Kesekit Guide
cdppcorp/KESE-KIT
Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).
A skill your agent uses when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products…
$ npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jabrena/plinth 805-regulations-eu-cyber-resilience-act --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/805-regulations-eu-cyber-resilience-act .claude/skills/805-regulations-eu-cyber-resilience-act && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "805-regulations-eu-cyber-resilience-act" agent skill from https://github.com/jabrena/plinth/tree/main/skills/805-regulations-eu-cyber-resilience-act into .claude/skills/805-regulations-eu-cyber-resilience-act/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "805-regulations-eu-cyber-resilience-act", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jabrena/plinth/tree/main/skills/805-regulations-eu-cyber-resilience-actType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jabrena/plinth 805-regulations-eu-cyber-resilience-act --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/805-regulations-eu-cyber-resilience-act .agents/skills/805-regulations-eu-cyber-resilience-act && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "805-regulations-eu-cyber-resilience-act" agent skill from https://github.com/jabrena/plinth/tree/main/skills/805-regulations-eu-cyber-resilience-act into .agents/skills/805-regulations-eu-cyber-resilience-act/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "805-regulations-eu-cyber-resilience-act", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jabrena/plinth 805-regulations-eu-cyber-resilience-act --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/805-regulations-eu-cyber-resilience-act .cursor/skills/805-regulations-eu-cyber-resilience-act && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "805-regulations-eu-cyber-resilience-act" agent skill from https://github.com/jabrena/plinth/tree/main/skills/805-regulations-eu-cyber-resilience-act into .cursor/skills/805-regulations-eu-cyber-resilience-act/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "805-regulations-eu-cyber-resilience-act", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jabrena/plinth.git --path skills/805-regulations-eu-cyber-resilience-act--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jabrena/plinth 805-regulations-eu-cyber-resilience-act --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/805-regulations-eu-cyber-resilience-act .gemini/skills/805-regulations-eu-cyber-resilience-act && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "805-regulations-eu-cyber-resilience-act" agent skill from https://github.com/jabrena/plinth/tree/main/skills/805-regulations-eu-cyber-resilience-act into .gemini/skills/805-regulations-eu-cyber-resilience-act/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "805-regulations-eu-cyber-resilience-act", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jabrena/plinth 805-regulations-eu-cyber-resilience-actInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/805-regulations-eu-cyber-resilience-act .github/skills/805-regulations-eu-cyber-resilience-act && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "805-regulations-eu-cyber-resilience-act" agent skill from https://github.com/jabrena/plinth/tree/main/skills/805-regulations-eu-cyber-resilience-act into .github/skills/805-regulations-eu-cyber-resilience-act/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "805-regulations-eu-cyber-resilience-act", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jabrena/plinth 805-regulations-eu-cyber-resilience-act --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/805-regulations-eu-cyber-resilience-act .opencode/skills/805-regulations-eu-cyber-resilience-act && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "805-regulations-eu-cyber-resilience-act" agent skill from https://github.com/jabrena/plinth/tree/main/skills/805-regulations-eu-cyber-resilience-act into .opencode/skills/805-regulations-eu-cyber-resilience-act/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "805-regulations-eu-cyber-resilience-act", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
805-regulations-eu-cyber-resilience-actA skill your agent uses when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products…
805 Regulations Eu Cyber Resilience Act is an agent skill from jabrena/plinth. Use when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design, vulnerability handling, security update, SBOM, product documentation, or release-readiness controls. Part of Plinth Toolkit
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files and assets (for example `assets/reports/805-eu-cyber-resilience-act-engineering-review-report-template.md`, `references/805-regulations-eu-cyber-resilience-act-chapters-summary.md` and `references/805-regulations-eu-cyber-resilience-act-engineering-examples.md`).
It sits in Security, covering Supply chain security, Secure coding and Technical writing. It works with Java. The repository describes itself as: Plinth is an AI-native engineering toolkit for modern Java enterprise SDLC, built around reusable Commands, Agents, Skills, and MCP Servers. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit dca88dc. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
805 Regulations Eu Cyber Resilience Act loads about 3k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 1,233 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jabrena/plinth at commit dca88dc, republished under its Apache-2.0 licence (© jabrena). 1,233 words, ~2,996 tokens.
