HIPAA Safe Harbor Coverage Audit
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
Implement PCI DSS requirements for payment card data. An agent skill from sickn33/agentic-awesome-skills.
$ npx skills add sickn33/agentic-awesome-skills --skill pci-dss-compliance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills pci-dss-compliance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pci-dss-compliance .claude/skills/pci-dss-compliance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pci-dss-compliance" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/pci-dss-compliance into .claude/skills/pci-dss-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-dss-compliance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/pci-dss-complianceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill pci-dss-compliance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills pci-dss-compliance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/pci-dss-compliance .agents/skills/pci-dss-compliance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pci-dss-compliance" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/pci-dss-compliance into .agents/skills/pci-dss-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-dss-compliance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill pci-dss-compliance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills pci-dss-compliance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/pci-dss-compliance .cursor/skills/pci-dss-compliance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pci-dss-compliance" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/pci-dss-compliance into .cursor/skills/pci-dss-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-dss-compliance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/pci-dss-compliance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill pci-dss-compliance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills pci-dss-compliance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/pci-dss-compliance .gemini/skills/pci-dss-compliance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pci-dss-compliance" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/pci-dss-compliance into .gemini/skills/pci-dss-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-dss-compliance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills pci-dss-complianceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill pci-dss-compliance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/pci-dss-compliance .github/skills/pci-dss-compliance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pci-dss-compliance" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/pci-dss-compliance into .github/skills/pci-dss-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-dss-compliance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill pci-dss-compliance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills pci-dss-compliance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/pci-dss-compliance .opencode/skills/pci-dss-compliance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pci-dss-compliance" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/pci-dss-compliance into .opencode/skills/pci-dss-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-dss-compliance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pci-dss-complianceImplement PCI DSS requirements for payment card data. An agent skill from sickn33/agentic-awesome-skills.
Pci Dss Compliance is an agent skill from sickn33/agentic-awesome-skills. Implement PCI DSS requirements for payment card data. Configure cardholder data environment and security controls. Use when processing payment cards.
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Checklist and framework guidance; no privileged tooling required. Apply controls through your own change process.
It sits in Legal & Compliance, covering Healthcare and finance regulation. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
Read from SKILL.md and the folder at commit 1c7bdea. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
awsyumaptFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Checklist and framework guidance; no privileged tooling required. Apply controls through your own change process.
From compatibility in the SKILL.md frontmatter.
Pci Dss Compliance loads about 4.5k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 264 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit 1c7bdea, republished under its MIT licence (© sickn33). 264 words, ~4,457 tokens.
.claude/skills/pci-dss-compliance/SKILL.md (or your agent's skills folder).Implement PCI DSS v4.0 requirements for protecting cardholder data across the Cardholder Data Environment (CDE), including network segmentation, encryption, access controls, and ongoing testing.
saq_types:
SAQ_A:
description: "Card-not-present merchants using fully outsourced payment"
applies_when:
- All payment processing fully outsourced to PCI-compliant third party
- No electronic storage, processing, or transmission of cardholder data
- Only payment page redirects or iframes from compliant provider
