Agent skill

Cis Controls

by Hack23 in Hack23/cia

Implement CIS Controls v8 critical security controls for effective cyber defense in CIA platform

Apache-2.0Auto-check passedSecurity

Install Cis Controls

skills CLI
$ npx skills add Hack23/cia --skill cis-controls -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia cis-controls --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/cis-controls .claude/skills/cis-controls && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cis-controls
GitHub stars
239
Token cost
~1.5k tokens
SKILL.md length
224 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implement CIS Controls v8 critical security controls for effective cyber defense in CIA platform

  • Works in 3 steps: IG1 (Implementation Group 1) - Essential… → IG2 - Additional controls for… → IG3 - Comprehensive controls for large…
  • Security work in your project
  • SKILL.md covers Purpose, When to Use, Critical CIS Controls and Implementation Priority, plus 3 more sections
  • Calls aws and mvn; needs ADMIN_PASSWORD

What it does

Cis Controls is an agent skill from Hack23/cia. Implement CIS Controls v8 critical security controls for effective cyber defense in CIA platform

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/cis-controls”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. IG1 (Implementation Group 1) - Essential for all organizations
  2. IG2 - Additional controls for medium-sized organizations
  3. IG3 - Comprehensive controls for large organizations

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws
    • mvn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • cisecurity.org
    • iso.org
    • nist.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ADMIN_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cis Controls loads about 1.5k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 224 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 224 words, ~1,515 tokens.

Download SKILL.mdSave it as .claude/skills/cis-controls/SKILL.md (or your agent's skills folder).
name
cis-controls
description
Implement CIS Controls v8 critical security controls for effective cyber defense in CIA platform
license
Apache-2.0

CIS Controls v8 Implementation Skill

Purpose

Implement prioritized CIS Controls for cyber defense, focusing on high-impact security controls.

When to Use

  • ✅ Security hardening activities
  • ✅ Compliance assessments
  • ✅ Security baseline establishment
  • ✅ Vendor security reviews

Critical CIS Controls

Control 1: Inventory and Control of Enterprise Assets
bash
# Maintain asset inventory
aws ec2 describe-instances --query 'Reservations[*].Instances[*].[InstanceId,Tags[?Key==`Name`].Value|[0],State.Name]' --output table

# Tag all resources
aws ec2 create-tags --resources i-1234567890abcdef0 --tags Key=Application,Value=CIA Key=Environment,Value=Production
Control 2: Inventory and Control of Software Assets
xml
<!-- Track all dependencies in pom.xml -->
<dependencies>
    <dependency>
        <groupId>org.springframework</groupId>
        <artifactId>spring-webmvc</artifactId>
        <version>${spring.version}</version> <!-- Version via parent property -->
    </dependency>
</dependencies>
Control 3: Data Protection
java
@Service
public class DataProtectionService {
    @Autowired
    private BytesEncryptor encryptor;
    
    public void protectSensitiveData(SensitiveData data) {
        // Encrypt at rest
        data.setEncryptedContent(encryptor.encrypt(data.getPlainContent()));
        
        // Classify data
        data.setClassification(DataClassification.CONFIDENTIAL);
        
        // Set retention period
        data.setRetentionUntil(LocalDate.now().plusYears(7));
        
        dataRepository.save(data);
    }
}
Control 4: Secure Configuration
yaml
# application-production.yml - Secure defaults
spring:
  security:
    user:
      name: ${ADMIN_USERNAME}
      password: ${ADMIN_PASSWORD}
  
server:
  port: 8443
  ssl:
    enabled: true
  error:
    include-stacktrace: never
Control 5: Account Management
java
@Service
public class AccountManagementService {
    
    @Scheduled(cron = "0 0 2 * * *") // Daily at 2 AM
    public void reviewAccounts() {
        // Disable inactive accounts
        List<User> inactiveUsers = userRepository.findInactiveSince(
            LocalDateTime.now().minusDays(90)
        );
        
        inactiveUsers.forEach(user -> {
            user.setEnabled(false);
            auditLog.log("Account disabled due to inactivity: " + user.getUsername());
        });
        
