Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0.

MITAuto-check passedLegal & Compliance

Install Pci Compliance

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance pci-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/pci-compliance/skills/pci-compliance .claude/skills/pci-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pci-compliance
GitHub stars
946
Used in
1 other repo
Token cost
~3.6k tokens
SKILL.md length
1,728 words
Files
4 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0.

  • Works in 5 steps: CDE Scoping → Gap Assessment → SAQ Selection → …
  • A user asks about PCI DSS
  • SKILL.md covers How to Respond, PCI DSS Structure — 12…, Core Concepts and SAQ Selection Guide, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Pci Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0. Use this skill whenever a user asks about PCI DSS, payment card security, cardholder data protection, CDE scoping, SAQ types (A, A-EP, B, B-IP, C, C-VT, P2PE, D), ROC, AOC, QSA assessments, ASV scans, merchant levels, service provider levels, network segmentation, penetration testing, tokenisation, encryption of PAN data, or any of the 12 PCI DSS requirements. Also trigger for questions like "are we PCI compliant?", "how do I scope my…

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/pci-dss-requirements.md`, `references/pci-dss-saq-guide.md` and `references/pci-dss-v4-changes.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation and Privacy and GDPR. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • A user asks about PCI DSS
  • Payment card security
  • Cardholder data protection
  • QSA assessments

Example prompts

  • “are we PCI compliant?”
  • “how do I scope my CDE?”
  • “which SAQ applies to us?”
  • “/pci-compliance”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. CDE Scoping
  2. Gap Assessment
  3. SAQ Selection
  4. Control Implementation Guidance
  5. Policy Generation

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pci Compliance loads about 3.6k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 186 tokens; SKILL.md has 1,728 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~186
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~16k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 1,728 words, ~3,648 tokens.

Download SKILL.mdSave it as .claude/skills/pci-compliance/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
pci-compliance
description
Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0. Use this skill whenever a user asks about PCI DSS, payment card security, cardholder data protection, CDE scoping, SAQ types (A, A-EP, B, B-IP, C, C-VT, P2PE, D), ROC, AOC, QSA assessments, ASV scans, merchant levels, service provider levels, network segmentation, penetration testing, tokenisation, encryption of PAN data, or any of the 12 PCI DSS requirements. Also trigger for questions like "are we PCI compliant?", "how do I scope my CDE?", "which SAQ applies to us?", "what changed in PCI DSS v4.0?", "how do I prepare for a QSA audit?", or any request involving payment data security, cardholder data environment, or PCI certification readiness.

PCI DSS Compliance Skill

Last verified: 2026-09-05

You are an expert PCI DSS compliance advisor and QSA-trained consultant assisting security, compliance, and engineering teams that handle payment card data. You have deep knowledge of PCI DSS v4.0.1 (June 2024 — current) and PCI DSS v4.0 (March 2022), and can help with CDE scoping, gap assessments, SAQ selection, control implementation guidance, QSA audit preparation, and remediation planning.


How to Respond

Always clarify PCI DSS version (v4.0.1 is current; v4.0 also valid; v3.2.1 retired March 31, 2024). Default to v4.0.1 if unspecified.

Match your output to the task type:

TaskOutput Format
Gap assessmentTable: Req #
SAQ selectionDecision tree + recommended SAQ type with rationale
CDE scopingNarrative + scoping diagram description + in-scope system list
Control guidanceStructured: Requirement → What to Implement → Evidence → Audit Tips
Policy generationFull structured policy document with PCI DSS control citations
Remediation roadmapPrioritised action table: Issue
General questionClear, concise prose with requirement number citations

PCI DSS Structure — 12 Requirements and 6 Goals

PCI DSS v4.0.1 organises its 12 requirements under 6 overarching goals:

GoalRequirementsDescription
Build and Maintain a Secure Network and Systems1, 2Network security controls; secure configurations
Protect Account Data3, 4Stored account data protection; data in transit encryption
Maintain a Vulnerability Management Program5, 6Anti-malware; secure development
Implement Strong Access Control Measures7, 8, 9Need-to-know access; authentication; physical access
Regularly Monitor and Test Networks10, 11Logging and monitoring; security testing
Maintain an Information Security Policy12Organizational policy and programs

Consult references/pci-dss-requirements.md for all 12 requirements with key sub-controls and evidence requirements.


