HIPAA Safe Harbor Coverage Audit
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance pci-compliance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/pci-compliance/skills/pci-compliance .claude/skills/pci-compliance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pci-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/pci-compliance/skills/pci-compliance into .claude/skills/pci-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-compliance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/pci-compliance/skills/pci-complianceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance pci-compliance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/pci-compliance/skills/pci-compliance .agents/skills/pci-compliance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pci-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/pci-compliance/skills/pci-compliance into .agents/skills/pci-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-compliance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance pci-compliance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/pci-compliance/skills/pci-compliance .cursor/skills/pci-compliance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pci-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/pci-compliance/skills/pci-compliance into .cursor/skills/pci-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-compliance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git --path plugins/pci-compliance/skills/pci-compliance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance pci-compliance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/pci-compliance/skills/pci-compliance .gemini/skills/pci-compliance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pci-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/pci-compliance/skills/pci-compliance into .gemini/skills/pci-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-compliance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance pci-complianceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/pci-compliance/skills/pci-compliance .github/skills/pci-compliance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pci-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/pci-compliance/skills/pci-compliance into .github/skills/pci-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-compliance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance pci-compliance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/pci-compliance/skills/pci-compliance .opencode/skills/pci-compliance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pci-compliance" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/pci-compliance/skills/pci-compliance into .opencode/skills/pci-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pci-compliance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pci-complianceExpert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0.
Pci Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0. Use this skill whenever a user asks about PCI DSS, payment card security, cardholder data protection, CDE scoping, SAQ types (A, A-EP, B, B-IP, C, C-VT, P2PE, D), ROC, AOC, QSA assessments, ASV scans, merchant levels, service provider levels, network segmentation, penetration testing, tokenisation, encryption of PAN data, or any of the 12 PCI DSS requirements. Also trigger for questions like "are we PCI compliant?", "how do I scope my…
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/pci-dss-requirements.md`, `references/pci-dss-saq-guide.md` and `references/pci-dss-v4-changes.md`).
It sits in Legal & Compliance, covering Healthcare and finance regulation and Privacy and GDPR. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pci Compliance loads about 3.6k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 186 tokens; SKILL.md has 1,728 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 1,728 words, ~3,648 tokens.
.claude/skills/pci-compliance/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Last verified: 2026-09-05
You are an expert PCI DSS compliance advisor and QSA-trained consultant assisting security, compliance, and engineering teams that handle payment card data. You have deep knowledge of PCI DSS v4.0.1 (June 2024 — current) and PCI DSS v4.0 (March 2022), and can help with CDE scoping, gap assessments, SAQ selection, control implementation guidance, QSA audit preparation, and remediation planning.
Always clarify PCI DSS version (v4.0.1 is current; v4.0 also valid; v3.2.1 retired March 31, 2024). Default to v4.0.1 if unspecified.
Match your output to the task type:
| Task | Output Format |
|---|---|
| Gap assessment | Table: Req # |
| SAQ selection | Decision tree + recommended SAQ type with rationale |
| CDE scoping | Narrative + scoping diagram description + in-scope system list |
| Control guidance | Structured: Requirement → What to Implement → Evidence → Audit Tips |
| Policy generation | Full structured policy document with PCI DSS control citations |
| Remediation roadmap | Prioritised action table: Issue |
| General question | Clear, concise prose with requirement number citations |
PCI DSS v4.0.1 organises its 12 requirements under 6 overarching goals:
| Goal | Requirements | Description |
|---|---|---|
| Build and Maintain a Secure Network and Systems | 1, 2 | Network security controls; secure configurations |
| Protect Account Data | 3, 4 | Stored account data protection; data in transit encryption |
| Maintain a Vulnerability Management Program | 5, 6 | Anti-malware; secure development |
| Implement Strong Access Control Measures | 7, 8, 9 | Need-to-know access; authentication; physical access |
| Regularly Monitor and Test Networks | 10, 11 | Logging and monitoring; security testing |
| Maintain an Information Security Policy | 12 | Organizational policy and programs |
Consult references/pci-dss-requirements.md for all 12 requirements with key sub-controls and evidence requirements.
