Agent skill

804 Regulations Eu Nis2

by jabrena in jabrena/plinth

A skill your agent uses when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory.

Apache-2.0Auto-check passedDevOps & Cloud

Install 804 Regulations Eu Nis2

skills CLI
$ npx skills add jabrena/plinth --skill 804-regulations-eu-nis2 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jabrena/plinth 804-regulations-eu-nis2 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/804-regulations-eu-nis2 .claude/skills/804-regulations-eu-nis2 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
804-regulations-eu-nis2
GitHub stars
447
Token cost
~2.8k tokens
SKILL.md length
1,176 words
Files
4 (incl. references, assets)
Skills in repo
124
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory.

  • Modifying Java enterprise systems from a maintainer-authored
  • SKILL.md covers Scope, NIS2 Engineering Review, Constraints and When to use this skill, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Maintainer-sanitized NIS2 engineering evidence inventory

What it does

804 Regulations Eu Nis2 is an agent skill from jabrena/plinth. Use when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. Supports essential or important entities, critical-sector services, managed service providers, supply-chain dependencies, and cybersecurity incident escalation obligations without ingesting raw code, logs, runbooks, tickets, provider documents, or other operational free text. Part of Plinth Toolkit

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files and assets (for example `assets/reports/804-nis2-engineering-review-report-template.md`, `references/804-regulations-eu-nis2-chapters-summary.md` and `references/804-regulations-eu-nis2-engineering-examples.md`).

It sits in DevOps & Cloud, covering Runbooks and postmortems and Supply chain security. It works with Java. The repository describes itself as: Plinth is an AI-native engineering toolkit for modern Java enterprise SDLC, built around reusable Commands, Agents, Skills, and MCP Servers. The licence is Apache-2.0.

When your agent uses it

  • Modifying Java enterprise systems from a maintainer-authored
  • Maintainer-sanitized NIS2 engineering evidence inventory

Example prompts

  • “/804-regulations-eu-nis2”

What it can do on your machine

Read from SKILL.md and the folder at commit dca88dc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • eur-lex.europa.eu

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

804 Regulations Eu Nis2 loads about 2.8k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 1,176 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jabrena/plinth at commit dca88dc, republished under its Apache-2.0 licence (© jabrena). 1,176 words, ~2,842 tokens.

Download SKILL.mdSave it as .claude/skills/804-regulations-eu-nis2/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
804-regulations-eu-nis2
description
Use when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. Supports essential or important entities, critical-sector services, managed service providers, supply-chain dependencies, and cybersecurity incident escalation obligations without ingesting raw code, logs, runbooks, tickets, provider documents, or other operational free text. Part of Plinth Toolkit
license
Apache-2.0
metadata.author
Juan Antonio Breña Moral
metadata.version
0.19.0

NIS2 Regulation for Java Enterprise Cybersecurity Risk Management

Use this Skill to review Java enterprise applications, platforms, integrations, operational workflows, CI/CD pipelines, managed-service-provider tooling, or critical-sector services that may require NIS2-aware cybersecurity risk-management controls.

Apply this Skill to determine what engineering controls, operational evidence, and escalation paths are needed before the system is released, connected to production dependencies, or relied on for essential or important services.

Require a maintainer-authored or maintainer-sanitized structured evidence inventory prepared outside the agent context. Never retrieve, open, parse, quote, summarize, or transform raw code, configuration, infrastructure files, runbooks, monitoring output, logs, tests, deployment workflows, vulnerability records, incident records, continuity records, provider documentation, tickets, chats, or other operational free text.

This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, and reviewers identify when NIS2 concerns may apply and how to translate cybersecurity risk-management expectations into enterprise architecture controls such as asset and service inventories, dependency mapping, secure configuration, vulnerability handling, logging and monitoring, incident detection and escalation, backup and recovery, business continuity, supply-chain security, access control, cryptography, secure development, and change control.

The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, or a final regulatory determination.

The main question is:

When does a Java enterprise system require NIS2-aware cybersecurity controls, and what should developers build differently?

External reference: NIS2 Directive (EU) 2022/2555.

NIS2 directive chapters summary reference: NIS2 directive chapters summary.

