Audit applications and infrastructure handling payment card data against PCI DSS v4.0.

MITAuto-check: notesLegal & Compliance

Install Pci Audit

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill pci-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills pci-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pci-audit .claude/skills/pci-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pci-audit
GitHub stars
413
Token cost
~3.7k tokens
SKILL.md length
1,694 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Audit applications and infrastructure handling payment card data against PCI DSS v4.0.

  • The user mentions PCI
  • SKILL.md covers The scope question (do this…, Merchant levels and assessment…, Engineering-relevant… and Putting it together — audit…, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Cardholder data

What it does

Pci Audit is an agent skill from briiirussell/cybersecurity-skills. Audit applications and infrastructure handling payment card data against PCI DSS v4.0. Heavy emphasis on scope determination (the single most-leveraged variable) plus the engineering-relevant requirements — Req 3 (storage of CHD), Req 4 (transmission), Req 6 (secure SDLC), Req 7-8 (access), Req 10 (logging), Req 11 (testing), Req 12 (program). Use when the user mentions 'PCI,' 'PCI DSS,' 'PCI DSS 4.0,' 'payment card,' 'cardholder data,' 'CHD,' 'PAN,' 'PCI scope,' 'PCI compliance,' 'SAQ,' 'AoC,' 'attestation of…

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Healthcare and finance regulation and Natural language processing. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions PCI
  • Cardholder data
  • Attestation of compliance
  • Network segmentation for PCI

Example prompts

  • “PCI DSS,”
  • “PCI DSS 4.0,”
  • “payment card,”
  • “/pci-audit”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, Write, WebSearch

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • Write
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pci Audit loads about 3.7k tokens when it runs. Until then it costs about 168 tokens; SKILL.md has 1,694 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~168
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, Write, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,694 words, ~3,709 tokens.

Download SKILL.mdSave it as .claude/skills/pci-audit/SKILL.md (or your agent's skills folder).
name
pci-audit
description
Audit applications and infrastructure handling payment card data against PCI DSS v4.0. Heavy emphasis on scope determination (the single most-leveraged variable) plus the engineering-relevant requirements — Req 3 (storage of CHD), Req 4 (transmission), Req 6 (secure SDLC), Req 7-8 (access), Req 10 (logging), Req 11 (testing), Req 12 (program). Use when the user mentions 'PCI,' 'PCI DSS,' 'PCI DSS 4.0,' 'payment card,' 'cardholder data,' 'CHD,' 'PAN,' 'PCI scope,' 'PCI compliance,' 'SAQ,' 'AoC,' 'attestation of compliance,' 'tokenization,' 'P2PE,' 'network segmentation for PCI,' or audits any system that stores, processes, or transmits payment card data.
allowed-tools
Read, Grep, Glob, Bash, Write, WebSearch

PCI Audit — Payment Card Industry Data Security Standard

PCI DSS v4.0 (effective March 2025) is the security standard for any environment that stores, processes, or transmits payment card data. Twelve high-level requirements; hundreds of sub-requirements. Most organizations pass or fail on a single decision: scope.

This skill emphasizes scope determination first, then the engineering-relevant requirements. Final compliance attestation (SAQ self-assessment or QSA audit producing an Attestation of Compliance) is a process this skill prepares for — it is not the attestation itself.

Cross-references: crypto-audit for Req 3 / 4 cryptographic detail; iam-audit for Req 7-8; siem-detection for Req 10 logging; dependency-audit and owasp-audit for Req 6 (secure SDLC); incident-triage for Req 12.10 (incident response).

The scope question (do this first)

"Scope" in PCI DSS means: the systems that store, process, or transmit cardholder data (CHD), plus systems that can affect the security of those systems (connected-to and security-impacting systems). Everything in scope is subject to all 12 requirements. Everything out of scope is not.

Most PCI failures are scope failures. A system pulled into scope by accident creates years of compliance debt; a system kept out of scope via good architecture saves substantial cost.

Determine scope

For every system in the environment, classify:

TypeDefinitionIn scope?
CDE (Cardholder Data Environment)Stores, processes, or transmits PAN, expiration, service code, name when paired with PAN, or sensitive authentication dataYes — full PCI DSS
Connected-toHas direct connectivity to the CDE without compensating segmentationYes
Security-impactingProvides security services to the CDE (auth, logging, monitoring, time sync, DNS)Yes
SegmentedNo direct connectivity; segmentation validated annuallyNo
Cardholder data flow only as masked / tokenizedThe system handles tokens or masked PANs that cannot be reversed without out-of-band accessUsually No, but verify the token type — surrogate tokens reversible by the merchant are still in scope

Audit step: trace every payment flow end-to-end. Where does the PAN enter the environment, where does it go, where does it stop. Every system the PAN touches is in scope; every system that touches that system without segmentation is also in scope.

