Install the "iso-27001-controls" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/iso-27001-controls into .claude/skills/iso-27001-controls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso-27001-controls", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add Hack23/cia --skill iso-27001-controls -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "iso-27001-controls" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/iso-27001-controls into .agents/skills/iso-27001-controls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso-27001-controls", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Hack23/cia --skill iso-27001-controls -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "iso-27001-controls" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/iso-27001-controls into .cursor/skills/iso-27001-controls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso-27001-controls", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add Hack23/cia --skill iso-27001-controls -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "iso-27001-controls" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/iso-27001-controls into .gemini/skills/iso-27001-controls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso-27001-controls", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
GitHub CLI
$ gh skill install Hack23/cia iso-27001-controls
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add Hack23/cia --skill iso-27001-controls -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "iso-27001-controls" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/iso-27001-controls into .github/skills/iso-27001-controls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso-27001-controls", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Hack23/cia --skill iso-27001-controls -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "iso-27001-controls" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/iso-27001-controls into .opencode/skills/iso-27001-controls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "iso-27001-controls", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
iso-27001-controls
GitHub stars
239
Token cost
~4.4k tokens
SKILL.md length
692 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0
At a glance
Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations
Works in 6 steps: Security requirements gathering → Threat modeling (STRIDE) → Secure coding standards → …
Tasks that involve SOC 2 and security compliance
SKILL.md covers Purpose, When to Use This Skill, Key ISO 27001:2022 Controls… and Control Implementation Checklist, plus 5 more sections
Calls mvn and docker-compose; needs SONAR_TOKEN
What it does
Iso 27001 Controls is an agent skill from Hack23/cia. Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations
Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering SOC 2 and security compliance. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.
When your agent uses it
Tasks that involve SOC 2 and security compliance
Example prompts
“/iso-27001-controls”
Requirements
Docker
A credential in SONAR_TOKEN
Workflow steps
6 steps, taken from the first numbered list in SKILL.md.
1Security requirements gathering
2Threat modeling (STRIDE)
3Secure coding standards
4Security testing (SAST, DAST)
5Security code reviews
6Vulnerability management
What it can do on your machine
Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
mvn
docker-compose
From the folder's file list and the shell code blocks in SKILL.md.
Network
Links to these hosts (documentation or services it may open):
github.com
iso.org
nist.gov
cisecurity.org
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names these keys or tokens, usually read from environment variables:
SONAR_TOKEN
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Iso 27001 Controls loads about 4.4k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 692 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~34
When it runs· the whole SKILL.md, loaded when a task matches
~4.4k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/iso-27001-controls/SKILL.md (or your agent's skills folder).
name
iso-27001-controls
description
Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations
license
Apache-2.0
ISO 27001:2022 Controls Implementation Skill
Purpose
This skill provides guidance for implementing and verifying ISO 27001:2022 Annex A controls within the CIA platform, ensuring systematic information security management aligned with Hack23 ISMS framework.