        userRepository.saveAll(inactiveUsers);
    }
}
Control 6: Access Control Management
java
@PreAuthorize("hasRole('ADMIN')")
public void deleteUser(String userId) {
    // Enforce least privilege
    auditLogger.logPrivilegedAction("DELETE_USER", userId);
    userRepository.deleteById(userId);
}
Control 8: Audit Log Management
java
@Aspect
@Component
public class AuditLoggingAspect {
    @Around("@annotation(Audited)")
    public Object auditMethod(ProceedingJoinPoint joinPoint) throws Throwable {
        String action = joinPoint.getSignature().getName();
        String user = SecurityContextHolder.getContext().getAuthentication().getName();
        
        auditLog.info("Action: {}, User: {}, Timestamp: {}", 
            action, user, Instant.now());
        
        return joinPoint.proceed();
    }
}
Control 16: Application Software Security
bash
# Security scanning in CI/CD
mvn org.owasp:dependency-check-maven:check
mvn sonar:sonar -Dsonar.qualitygate.wait=true

Implementation Priority

  1. IG1 (Implementation Group 1) - Essential for all organizations

    • Controls 1-6: Basic cyber hygiene
  2. IG2 - Additional controls for medium-sized organizations

    • Controls 7-16: Enhanced security
  3. IG3 - Comprehensive controls for large organizations

    • Controls 17-18: Advanced/specialized

Hack23 ISMS Policy References

CIS Controls Implementation:

All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC

CIA Platform Architecture References

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/cis-controls of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Cis Controls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cis Controls compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cis Controls this skillHack23/cia239—~1.5kAutomated safety check: PassApache-2.0
Eu CraSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~4kAutomated safety check: PassMIT
OmniRoute Audit and Policy CLIdiegosouzapw/OmniRoute74k—~733Automated safety check: PassMIT
Building Malware Incident Communication Templatemukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0
Implementing Usb Device Control Policymukul975/Anthropic-Cybersecurity-Skills34k—~1.4kAutomated safety check: PassApache-2.0
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0

Similar skills

  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    939 GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • OmniRoute Audit and Policy CLI

    diegosouzapw/OmniRoute

    Command reference for omniroute's audit, logs, policy and telemetry commands: search and export audit trails, manage access policies and review request history for compliance work.

    74k GitHub stars~733 tokensUpdated today
    SecurityAuto-check passed
  • Building Malware Incident Communication Template

    mukul975/Anthropic-Cybersecurity-Skills

    Build structured communication templates for malware incidents (ransomware, wiper, trojan, worm), covering internal stakeholder notifications, executive briefings, technical advisories for IT teams…

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Usb Device Control Policy

    mukul975/Anthropic-Cybersecurity-Skills

    Implements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices.

    34k GitHub stars~1.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Official

    Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF).

    21k GitHub starsUsed in 1 repo~4.2k tokens
    SecurityAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Questions about Cis Controls

What does Cis Controls do?

Implement CIS Controls v8 critical security controls for effective cyber defense in CIA platform. Cis Controls is an agent skill from Hack23/cia.

When should I use Cis Controls?

Cis Controls fits situations like: security work in your project.

How do I install Cis Controls in Claude Code?

Run `npx skills add Hack23/cia --skill cis-controls -a claude-code`. Or copy the skill folder (.github/skills/cis-controls in Hack23/cia) into .claude/skills/cis-controls in your project. Claude Code loads it when a task matches its description.

How do I install Cis Controls in Codex?

Run `npx skills add Hack23/cia --skill cis-controls -a codex`. Or copy the skill folder (.github/skills/cis-controls in Hack23/cia) into .agents/skills/cis-controls in your project. Codex loads it when a task matches its description.

Can I use Cis Controls in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill cis-controls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cis-controls, .gemini/skills/cis-controls, .github/skills/cis-controls and .opencode/skills/cis-controls in your project.

What does Cis Controls need to run?

Going by SKILL.md and its folder, Cis Controls needs the command-line tools its instructions call (aws and mvn) and credentials named ADMIN_PASSWORD.

Does Cis Controls access the network?

SKILL.md names 4 domains. As links in the text: github.com, cisecurity.org, iso.org and nist.gov. This is read from the text; nothing was executed.

Is Cis Controls safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cis Controls use?

Cis Controls is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cis Controls use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cis Controls?

Skills that share tags, products or a category with Cis Controls: Eu Cra (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars), OmniRoute Audit and Policy CLI (diegosouzapw/OmniRoute, 74k stars), Building Malware Incident Communication Template (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Usb Device Control Policy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cis Controls?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.