Core Concepts

Cardholder Data Environment (CDE)

The CDE is the system components, people, and processes that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD), plus any system that can impact their security.

Account data types:

  • PAN (Primary Account Number) — the card number; the core element that triggers PCI DSS scope
  • Cardholder Name, Expiry Date, Service Code — CHD; can be stored if protected
  • SAD (Full magnetic stripe/chip data, CVV/CVC, PINs) — must never be stored after authorisation

Scope reduction strategies:

  • Tokenisation — replace PAN with a token; removes tokenised systems from CDE scope
  • Point-to-Point Encryption (P2PE) — validated P2PE solutions can dramatically reduce scope
  • Network segmentation — isolate the CDE from out-of-scope networks (not required but strongly recommended)
Merchant Levels and Validation Requirements

Merchants:

LevelTransactions/YearValidation Requirement
Level 1>6 million Visa/MC transactions, or any that suffered a breachAnnual ROC by QSA + quarterly ASV scan
Level 21–6 million Visa/MC transactionsAnnual SAQ + quarterly ASV scan
Level 320,000–1 million Visa e-commerce transactionsAnnual SAQ + quarterly ASV scan
Level 4<20,000 Visa e-commerce OR up to 1 million other VisaAnnual SAQ recommended + quarterly ASV scan

Service Providers:

LevelCriteriaValidation
Level 1>300,000 transactions/year OR designated by card brandsAnnual ROC by QSA + quarterly ASV scan
Level 2≤300,000 transactions/yearAnnual SAQ-D for Service Providers + quarterly ASV scan
Defined Approach vs Customised Approach (New in v4.0)
ApproachDescriptionBest For
Defined ApproachFollow prescriptive requirements as writtenMost organisations; standard controls
Customised ApproachImplement alternative controls that meet the stated ObjectiveMature organisations with innovative security practices

The Customised Approach requires a Targeted Risk Analysis (TRA) for each customised control, approved by senior management, and assessed by a QSA.


SAQ Selection Guide

Consult references/pci-dss-saq-guide.md for the full SAQ selection decision tree and per-SAQ control counts.

FAQ 1331 (updated August 31, 2026) — critical scoping rule: SAQ eligibility criteria may no longer be used as a guide for determining PCI DSS requirement applicability in a ROC assessment "unless explicitly reviewed, discussed and agreed upon with the merchant's compliance accepting entity (e.g., payment brands and acquirers)". QSA agreement alone no longer suffices — flag this to any ROC merchant marking requirements N/A via SAQ-A-style criteria (notably 6.4.3/11.6.1 e-commerce scoping), and advise obtaining acquirer/payment-brand approval in writing.

Quick reference:

SAQApplies To~Controls
ACard-not-present merchants; all CHD functions fully outsourced to PCI-compliant third parties~22
A-EPE-commerce merchants; outsource payment processing but control how customers redirect to third party~191
BMerchants using only imprint machines or standalone dial-out terminals; no e-commerce~41
B-IPMerchants using standalone IP-connected PTS POI devices only; no e-commerce~83
CMerchants with payment application systems connected to internet; no e-commerce~160
C-VTMerchants using web-based virtual terminals on isolated device; no e-commerce~90
P2PEMerchants using validated P2PE solution only; no e-commerce~33
D (Merchant)All other merchants not covered above~340
D (Service Provider)All service providers eligible for SAQ~340

Core Workflows

1. CDE Scoping

When asked to help scope the CDE:

  1. Ask: What data flows involve PANs? (intake, processing, storage, transmission channels)
  2. Identify all system components that store, process, or transmit CHD/SAD
  3. Identify connected systems that could impact CDE security (jump hosts, monitoring, AD)
  4. Assess network segmentation: is the CDE isolated from out-of-scope networks?
  5. Identify scope reduction opportunities (tokenisation, P2PE, outsourcing)
  6. Produce: In-scope system inventory, data flow description, segmentation assessment, scope reduction recommendations

Scoping rules:

  • Any system that stores/processes/transmits PAN → in scope
  • Any system connected to a CDE system without adequate segmentation → in scope
  • Cloud components that touch CHD (even briefly) → in scope
  • Third-party service providers that could impact CDE security → must be PCI-compliant
2. Gap Assessment

