Agent skill

Hack23 Isms Compliance

by Hack23 in Hack23/cia

Hack23 ISMS organization-wide compliance requirements, policy enforcement, audit preparation

Apache-2.0Auto-check passedLegal & Compliance

Install Hack23 Isms Compliance

skills CLI
$ npx skills add Hack23/cia --skill hack23-isms-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia hack23-isms-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/hack23-isms-compliance .claude/skills/hack23-isms-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hack23-isms-compliance
GitHub stars
239
Token cost
~1.9k tokens
SKILL.md length
608 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Hack23 ISMS organization-wide compliance requirements, policy enforcement, audit preparation

  • Works in 4 steps: Documentation Review → Technical Controls Verification → Evidence Collection → …
  • Tasks that involve Audit readiness
  • SKILL.md covers Purpose, When to Use, ISMS Framework Overview and Compliance Checklist Per…, plus 7 more sections
  • Calls mvn

What it does

Hack23 Isms Compliance is an agent skill from Hack23/cia. Hack23 ISMS organization-wide compliance requirements, policy enforcement, audit preparation

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Audit readiness and Threat modeling. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Audit readiness
  • Tasks that involve Threat modeling

Example prompts

  • “/hack23-isms-compliance”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Documentation Review
  2. Technical Controls Verification
  3. Evidence Collection
  4. Metrics Preparation

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mvn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hack23 Isms Compliance loads about 1.9k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 608 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 608 words, ~1,896 tokens.

Download SKILL.mdSave it as .claude/skills/hack23-isms-compliance/SKILL.md (or your agent's skills folder).
name
hack23-isms-compliance
description
Hack23 ISMS organization-wide compliance requirements, policy enforcement, audit preparation
license
Apache-2.0

Hack23 ISMS Compliance Skill

Purpose

Ensure all Hack23 organization projects comply with the Information Security Management System (ISMS) requirements. Covers ISO 27001:2022, NIST CSF 2.0, CIS Controls v8, NIS2, and GDPR compliance across the development lifecycle. Provides actionable guidance for audit preparation and policy enforcement.

When to Use

  • ✅ Starting new projects or repositories under Hack23
  • ✅ Preparing for internal or external security audits
  • ✅ Reviewing compliance status of existing projects
  • ✅ Implementing security controls for new features
  • ✅ Creating or updating security policies and procedures
  • ✅ Responding to security incidents

Do NOT use for:

  • ❌ Specific code-level security patterns (use secure-code-review skill)
  • ❌ Threat modeling exercises (use threat-modeling skill)
  • ❌ Infrastructure security (use aws-cloudwatch-monitoring skill)

ISMS Framework Overview

┌─────────────────────────────────────────────────────────┐
│                  Hack23 ISMS Framework                   │
├─────────────────────────────────────────────────────────┤
│                                                         │
│  ┌──────────────┐  ┌──────────────┐  ┌──────────────┐  │
│  │ ISO 27001    │  │ NIST CSF 2.0 │  │ CIS Controls │  │
│  │ :2022        │  │              │  │ v8           │  │
│  │ 93 Controls  │  │ 6 Functions  │  │ 18 Controls  │  │
│  └──────────────┘  └──────────────┘  └──────────────┘  │
│                                                         │
│  ┌──────────────┐  ┌──────────────┐  ┌──────────────┐  │
│  │ NIS2         │  │ GDPR         │  │ EU CRA       │  │
│  │ Directive    │  │              │  │              │  │
│  │              │  │ Data Privacy │  │ Cyber        │  │
│  └──────────────┘  └──────────────┘  └──────────────┘  │
│                                                         │
│  Reference: github.com/Hack23/ISMS-PUBLIC               │
└─────────────────────────────────────────────────────────┘

Compliance Checklist Per Repository

Mandatory Documents
DocumentStatusDescription
SECURITY.mdRequiredSecurity policy and vulnerability reporting
SECURITY_ARCHITECTURE.mdRequiredSecurity architecture documentation
THREAT_MODEL.mdRequiredThreat model using STRIDE framework
LICENSE.txtRequiredApache 2.0 license file
CODEOWNERSRequiredCode ownership and review requirements
CODE_OF_CONDUCT.mdRequiredCommunity standards
Required GitHub Settings
  • Branch protection on main — require PR reviews
  • Secret scanning enabled with push protection
  • Dependabot alerts enabled for all ecosystems
  • Code scanning (CodeQL) enabled
  • OSSF Scorecard action configured
  • Signed commits required (recommended)
Required CI/CD Controls
  • OWASP Dependency Check in pipeline
  • SAST scanning (CodeQL or SonarCloud)
  • License compliance check
  • SBOM generation (CycloneDX)
  • Container scanning (if applicable)

ISO 27001:2022 Control Mapping

Key Controls for Development
Control IDControl NameImplementation
A.5.1Policies for information securitySECURITY.md, ISMS policies
A.8.4Access to source codeGitHub branch protection, CODEOWNERS
A.8.9Configuration managementInfrastructure as Code, version control
A.8.25Secure development lifecycleCI/CD pipeline with security gates
A.8.26Application security requirementsInput validation, OWASP Top 10
A.8.28Secure codingCode review, SAST scanning
A.8.31Separation of environmentsDev/staging/prod separation
A.8.33Test informationNo production data in test environments

NIST CSF 2.0 Mapping

FunctionCategoryCIA Platform Implementation
IdentifyAsset ManagementRepository inventory, SBOM
ProtectAccess ControlSpring Security, RBAC
ProtectData SecurityEncryption, input validation
DetectContinuous MonitoringCodeQL, Dependabot, OSSF
RespondIncident ResponseSECURITY.md reporting process
RecoverRecovery PlanningBackup procedures, DR plans