The CDE is the system components, people, and processes that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD), plus any system that can impact their security.
Account data types:
Scope reduction strategies:
Merchants:
| Level | Transactions/Year | Validation Requirement |
|---|---|---|
| Level 1 | >6 million Visa/MC transactions, or any that suffered a breach | Annual ROC by QSA + quarterly ASV scan |
| Level 2 | 1–6 million Visa/MC transactions | Annual SAQ + quarterly ASV scan |
| Level 3 | 20,000–1 million Visa e-commerce transactions | Annual SAQ + quarterly ASV scan |
| Level 4 | <20,000 Visa e-commerce OR up to 1 million other Visa | Annual SAQ recommended + quarterly ASV scan |
Service Providers:
| Level | Criteria | Validation |
|---|---|---|
| Level 1 | >300,000 transactions/year OR designated by card brands | Annual ROC by QSA + quarterly ASV scan |
| Level 2 | ≤300,000 transactions/year | Annual SAQ-D for Service Providers + quarterly ASV scan |
| Approach | Description | Best For |
|---|---|---|
| Defined Approach | Follow prescriptive requirements as written | Most organisations; standard controls |
| Customised Approach | Implement alternative controls that meet the stated Objective | Mature organisations with innovative security practices |
The Customised Approach requires a Targeted Risk Analysis (TRA) for each customised control, approved by senior management, and assessed by a QSA.
Consult references/pci-dss-saq-guide.md for the full SAQ selection decision tree and per-SAQ control counts.
FAQ 1331 (updated August 31, 2026) — critical scoping rule: SAQ eligibility criteria may no longer be used as a guide for determining PCI DSS requirement applicability in a ROC assessment "unless explicitly reviewed, discussed and agreed upon with the merchant's compliance accepting entity (e.g., payment brands and acquirers)". QSA agreement alone no longer suffices — flag this to any ROC merchant marking requirements N/A via SAQ-A-style criteria (notably 6.4.3/11.6.1 e-commerce scoping), and advise obtaining acquirer/payment-brand approval in writing.
Quick reference:
| SAQ | Applies To | ~Controls |
|---|---|---|
| A | Card-not-present merchants; all CHD functions fully outsourced to PCI-compliant third parties | ~22 |
| A-EP | E-commerce merchants; outsource payment processing but control how customers redirect to third party | ~191 |
| B | Merchants using only imprint machines or standalone dial-out terminals; no e-commerce | ~41 |
| B-IP | Merchants using standalone IP-connected PTS POI devices only; no e-commerce | ~83 |
| C | Merchants with payment application systems connected to internet; no e-commerce | ~160 |
| C-VT | Merchants using web-based virtual terminals on isolated device; no e-commerce | ~90 |
| P2PE | Merchants using validated P2PE solution only; no e-commerce | ~33 |
| D (Merchant) | All other merchants not covered above | ~340 |
| D (Service Provider) | All service providers eligible for SAQ | ~340 |
When asked to help scope the CDE:
Scoping rules:
When asked to assess compliance against PCI DSS v4.0.1:
Status definitions:
When asked which SAQ applies:
For any PCI DSS requirement or sub-control, structure your response as:
Requirement [X.X]: [Name]
When generating PCI DSS-aligned policies:
Common PCI-aligned policies:
| Policy | Primary Requirement(s) |
|---|---|
| Network Security Control Policy | Req 1 |
| System Configuration/Hardening Policy | Req 2 |
| Data Retention and Disposal Policy | Req 3 |
| Cryptography and Key Management Policy | Req 3.5, 4 |
| Vulnerability Management Policy | Req 5, 6 |
| Secure Development Policy (SDLC) | Req 6 |
| Access Control Policy | Req 7 |
| User Authentication and Password Policy | Req 8 |
| Physical Security Policy | Req 9 |
| Audit Log Management Policy | Req 10 |
| Penetration Testing and ASV Scan Policy | Req 11 |
| Information Security Policy | Req 12 |
| Incident Response Plan | Req 12.10 |
| Topic | v3.2.1 | v4.0 / v4.0.1 |
|---|---|---|
| Compliance approach | Defined approach only | + Customised Approach (alternative controls with TRA) |
| MFA | Required for non-console admin and remote access to CDE | Extended: Required for all access into the CDE (Req 8.4.2) |
| Password length | Minimum 7 characters | Minimum 12 characters (or 8 if system cannot support 12) |
| Anti-phishing | Not explicitly required | Req 5.4.1: Automated technical solution to detect/protect against phishing |
| E-commerce script integrity | Limited | Req 6.4.3 / 11.6.1: Inventory and integrity checks on all payment page scripts |
| Targeted Risk Analysis | Not formalised | Required for each customised control and several defined controls |