When to Use This Skill
Apply this skill when:
✅ Implementing new security controls
✅ Conducting ISMS audits or reviews
✅ Responding to security incidents
✅ Preparing for ISO 27001 certification audits
✅ Reviewing security architecture changes
✅ Updating security documentation
Key ISO 27001:2022 Controls for Software Development
A.5 - Organizational Controls
A.5.10 - Acceptable Use of Information
✅ Document acceptable use policy for CIA platform
✅ Define data classification (Public, Internal, Confidential, Restricted)
✅ Specify usage restrictions for political data
A.5.15 - Access Control
✅ Implement RBAC (Role-Based Access Control)
✅ Enforce least privilege principle
✅ Regular access reviews (quarterly)
A.5.17 - Authentication Information
✅ Strong password policy (12+ chars, complexity)
✅ MFA for privileged accounts
✅ Secure password storage (bcrypt, Argon2)
A.5.23 - Information Security for Cloud Services
✅ AWS security configuration review
✅ Cloud provider security assessment
✅ Data sovereignty compliance (EU GDPR)
A.8 - Technical Controls
A.8.1 - User Endpoint Devices
✅ Developer workstation security standards
✅ Encrypted disks (BitLocker, FileVault)
✅ Antivirus/EDR software required
A.8.2 - Privileged Access Rights
java
@Configuration
@EnableGlobalMethodSecurity(prePostEnabled = true)
public class MethodSecurityConfig {
@Bean
public RoleHierarchy roleHierarchy() {
RoleHierarchyImpl hierarchy = new RoleHierarchyImpl();
hierarchy.setHierarchy("ROLE_ADMIN > ROLE_USER\n" +
"ROLE_USER > ROLE_GUEST");
return hierarchy;
}
}
@Service
public class PrivilegedOperationService {
@PreAuthorize("hasRole('ADMIN')")
@Audited
public void modifySystemConfiguration(ConfigurationChange change) {
// Log privileged action
auditLogger.log("PRIVILEGED_ACTION", "System config modified", change);
// Perform operation
configurationRepository.save(change);
}
}
A.8.3 - Information Access Restriction
java
@Entity
@Table(name = "document")
public class Document {
@Id
private String id;
@Enumerated(EnumType.STRING)
private DataClassification classification; // PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED
private String ownerId;
@ElementCollection
private Set<String> authorizedUserIds;
}
@Service
public class DocumentAccessService {
public Document getDocument(String documentId, String userId) {
Document doc = documentRepository.findById(documentId)
.orElseThrow(() -> new ResourceNotFoundException("Document not found"));
// Enforce access control based on classification
if (!canAccess(doc, userId)) {
auditLogger.logAccessDenied(userId, documentId);
throw new AccessDeniedException("Insufficient permissions");
}
return doc;
}
private boolean canAccess(Document doc, String userId) {
switch (doc.getClassification()) {
case PUBLIC:
return true;
case INTERNAL:
return userService.isInternalUser(userId);
case CONFIDENTIAL:
return doc.getAuthorizedUserIds().contains(userId);
case RESTRICTED:
return doc.getOwnerId().equals(userId) ||
userService.isAdmin(userId);
default:
return false;
}
}
}
Iso 27001 Controls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations. Iso 27001 Controls is an agent skill from Hack23/cia.
When should I use Iso 27001 Controls?
Iso 27001 Controls fits situations like: tasks that involve SOC 2 and security compliance.
How do I install Iso 27001 Controls in Claude Code?
Run `npx skills add Hack23/cia --skill iso-27001-controls -a claude-code`. Or copy the skill folder (.github/skills/iso-27001-controls in Hack23/cia) into .claude/skills/iso-27001-controls in your project. Claude Code loads it when a task matches its description.
How do I install Iso 27001 Controls in Codex?
Run `npx skills add Hack23/cia --skill iso-27001-controls -a codex`. Or copy the skill folder (.github/skills/iso-27001-controls in Hack23/cia) into .agents/skills/iso-27001-controls in your project. Codex loads it when a task matches its description.
Can I use Iso 27001 Controls in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill iso-27001-controls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iso-27001-controls, .gemini/skills/iso-27001-controls, .github/skills/iso-27001-controls and .opencode/skills/iso-27001-controls in your project.
What does Iso 27001 Controls need to run?
Going by SKILL.md and its folder, Iso 27001 Controls needs the command-line tools its instructions call (mvn and docker-compose) and credentials named SONAR_TOKEN. Our summary lists: Docker; A credential in SONAR_TOKEN.
Does Iso 27001 Controls access the network?
SKILL.md names 4 domains. As links in the text: github.com, iso.org, nist.gov and cisecurity.org. This is read from the text; nothing was executed.
Is Iso 27001 Controls safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Iso 27001 Controls use?
Iso 27001 Controls is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Iso 27001 Controls use?
About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Iso 27001 Controls?
Skills that share tags, products or a category with Iso 27001 Controls: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars), Soc2 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars), Grc Knowledge (mlunato47/claude-grc-plugin, 183 stars) and Information Security Manager Iso27001 (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Iso 27001 Controls?
Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.
Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.