Reduce scope (the leveraged engineering work)

The highest-ROI PCI work is usually scope reduction:

  • Use a hosted payment page — let Stripe / Adyen / Braintree / Worldpay host the input form. The PAN never reaches your servers. The browser communicates directly with the processor. Your scope shrinks to "iframe integration."
  • Use tokenization — payment processor converts PAN into a token your systems store instead. The token is meaningless without processor-side access. Your systems handle tokens, not PANs.
  • Use P2PE (Point-to-Point Encryption) — for terminal-present commerce, encrypt at the swipe so plaintext never traverses your network.
  • Network segmentation — for retained CDE, ensure firewall / VLAN / namespace separation between CDE and the rest. Default-deny at the CDE perimeter.

A merchant doing 1M transactions/year via Stripe Checkout with no PAN on their servers is radically less in scope than the same merchant taking PANs into their own form and proxying to Stripe. Same merchant; very different audit.

Merchant levels and assessment types (compliance posture, not engineering)

Briefly, because it sets the audit cadence and rigor:

LevelVolume (Visa)Validation requirement
1> 6M transactions/year, or breached merchant of any volumeAnnual on-site QSA assessment → AoC
21M-6M transactions/yearAnnual SAQ (self) or QSA assessment (Visa requires QSA from 2024)
320K-1M e-commerce transactions/yearAnnual SAQ
4All otherAnnual SAQ

SAQ types (Self-Assessment Questionnaire) match the merchant's CDE shape — SAQ A (fully outsourced e-commerce), SAQ A-EP (e-commerce that does some redirection), SAQ B (terminal only, dial / IP without electronic storage), SAQ C-VT (web-based virtual terminal), SAQ D (everything else, the longest). The right SAQ is the one whose conditions all match your environment.

Engineering-relevant requirements (the subset this skill audits)

Req 3 — Protect stored cardholder data

The default position: do not store PAN. If you must, encrypt at rest and minimize the data retained.

  • PAN at rest must be unreadable: strong cryptography (AES-256), key management per Req 3.6 (see crypto-audit), key rotation, separation of duties on key custody
  • Sensitive authentication data (CVV / CVV2, full magnetic stripe, PIN / PIN block) must not be stored after authorization — period, regardless of encryption
  • Mask PAN on display by default — typically first 6 + last 4
  • Render PAN unreadable in any other form (backups, logs, debug output)

Audit grep patterns:

  • Database schemas: columns named pan, card_number, cc_number, cardnum, account_number
  • Code paths writing card data: pan, cardNumber, regex ^4[0-9]{12,15}$ (Visa), ^5[1-5][0-9]{14}$ (Mastercard), ^3[47][0-9]{13}$ (Amex), ^6(?:011|5[0-9]{2})[0-9]{12}$ (Discover)
  • Logs: console\.log.*cardNumber, logger\..*\.pan, log\..*card
  • Error reporting: confirm Sentry / Datadog / Bugsnag scrubbing rules redact card patterns (Luhn-valid 13-19 digit sequences)
  • Backups: confirm backup retention does not include unencrypted CHD

If a Luhn-valid PAN appears anywhere in source, lock files, or logs — that is a finding regardless of intent.

Req 4 — Protect transmission across open networks
  • TLS 1.2 or higher, modern cipher suites only (see crypto-audit for the configuration detail)
  • No PAN transmitted via end-user messaging tech (email, SMS, chat) — and reject any flow that does
  • Internal-only networks transmitting PAN should still encrypt (defense in depth — Req 4.2.1.1 in v4.0)
Req 6 — Develop and maintain secure systems and software

This is where the security audit family meets PCI. Most of this requirement is satisfied by running the existing skills:

  • 6.2 Custom software developed securely — see owasp-audit, api-audit
  • 6.3 Vulnerabilities identified and addressed — see vuln-research, dependency-audit, finding-triage
  • 6.4 Public-facing web applications protected from attacks — WAF or annual code review + post-release manual review
  • 6.5 Changes to all system components managed securely — change management, separation of duties between dev and prod, sanitization of pre-production data before lower-environment use

Audit grep patterns:

  • Lower-environment configs containing real PANs (the common failure: staging seeded from a prod DB dump that included card data)
  • Code paths that bypass the secure SDLC (direct prod hotfix patterns, --no-verify on commits to prod-impacting branches)
Req 7 — Restrict access to cardholder data by business need to know
  • Role-based access — only personnel needing CHD for their job have access
  • Default-deny — access is granted explicitly, never inherited
  • Privileged user IDs documented and reviewed

See iam-audit for the full identity-and-access deep dive.