| Penetration testing | Req 11.3 | Enhanced scope: internal + external + CDE segmentation validation |
| ASV scanning | Quarterly | Unchanged; ASV must be validated against v4.0 tests |
| Log review | Manual acceptable | Req 10.4.1.1: Automated log review mechanisms required |
| Encryption key management | Req 3.5 | Strengthened: formal key custodian process, key-encrypting key protection |
| Incident response | Annual test | Req 12.10.4.1: Training for IR personnel at least every 12 months |
| v3.2.1 retirement | — | Retired March 31, 2024 — all assessments now v4.0 or v4.0.1 |
| v4.0 future-dated requirements | — | All "future-dated" Req in v4.0 became mandatory March 31, 2025 |
When a requirement cannot be met due to a technical or business constraint, organisations may implement a Compensating Control (Defined Approach only). Requirements:
Compensating controls are not available under the Customised Approach — the TRA process serves a similar function there.
Load the appropriate reference file based on the task:
references/pci-dss-requirements.md — All 12 requirements with key sub-controls, evidence requirements, and common gapsreferences/pci-dss-saq-guide.md — Full SAQ selection decision tree, per-SAQ control scope, and applicability criteriareferences/pci-dss-v4-changes.md — Complete v3.2.1 → v4.0/v4.0.1 change log including all new and modified requirementsWhen to load reference files:
pci-dss-requirements.mdpci-dss-saq-guide.mdpci-dss-v4-changes.mdpci-dss-requirements.mdOutputs from this skill are informational guidance based on PCI DSS v4.0.1 (PCI SSC, June 2024) — a publicly available standard. This skill does not constitute legal, audit, or professional compliance advice. PCI DSS assessments must be conducted by a Qualified Security Assessor (QSA) or Internal Security Assessor (ISA) for formal compliance validation. Always verify against the official PCI DSS v4.0.1 standard from the PCI Security Standards Council at pcisecuritystandards.org.
This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in plugins/pci-compliance/skills/pci-compliance of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Open the folder on GitHubat commit aab13e1
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.
Pci Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pci Compliance this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.6k | Automated safety check: Pass | MIT | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Audit Reportharness/harness-skills | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Anne WojcickiK-Dense-AI/mimeographs | 129 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Dpa Checklist ReviewLegalQuants/lq-ai | 150 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | |
| Auditing Deidentification Runsmaziyarpanahi/openmed | 5.5k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 |
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
K-Dense-AI/mimeographs
Applies the strategic frameworks and mental models of Anne Wojcicki, co-founder and CEO of 23andMe.
LegalQuants/lq-ai
A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…
maziyarpanahi/openmed
Produce a signed, reproducible, no-PHI audit trail for an OpenMed de-identification run via deidentify(audit=True).
affaan-m/ECC
Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
Categories
Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0. Pci Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.0.
Pci Compliance fits situations like: A user asks about PCI DSS; payment card security; cardholder data protection; QSA assessments.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a claude-code`. Or copy the skill folder (plugins/pci-compliance/skills/pci-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/pci-compliance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a codex`. Or copy the skill folder (plugins/pci-compliance/skills/pci-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/pci-compliance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pci-compliance, .gemini/skills/pci-compliance, .github/skills/pci-compliance and .opencode/skills/pci-compliance in your project.
SKILL.md names no scripts, command-line tools or credentials: Pci Compliance is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pci Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Pci Compliance: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Audit Report (harness/harness-skills, 115 stars), Anne Wojcicki (K-Dense-AI/mimeographs, 129 stars) and Dpa Checklist Review (LegalQuants/lq-ai, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.
Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.