requirements: ~22 questions
SAQ_A_EP:
description: "E-commerce merchants with website that affects payment security"
applies_when:
- E-commerce channel only
- Website controls redirect to or loads payment page from third party
- No direct processing but website could affect transaction security
requirements: ~191 questions
SAQ_B:
description: "Merchants with only imprint machines or standalone terminals"
applies_when:
- Only standalone POS terminals (dial-out or IP connected)
- No electronic cardholder data storage
- No e-commerce channel
requirements: ~41 questions
SAQ_C:
description: "Merchants with payment application systems connected to internet"
applies_when:
- Payment application connected to internet
- No electronic cardholder data storage
- No e-commerce channel
requirements: ~160 questions
SAQ_D:
description: "All other merchants and all service providers"
applies_when:
- Stores cardholder data electronically
- Does not fit any other SAQ type
- Service providers eligible for SAQ D
requirements: "Full set of PCI DSS requirements"
scope_reduction_strategies:
- Use tokenization to replace PAN with non-sensitive tokens
- Use P2PE (Point-to-Point Encryption) validated solutions
- Outsource payment processing to reduce your CDE footprint
- Implement network segmentation to isolate CDErequirements:
req_1_network_security:
"1.1": "Network security controls defined and maintained"
"1.2": "Network security controls configured and maintained"
"1.3": "Network access to and from CDE is restricted"
"1.4": "Network connections between trusted and untrusted networks controlled"
"1.5": "Risks to CDE from devices connecting to untrusted networks mitigated"
req_2_secure_configuration:
"2.1": "Secure configuration standards defined and applied"
"2.2": "System components configured and managed securely"
req_3_protect_stored_data:
"3.1": "Processes for protecting stored account data defined"
"3.2": "Storage of account data is minimized"
"3.3": "Sensitive authentication data not stored after authorization"
"3.4": "PAN masked when displayed (first 6, last 4 maximum)"
"3.5": "PAN secured wherever stored"
"3.6": "Cryptographic keys managed securely"
"3.7": "Key management procedures documented"
req_4_transmission_encryption:
"4.1": "Strong cryptography protects cardholder data during transmission"
"4.2": "PAN protected when sent via end-user messaging"
req_5_malware_protection:
"5.1": "Processes to protect against malware defined"
"5.2": "Malware prevented or detected and addressed"
"5.3": "Anti-malware mechanisms active and maintained"
"5.4": "Anti-phishing mechanisms protect against phishing"
req_6_secure_development:
"6.1": "Secure development processes defined"
"6.2": "Bespoke and custom software developed securely"
"6.3": "Security vulnerabilities identified and addressed"
"6.4": "Public-facing web applications protected against attacks"
"6.5": "Changes to all system components managed securely"
req_7_access_restriction:
"7.1": "Access to system components and data restricted by business need"
"7.2": "Access appropriately defined and assigned"
"7.3": "Access to system components and data managed via access control"
req_8_user_identification:
"8.1": "Processes for user identification defined"
"8.2": "User identification and accounts managed"
"8.3": "Strong authentication established"
"8.4": "MFA implemented for all access into CDE"
"8.5": "MFA systems configured to prevent misuse"
"8.6": "System and application accounts managed"
req_9_physical_access:
"9.1": "Physical access controls defined"
"9.2": "Physical access to CDE managed"
"9.3": "Physical access for personnel and visitors authorized"
"9.4": "Media with cardholder data managed securely"
"9.5": "POI devices protected from tampering"
req_10_logging:
"10.1": "Audit logging processes defined"
"10.2": "Audit logs record required events"
"10.3": "Audit logs protected from destruction and modification"
"10.4": "Audit logs reviewed for anomalies"
"10.5": "Audit log history retained"
"10.6": "Time synchronization mechanisms configured"
"10.7": "Audit logs retained for at least 12 months (3 months immediately available)"
req_11_testing:
"11.1": "Security testing processes defined"
"11.2": "Wireless access points managed"
"11.3": "Vulnerabilities identified and addressed"
"11.4": "External and internal penetration testing performed"
"11.5": "Network intrusions and changes detected and responded to"
"11.6": "Unauthorized changes to payment pages detected"
req_12_policies:
"12.1": "Information security policy established"
"12.2": "Acceptable use policies defined"
"12.3": "Risks to CDE formally identified and managed"
"12.4": "PCI DSS compliance managed"
"12.5": "PCI DSS scope documented and validated"
"12.6": "Security awareness program"
"12.8": "Third-party service providers managed"
"12.9": "TPSPs acknowledge responsibility for cardholder data"
"12.10": "Security incidents responded to immediately" ┌──────────────────────────────────────┐
│ INTERNET │
└──────────────┬───────────────────────┘
│
┌──────────────▼───────────────────────┐
│ DMZ (Public Subnet) │
│ WAF → Load Balancer → Web Servers │
└──────────────┬───────────────────────┘