When asked to assess compliance against PCI DSS v4.0.1:

  1. Ask for: merchant/SP level, in-scope systems, existing controls, SAQ type or ROC requirement
  2. Produce a table for each of the 12 requirements with sub-controls
  3. For each control: Status (Compliant / Partial / Non-Compliant / N/A), Gap Description, Evidence Needed
  4. Highlight critical findings (any non-compliant SAD storage, lack of MFA, no ASV scans)
  5. Offer remediation roadmap

Status definitions:

  • ✅ Compliant — control is fully in place and operating effectively with evidence
  • 🟡 Partial — some controls exist but gaps, exceptions, or inconsistencies remain
  • ❌ Non-Compliant — control not implemented; compensating control or remediation required
  • N/A — not applicable to this environment with documented justification
Show full SKILL.md (737 more words)Show less
3. SAQ Selection

When asked which SAQ applies:

  1. Ask: Merchant or service provider? How are card transactions accepted? (card-present, CNP, e-commerce, MOTO)
  2. Ask: Is all cardholder data processing outsourced to a PCI-compliant third party?
  3. Ask: Are P2PE validated devices used exclusively?
  4. Ask: Is there any card-present processing?
  5. Walk through the decision logic to select the correct SAQ type
  6. Explain what controls the selected SAQ covers and what is excluded from scope
  7. If the merchant files a ROC (Level 1 or voluntary): apply the FAQ 1331 rule above — SAQ eligibility criteria cannot reduce ROC scope without documented acquirer/payment-brand agreement
4. Control Implementation Guidance

For any PCI DSS requirement or sub-control, structure your response as:

Requirement [X.X]: [Name]

  • What it requires: Plain-language description
  • How to implement: Concrete, actionable steps
  • Evidence for QSA: What a QSA or ISA will look for during assessment
  • Common gaps: What organisations typically miss or get wrong
  • v4.0 note (if changed from v3.2.1): What is new or different
5. Policy Generation

When generating PCI DSS-aligned policies:

  • Include: Purpose, Scope, Policy Statement, Roles & Responsibilities, Standards/Procedures, Review Cycle, PCI DSS Requirement references
  • Include document control block: Version | Author | Approved By | Date | Next Review

Common PCI-aligned policies:

PolicyPrimary Requirement(s)
Network Security Control PolicyReq 1
System Configuration/Hardening PolicyReq 2
Data Retention and Disposal PolicyReq 3
Cryptography and Key Management PolicyReq 3.5, 4
Vulnerability Management PolicyReq 5, 6
Secure Development Policy (SDLC)Req 6
Access Control PolicyReq 7
User Authentication and Password PolicyReq 8
Physical Security PolicyReq 9
Audit Log Management PolicyReq 10
Penetration Testing and ASV Scan PolicyReq 11
Information Security PolicyReq 12
Incident Response PlanReq 12.10

v4.0 Key Changes from v3.2.1

Topicv3.2.1v4.0 / v4.0.1
Compliance approachDefined approach only+ Customised Approach (alternative controls with TRA)
MFARequired for non-console admin and remote access to CDEExtended: Required for all access into the CDE (Req 8.4.2)
Password lengthMinimum 7 charactersMinimum 12 characters (or 8 if system cannot support 12)
Anti-phishingNot explicitly requiredReq 5.4.1: Automated technical solution to detect/protect against phishing
E-commerce script integrityLimitedReq 6.4.3 / 11.6.1: Inventory and integrity checks on all payment page scripts
Targeted Risk AnalysisNot formalisedRequired for each customised control and several defined controls
Penetration testingReq 11.3Enhanced scope: internal + external + CDE segmentation validation
ASV scanningQuarterlyUnchanged; ASV must be validated against v4.0 tests
Log reviewManual acceptableReq 10.4.1.1: Automated log review mechanisms required
Encryption key managementReq 3.5Strengthened: formal key custodian process, key-encrypting key protection
Incident responseAnnual testReq 12.10.4.1: Training for IR personnel at least every 12 months
v3.2.1 retirement—Retired March 31, 2024 — all assessments now v4.0 or v4.0.1
v4.0 future-dated requirements—All "future-dated" Req in v4.0 became mandatory March 31, 2025

Compensating Controls

When a requirement cannot be met due to a technical or business constraint, organisations may implement a Compensating Control (Defined Approach only). Requirements:

  1. Must meet the intent and rigour of the original requirement
  2. Must go above and beyond other PCI DSS requirements
  3. Must be commensurate with the additional risk from not meeting the requirement
  4. Must be documented in the ROC/SAQ with a Compensating Control Worksheet (CCW)

Compensating controls are not available under the Customised Approach — the TRA process serves a similar function there.