Show full SKILL.md (696 more words)Show less
Req 8 — Identify users and authenticate access
  • Unique IDs (no shared accounts) for every user — including service accounts
  • Strong authentication — passwords meeting current PCI complexity requirements, MFA for non-console administrative access AND for all remote network access AND (new in v4.0) for all access into the CDE
  • MFA must be phishing-resistant for the most sensitive access paths (recommended in v4.0)
  • Account lockout, session timeout, password rotation per current PCI parameters (v4.0 relaxed some legacy requirements — verify current text)

See iam-audit for implementation patterns and identity-provider integration.

Req 10 — Log and monitor all access to network resources and cardholder data
  • Every access to CHD logged — who, when, what, from where
  • Logs centralized, time-synced (Req 10.6 — NTP), retained at least 12 months (3 months immediately available)
  • Logs reviewed daily — manual or automated. Anomalies trigger investigation
  • Log integrity protected — separate system, write-only, immutable storage

See siem-detection for the engineering implementation; see soc-operations for the review cadence.

Req 11 — Test security of systems and networks regularly
  • Vulnerability scans — internal and external, quarterly. External scans must be by an ASV (Approved Scanning Vendor)
  • Penetration tests — annual at minimum, after significant changes. Internal AND external. Network and application layer. Tested by qualified internal resource or third party
  • Segmentation testing (for environments relying on segmentation to reduce scope) — annual penetration testing specifically to validate segmentation
  • File integrity monitoring on critical files / configs

See dependency-audit (vulnerability scan), web-pentest (annual app pentest), red-team-engagement (annual offensive engagement for higher levels).

Req 12 — Maintain an information security policy

The program-level layer. Engineering inputs:

  • 12.10 Incident response plan — see incident-triage. Tested at least annually
  • 12.5 Third-party / service-provider management — DPA-like attestations, annual review of provider compliance (your processor will send you an AoC; you must retain it)
  • 12.6 Security awareness training — for personnel handling CHD

Putting it together — audit checklist

markdown
# PCI DSS v4.0 Audit Findings
## Merchant: [name]
## Merchant level: [1/2/3/4]
## SAQ type: [A / A-EP / B / C-VT / D / not applicable - Level 1 QSA]
## Date: [date]
## Auditor: [name + qualification]

### Scope determination
- [ ] Payment data flow diagrammed end-to-end
- [ ] CDE explicitly bounded
- [ ] Connected-to systems enumerated
- [ ] Segmentation evidence documented
- [ ] Scope-reduction opportunities identified

### Per-requirement findings
| Req | Compliant? | Findings | Severity |
|-----|------------|----------|----------|
| 3 — Stored CHD | | | |
| 4 — Transmission | | | |
| 6 — Secure SDLC | | | |
| 7 — Access restriction | | | |
| 8 — Authentication | | | |
| 10 — Logging | | | |
| 11 — Testing | | | |
| 12 — Program | | | |

### Per-finding detail
[Title, req reference, severity, location, vulnerable config, remediation, verification]

### Recommended scope reductions (if applicable)
[Hosted payment page, tokenization, network segmentation improvements with effort estimates]

### Compensating controls (if used)
[Each compensating control: control description, what it compensates for, evidence of effectiveness, review cadence]

Disposition rule (Fixed / Deferred / Accepted Risk) per owasp-audit. PCI accepted-risk is heavily disfavored — most "accepted risks" should be Compensating Controls with documented evidence of effectiveness.

