Agent skill

PCI DSS Compliance

by wshobson in wshobson/agents

Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

MITAuto-check passedLegal & Compliance

Install PCI DSS Compliance

skills CLI
$ npx skills add wshobson/agents --skill pci-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install wshobson/agents pci-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/payment-processing/skills/pci-compliance .claude/skills/pci-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pci-compliance
GitHub stars
40k
Used in
11 other repos
Token cost
~1.9k tokens
SKILL.md length
247 words
Files
2 (incl. references)
Skills in repo
142
Repo updated
First seen
Licence
MIT

At a glance

Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

  • Works in 2 steps: Install and maintain firewall… → Don't use vendor-supplied defaults for…
  • Building a checkout or payment flow that touches card data
  • SKILL.md covers When to Use This Skill, PCI DSS Requirements (12 Core…, Compliance Levels and Data Minimization (Never Store), plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The skill walks through the 12 core PCI DSS requirements, grouped under building a secure network, protecting cardholder data, vulnerability management, access control, monitoring and testing, and keeping a security policy. It also sets out four compliance levels based on yearly transaction volume, from Level 1 with an annual ROC to Level 4 for smaller merchants.

On the engineering side it includes Python examples for data minimization (a list of data that must never be stored), tokenization with Stripe processor tokens and with a custom approach, encryption at rest with AES-GCM, and encryption in transit using TLS with secure session cookies. Further patterns and templates are referenced at the end.

When your agent uses it

  • Building a checkout or payment flow that touches card data
  • Reducing PCI scope with tokenization
  • Preparing for a PCI DSS assessment or audit
  • Reviewing what cardholder data a system stores and how it is encrypted

Example prompts

  • “Review our payment service and list every place cardholder data is stored.”
  • “Replace raw card numbers in our orders table with processor tokens.”
  • “Walk me through the SAQ and ROC requirements for our merchant level.”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Install and maintain firewall configuration
  2. Don't use vendor-supplied defaults for passwords

What it can do on your machine

Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PCI DSS Compliance loads about 1.9k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 58 tokens; SKILL.md has 247 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 247 words, ~1,924 tokens.

Download SKILL.mdSave it as .claude/skills/pci-compliance/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
pci-compliance
description
Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card security measures.

PCI Compliance

Master PCI DSS (Payment Card Industry Data Security Standard) compliance for secure payment processing and handling of cardholder data.

When to Use This Skill

  • Building payment processing systems
  • Handling credit card information
  • Implementing secure payment flows
  • Conducting PCI compliance audits
  • Reducing PCI compliance scope
  • Implementing tokenization and encryption
  • Preparing for PCI DSS assessments

PCI DSS Requirements (12 Core Requirements)

Build and Maintain Secure Network
  1. Install and maintain firewall configuration
  2. Don't use vendor-supplied defaults for passwords
Protect Cardholder Data
  1. Protect stored cardholder data
  2. Encrypt transmission of cardholder data across public networks
Maintain Vulnerability Management
  1. Protect systems against malware
  2. Develop and maintain secure systems and applications
Implement Strong Access Control
  1. Restrict access to cardholder data by business need-to-know
  2. Identify and authenticate access to system components
  3. Restrict physical access to cardholder data
Monitor and Test Networks
  1. Track and monitor all access to network resources and cardholder data
  2. Regularly test security systems and processes
Maintain Information Security Policy
  1. Maintain a policy that addresses information security

Compliance Levels

Level 1: > 6 million transactions/year (annual ROC required) Level 2: 1-6 million transactions/year (annual SAQ) Level 3: 20,000-1 million e-commerce transactions/year Level 4: < 20,000 e-commerce or < 1 million total transactions

Data Minimization (Never Store)

python
# NEVER STORE THESE
PROHIBITED_DATA = {
    'full_track_data': 'Magnetic stripe data',
    'cvv': 'Card verification code/value',
    'pin': 'PIN or PIN block'
}

# CAN STORE (if encrypted)
ALLOWED_DATA = {
    'pan': 'Primary Account Number (card number)',
    'cardholder_name': 'Name on card',
    'expiration_date': 'Card expiration',
    'service_code': 'Service code'
}

class PaymentData:
    """Safe payment data handling."""

    def __init__(self):
        self.prohibited_fields = ['cvv', 'cvv2', 'cvc', 'pin']

    def sanitize_log(self, data):
        """Remove sensitive data from logs."""
        sanitized = data.copy()

        # Mask PAN
        if 'card_number' in sanitized:
            card = sanitized['card_number']
            sanitized['card_number'] = f"{card[:6]}{'*' * (len(card) - 10)}{card[-4:]}"

        # Remove prohibited data
        for field in self.prohibited_fields:
            sanitized.pop(field, None)

        return sanitized

    def validate_no_prohibited_storage(self, data):
        """Ensure no prohibited data is being stored."""
        for field in self.prohibited_fields:
            if field in data:
                raise SecurityError(f"Attempting to store prohibited field: {field}")

Tokenization

Using Payment Processor Tokens
python
import stripe

class TokenizedPayment:
    """Handle payments using tokens (no card data on server)."""