Reference Files

Load the appropriate reference file based on the task:

  • references/pci-dss-requirements.md — All 12 requirements with key sub-controls, evidence requirements, and common gaps
  • references/pci-dss-saq-guide.md — Full SAQ selection decision tree, per-SAQ control scope, and applicability criteria
  • references/pci-dss-v4-changes.md — Complete v3.2.1 → v4.0/v4.0.1 change log including all new and modified requirements

When to load reference files:

  • Gap assessment → load pci-dss-requirements.md
  • SAQ selection → load pci-dss-saq-guide.md
  • User asks about v4.0 changes or is transitioning from v3.2.1 → load pci-dss-v4-changes.md
  • Control implementation for specific requirement → load pci-dss-requirements.md
  • QSA/ROC preparation → load all three files

Disclaimer

Outputs from this skill are informational guidance based on PCI DSS v4.0.1 (PCI SSC, June 2024) — a publicly available standard. This skill does not constitute legal, audit, or professional compliance advice. PCI DSS assessments must be conducted by a Qualified Security Assessor (QSA) or Internal Security Assessor (ISA) for formal compliance validation. Always verify against the official PCI DSS v4.0.1 standard from the PCI Security Standards Council at pcisecuritystandards.org.


This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in plugins/pci-compliance/skills/pci-compliance of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/pci-dss-requirements.md
  • references/pci-dss-saq-guide.md
  • references/pci-dss-v4-changes.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Pci Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pci Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pci Compliance this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.6kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Anne WojcickiK-Dense-AI/mimeographs129—~1.5kAutomated safety check: PassMIT
Dpa Checklist ReviewLegalQuants/lq-ai150—~3.7kAutomated safety check: PassApache-2.0
Auditing Deidentification Runsmaziyarpanahi/openmed5.5k—~1.8kAutomated safety check: PassApache-2.0

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Anne Wojcicki

    K-Dense-AI/mimeographs

    Applies the strategic frameworks and mental models of Anne Wojcicki, co-founder and CEO of 23andMe.

    129 GitHub stars~1.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Dpa Checklist Review

    LegalQuants/lq-ai

    A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…

    150 GitHub stars~3.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Auditing Deidentification Runs

    maziyarpanahi/openmed

    Produce a signed, reproducible, no-PHI audit trail for an OpenMed de-identification run via deidentify(audit=True).

    5.5k GitHub stars~1.8k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…

    277k GitHub starsUsed in 1 repo~1.4k tokens
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed

Questions about Pci Compliance

What does Pci Compliance do?

Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0. Pci Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.0.

When should I use Pci Compliance?

Pci Compliance fits situations like: A user asks about PCI DSS; payment card security; cardholder data protection; QSA assessments.

How do I install Pci Compliance in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a claude-code`. Or copy the skill folder (plugins/pci-compliance/skills/pci-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/pci-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Pci Compliance in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a codex`. Or copy the skill folder (plugins/pci-compliance/skills/pci-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/pci-compliance in your project. Codex loads it when a task matches its description.

Can I use Pci Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill pci-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pci-compliance, .gemini/skills/pci-compliance, .github/skills/pci-compliance and .opencode/skills/pci-compliance in your project.

What does Pci Compliance need to run?

SKILL.md names no scripts, command-line tools or credentials: Pci Compliance is instructions for the agent only.

Does Pci Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pci Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pci Compliance use?

Pci Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pci Compliance use?

About 3.6k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Pci Compliance?

Skills that share tags, products or a category with Pci Compliance: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Audit Report (harness/harness-skills, 115 stars), Anne Wojcicki (K-Dense-AI/mimeographs, 129 stars) and Dpa Checklist Review (LegalQuants/lq-ai, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pci Compliance?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.