Java engineering examples reference: NIS2 engineering examples.

Report template asset: NIS2 engineering review report template.

Scope

This Skill applies to:

  • Java systems supporting essential or important entities, critical-sector services, managed service providers, cloud or platform services, operational technology integrations, public-sector services, health, energy, transport, banking, financial-market infrastructure, digital infrastructure, or ICT service management
  • Spring Boot, Quarkus, Micronaut, and framework-agnostic Java services with cybersecurity risk-management, continuity, incident-readiness, or supply-chain security requirements
  • Systems with critical APIs, databases, message brokers, schedulers, batch jobs, IAM, secrets, observability, deployment pipelines, infrastructure dependencies, or external service providers
  • Incident detection, severity triage, escalation, evidence capture, backup and recovery, continuity, change control, secure configuration, vulnerability management, and operational assurance workflows
  • Dependency and provider reviews involving libraries, containers, CI/CD actions, SaaS platforms, managed databases, cloud services, observability providers, IAM providers, and external APIs

NIS2 Engineering Review

Treat entity classification, member-state applicability, incident-reporting obligations, and regulatory interpretation as governance decisions for legal, compliance, security, risk, resilience, business-continuity, and executive accountability owners.

Engineering teams should still create evidence that makes those decisions reviewable:

  • Which essential or important service depends on the Java system
  • Which assets, data stores, APIs, jobs, queues, credentials, providers, and deployment environments are in scope
  • Which cybersecurity risks, vulnerabilities, misconfigurations, and dependency exposures are identified and tracked
  • Which incidents can be detected, triaged, escalated, contained, reconstructed, and handed off
  • Which backup, recovery, continuity, rollback, and change-control evidence exists
  • Which supply-chain and provider risks are documented, monitored, and assigned to owners

Constraints

Translate NIS2 concerns into engineering controls for Java enterprise systems. Do not provide legal advice or replace review by legal, compliance, security, risk, resilience, business-continuity, procurement, or executive accountability owners.

  • NOT LEGAL ADVICE: Frame findings as cybersecurity engineering controls and escalation points; recommend qualified review for entity classification, member-state applicability, reporting obligations, and regulatory interpretation
  • SANITIZED EVIDENCE ONLY: Require a maintainer-authored or maintainer-sanitized structured evidence inventory; if it is missing or incomplete, stop and request a corrected inventory
  • NO RAW OPERATIONAL CONTENT: Never retrieve, open, parse, quote, summarize, or transform raw code, configuration, infrastructure files, runbooks, dashboards, monitoring output, logs, tests, deployment workflows, vulnerability or incident records, continuity records, provider documentation, tickets, chats, or other operational free text
  • SCOPE FIRST: Identify whether the system supports an essential entity, important entity, critical-sector service, managed service provider, or supply-chain dependency before recommending controls
  • ASSET AND SERVICE INVENTORY: Require traceable inventories for applications, APIs, jobs, data stores, queues, credentials, providers, deployment environments, network paths, and operational owners
  • CYBERSECURITY RISK MANAGEMENT: Review secure configuration, vulnerability handling, dependency management, hardening, patch evidence, risk acceptance, and exception ownership
  • INCIDENT READINESS: Verify detection, logging, monitoring, severity classification, escalation, containment, evidence capture, handoff, post-incident review, and corrective action paths
  • CONTINUITY CONTROLS: Review sanitized inventory facts about backup, restore, continuity, failover, rollback, capacity, recovery targets, runbook coverage, and tested recovery evidence
  • SUPPLY-CHAIN SECURITY: Do not treat libraries, build plugins, containers, CI/CD actions, SaaS tools, cloud services, managed databases, IAM, or observability providers as invisible dependencies
  • ACCESS AND CRYPTOGRAPHY: Verify least privilege, MFA signals, secrets management, credential rotation, secure transport, encryption, key ownership, and privileged operation auditability
  • CHANGE CONTROL: Treat releases, configuration changes, schema migrations, IAM changes, dependency upgrades, provider changes, and emergency fixes as cybersecurity risk events requiring traceable review
Show full SKILL.md (384 more words)Show less

