Agent skill

Pci Secure Software

by transilienceai in transilienceai/communitytools

Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.

MITAuto-check passedDevelopment

Install Pci Secure Software

skills CLI
$ npx skills add transilienceai/communitytools --skill pci-secure-software -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install transilienceai/communitytools pci-secure-software --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/transilienceai/communitytools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pci-secure-software .claude/skills/pci-secure-software && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pci-secure-software
GitHub stars
562
Token cost
~1.8k tokens
SKILL.md length
543 words
Files
28
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.

  • Works in 6 steps: INTAKE — scaffold the engagement… → APPLICABILITY — evidence-backed… → GATHER — per objective family, gather… → …
  • Asked to assess
  • SKILL.md covers About this skill, Persona — Asa, What you produce and The deterministic source of…, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Pci Secure Software is an agent skill from transilienceai/communitytools. Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation. Deterministically enumerates every applicable Test Requirement from a pinned catalog, gathers source/doc evidence, and emits an evidence-bound per-requirement verdict (MET / NOTMET / PARTIALLYMET / NOTAPPLICABLE / REQUIRESMANUALREVIEW) with file+line citations, then a Transilience gap report. Use when asked to assess, gap-assess, or check an application's readiness against the PCI…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 32 other files (for example `reference/INDEX.md`, `reference/VERSIONS.md` and `reference/agents/citation-verifier.md`).

It sits in Development, covering Architecture decision records and Citation management. The repository describes itself as: Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research. The licence is MIT.

When your agent uses it

  • Asked to assess
  • Check an applications readiness against the PCI Secure Software Standard v2.0 / PCI SSF
  • Map source code and design docs to PCI SSS Security Objectives and Test Requirements

Example prompts

  • “/pci-secure-software”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. INTAKE — scaffold the engagement OUTPUT_DIR; parse the scope file; fingerprint the tech stack (skills/techstack-identification); capture…
  2. APPLICABILITY — evidence-backed APPLICABLE/NOT_APPLICABLE per conditional Security Objective (4, 7) and Module (A/B/C/D); excluding any…
  3. GATHER — per objective family, gather source/doc evidence using the matching reference/scenarios/ playbook and reused sub-skills.
  4. DYNAMIC — where a requirement needs dynamic analysis and a running instance is authorized, perform it (incl. negative testing); otherwise…
  5. VERDICT + VERIFY — assign each Test Requirement a status with cited evidence; N blind adversarial refuters attack every MET…
  6. REPORT — coverage-gated gap report with the disclaimer + a Coverage & Limitations section listing every manual-review / quarantined /…

What it can do on your machine

Read from SKILL.md and the folder at commit 95fdc12. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pci Secure Software loads about 1.8k tokens when it runs. Until then it costs about 187 tokens; SKILL.md has 543 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~187
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from transilienceai/communitytools at commit 95fdc12, republished under its MIT licence (© transilienceai). 543 words, ~1,844 tokens.

Download SKILL.mdSave it as .claude/skills/pci-secure-software/SKILL.md (or your agent's skills folder). This skill also uses 27 other files; get the full folder from GitHub.
name
pci-secure-software
description
Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation. Deterministically enumerates every applicable Test Requirement from a pinned catalog, gathers source/doc evidence, and emits an evidence-bound per-requirement verdict (MET / NOT_MET / PARTIALLY_MET / NOT_APPLICABLE / REQUIRES_MANUAL_REVIEW) with file+line citations, then a Transilience gap report. Use when asked to assess, gap-assess, or check an application's readiness against the PCI Secure Software Standard v2.0 / PCI SSF, or to map source code and design docs to PCI SSS Security Objectives and Test Requirements. Produces a readiness gap-analysis only — NOT an official PCI validation.
model
opus
context
fork

pci-secure-software

About this skill

A knowledge layer + orchestration contract for running a forensically-defensible PCI Secure Software Standard (SSS) v2.0 readiness assessment of an application end-to-end, from its source code, design documentation, and dependency manifests. Every verdict is anchored to a real file:line + quoted snippet; every requirement comes from a pinned catalog, never model memory.

This is a readiness gap-analysis, not an official PCI validation. The PCI SSS defines no In-Place/Not-in-Place marking scheme — marking occurs solely in the ROV/AOV templates assessed by a qualified assessor. Say so in every report.

Persona — Asa

When you operate this tool you are Asa, a senior software-security assessor. Methodical, catalog-grounded, honest about scope. Walk the pipeline cleanly; one status line per phase. When evidence cannot prove a requirement, you record REQUIRES_MANUAL_REVIEW — never a convenient MET. You fail closed.

What you produce

Per applicable Test Requirement: a status verdict + the evidence that proves it (or the gap) + the why + a remediation suggestion. Aggregated into Compliance-Assessment-Report.pdf + compliance-report.json + tracker.csv, gated on 100% coverage and deterministic citation verification.

The deterministic source of truth

The requirement set is never generated by the model. It is loaded from the pinned catalog reference/catalog/pci-sss-v2.0.json (one entry per lettered Test Requirement) and filtered to the applicable set by tools/pci-sss/applicability.py. See reference/catalog/INDEX.md and reference/core/applicability.md.

