transaction monitoring or fraud detection

Integration Points

SkillIntegration
infrastructure-compliance-auditorValidates network segmentation, TLS configuration, endpoint security, and logging controls that satisfy PCI DSS Requirements 1, 2, 4, 10, 11
nist-csf-specialistCSF functions map to PCI DSS requirements; use the control mapper to build unified control matrices for dual-compliance programs
soc2-compliance-expertSOC 2 CC6 (access), CC7 (operations), CC8 (change management) overlap significantly with PCI DSS; leverage shared evidence
information-security-manager-iso27001ISO 27001 Annex A controls provide a management system framework supporting PCI DSS compliance
nis2-directive-specialistEU entities subject to both NIS2 and PCI DSS can map shared controls (encryption, incident response, access control)

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references) in ra-qm-team/pci-dss-specialist of borghei/Claude-Skills.

  • SKILL.md
  • references/infrastructure-controls-and-roadmap.md
  • references/pci-dss-requirements-guide.md
  • references/pci-infrastructure-security.md
  • references/requirements-and-changes.md
  • references/scoping-and-assessment.md
  • references/tools-validation-troubleshooting.md
  • scripts/pci_compliance_checker.py
  • scripts/pci_scope_analyzer.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Pci Dss Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pci Dss Specialist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pci Dss Specialist this skillborghei/Claude-Skills891—~1.9kAutomated safety check: PassMIT
Grc Knowledgemlunato47/claude-grc-plugin184—~6.1kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Security Compliancesangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT
Eks Securityaws-samples/appmod-blueprints115—~4.7kAutomated safety check: PassMIT-0

Similar skills

  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    852 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Compliance

    RightNow-AI/openfang

    Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

    18k GitHub stars~921 tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    891 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    891 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    891 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    891 GitHub stars~3.6k tokensUpdated 3 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    891 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    891 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed

Questions about Pci Dss Specialist

What does Pci Dss Specialist do?

PCI DSS v4.0 payment card data security compliance, assessment, and implementation. Pci Dss Specialist is an agent skill from borghei/Claude-Skills.0 payment card data security compliance, assessment, and implementation.

When should I use Pci Dss Specialist?

Pci Dss Specialist fits situations like: PCI DSS scoping; cardholder data environment (CDE) security; SAQ and ROC preparation; merchant compliance.

How do I install Pci Dss Specialist in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill pci-dss-specialist -a claude-code`. Or copy the skill folder (ra-qm-team/pci-dss-specialist in borghei/Claude-Skills) into .claude/skills/pci-dss-specialist in your project. Claude Code loads it when a task matches its description.

How do I install Pci Dss Specialist in Codex?

Run `npx skills add borghei/Claude-Skills --skill pci-dss-specialist -a codex`. Or copy the skill folder (ra-qm-team/pci-dss-specialist in borghei/Claude-Skills) into .agents/skills/pci-dss-specialist in your project. Codex loads it when a task matches its description.

Can I use Pci Dss Specialist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill pci-dss-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pci-dss-specialist, .gemini/skills/pci-dss-specialist, .github/skills/pci-dss-specialist and .opencode/skills/pci-dss-specialist in your project.

What does Pci Dss Specialist need to run?

Going by SKILL.md and its folder, Pci Dss Specialist needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Pci Dss Specialist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pci Dss Specialist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Pci Dss Specialist use?

Pci Dss Specialist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pci Dss Specialist use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 22k tokens, read only when the agent opens those files.

What are the alternatives to Pci Dss Specialist?

Skills that share tags, products or a category with Pci Dss Specialist: Grc Knowledge (mlunato47/claude-grc-plugin, 184 stars), Audit Report (harness/harness-skills, 115 stars), Security Compliance (sangrokjung/claude-forge, 852 stars) and Ciso Advisor (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pci Dss Specialist?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 891 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.