When to use this skill

  • Review a Java platform for NIS2 cybersecurity controls
  • Design operational evidence for critical-sector or important services
  • Add incident detection, escalation, backup, recovery, continuity, or supply-chain security controls
  • Assess cybersecurity risk management before production release
  • Check whether Java service dependencies, CI/CD workflows, or provider integrations have NIS2-aware evidence

Workflow

  1. Read directive chapters summary, engineering examples, and report template

Read references/804-regulations-eu-nis2-chapters-summary.md, references/804-regulations-eu-nis2-engineering-examples.md, and assets/reports/804-nis2-engineering-review-report-template.md in that order. Use the directive chapters summary for NIS2 chapter, article, annex, scope, reporting, supervision, enforcement, and owner-handoff context. Use the engineering examples for Java control patterns such as asset and service inventory, incident detection and escalation, vulnerability and dependency evidence, backup and continuity evidence, supply-chain risk, secure change control, and Java release-policy controls. Do not start implementation review until the directive chapters summary, examples reference, and report template are understood.

  1. Classify the cybersecurity scope from sanitized facts

Use only the maintainer-prepared evidence inventory to identify service context, possible essential or important entity signals, sector signals, system owner, security owner, resilience owner, deployment environments, assets, data stores, messaging systems, IAM, secrets-management controls, third-party providers, recovery expectations, and incident pathways. Escalate unclear applicability, entity classification, member-state implementation, reporting obligations, or regulatory interpretation to legal, compliance, security, risk, resilience, or executive accountability owners.

  1. Review the sanitized engineering evidence inventory

Review only structured control facts and stable evidence references supplied in the maintainer-prepared inventory. Check for gaps between claimed controls and referenced evidence without following links or opening raw code, configuration, infrastructure files, runbooks, dashboards, monitoring output, logs, tests, deployment workflows, vulnerability or incident records, continuity records, or provider documentation.

  1. Recommend engineering controls

Map NIS2 concerns to engineering actions: asset and service inventory, secure configuration, dependency and vulnerability management, incident detection and escalation, evidence-safe logging, monitoring and alerting, backup and restore verification, continuity and rollback plans, supply-chain risk review, access control, cryptography, secure development, and change approval.

  1. Generate review report and owner handoffs

Use assets/reports/804-nis2-engineering-review-report-template.md to produce a concise engineering review with scope, sanitized evidence inventory entries, NIS2 risk signals, potential violation or non-compliance signals, engineering gaps, recommended controls, owner handoffs, residual risks, release decision, and validation steps. State explicitly that legal applicability, entity classification, reporting duties, and regulatory interpretation require qualified owner review.

Reference

For detailed guidance, examples, and constraints, see:

© jabrena, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references, assets) in skills/804-regulations-eu-nis2 of jabrena/plinth.

  • SKILL.md
  • assets/reports/804-nis2-engineering-review-report-template.md
  • references/804-regulations-eu-nis2-chapters-summary.md
  • references/804-regulations-eu-nis2-engineering-examples.md

Open the folder on GitHubat commit dca88dc

Compare with similar skills

804 Regulations Eu Nis2 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

804 Regulations Eu Nis2 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
804 Regulations Eu Nis2 this skilljabrena/plinth447—~2.8kAutomated safety check: PassApache-2.0
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Release Processpadamson/playwright-rust159—~4.2kAutomated safety check: PassApache-2.0
Code Assessmentadobe/skills197—~2.8kAutomated safety check: PassApache-2.0
Trader Memory Coretradermonty/claude-trading-skills3k2 repos~4.3kAutomated safety check: PassMIT
Author Migrationnrwl/nx29k—~12kAutomated safety check: NotesMIT

Similar skills

  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Release Process

    padamson/playwright-rust

    End-to-end release runbook for playwright-rust — version bump, supply-chain refresh, per-crate CHANGELOGs, tag-prefix routing for the three workspace crates, the safer push-then-tag workflow that…

    159 GitHub stars~4.2k tokensUpdated today
    Testing & QAAuto-check passed
  • Code Assessment

    adobe/skills

    Detect, review, and fix code-quality and correctness issues in an AEM as a Cloud Service project — locally, with no external services or network calls.

