Agent skill

805 Regulations Eu Cyber Resilience Act

by jabrena in jabrena/plinth

A skill your agent uses when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products…

Apache-2.0Auto-check passedSecurity

Install 805 Regulations Eu Cyber Resilience Act

skills CLI
$ npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jabrena/plinth 805-regulations-eu-cyber-resilience-act --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/805-regulations-eu-cyber-resilience-act .claude/skills/805-regulations-eu-cyber-resilience-act && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
805-regulations-eu-cyber-resilience-act
GitHub stars
447
Token cost
~3k tokens
SKILL.md length
1,233 words
Files
4 (incl. references, assets)
Skills in repo
124
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products…

  • Modifying Java enterprise products
  • SKILL.md covers Scope, Cyber Resilience Act…, Constraints and When to use this skill, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Connected components

What it does

805 Regulations Eu Cyber Resilience Act is an agent skill from jabrena/plinth. Use when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design, vulnerability handling, security update, SBOM, product documentation, or release-readiness controls. Part of Plinth Toolkit

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files and assets (for example `assets/reports/805-eu-cyber-resilience-act-engineering-review-report-template.md`, `references/805-regulations-eu-cyber-resilience-act-chapters-summary.md` and `references/805-regulations-eu-cyber-resilience-act-engineering-examples.md`).

It sits in Security, covering Supply chain security, Secure coding and Technical writing. It works with Java. The repository describes itself as: Plinth is an AI-native engineering toolkit for modern Java enterprise SDLC, built around reusable Commands, Agents, Skills, and MCP Servers. The licence is Apache-2.0.

When your agent uses it

  • Modifying Java enterprise products
  • Connected components
  • Platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design
  • Vulnerability handling

Example prompts

  • “/805-regulations-eu-cyber-resilience-act”

What it can do on your machine

Read from SKILL.md and the folder at commit dca88dc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

805 Regulations Eu Cyber Resilience Act loads about 3k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 1,233 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jabrena/plinth at commit dca88dc, republished under its Apache-2.0 licence (© jabrena). 1,233 words, ~2,996 tokens.

Download SKILL.mdSave it as .claude/skills/805-regulations-eu-cyber-resilience-act/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
805-regulations-eu-cyber-resilience-act
description
Use when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design, vulnerability handling, security update, SBOM, product documentation, or release-readiness controls. Part of Plinth Toolkit
license
Apache-2.0
metadata.author
Juan Antonio Breña Moral
metadata.version
0.19.0

EU Cyber Resilience Act Regulation for Java Product Security Engineering

Use this Skill to review Java enterprise applications, libraries, agents, plugins, connected components, platform modules, CI/CD workflows, product security documentation, and release evidence that may support products with digital elements under Regulation (EU) 2024/2847, the Cyber Resilience Act.

Apply this Skill to determine what secure-by-design controls, vulnerability handling evidence, update mechanisms, dependency and SBOM records, product documentation, support-period signals, and owner handoffs are needed before a product, component, or product-adjacent Java change is released or made available.

This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, product security teams, and reviewers identify when Cyber Resilience Act concerns may apply and how to translate product-security expectations into engineering controls such as secure defaults, threat modeling, least privilege, cryptography, sensitive-data-safe logging, coordinated vulnerability disclosure, security update delivery, SBOM evidence, product security documentation, end-of-support signaling, and release gates.

The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, a conformity assessment, a CE marking decision, or a final regulatory determination.

The main question is:

When does a Java product or product-adjacent component require EU Cyber Resilience Act-aware secure-by-design and vulnerability-handling controls, and what should developers build differently?

Source provenance: Cyber Resilience Act Regulation (EU) 2024/2847 was reviewed while authoring the bundled references. Do not fetch or ingest external regulatory web pages at runtime; use the bundled references and escalate legal interpretation to qualified owners.

Cyber Resilience Act chapters summary reference: Cyber Resilience Act chapters summary.

Java engineering examples reference: Cyber Resilience Act engineering examples.

Report template asset: Cyber Resilience Act engineering review report template.