GDPR Compliance for Political Data

Data Classification
CategoryExamplesHandling
Public political dataVotes, speeches, motionsOpen access, no restrictions
Politician profilesName, party, committeePublic figure exception applies
User accountsEmail, preferencesMinimize, encrypt, consent required
Analytics dataUsage patternsAnonymize, aggregate
Show full SKILL.md (244 more words)Show less
GDPR Requirements Checklist
  • Data Processing Register maintained
  • Privacy Impact Assessment for new features
  • Data retention periods defined and enforced
  • Right to erasure implemented for user data
  • Data breach notification procedure documented
  • Third-party data processor agreements in place

Audit Preparation Guide

Pre-Audit Checklist
  1. Documentation Review

    • All mandatory documents up to date
    • Architecture diagrams current
    • Risk register reviewed within 90 days
  2. Technical Controls Verification

    • Run full security scan suite
    • Verify all CI/CD security gates active
    • Check dependency vulnerability status
    • Review access control configuration
  3. Evidence Collection

    bash
    # Generate compliance evidence
    mvn dependency-check:check           # Vulnerability scan
    mvn org.cyclonedx:cyclonedx-maven-plugin:makeBom  # SBOM
    mvn site                             # Project reports
  4. Metrics Preparation

    • Mean time to remediate vulnerabilities
    • Code coverage percentages
    • Open security issue count and age
    • Dependency update compliance rate

Policy Enforcement

Automated Enforcement
yaml
# Branch protection rules (enforce via GitHub API)
protection:
  required_reviews: 1
  dismiss_stale_reviews: true
  require_code_owner_reviews: true
  required_status_checks:
    - "build"
    - "codeql"
    - "dependency-check"
  enforce_admins: true
Manual Review Requirements
Change TypeReviewerApproval
Security policySecurity leadRequired
Architecture changeTech leadRequired
New dependencyAny reviewerRequired + security scan
CI/CD pipelineDevOps + SecurityBoth required
Data model changeTech leadRequired

Incident Response Alignment

When a security incident occurs:

  1. Detect — CodeQL alerts, Dependabot alerts, manual report via SECURITY.md
  2. Contain — Disable affected component, revoke compromised credentials
  3. Eradicate — Fix vulnerability, update dependencies
  4. Recover — Deploy fix, verify resolution
  5. Lessons Learned — Update threat model, create ADR if architectural change needed

ISMS Reference

The authoritative ISMS documentation is maintained at:

  • Repository: github.com/Hack23/ISMS-PUBLIC
  • Secure Development Policy: Secure_Development_Policy.md
  • Key Management Policy: Key_Management_Policy.md
  • Access Control Policy: Access_Control_Policy.md

All Hack23 projects must align with these organization-wide policies.

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/hack23-isms-compliance of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Hack23 Isms Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hack23 Isms Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hack23 Isms Compliance this skillHack23/cia239—~1.9kAutomated safety check: PassApache-2.0
X Raypashov/skills1.2k1 repos~10kAutomated safety check: PassMIT
Xray Pre Auditccashwell/evm-cortex131—~25kAutomated safety check: PassMIT
Hardening Windows Endpoint With Cis Benchmarkmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Hardening Linux Endpoint With Cis Benchmarkmukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: NotesApache-2.0
PCI DSS Compliancewshobson/agents40k10 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • X Ray

    pashov/skills

    Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…

    1.2k GitHub starsUsed in 1 repo~10k tokens
    SecurityAuto-check passed
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Hardening Windows Endpoint With Cis Benchmark

    mukul975/Anthropic-Cybersecurity-Skills

    Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements.

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hardening Linux Endpoint With Cis Benchmark

    mukul975/Anthropic-Cybersecurity-Skills

    Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements.

    34k GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • PCI DSS Compliance

    wshobson/agents

    Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

    40k GitHub starsUsed in 10 repos~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    849 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Questions about Hack23 Isms Compliance

What does Hack23 Isms Compliance do?

Hack23 ISMS organization-wide compliance requirements, policy enforcement, audit preparation. Hack23 Isms Compliance is an agent skill from Hack23/cia.

When should I use Hack23 Isms Compliance?

Hack23 Isms Compliance fits situations like: tasks that involve Audit readiness; tasks that involve Threat modeling.

How do I install Hack23 Isms Compliance in Claude Code?

Run `npx skills add Hack23/cia --skill hack23-isms-compliance -a claude-code`. Or copy the skill folder (.github/skills/hack23-isms-compliance in Hack23/cia) into .claude/skills/hack23-isms-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Hack23 Isms Compliance in Codex?

Run `npx skills add Hack23/cia --skill hack23-isms-compliance -a codex`. Or copy the skill folder (.github/skills/hack23-isms-compliance in Hack23/cia) into .agents/skills/hack23-isms-compliance in your project. Codex loads it when a task matches its description.

Can I use Hack23 Isms Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill hack23-isms-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hack23-isms-compliance, .gemini/skills/hack23-isms-compliance, .github/skills/hack23-isms-compliance and .opencode/skills/hack23-isms-compliance in your project.

What does Hack23 Isms Compliance need to run?

Going by SKILL.md and its folder, Hack23 Isms Compliance needs the command-line tools its instructions call (mvn).

Does Hack23 Isms Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hack23 Isms Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hack23 Isms Compliance use?

Hack23 Isms Compliance is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hack23 Isms Compliance use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hack23 Isms Compliance?

Skills that share tags, products or a category with Hack23 Isms Compliance: X Ray (pashov/skills, 1.2k stars), Xray Pre Audit (ccashwell/evm-cortex, 131 stars), Hardening Windows Endpoint With Cis Benchmark (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Hardening Linux Endpoint With Cis Benchmark (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hack23 Isms Compliance?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.