│ Firewall (Req 1.3)
┌──────────────▼───────────────────────┐
│ CDE (Cardholder Data Environment) │
│ ┌─────────┐ ┌──────────┐ │
│ │ Payment │ │ Card DB │ │
│ │ App │ │(encrypted)│ │
│ └─────────┘ └──────────┘ │
│ ┌─────────┐ ┌──────────┐ │
│ │Token Svc│ │ HSM/KMS │ │
│ └─────────┘ └──────────┘ │
└──────────────┬───────────────────────┘
│ Firewall (Req 1.3)
┌──────────────▼───────────────────────┐
│ Non-CDE (Corporate Network) │
│ App servers, internal tools │
│ (no cardholder data) │
└──────────────────────────────────────┘# AWS Security Group for CDE isolation
aws ec2 create-security-group \
--group-name cde-app-sg \
--description "CDE Application Security Group" \
--vpc-id vpc-CDE
# Allow only HTTPS from WAF/ALB
aws ec2 authorize-security-group-ingress \
--group-id sg-CDE-APP \
--protocol tcp --port 443 \
--source-group sg-ALB
# CDE database - only accessible from CDE app servers
aws ec2 create-security-group \
--group-name cde-db-sg \
--description "CDE Database Security Group" \
--vpc-id vpc-CDE
aws ec2 authorize-security-group-ingress \
--group-id sg-CDE-DB \
--protocol tcp --port 5432 \
--source-group sg-CDE-APP
# Deny all other inbound by default (security groups are deny-all by default in AWS)
# Document all rules for Req 1.2 - firewall/security group documentationencryption_requirements:
stored_data_req_3:
pan_encryption:
algorithm: AES-256
mode: GCM (preferred) or CBC with HMAC
key_storage: HSM or dedicated key management service
never_store:
- Full track data (magnetic stripe)
- CVV/CVC/CAV2
- PIN / PIN block
pan_display_masking:
rule: "Show maximum first 6 and last 4 digits"
examples:
masked: "4111 11** **** 1111"
acceptable_for_business: "First 6 and last 4"
implementation: "Apply masking at application layer before rendering"
key_management_req_3_6:
- Generate keys using approved random number generator
- Protect keys with key-encrypting keys (KEKs)
- Store key components separately (split knowledge, dual control)
- Rotate keys at least annually (or per crypto period)
- Retire and replace keys when compromised
- Document key custodian responsibilities
transmission_req_4:
protocols:
required: "TLS 1.2 or higher"
prohibited: "SSL, TLS 1.0, TLS 1.1"
cipher_suites:
preferred:
- TLS_AES_256_GCM_SHA384
- TLS_CHACHA20_POLY1305_SHA256
minimum: "128-bit key strength"
certificate_management:
- Use certificates from trusted CAs
- Verify hostname and certificate validity
- Monitor certificate expiration
tokenization_strategy:
description: "Replace PAN with non-reversible token to reduce CDE scope"
implementation:
- Use format-preserving tokens (same length/format as PAN)
- Token vault in isolated CDE segment
- Token-to-PAN mapping encrypted and access-controlled
- De-tokenization requires authenticated API call
- Log all de-tokenization requests
scope_benefit: "Systems using only tokens are out of PCI scope"# Req 11.3 - Internal vulnerability scanning (quarterly minimum)
# Using OpenVAS or Nessus
openvas-cli --scan-target 10.10.0.0/24 --scan-name "CDE-Quarterly-Scan" \
--profile "PCI DSS" --output pci-scan-$(date +%Y%m%d).xml
# Req 11.3 - External ASV scanning (quarterly, must pass)
# Schedule with Approved Scanning Vendor (Qualys, Tenable, etc.)
# ASV scan must show no vulnerabilities with CVSS >= 4.0
# Req 6.3 - Patch management
# Check for critical patches on CDE systems
yum check-update --security # RHEL/CentOS
apt list --upgradable 2>/dev/null | grep -i security # Debian/Ubuntu
# Req 11.4 - Penetration testing (annual for external, internal, and segmentation)
# Must be performed by qualified internal resource or third party
# Test both network layer and application layer
# Segmentation testing: verify CDE is isolated from non-CDE networks
# Req 11.5 - File integrity monitoring
# Using AIDE (Advanced Intrusion Detection Environment)
aide --init # Initialize baseline
aide --check # Compare against baseline
# OSSEC FIM configuration for CDE systems
# /var/ossec/etc/ossec.conf
# <syscheck>
# <frequency>3600</frequency>
# <directories check_all="yes">/etc,/usr/bin,/usr/sbin</directories>
# <directories check_all="yes">/opt/payment-app</directories>
# </syscheck>required_audit_events:
"10.2.1": "All individual user accesses to cardholder data"
"10.2.2": "All actions taken by any individual with root or admin privileges"
"10.2.3": "Access to all audit trails"
"10.2.4": "Invalid logical access attempts"
"10.2.5": "Changes to identification and authentication credentials"
"10.2.6": "Initialization, stopping, or pausing of audit logs"
"10.2.7": "Creation and deletion of system-level objects"
log_entry_requirements:
"10.3.1": "User identification"
"10.3.2": "Type of event"
"10.3.3": "Date and time"
"10.3.4": "Success or failure indication"
"10.3.5": "Origination of event"
"10.3.6": "Identity or name of affected data/resource"
retention:
minimum: "12 months total"
immediately_available: "At least 3 months"
archive: "Remaining months can be in archive storage"
time_synchronization:
"10.6.1": "Synchronize clocks using NTP"
"10.6.2": "Time data protected from unauthorized access"
"10.6.3": "Time settings received from industry-accepted sources"
ntp_config: |