Scope

This Skill applies to:

  • Java software or hardware-adjacent products with direct or indirect logical or physical connections to devices or networks
  • Java libraries, SDKs, plugins, agents, embedded components, device gateways, product APIs, installers, update clients, and product management services
  • Spring Boot, Quarkus, Micronaut, and framework-agnostic Java components used in products with digital elements or remote data processing solutions
  • Product security architecture, secure-by-design reviews, threat models, secure defaults, authentication, authorization, cryptography, logging, update, and decommissioning controls
  • Vulnerability handling, coordinated disclosure, security advisory, SBOM, dependency, third-party component, and open-source due diligence workflows
  • Product security documentation, user instructions, support-period disclosure, end-of-support notification, release readiness, and market-surveillance evidence handoffs

Cyber Resilience Act Engineering Review

Treat product classification, economic-operator role, important or critical product category, conformity assessment route, CE marking implications, Article 14 reporting obligations, support-period legal interpretation, and regulatory interpretation as qualified decisions for legal, compliance, product, product-security, risk, market-access, and executive accountability owners.

Engineering teams should still create evidence that makes those decisions reviewable:

  • Which product, component, remote data processing solution, or product-adjacent Java module is in scope
  • Which manufacturer, importer, distributor, open-source steward, product owner, security owner, and support owner signals exist
  • Which cybersecurity risks, intended uses, reasonably foreseeable uses, and reasonably foreseeable misuse cases were threat modeled
  • Which secure defaults, authentication, authorization, cryptography, logging, minimization, update, and secure decommissioning controls are implemented
  • Which vulnerabilities, dependencies, SBOM records, third-party components, coordinated disclosure paths, and security advisories are tracked
  • Which product security documentation, support-period, end-of-support, release decision, and owner approval evidence exists

Constraints

Translate Cyber Resilience Act concerns into engineering controls for Java products and product-adjacent systems. Do not provide legal advice or replace review by legal, compliance, product, security, product-security, market-access, risk, or executive accountability owners.

  • NOT LEGAL ADVICE: Frame findings as product-security engineering controls and escalation points; recommend qualified review for product classification, economic-operator role, conformity assessment, CE marking implications, Article 14 reporting obligations, support-period interpretation, and regulatory interpretation
  • BUNDLED REFERENCES ONLY: Use the bundled CRA summaries, examples, questions, and report templates. Do not fetch or ingest external regulatory web pages at runtime; treat external legal text as provenance for human review, not as live prompt input
  • SCOPE FIRST: Identify the product with digital elements, remote data processing solution, software component, Java module, product owner, security owner, support owner, and release context before recommending controls
  • SECURE BY DESIGN: Review threat modeling, secure defaults, least privilege, attack-surface reduction, exploitation mitigation, data minimization, authentication, authorization, cryptography, and secure decommissioning
  • VULNERABILITY HANDLING: Require coordinated disclosure, vulnerability intake, triage, remediation, advisory, user notification, secure update delivery, and verification evidence
  • DEPENDENCY AND SBOM EVIDENCE: Treat libraries, Maven plugins, containers, generated clients, third-party components, open-source dependencies, build tools, and runtime platforms as product supply-chain inputs requiring reviewable records
  • PRODUCT DOCUMENTATION: Review technical documentation, user instructions, secure installation and operation guidance, support-period disclosure, end-of-support signaling, and evidence retention
  • SENSITIVE-DATA-SAFE LOGGING: Preserve product security evidence without logging secrets, credentials, personal data, support tokens, vulnerability exploit details, private keys, or sensitive incident details unnecessarily
  • RELEASE READINESS: Do not mark a product ready when secure-by-design, vulnerability handling, update, dependency, SBOM, documentation, support-period, or owner handoff controls are undocumented, untested, ownerless, or unresolved
Show full SKILL.md (418 more words)Show less