6-phase pipeline

  1. INTAKE — scaffold the engagement OUTPUT_DIR; parse the scope file; fingerprint the tech stack (skills/techstack-identification); capture the 7-key AppContext.
  2. APPLICABILITY — evidence-backed APPLICABLE/NOT_APPLICABLE per conditional Security Objective (4, 7) and Module (A/B/C/D); excluding any unit requires negative evidence. Build the deterministic work-list. See reference/core/applicability.md.
  3. GATHER — per objective family, gather source/doc evidence using the matching reference/scenarios/ playbook and reused sub-skills.
  4. DYNAMIC — where a requirement needs dynamic analysis and a running instance is authorized, perform it (incl. negative testing); otherwise the requirement is REQUIRES_MANUAL_REVIEW, never a faked MET.
  5. VERDICT + VERIFY — assign each Test Requirement a status with cited evidence; N blind adversarial refuters attack every MET; tools/pci-sss/citation_verify.py greps every citation; quarantine + downgrade on miss; aggregate letter verdicts → requirement → objective.
  6. REPORT — coverage-gated gap report with the disclaimer + a Coverage & Limitations section listing every manual-review / quarantined / dynamic-not-run item.
Show full SKILL.md (194 more words)Show less

Running an assessment (sharded workflow)

The assessment runs as the pci-compliance workflow, sharded by Security Objective to respect the agent budget. From a project where this skill is mounted:

  1. Workflow('pci-compliance', { scope_file: 'projects/compliance/pci-sss-scope.md', mode: 'intake' }) → returns engagement_dir + applicable objectives.
  2. For each applicable objective O: Workflow('pci-compliance', { engagement_dir, mode: 'assess', objective: O }).
  3. Workflow('pci-compliance', { engagement_dir, mode: 'report' }) → Verify + Report.

Or mode: 'full' for a small app / max_requirements-limited run. Options: votes (default 3), maxConcurrent (default 4), dryRun, max_requirements.

When to load which reference

TriggerLoad
Need the applicable requirement settools/pci-sss/applicability.py + reference/catalog/INDEX.md
Deciding a status value / aggregationreference/core/schema.md
Deciding module / objective applicabilityreference/core/applicability.md
Assessing a specific objective familymatching reference/scenarios/ playbook
A MET verdict must be verifiedreference/anti-hallucination/citation-verifier.md
"Did you cover everything?"reference/anti-hallucination/coverage-gate.md
Spawning an assessor / refuter / verdict agentreference/agents/
Writing the deliverablereference/reporting/gap-report.md
Any version stringreference/VERSIONS.md

Anti-hallucination contract

Ten layers (full map in reference/anti-hallucination/control-stack.md): deterministic enumeration, 100% coverage gate, evidence-bound verdicts, a deterministic non-LLM citation-verifier, blind adversarial refutation, dynamic-analysis honesty, negative-evidence applicability, catalog fidelity self-test, append-only evidence, and independent blind re-verification.

Catalogue

reference/
├── INDEX.md                  reference router
├── VERSIONS.md               version pins (catalog / tools / standard)
├── core/                     schema.md (data contracts) + applicability.md (AppContext)
├── catalog/                  pci-sss-v2.0.json (the pinned source of truth) + INDEX.md
├── anti-hallucination/       control-stack, coverage-gate, citation-verifier
├── agents/                   evidence-gatherer, dynamic-tester, verdict-assessor, refutation-validator, citation-verifier
├── scenarios/                9 per-objective assessment playbooks
└── reporting/                gap-report (deliverable spec) + output-discipline (pointer)

The deterministic engine lives in tools/pci-sss/ (applicability.py, citation_verify.py, coverage_gate.py, aggregate.py, validate_catalog.py, build_catalog.py); the orchestration lives in .claude/workflows/pci-compliance.js.

References

reference/INDEX.md · reference/core/schema.md · reference/anti-hallucination/control-stack.md · reference/reporting/gap-report.md

© transilienceai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 27 other files in skills/pci-secure-software of transilienceai/communitytools.

  • SKILL.md
  • reference/INDEX.md
  • reference/VERSIONS.md
  • reference/agents/citation-verifier.md
  • reference/agents/dynamic-tester.md
  • reference/agents/evidence-gatherer.md
  • reference/agents/refutation-validator.md
  • reference/agents/verdict-assessor.md
  • reference/anti-hallucination/citation-verifier.md
  • reference/anti-hallucination/control-stack.md
  • reference/anti-hallucination/coverage-gate.md
  • reference/catalog/INDEX.md
  • reference/catalog/pci-sss-v2.0.json
  • reference/core/applicability.md
  • reference/core/schema.md
  • reference/reporting
  • … and 12 more

Open the folder on GitHubat commit 95fdc12

Compare with similar skills

Pci Secure Software next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pci Secure Software compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pci Secure Software this skilltransilienceai/communitytools562—~1.8kAutomated safety check: PassMIT
Agentic System Designooiyeefei/ccc494—~7.3kAutomated safety check: PassMIT
Tiger Releasesafreita1/TIGER164—~1.8kAutomated safety check: PassMIT
Track Ideacdiggins/plato106—~1.3kAutomated safety check: PassMIT
Web Debug Searchwanshuiyin/Auto-claude-code-research-in-sleep17k1 repos~3.7kAutomated safety check: PassMIT
Paper GraphEvoScientist/EvoSkills476—~7.1kAutomated safety check: PassApache-2.0

Similar skills

  • Prescriptive Q&A workflow for designing agentic pipelines, multi-model councils, sub-agent hierarchies, and tool-loop hardening for any domain.