# /etc/ntp.conf or chrony.conf for CDE systems
server 0.pool.ntp.org iburst
server 1.pool.ntp.org iburst
driftfile /var/lib/ntp/drift
restrict default nomodify notrap nopeer noquery
restrict 127.0.0.1pci_dss_checklist:
scoping:
- [ ] CDE boundaries identified and documented
- [ ] All in-scope systems inventoried
- [ ] Network segmentation validated
- [ ] Data flow diagrams current and accurate
- [ ] SAQ type determined (if applicable)
- [ ] Third-party service providers identified
network_security:
- [ ] Firewalls/security groups restrict CDE access
- [ ] Default deny rules on all CDE boundaries
- [ ] Wireless networks segmented from CDE
- [ ] Remote access uses MFA
- [ ] All firewall rules documented with business justification
- [ ] Rules reviewed semi-annually
data_protection:
- [ ] PAN masked when displayed (first 6, last 4 max)
- [ ] Stored PAN encrypted with AES-256 or equivalent
- [ ] Sensitive auth data not stored after authorization
- [ ] Encryption keys managed per Req 3.6/3.7
- [ ] TLS 1.2+ for all cardholder data transmission
- [ ] Tokenization implemented where feasible
access_control:
- [ ] Access restricted on need-to-know basis
- [ ] Unique IDs for all users
- [ ] MFA for all access into CDE
- [ ] MFA for all remote/non-console admin access
- [ ] Default/vendor passwords changed
- [ ] Shared/group accounts not used (or tightly controlled)
- [ ] Access reviewed at least every 6 months
monitoring:
- [ ] Audit logs capture all required events (Req 10.2)
- [ ] Log entries include all required fields (Req 10.3)
- [ ] Logs protected from modification
- [ ] Logs retained 12 months (3 months immediately available)
- [ ] Time synchronization configured (NTP)
- [ ] Daily log review process or automated alerting
- [ ] File integrity monitoring on critical files
testing:
- [ ] Internal vulnerability scans quarterly
- [ ] External ASV scans quarterly (passing)
- [ ] Internal penetration test annually
- [ ] External penetration test annually
- [ ] Segmentation test annually (or after changes)
- [ ] Web application assessment annually (or WAF deployed)
- [ ] IDS/IPS monitoring all CDE network traffic
policies:
- [ ] Information security policy reviewed annually
- [ ] Security awareness training for all personnel
- [ ] Incident response plan documented and tested
- [ ] Third-party service provider compliance confirmed
- [ ] Risk assessment performed annuallyMap this skill's control checklist to our current evidence and list gaps.Adapted from BagelHole/DevOps-Security-Agent-Skills (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.
© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/pci-dss-compliance of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit 1c7bdea
We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Pci Dss Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pci Dss Compliance this skillsickn33/agentic-awesome-skills | 47k | 2 repos | ~4.5k | Automated safety check: Pass | MIT | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed | 5.5k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~4.6k | Automated safety check: Notes | MIT | |
| Fda Consultant Specialistdavila7/claude-code-templates | 33k | 1 repos | ~2.7k | Automated safety check: Pass | MIT |
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
K-Dense-AI/scientific-agent-skills
Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.
davila7/claude-code-templates
Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.
mlunato47/claude-grc-plugin
Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Categories
Implement PCI DSS requirements for payment card data. An agent skill from sickn33/agentic-awesome-skills. Pci Dss Compliance is an agent skill from sickn33/agentic-awesome-skills. Implement PCI DSS requirements for payment card data.
Pci Dss Compliance fits situations like: processing payment cards; tasks that involve Healthcare and finance regulation.
Run `npx skills add sickn33/agentic-awesome-skills --skill pci-dss-compliance -a claude-code`. Or copy the skill folder (skills/pci-dss-compliance in sickn33/agentic-awesome-skills) into .claude/skills/pci-dss-compliance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill pci-dss-compliance -a codex`. Or copy the skill folder (skills/pci-dss-compliance in sickn33/agentic-awesome-skills) into .agents/skills/pci-dss-compliance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill pci-dss-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pci-dss-compliance, .gemini/skills/pci-dss-compliance, .github/skills/pci-dss-compliance and .opencode/skills/pci-dss-compliance in your project.
Going by SKILL.md and its folder, Pci Dss Compliance needs the command-line tools its instructions call (aws, yum and apt). Compatibility (from SKILL.md): Checklist and framework guidance; no privileged tooling required. Apply controls through your own change process..
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pci Dss Compliance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pci Dss Compliance: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,443 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 10, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.