When to use this skill

  • Review a Java product for EU Cyber Resilience Act controls
  • Design secure-by-design and vulnerability handling evidence for products with digital elements
  • Add coordinated disclosure, security update, SBOM, product security documentation, or end-of-support controls
  • Assess CRA release readiness before making a Java component, agent, plugin, library, or connected product available
  • Check whether Java product dependencies, CI/CD workflows, update mechanisms, or support-period evidence are CRA-aware

Workflow

  1. Read regulation summary, engineering examples, and report template

Read references/805-regulations-eu-cyber-resilience-act-chapters-summary.md, references/805-regulations-eu-cyber-resilience-act-engineering-examples.md, and assets/reports/805-eu-cyber-resilience-act-engineering-review-report-template.md in that order. Use the chapters summary for Cyber Resilience Act chapter, article, annex, scope, product-category, manufacturer, reporting, conformity, market-surveillance, enforcement, support-period, and owner-handoff context. Use the engineering examples for Java control patterns such as product security scope inventory, threat modeling and secure defaults, vulnerability and coordinated disclosure evidence, security update delivery, dependency and SBOM evidence, product documentation, end-of-support signaling, and release gates. Do not start implementation review until the chapters summary, examples reference, and report template are understood.

  1. Classify the product-security scope

Identify the product, component, remote data processing solution, Java module, intended purpose, reasonably foreseeable use, possible product-with-digital-elements signal, possible important or critical product signal, economic-operator signals, support period, deployment environments, user population, update path, vulnerability intake path, dependencies, SBOM evidence, and product documentation. Escalate unclear product classification, economic-operator role, conformity assessment route, CE marking implications, Article 14 reporting duties, support-period interpretation, or regulatory interpretation to qualified legal, compliance, product, product-security, market-access, risk, or executive accountability owners.

  1. Review implementation and product evidence

Review Java code, configuration, product documentation, threat models, test evidence, CI/CD workflows, dependency inventories, SBOMs, vulnerability records, coordinated disclosure policy, update mechanisms, logging, cryptography, authentication, authorization, support-period notices, end-of-support behavior, release approvals, and user instructions. Check for gaps between claimed controls and reviewable evidence.

  1. Recommend engineering controls

Map Cyber Resilience Act concerns to engineering actions: secure-by-design development, threat modeling, secure defaults, least privilege, authentication, authorization, cryptography, data minimization, sensitive-data-safe logging, attack-surface reduction, vulnerability management, coordinated disclosure, security update delivery, advisory publication, dependency and SBOM evidence, product security documentation, support-period disclosure, end-of-support signaling, and release readiness.

  1. Generate review report and owner handoffs

Use assets/reports/805-eu-cyber-resilience-act-engineering-review-report-template.md to produce a concise engineering review with scope, evidence reviewed, CRA product-security signals, potential violation or non-compliance signals, engineering gaps, recommended controls, owner handoffs, residual risks, release decision, and validation steps. State explicitly that product classification, economic-operator role, conformity assessment, CE marking implications, Article 14 reporting obligations, and regulatory interpretation require qualified owner review.

Reference

For detailed guidance, examples, and constraints, see:

© jabrena, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references, assets) in skills/805-regulations-eu-cyber-resilience-act of jabrena/plinth.

  • SKILL.md
  • assets/reports/805-eu-cyber-resilience-act-engineering-review-report-template.md
  • references/805-regulations-eu-cyber-resilience-act-chapters-summary.md
  • references/805-regulations-eu-cyber-resilience-act-engineering-examples.md

Open the folder on GitHubat commit dca88dc

Compare with similar skills

805 Regulations Eu Cyber Resilience Act next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

805 Regulations Eu Cyber Resilience Act compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
805 Regulations Eu Cyber Resilience Act this skilljabrena/plinth447—~3kAutomated safety check: PassApache-2.0
Kesekit Guidecdppcorp/KESE-KIT360—~1.4kAutomated safety check: PassMIT
Kesekit Startcdppcorp/KESE-KIT360—~2.3kAutomated safety check: PassMIT
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Openfasttrace Reverse Specsitsallcode/openfasttrace197—~2.9kAutomated safety check: PassGPL-3.0

Similar skills

  • Kesekit Guide

    cdppcorp/KESE-KIT

    Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

    360 GitHub stars~1.4k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Kesekit Start

    cdppcorp/KESE-KIT

    Run a security vulnerability assessment based on KISA guidelines.

