Agent skill

Report Of Compliance

by cyberful in cyberful/cyberful

Assemble reviewed compliance evidence into a versioned, traceable draft report for PCI DSS or GDPR.

AGPL-3.0Auto-check passedLegal & Compliance

Install Report Of Compliance

skills CLI
$ npx skills add cyberful/cyberful --skill report-of-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cyberful/cyberful report-of-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cyberful/cyberful.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cyberful/builtin/skills/report-of-compliance .claude/skills/report-of-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
report-of-compliance
GitHub stars
135
Token cost
~1.2k tokens
SKILL.md length
440 words
Files
17 (incl. scripts, references, assets)
Skills in repo
85
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Assemble reviewed compliance evidence into a versioned, traceable draft report for PCI DSS or GDPR.

  • Works in 6 steps: Read this file completely and the one… → Stage… → Prepare an input matching… → …
  • A reporting phase needs a requirement matrix
  • SKILL.md covers Select one profile, Required input, Compile the draft and Completion boundary
  • Runs Python scripts from its folder

What it does

Report Of Compliance is an agent skill from cyberful/cyberful. Assemble reviewed compliance evidence into a versioned, traceable draft report for PCI DSS or GDPR. Use when a reporting phase needs a requirement matrix, gaps, limitations, provenance, and qualification boundaries; never treat the draft as a certification or legal conclusion.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 22 other files, including scripts, reference files and assets (for example `agents/openai.yaml`, `assets/compliance-profile.schema.json` and `assets/compliance-report-draft.schema.json`).

It sits in Legal & Compliance, covering Privacy and GDPR and Healthcare and finance regulation. The repository describes itself as: Cyberful is an open-source AI Red Team for discovering, exploiting, verifying, and remediating vulnerabilities. The licence is AGPL-3.0.

When your agent uses it

  • A reporting phase needs a requirement matrix
  • Qualification boundaries
  • Never treat the draft as a certification
  • Legal conclusion

Example prompts

  • “/report-of-compliance”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Read this file completely and the one selected framework reference.
  2. Stage scripts/build_compliance_report.py, assets/compliance-report-input.schema.json, the selected profile, and…
  3. Prepare an input matching assets/compliance-report-input.schema.json. Keep the profile identifier identical to the staged profile.
  4. Run the staged script offline with --workspace, --input, --profile, and a new --output path. The script validates need identifiers…
  5. Review every gap, conflict, applicability rationale, limitation, and qualification claim against the referenced source artifacts. Route…
  6. Use the Markdown draft as a working deliverable. For PCI DSS, transfer reviewed content only into the current official template supplied…

What it can do on your machine

Read from SKILL.md and the folder at commit ec598a6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Report Of Compliance loads about 1.2k tokens when it runs, and up to ~2.8k if it reads all its reference files. Until then it costs about 75 tokens; SKILL.md has 440 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from cyberful/cyberful at commit ec598a6, republished under its AGPL-3.0 licence (© cyberful). 440 words, ~1,196 tokens.

Download SKILL.mdSave it as .claude/skills/report-of-compliance/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.
name
report-of-compliance
description
Assemble reviewed compliance evidence into a versioned, traceable draft report for PCI DSS or GDPR. Use when a reporting phase needs a requirement matrix, gaps, limitations, provenance, and qualification boundaries; never treat the draft as a certification or legal conclusion.
metadata.domain
governance-risk-compliance
metadata.subdomain
compliance-reporting
metadata.triggers
report on compliance, compliance evidence report, PCI DSS ROC draft, GDPR accountability report, requirement evidence matrix, compliance reporting package
metadata.tags
compliance-reporting, evidence-traceability, pci-dss, gdpr, accountability, attestation-boundary

Report of Compliance

Build a reviewable draft from evidence that already exists. This skill organizes provenance and reporting status; it does not perform missing tests, decide legal applicability, qualify an assessor, issue an attestation, or turn an unsupported statement into evidence.

Select one profile

Do not load both framework references unless the requested report deliberately covers both frameworks.

Required input

Establish the report identifier, entity and role, framework profile, assessment period, evidence cutoff, scope statement, assessor identity and qualification as declared facts. For each profile need, record one bounded status, rationale, evidence references, finding references, owner, and optional remediation date. References should point to sealed workarea artifacts or stable external records; do not copy cardholder data, sensitive authentication data, personal data, credentials, or full work papers into the input.

Use supported only for an evidence-backed statement. Use not-applicable-with-rationale only when a reviewer has supplied the applicability rationale. Preserve partially-supported, unsupported, not-tested, and conflicting-evidence honestly; the renderer must not collapse them into a positive conclusion.

Show full SKILL.md (197 more words)Show less

Compile the draft

  1. Read this file completely and the one selected framework reference.
  2. Stage scripts/build_compliance_report.py, assets/compliance-report-input.schema.json, the selected profile, and assets/templates/compliance-report.md.
  3. Prepare an input matching assets/compliance-report-input.schema.json. Keep the profile identifier identical to the staged profile.
  4. Run the staged script offline with --workspace, --input, --profile, and a new --output path. The script validates need identifiers, expands unobserved needs as not-tested, preserves evidence references, and emits deterministic JSON with a bounded Markdown draft.
  5. Review every gap, conflict, applicability rationale, limitation, and qualification claim against the referenced source artifacts. Route missing technical evidence to the appropriate plan, trace, test, audit, or analyze skill instead of inventing prose.
  6. Use the Markdown draft as a working deliverable. For PCI DSS, transfer reviewed content only into the current official template supplied through the engagement; for GDPR, adapt the report title and jurisdictional sections without representing it as an authority-issued form.