Common audit findings (real-world starting hypotheses)

  • PAN in logs — error / debug / access logs containing card data, captured by Sentry / Datadog / Bugsnag, retained beyond authorization
  • Sensitive authentication data persistence — CVV stored "for re-billing convenience" (forbidden), or full track data captured by accident
  • Lower environments seeded from production — staging database contains real PANs from a prod dump that was not sanitized
  • Tokenization scope misunderstanding — surrogate tokens stored in your DB that are reversible by your processor account are still in scope; only one-way tokens reduce scope
  • Iframe vs proxy — "hosted payment page" implemented as a proxy where your server briefly handles the PAN before forwarding (still in scope) vs a true iframe where your server never sees it (out of scope)
  • Segmentation by firewall rule, not by architecture — firewall rule "permits" only specific traffic but the systems share a VLAN; effective segmentation requires architectural separation
  • MFA gaps — v4.0 broadened MFA requirements; older environments that met v3.2.1 may have gaps

Boundaries

  • This skill is the engineering-side audit and preparation. Final compliance attestation (signed SAQ for self-assessing merchants, AoC produced by a QSA for higher-tier merchants) is a separate process
  • For QSA-led Level 1 assessments, this skill produces inputs to the QSA; it does not replace the QSA's independent assessment
  • Refuse to help build flows that violate PCI DSS — storing CVV, transmitting PAN via email, bypassing tokenization to capture raw cards
  • Where the audit surfaces an active compromise (PAN already exposed, suspected breach), pivot to incident-triage — PCI breach response has specific timing and notification requirements (acquirer notification typically within 24 hours)
  • Brand-specific rules (Visa, Mastercard, Amex, Discover, JCB) layer on top of PCI DSS — for merchants with brand-specific obligations (e.g., Visa's Cardholder Information Security Program), consult the card brand's program documentation

References

  • PCI DSS v4.0 — pcisecuritystandards.org/document_library
  • PCI DSS v4.0 Quick Reference Guide — practitioner-focused summary
  • SAQ Instructions and Guidelines — for self-assessing merchants
  • PCI SSC FAQ database — official interpretive guidance
  • QIR / QSA / PFI / ASV registries — for approved assessor / vendor selection
  • Visa Cardholder Information Security Program (CISP) — Visa-specific layered requirements
  • Mastercard Site Data Protection (SDP) Program — Mastercard layer
  • Open Web Application Security Project (OWASP) — Req 6 substantive content
  • NIST SP 800-53 — control catalog that maps cleanly to many PCI requirements
  • "PCI Compliance" — Branden Williams, Anton Chuvakin — practitioner book, updated through v4.0

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/pci-audit of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Pci Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pci Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pci Audit this skillbriiirussell/cybersecurity-skills413—~3.7kAutomated safety check: NotesMIT
Pci Dss Specialistborghei/Claude-Skills891—~1.9kAutomated safety check: PassMIT
OpenMed Model Card Writermaziyarpanahi/openmed5.5k—~1.8kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • Pci Dss Specialist

    borghei/Claude-Skills

    PCI DSS v4.0 payment card data security compliance, assessment, and implementation.

    891 GitHub stars~1.9k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • OpenMed Model Card Writer

    maziyarpanahi/openmed

    Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.

    5.5k GitHub stars~1.8k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes

Questions about Pci Audit

What does Pci Audit do?

Audit applications and infrastructure handling payment card data against PCI DSS v4.0. Pci Audit is an agent skill from briiirussell/cybersecurity-skills.0.

When should I use Pci Audit?

Pci Audit fits situations like: the user mentions PCI; cardholder data; attestation of compliance; network segmentation for PCI.

How do I install Pci Audit in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill pci-audit -a claude-code`. Or copy the skill folder (skills/pci-audit in briiirussell/cybersecurity-skills) into .claude/skills/pci-audit in your project. Claude Code loads it when a task matches its description.

How do I install Pci Audit in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill pci-audit -a codex`. Or copy the skill folder (skills/pci-audit in briiirussell/cybersecurity-skills) into .agents/skills/pci-audit in your project. Codex loads it when a task matches its description.

Can I use Pci Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill pci-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pci-audit, .gemini/skills/pci-audit, .github/skills/pci-audit and .opencode/skills/pci-audit in your project.

What does Pci Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Pci Audit is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Write, WebSearch.

Does Pci Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pci Audit safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Pci Audit use?

Pci Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pci Audit use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pci Audit?

Skills that share tags, products or a category with Pci Audit: Pci Dss Specialist (borghei/Claude-Skills, 891 stars), OpenMed Model Card Writer (maziyarpanahi/openmed, 5.5k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars) and HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pci Audit?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.