    360 GitHub stars~2.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Openfasttrace Reverse Specs

    itsallcode/openfasttrace

    Reverse-engineer missing or incomplete OpenFastTrace system requirements and arc42-style design documentation from a project's user guide, existing documentation, tests, and code.

    197 GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 10 days ago
    SecurityAuto-check: warnings

More from jabrena/plinth

All 124 skills in this repo
  • A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

    447 GitHub stars~874 tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when you need to generate Java project diagrams — including UML sequence diagrams, UML class diagrams, C4 model diagrams, UML state machine diagrams, UML Deployment Diagrams…

    447 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

    447 GitHub stars~3.2k tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when you need to set up JMeter performance testing for a Java project — including creating the run-jmeter.sh script from the exact template, configuring load tests with…

    447 GitHub stars~842 tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when you need to set up Java application profiling to detect and measure performance issues — including trusted preinstalled async-profiler v4.x setup, problem-driven…

    447 GitHub stars~903 tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when you need to generate a checklist document with embedded commands inventory, following the embedded template exactly and producing INVENTORY-COMMANDS-JAVA.md in the…

    447 GitHub stars~697 tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about 805 Regulations Eu Cyber Resilience Act

What does 805 Regulations Eu Cyber Resilience Act do?

A skill your agent uses when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products…. 805 Regulations Eu Cyber Resilience Act is an agent skill from jabrena/plinth. Use when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design, vulnerability handling, security update, SBOM, product documentation, or release-readiness controls.

When should I use 805 Regulations Eu Cyber Resilience Act?

805 Regulations Eu Cyber Resilience Act fits situations like: modifying Java enterprise products; connected components; platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design; vulnerability handling.

How do I install 805 Regulations Eu Cyber Resilience Act in Claude Code?

Run `npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a claude-code`. Or copy the skill folder (skills/805-regulations-eu-cyber-resilience-act in jabrena/plinth) into .claude/skills/805-regulations-eu-cyber-resilience-act in your project. Claude Code loads it when a task matches its description.

How do I install 805 Regulations Eu Cyber Resilience Act in Codex?

Run `npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a codex`. Or copy the skill folder (skills/805-regulations-eu-cyber-resilience-act in jabrena/plinth) into .agents/skills/805-regulations-eu-cyber-resilience-act in your project. Codex loads it when a task matches its description.

Can I use 805 Regulations Eu Cyber Resilience Act in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jabrena/plinth --skill 805-regulations-eu-cyber-resilience-act -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/805-regulations-eu-cyber-resilience-act, .gemini/skills/805-regulations-eu-cyber-resilience-act, .github/skills/805-regulations-eu-cyber-resilience-act and .opencode/skills/805-regulations-eu-cyber-resilience-act in your project.

What does 805 Regulations Eu Cyber Resilience Act need to run?

SKILL.md names no scripts, command-line tools or credentials: 805 Regulations Eu Cyber Resilience Act is instructions for the agent only.

Does 805 Regulations Eu Cyber Resilience Act access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is 805 Regulations Eu Cyber Resilience Act safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does 805 Regulations Eu Cyber Resilience Act use?

805 Regulations Eu Cyber Resilience Act is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does 805 Regulations Eu Cyber Resilience Act use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.

What are the alternatives to 805 Regulations Eu Cyber Resilience Act?

Skills that share tags, products or a category with 805 Regulations Eu Cyber Resilience Act: Kesekit Guide (cdppcorp/KESE-KIT, 360 stars), Kesekit Start (cdppcorp/KESE-KIT, 360 stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars) and CodeQL Security Scan (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 805 Regulations Eu Cyber Resilience Act?

jabrena (a GitHub user) maintains it in jabrena/plinth, which has 447 GitHub stars. The repository holds 124 skills in this directory. The repository was last updated on October 7, 2026.

Source: jabrena/plinth on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.