    494 GitHub stars~7.3k tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Tiger Release

    safreita1/TIGER

    Prepare and publish a TIGER release by keeping implementation, tests, source and hosted documentation, citations, version metadata, GitHub, and PyPI artifacts synchronized.

    164 GitHub stars~1.8k tokensUpdated 26 days ago
    DevelopmentAuto-check passed
  • Track Idea

    cdiggins/plato

    Log a new idea into tracker/ with elaboration — assumptions, design decisions, related work links, approach brainstorm, and simplest implementation.

    106 GitHub stars~1.3k tokensUpdated 13 days ago
    DevelopmentAuto-check passed
  • Web Debug Search

    wanshuiyin/Auto-claude-code-research-in-sleep

    Search GitHub, Stack Exchange, Chinese technical communities, official documentation, and general developer web sources for software errors, compatibility problems, API usage questions, and…

    17k GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check passed
  • Paper Graph

    EvoScientist/EvoSkills

    Map the genealogical lineage and historical progression of a research field.

    476 GitHub stars~7.1k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • D365 Solution Blueprint

    github/awesome-copilot

    Official

    Authors a Dynamics 365 Finance and Supply Chain Management Solution Blueprint from scratch through a structured, section-by-section architect interview, establishing scope, target operating model…

    40k GitHub stars~2.7k tokensUpdated today
    DevelopmentAuto-check passed

More from transilienceai/communitytools

All 35 skills in this repo
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    562 GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Workflow

    transilienceai/communitytools

    GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.

    562 GitHub stars~812 tokensUpdated 2 mo ago
    Auto-check: notes
  • Protect With Password

    transilienceai/communitytools

    Generate ONE strong password and apply it to each referenced file (PDF, Word, Excel, PowerPoint, or any type).

    562 GitHub stars~583 tokensUpdated 2 mo ago
    Auto-check passed
  • Skill Update

    transilienceai/communitytools

    Skill creation, update and management — generates skill directory structure, validates against best practices, enforces line count limits.

    562 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Source Code Scanning

    transilienceai/communitytools

    Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

    562 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Transilience Report Style

    transilienceai/communitytools

    Generate a Transilience-branded PDF report (pentest, vuln assessment, compliance, threat intel) from a single findings JSON using the bundled ReportLab generator.

    562 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Pci Secure Software

What does Pci Secure Software do?

Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation. Pci Secure Software is an agent skill from transilienceai/communitytools.0 readiness gap-assessment of an application from its source code and documentation.

When should I use Pci Secure Software?

Pci Secure Software fits situations like: asked to assess; check an applications readiness against the PCI Secure Software Standard v2.0 / PCI SSF; map source code and design docs to PCI SSS Security Objectives and Test Requirements.

How do I install Pci Secure Software in Claude Code?

Run `npx skills add transilienceai/communitytools --skill pci-secure-software -a claude-code`. Or copy the skill folder (skills/pci-secure-software in transilienceai/communitytools) into .claude/skills/pci-secure-software in your project. Claude Code loads it when a task matches its description.

How do I install Pci Secure Software in Codex?

Run `npx skills add transilienceai/communitytools --skill pci-secure-software -a codex`. Or copy the skill folder (skills/pci-secure-software in transilienceai/communitytools) into .agents/skills/pci-secure-software in your project. Codex loads it when a task matches its description.

Can I use Pci Secure Software in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add transilienceai/communitytools --skill pci-secure-software -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pci-secure-software, .gemini/skills/pci-secure-software, .github/skills/pci-secure-software and .opencode/skills/pci-secure-software in your project.

What does Pci Secure Software need to run?

SKILL.md names no scripts, command-line tools or credentials: Pci Secure Software is instructions for the agent only.

Does Pci Secure Software access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pci Secure Software safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pci Secure Software use?

Pci Secure Software is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pci Secure Software use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pci Secure Software?

Skills that share tags, products or a category with Pci Secure Software: Agentic System Design (ooiyeefei/ccc, 494 stars), Tiger Release (safreita1/TIGER, 164 stars), Track Idea (cdiggins/plato, 106 stars) and Web Debug Search (wanshuiyin/Auto-claude-code-research-in-sleep, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pci Secure Software?

transilienceai (a GitHub organization) maintains it in transilienceai/communitytools, which has 562 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on July 29, 2026.

Source: transilienceai/communitytools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.