.claude/skills/805-regulations-eu-cyber-resilience-act/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Use this Skill to review Java enterprise applications, libraries, agents, plugins, connected components, platform modules, CI/CD workflows, product security documentation, and release evidence that may support products with digital elements under Regulation (EU) 2024/2847, the Cyber Resilience Act.
Apply this Skill to determine what secure-by-design controls, vulnerability handling evidence, update mechanisms, dependency and SBOM records, product documentation, support-period signals, and owner handoffs are needed before a product, component, or product-adjacent Java change is released or made available.
This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, product security teams, and reviewers identify when Cyber Resilience Act concerns may apply and how to translate product-security expectations into engineering controls such as secure defaults, threat modeling, least privilege, cryptography, sensitive-data-safe logging, coordinated vulnerability disclosure, security update delivery, SBOM evidence, product security documentation, end-of-support signaling, and release gates.
The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, a conformity assessment, a CE marking decision, or a final regulatory determination.
The main question is:
When does a Java product or product-adjacent component require EU Cyber Resilience Act-aware secure-by-design and vulnerability-handling controls, and what should developers build differently?
Source provenance: Cyber Resilience Act Regulation (EU) 2024/2847 was reviewed while authoring the bundled references. Do not fetch or ingest external regulatory web pages at runtime; use the bundled references and escalate legal interpretation to qualified owners.
Cyber Resilience Act chapters summary reference: Cyber Resilience Act chapters summary.
Java engineering examples reference: Cyber Resilience Act engineering examples.
Report template asset: Cyber Resilience Act engineering review report template.
This Skill applies to:
Treat product classification, economic-operator role, important or critical product category, conformity assessment route, CE marking implications, Article 14 reporting obligations, support-period legal interpretation, and regulatory interpretation as qualified decisions for legal, compliance, product, product-security, risk, market-access, and executive accountability owners.
Engineering teams should still create evidence that makes those decisions reviewable:
Translate Cyber Resilience Act concerns into engineering controls for Java products and product-adjacent systems. Do not provide legal advice or replace review by legal, compliance, product, security, product-security, market-access, risk, or executive accountability owners.
Read references/805-regulations-eu-cyber-resilience-act-chapters-summary.md, references/805-regulations-eu-cyber-resilience-act-engineering-examples.md, and assets/reports/805-eu-cyber-resilience-act-engineering-review-report-template.md in that order. Use the chapters summary for Cyber Resilience Act chapter, article, annex, scope, product-category, manufacturer, reporting, conformity, market-surveillance, enforcement, support-period, and owner-handoff context. Use the engineering examples for Java control patterns such as product security scope inventory, threat modeling and secure defaults, vulnerability and coordinated disclosure evidence, security update delivery, dependency and SBOM evidence, product documentation, end-of-support signaling, and release gates. Do not start implementation review until the chapters summary, examples reference, and report template are understood.
Identify the product, component, remote data processing solution, Java module, intended purpose, reasonably foreseeable use, possible product-with-digital-elements signal, possible important or critical product signal, economic-operator signals, support period, deployment environments, user population, update path, vulnerability intake path, dependencies, SBOM evidence, and product documentation. Escalate unclear product classification, economic-operator role, conformity assessment route, CE marking implications, Article 14 reporting duties, support-period interpretation, or regulatory interpretation to qualified legal, compliance, product, product-security, market-access, risk, or executive accountability owners.
Review Java code, configuration, product documentation, threat models, test evidence, CI/CD workflows, dependency inventories, SBOMs, vulnerability records, coordinated disclosure policy, update mechanisms, logging, cryptography, authentication, authorization, support-period notices, end-of-support behavior, release approvals, and user instructions. Check for gaps between claimed controls and reviewable evidence.
Map Cyber Resilience Act concerns to engineering actions: secure-by-design development, threat modeling, secure defaults, least privilege, authentication, authorization, cryptography, data minimization, sensitive-data-safe logging, attack-surface reduction, vulnerability management, coordinated disclosure, security update delivery, advisory publication, dependency and SBOM evidence, product security documentation, support-period disclosure, end-of-support signaling, and release readiness.
