Agent skill

Implementing Pci Dss Compliance Controls

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Implements PCI DSS 4.0.1's 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data, including the customized validation approach, enhanced…

Apache-2.0Auto-check passedLegal & Compliance

Install Implementing Pci Dss Compliance Controls

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-pci-dss-compliance-controls -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-pci-dss-compliance-controls --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-pci-dss-compliance-controls .claude/skills/implementing-pci-dss-compliance-controls && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-pci-dss-compliance-controls
GitHub stars
34k
Token cost
~1.6k tokens
SKILL.md length
770 words
Files
7 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements PCI DSS 4.0.1's 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data, including the customized validation approach, enhanced…

  • Works in 6 steps: Scoping and Assessment (Weeks 1-4) → Network and System Security (Weeks 5-12) → Data Protection (Weeks 13-20) → …
  • Scoping a cardholder data environment
  • SKILL.md covers Overview, When to Use, Prerequisites and Core Concepts, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Implementing Pci Dss Compliance Controls is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements PCI DSS 4.0.1's 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data, including the customized validation approach, enhanced authentication, and continuous monitoring controls introduced by the 51 requirements mandatory since March 2025. Use when scoping a cardholder data environment, building PCI DSS 4.0.1 compliance controls, or preparing for a PCI assessment.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Scoping a cardholder data environment
  • Building PCI DSS 4.0.1 compliance controls
  • Preparing for a PCI assessment

Example prompts

  • “Use the implementing-pci-dss-compliance-controls skill to implement PCI DSS 4.0.1's 12 requirements across 6 control objectives for organizations…”
  • “/implementing-pci-dss-compliance-controls”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Scoping and Assessment (Weeks 1-4)
  2. Network and System Security (Weeks 5-12)
  3. Data Protection (Weeks 13-20)
  4. Access Controls (Weeks 21-28)
  5. Monitoring and Testing (Weeks 29-36)
  6. Policy and Governance (Weeks 37-42)

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • pcisecuritystandards.org
    • upguard.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Pci Dss Compliance Controls loads about 1.6k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 119 tokens; SKILL.md has 770 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~119
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 770 words, ~1,640 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-pci-dss-compliance-controls/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
implementing-pci-dss-compliance-controls
description
Implements PCI DSS 4.0.1's 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data, including the customized validation approach, enhanced authentication, and continuous monitoring controls introduced by the 51 requirements mandatory since March 2025. Use when scoping a cardholder data environment, building PCI DSS 4.0.1 compliance controls, or preparing for a PCI assessment.
domain
cybersecurity
subdomain
compliance-governance
tags
compliance, governance, pci-dss, payment-security, cardholder-data
nist_csf
GV.PO-01, PR.DS-01, PR.AA-01, DE.CM-01, ID.RA-01
version
1.0
author
mahipal
license
Apache-2.0
mitre_attack
T1078, T1530, T1685.002

Implementing PCI DSS Compliance Controls

Overview

PCI DSS 4.0.1 establishes 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data. With PCI DSS 3.2.1 retiring April 2024 and 51 new requirements becoming mandatory March 31, 2025, this skill covers implementing all requirements including the new customized validation approach, enhanced authentication, and continuous monitoring controls.

When to Use

  • When deploying or configuring implementing pci dss compliance controls capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Understanding of payment card processing flows and cardholder data environment (CDE)
  • Knowledge of network segmentation and security architecture
  • Access to cardholder data environment for scoping
  • Understanding of PCI compliance validation levels (merchant levels 1-4, service provider levels 1-2)

Core Concepts

12 PCI DSS Requirements by Control Objective

Build and Maintain a Secure Network and Systems

  1. Install and maintain network security controls (firewalls, NSCs)
  2. Apply secure configurations to all system components

Protect Account Data 3. Protect stored account data (encryption, tokenization, truncation) 4. Protect cardholder data with strong cryptography during transmission

Maintain a Vulnerability Management Program 5. Protect all systems and networks from malicious software 6. Develop and maintain secure systems and software

Implement Strong Access Control Measures 7. Restrict access to system components and cardholder data by business need to know 8. Identify users and authenticate access to system components 9. Restrict physical access to cardholder data

Regularly Monitor and Test Networks 10. Log and monitor all access to system components and cardholder data 11. Test security of systems and networks regularly

Maintain an Information Security Policy 12. Support information security with organizational policies and programs

Key PCI DSS 4.0 Changes
  • Customized Approach: Alternative to defined approach, allowing custom control design with objective-based validation
  • MFA for all CDE access: Extended beyond admin to all access to cardholder data (Req 8.4.2)
  • Targeted Risk Analysis: Organizations perform their own risk analysis for flexible requirements
  • Authenticated Vulnerability Scanning: Internal scans must use authenticated scanning (Req 11.3.1.1)
  • Anti-phishing mechanisms: Technical controls to detect and protect against phishing (Req 5.4.1)
  • Automated log review: Automated mechanisms for review of audit logs (Req 10.4.1.1)