Completion boundary

Complete when every profile need is represented, source/profile digests and evidence references are retained, limitations and unresolved needs are visible, and the artifact is explicitly labeled draft. Approval, signature, QSA/ISA work, DPO or counsel review, supervisory-authority acceptance, and formal compliance status remain outside this skill.

© cyberful, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 16 other files (scripts, references, assets) in cyberful/builtin/skills/report-of-compliance of cyberful/cyberful.

  • SKILL.md
  • agents/openai.yaml
  • assets/compliance-profile.schema.json
  • assets/compliance-report-draft.schema.json
  • assets/compliance-report-input.example.json
  • assets/compliance-report-input.schema.json
  • assets/profiles/gdpr-eu-2016-679.json
  • assets/profiles/pci-dss-4.0.1.json
  • assets/templates/compliance-report.md
  • references/framework-selection.md
  • references/gdpr-accountability.md
  • references/pci-dss-4.0.1.md
  • references/qualification-and-attestation.md
  • scripts/build_compliance_report.py
  • scripts/manifest.json
  • … and 2 more

Open the folder on GitHubat commit ec598a6

Compare with similar skills

Report Of Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Report Of Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Report Of Compliance this skillcyberful/cyberful135—~1.2kAutomated safety check: PassAGPL-3.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Anne WojcickiK-Dense-AI/mimeographs129—~1.5kAutomated safety check: PassMIT
Dpa Checklist ReviewLegalQuants/lq-ai150—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Anne Wojcicki

    K-Dense-AI/mimeographs

    Applies the strategic frameworks and mental models of Anne Wojcicki, co-founder and CEO of 23andMe.

    129 GitHub stars~1.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Dpa Checklist Review

    LegalQuants/lq-ai

    A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…

    150 GitHub stars~3.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Auditing Deidentification Runs

    maziyarpanahi/openmed

    Produce a signed, reproducible, no-PHI audit trail for an OpenMed de-identification run via deidentify(audit=True).

    5.5k GitHub stars~1.8k tokensUpdated today
    Legal & ComplianceAuto-check passed

More from cyberful/cyberful

All 85 skills in this repo
  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    135 GitHub stars~649 tokensUpdated 1 mo ago
    Auto-check passed
  • Audit Kubernetes admission and policy-as-code enforcement against local workload manifests, exception paths, namespace scope, and deployment evidence.

    135 GitHub stars~610 tokensUpdated 1 mo ago
    Auto-check passed
  • Audit PCI DSS penetration-test methodology, scope, internal and external reports, segmentation results, tester independence, remediation, retesting, retention, and multi-tenant support evidence.

    135 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Content Discovery

    cyberful/cyberful

    Design and interpret advanced content discovery with ffuf and complementary web fuzzers.

    135 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Network Recon

    cyberful/cyberful

    Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.

    135 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Sast Toolchain

    cyberful/cyberful

    Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits.

    135 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Report Of Compliance

What does Report Of Compliance do?

Assemble reviewed compliance evidence into a versioned, traceable draft report for PCI DSS or GDPR. Report Of Compliance is an agent skill from cyberful/cyberful. Assemble reviewed compliance evidence into a versioned, traceable draft report for PCI DSS or GDPR.

When should I use Report Of Compliance?

Report Of Compliance fits situations like: A reporting phase needs a requirement matrix; qualification boundaries; never treat the draft as a certification; legal conclusion.

How do I install Report Of Compliance in Claude Code?

Run `npx skills add cyberful/cyberful --skill report-of-compliance -a claude-code`. Or copy the skill folder (cyberful/builtin/skills/report-of-compliance in cyberful/cyberful) into .claude/skills/report-of-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Report Of Compliance in Codex?

Run `npx skills add cyberful/cyberful --skill report-of-compliance -a codex`. Or copy the skill folder (cyberful/builtin/skills/report-of-compliance in cyberful/cyberful) into .agents/skills/report-of-compliance in your project. Codex loads it when a task matches its description.

Can I use Report Of Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cyberful/cyberful --skill report-of-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/report-of-compliance, .gemini/skills/report-of-compliance, .github/skills/report-of-compliance and .opencode/skills/report-of-compliance in your project.

What does Report Of Compliance need to run?

Going by SKILL.md and its folder, Report Of Compliance needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Report Of Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Report Of Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Report Of Compliance use?

Report Of Compliance is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Report Of Compliance use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Report Of Compliance?

Skills that share tags, products or a category with Report Of Compliance: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Audit Report (harness/harness-skills, 115 stars) and Anne Wojcicki (K-Dense-AI/mimeographs, 129 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Report Of Compliance?

cyberful (a GitHub organization) maintains it in cyberful/cyberful, which has 135 GitHub stars. The repository holds 85 skills in this directory. The repository was last updated on August 24, 2026.

Source: cyberful/cyberful on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.