Use assets/reports/805-eu-cyber-resilience-act-engineering-review-report-template.md to produce a concise engineering review with scope, evidence reviewed, CRA product-security signals, potential violation or non-compliance signals, engineering gaps, recommended controls, owner handoffs, residual risks, release decision, and validation steps. State explicitly that product classification, economic-operator role, conformity assessment, CE marking implications, Article 14 reporting obligations, and regulatory interpretation require qualified owner review.
For detailed guidance, examples, and constraints, see:
© jabrena, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references, assets) in skills/805-regulations-eu-cyber-resilience-act of jabrena/plinth.
Open the folder on GitHubat commit dca88dc
805 Regulations Eu Cyber Resilience Act next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| 805 Regulations Eu Cyber Resilience Act this skilljabrena/plinth | 447 | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Kesekit Guidecdppcorp/KESE-KIT | 360 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Kesekit Startcdppcorp/KESE-KIT | 360 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| CodeQL Security Scantrailofbits/skills | 7.5k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Openfasttrace Reverse Specsitsallcode/openfasttrace | 197 | — | ~2.9k | Automated safety check: Pass | GPL-3.0 |
cdppcorp/KESE-KIT
Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).
cdppcorp/KESE-KIT
Run a security vulnerability assessment based on KISA guidelines.
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
itsallcode/openfasttrace
Reverse-engineer missing or incomplete OpenFastTrace system requirements and arc42-style design documentation from a project's user guide, existing documentation, tests, and code.
bodadotsh/npm-security-best-practices
Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.
jabrena/plinth
A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…
jabrena/plinth
A skill your agent uses when you need to generate Java project diagrams — including UML sequence diagrams, UML class diagrams, C4 model diagrams, UML state machine diagrams, UML Deployment Diagrams…
jabrena/plinth
A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…
jabrena/plinth
A skill your agent uses when you need to set up JMeter performance testing for a Java project — including creating the run-jmeter.sh script from the exact template, configuring load tests with…
jabrena/plinth
A skill your agent uses when you need to set up Java application profiling to detect and measure performance issues — including trusted preinstalled async-profiler v4.x setup, problem-driven…
jabrena/plinth
A skill your agent uses when you need to generate a checklist document with embedded commands inventory, following the embedded template exactly and producing INVENTORY-COMMANDS-JAVA.md in the…
Works with
Categories
A skill your agent uses when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products…. 805 Regulations Eu Cyber Resilience Act is an agent skill from jabrena/plinth. Use when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design, vulnerability handling, security update, SBOM, product documentation, or release-readiness controls.
805 Regulations Eu Cyber Resilience Act fits situations like: modifying Java enterprise products; connected components; platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design; vulnerability handling.
Run `npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a claude-code`. Or copy the skill folder (skills/805-regulations-eu-cyber-resilience-act in jabrena/plinth) into .claude/skills/805-regulations-eu-cyber-resilience-act in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a codex`. Or copy the skill folder (skills/805-regulations-eu-cyber-resilience-act in jabrena/plinth) into .agents/skills/805-regulations-eu-cyber-resilience-act in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/805-regulations-eu-cyber-resilience-act, .gemini/skills/805-regulations-eu-cyber-resilience-act, .github/skills/805-regulations-eu-cyber-resilience-act and .opencode/skills/805-regulations-eu-cyber-resilience-act in your project.
SKILL.md names no scripts, command-line tools or credentials: 805 Regulations Eu Cyber Resilience Act is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
805 Regulations Eu Cyber Resilience Act is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with 805 Regulations Eu Cyber Resilience Act: Kesekit Guide (cdppcorp/KESE-KIT, 360 stars), Kesekit Start (cdppcorp/KESE-KIT, 360 stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars) and CodeQL Security Scan (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jabrena (a GitHub user) maintains it in jabrena/plinth, which has 447 GitHub stars. The repository holds 124 skills in this directory. The repository was last updated on October 7, 2026.
Source: jabrena/plinth on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.