    197 GitHub stars~2.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Trader Memory Core

    tradermonty/claude-trading-skills

    Track investment theses across their lifecycle — from screening idea to closed position with postmortem.

    3k GitHub starsUsed in 2 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Author or scope a first-party Nx migration. An agent skill from nrwl/nx.

    29k GitHub stars~12k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Write Notes Like Deepseek

    czm15053/write-notes-like-deepseek

    A skill your agent uses when a change is non-trivial by DSH standards (behavior, architecture, cross-file contracts, process/tooling, testing strategy, or on-disk/wire/config formats), when choosing…

    508 GitHub stars~2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed

More from jabrena/plinth

All 124 skills in this repo
  • A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

    447 GitHub stars~874 tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when you need to generate Java project diagrams — including UML sequence diagrams, UML class diagrams, C4 model diagrams, UML state machine diagrams, UML Deployment Diagrams…

    447 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

    447 GitHub stars~3.2k tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when you need to set up JMeter performance testing for a Java project — including creating the run-jmeter.sh script from the exact template, configuring load tests with…

    447 GitHub stars~842 tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when you need to set up Java application profiling to detect and measure performance issues — including trusted preinstalled async-profiler v4.x setup, problem-driven…

    447 GitHub stars~903 tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when you need to generate a checklist document with embedded commands inventory, following the embedded template exactly and producing INVENTORY-COMMANDS-JAVA.md in the…

    447 GitHub stars~697 tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about 804 Regulations Eu Nis2

What does 804 Regulations Eu Nis2 do?

A skill your agent uses when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. 804 Regulations Eu Nis2 is an agent skill from jabrena/plinth. Use when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory.

When should I use 804 Regulations Eu Nis2?

804 Regulations Eu Nis2 fits situations like: modifying Java enterprise systems from a maintainer-authored; maintainer-sanitized NIS2 engineering evidence inventory.

How do I install 804 Regulations Eu Nis2 in Claude Code?

Run `npx skills add jabrena/plinth --skill 804-regulations-eu-nis2 -a claude-code`. Or copy the skill folder (skills/804-regulations-eu-nis2 in jabrena/plinth) into .claude/skills/804-regulations-eu-nis2 in your project. Claude Code loads it when a task matches its description.

How do I install 804 Regulations Eu Nis2 in Codex?

Run `npx skills add jabrena/plinth --skill 804-regulations-eu-nis2 -a codex`. Or copy the skill folder (skills/804-regulations-eu-nis2 in jabrena/plinth) into .agents/skills/804-regulations-eu-nis2 in your project. Codex loads it when a task matches its description.

Can I use 804 Regulations Eu Nis2 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jabrena/plinth --skill 804-regulations-eu-nis2 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/804-regulations-eu-nis2, .gemini/skills/804-regulations-eu-nis2, .github/skills/804-regulations-eu-nis2 and .opencode/skills/804-regulations-eu-nis2 in your project.

What does 804 Regulations Eu Nis2 need to run?

SKILL.md names no scripts, command-line tools or credentials: 804 Regulations Eu Nis2 is instructions for the agent only.

Does 804 Regulations Eu Nis2 access the network?

SKILL.md names 1 domain. As links in the text: eur-lex.europa.eu. This is read from the text; nothing was executed.

Is 804 Regulations Eu Nis2 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does 804 Regulations Eu Nis2 use?

804 Regulations Eu Nis2 is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does 804 Regulations Eu Nis2 use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9k tokens, read only when the agent opens those files.

What are the alternatives to 804 Regulations Eu Nis2?

Skills that share tags, products or a category with 804 Regulations Eu Nis2: Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), Release Process (padamson/playwright-rust, 159 stars), Code Assessment (adobe/skills, 197 stars) and Trader Memory Core (tradermonty/claude-trading-skills, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 804 Regulations Eu Nis2?

jabrena (a GitHub user) maintains it in jabrena/plinth, which has 447 GitHub stars. The repository holds 124 skills in this directory. The repository was last updated on October 7, 2026.

Source: jabrena/plinth on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.