Workflow

Phase 1: Scoping and Assessment (Weeks 1-4)
  1. Identify all cardholder data flows (card present, card not present, storage)
  2. Define Cardholder Data Environment (CDE) boundaries
  3. Validate network segmentation effectiveness
  4. Determine compliance validation level
  5. Conduct PCI DSS gap assessment against all 12 requirements
Phase 2: Network and System Security (Weeks 5-12)
  1. Deploy and configure network security controls (Req 1)
  2. Implement network segmentation to minimize CDE scope
  3. Harden system configurations using CIS Benchmarks (Req 2)
  4. Implement WAF for public-facing web applications (Req 6.4.1)
  5. Deploy anti-malware on all in-scope systems (Req 5)
Show full SKILL.md (301 more words)Show less
Phase 3: Data Protection (Weeks 13-20)
  1. Implement encryption for stored cardholder data (Req 3)
  2. Deploy tokenization where possible to reduce scope
  3. Enforce TLS 1.2+ for all cardholder data transmission (Req 4)
  4. Implement key management procedures
  5. Deploy data discovery tools to locate unencrypted cardholder data
Phase 4: Access Controls (Weeks 21-28)
  1. Implement RBAC based on business need to know (Req 7)
  2. Deploy MFA for all access to CDE (Req 8)
  3. Implement unique user IDs for all users
  4. Enforce password policies meeting PCI DSS 4.0 requirements
  5. Implement physical access controls for CDE facilities (Req 9)
Phase 5: Monitoring and Testing (Weeks 29-36)
  1. Deploy centralized logging for all CDE components (Req 10)
  2. Implement automated log review mechanisms
  3. Conduct internal and external vulnerability scans (Req 11)
  4. Perform penetration testing (internal and external)
  5. Implement file integrity monitoring (FIM) for critical files
Phase 6: Policy and Governance (Weeks 37-42)
  1. Develop comprehensive information security policy (Req 12)
  2. Implement security awareness training including anti-phishing
  3. Establish incident response plan specific to cardholder data
  4. Conduct targeted risk analyses for flexible requirements
  5. Document and validate all controls for assessment

Key Artifacts

  • CDE Scope Documentation and Network Diagrams
  • Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC)
  • Attestation of Compliance (AOC)
  • Quarterly ASV Scan Reports
  • Annual Penetration Test Report
  • Risk Assessment Documentation
  • Security Policies and Procedures

Common Pitfalls

  • Scope creep due to inadequate network segmentation
  • Storing prohibited data (CVV, full track data) after authorization
  • Missing the March 2025 deadline for new mandatory requirements
  • Treating PCI DSS as annual compliance rather than continuous security
  • Not including cloud and container environments in CDE scope

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references, assets) in skills/implementing-pci-dss-compliance-controls of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Pci Dss Compliance Controls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Pci Dss Compliance Controls compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Pci Dss Compliance Controls this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Fda Consultant Specialistdavila7/claude-code-templates33k1 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    33k GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing Pci Dss Compliance Controls

What does Implementing Pci Dss Compliance Controls do?

Implements PCI DSS 4.0.1's 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data, including the customized validation approach, enhanced…. Implementing Pci Dss Compliance Controls is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.1's 12 requirements across 6 control objectives for organizations that store, process, or transmit cardholder data, including the customized validation approach, enhanced authentication, and continuous monitoring controls introduced by the 51 requirements mandatory since March 2025.

When should I use Implementing Pci Dss Compliance Controls?

Implementing Pci Dss Compliance Controls fits situations like: scoping a cardholder data environment; building PCI DSS 4.0.1 compliance controls; preparing for a PCI assessment.

How do I install Implementing Pci Dss Compliance Controls in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-pci-dss-compliance-controls -a claude-code`. Or copy the skill folder (skills/implementing-pci-dss-compliance-controls in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-pci-dss-compliance-controls in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Pci Dss Compliance Controls in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-pci-dss-compliance-controls -a codex`. Or copy the skill folder (skills/implementing-pci-dss-compliance-controls in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-pci-dss-compliance-controls in your project. Codex loads it when a task matches its description.

Can I use Implementing Pci Dss Compliance Controls in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-pci-dss-compliance-controls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-pci-dss-compliance-controls, .gemini/skills/implementing-pci-dss-compliance-controls, .github/skills/implementing-pci-dss-compliance-controls and .opencode/skills/implementing-pci-dss-compliance-controls in your project.

What does Implementing Pci Dss Compliance Controls need to run?

Going by SKILL.md and its folder, Implementing Pci Dss Compliance Controls needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Pci Dss Compliance Controls access the network?

SKILL.md names 2 domains. As links in the text: pcisecuritystandards.org and upguard.com. This is read from the text; nothing was executed.

Is Implementing Pci Dss Compliance Controls safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Pci Dss Compliance Controls use?

Implementing Pci Dss Compliance Controls is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Pci Dss Compliance Controls use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Pci Dss Compliance Controls?

Skills that share tags, products or a category with Implementing Pci Dss Compliance Controls: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Pci Dss Compliance Controls?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.