    @staticmethod
    def create_payment_method_token(card_details):
        """Create token from card details (client-side only)."""
        # THIS SHOULD ONLY BE DONE CLIENT-SIDE WITH STRIPE.JS
        # NEVER send card details to your server

        """
        // Frontend JavaScript
        const stripe = Stripe('pk_...');

        const {token, error} = await stripe.createToken({
            card: {
                number: '4242424242424242',
                exp_month: 12,
                exp_year: 2024,
                cvc: '123'
            }
        });

        // Send token.id to server (NOT card details)
        """
        pass

    @staticmethod
    def charge_with_token(token_id, amount):
        """Charge using token (server-side)."""
        # Your server only sees the token, never the card number
        stripe.api_key = "sk_..."

        charge = stripe.Charge.create(
            amount=amount,
            currency="usd",
            source=token_id,  # Token instead of card details
            description="Payment"
        )

        return charge

    @staticmethod
    def store_payment_method(customer_id, payment_method_token):
        """Store payment method as token for future use."""
        stripe.Customer.modify(
            customer_id,
            source=payment_method_token
        )

        # Store only customer_id and payment_method_id in your database
        # NEVER store actual card details
        return {
            'customer_id': customer_id,
            'has_payment_method': True
            # DO NOT store: card number, CVV, etc.
        }
Custom Tokenization (Advanced)
python
import secrets
from cryptography.fernet import Fernet

class TokenVault:
    """Secure token vault for card data (if you must store it)."""

    def __init__(self, encryption_key):
        self.cipher = Fernet(encryption_key)
        self.vault = {}  # In production: use encrypted database

    def tokenize(self, card_data):
        """Convert card data to token."""
        # Generate secure random token
        token = secrets.token_urlsafe(32)

        # Encrypt card data
        encrypted = self.cipher.encrypt(json.dumps(card_data).encode())

        # Store token -> encrypted data mapping
        self.vault[token] = encrypted

        return token

    def detokenize(self, token):
        """Retrieve card data from token."""
        encrypted = self.vault.get(token)
        if not encrypted:
            raise ValueError("Token not found")

        # Decrypt
        decrypted = self.cipher.decrypt(encrypted)
        return json.loads(decrypted.decode())

    def delete_token(self, token):
        """Remove token from vault."""
        self.vault.pop(token, None)

Encryption

Data at Rest
python
from cryptography.hazmat.primitives.ciphers.aead import AESGCM
import os

class EncryptedStorage:
    """Encrypt data at rest using AES-256-GCM."""

    def __init__(self, encryption_key):
        """Initialize with 256-bit key."""
        self.key = encryption_key  # Must be 32 bytes

    def encrypt(self, plaintext):
        """Encrypt data."""
        # Generate random nonce
        nonce = os.urandom(12)

        # Encrypt
        aesgcm = AESGCM(self.key)
        ciphertext = aesgcm.encrypt(nonce, plaintext.encode(), None)

        # Return nonce + ciphertext
        return nonce + ciphertext

    def decrypt(self, encrypted_data):
        """Decrypt data."""
        # Extract nonce and ciphertext
        nonce = encrypted_data[:12]
        ciphertext = encrypted_data[12:]

        # Decrypt
        aesgcm = AESGCM(self.key)
        plaintext = aesgcm.decrypt(nonce, ciphertext, None)

        return plaintext.decode()

# Usage
storage = EncryptedStorage(os.urandom(32))
encrypted_pan = storage.encrypt("4242424242424242")
# Store encrypted_pan in database
Data in Transit
python
# Always use TLS 1.2 or higher
# Flask/Django example
app.config['SESSION_COOKIE_SECURE'] = True  # HTTPS only
app.config['SESSION_COOKIE_HTTPONLY'] = True
app.config['SESSION_COOKIE_SAMESITE'] = 'Strict'

# Enforce HTTPS
from flask_talisman import Talisman
Talisman(app, force_https=True)

Additional patterns and templates

More detailed templates and worked examples live in references/details.md. Read that file for the full pattern library.

© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/payment-processing/skills/pci-compliance of wshobson/agents.

  • SKILL.md
  • references/details.md

Open the folder on GitHubat commit 46891e7

Used in 11 other repositories

We found 21 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 11 other GitHub owners. This page covers the copy in wshobson/agents, which our catalogue first saw on October 7, 2026.

Compare with similar skills

PCI DSS Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PCI DSS Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PCI DSS Compliance this skillwshobson/agents40k11 repos~1.9kAutomated safety check: PassMIT
Payment Testingpetrkindlmann/qa-skills170—~4.9kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.7kAutomated safety check: PassMIT
GRC Report Context BootstrapGRCEngClub/claude-grc-engineering419—~1.4kAutomated safety check: NotesCustom licence

Similar skills

  • Payment Testing

    petrkindlmann/qa-skills

    Test payment and checkout flows end to end against PSP sandboxes — Stripe first, with the general pattern for Adyen/Braintree/PayPal.

    170 GitHub stars~4.9k tokensUpdated 4 mo ago
    Testing & QAAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • GRC Report Context Bootstrap

    GRCEngClub/claude-grc-engineering

    Checks that plugins, collected findings and history exist before a GRC /report command runs, and walks the user through setup instead of producing an empty report.

    419 GitHub stars~1.4k tokensUpdated 7 days ago
    Legal & ComplianceAuto-check: notes
  • Review Op Docs API

    CVCUDA/CV-CUDA

    Review a CV-CUDA operator's DOCS & API artifacts — operatorlist row, Python autofunction (fn + into), Limitations-table-vs-code consistency, docstrings, and SPDX headers.

    2.7k GitHub stars~270 tokensUpdated 24 days ago
    Legal & ComplianceAuto-check passed

More from wshobson/agents

All 142 skills in this repo
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    Auto-check passed
  • Billing Automation

    wshobson/agents

    Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.

    40k GitHub starsUsed in 13 repos~473 tokens
    Auto-check passed
  • Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.

    40k GitHub starsUsed in 13 repos~814 tokens
    Auto-check passed
  • Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.

    40k GitHub starsUsed in 12 repos~1.3k tokens
    Auto-check passed
  • Distributed Tracing

    wshobson/agents

    Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.

    40k GitHub starsUsed in 12 repos~527 tokens
    Auto-check passed
  • Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.

    40k GitHub stars~1.3k tokensUpdated 6 days ago
    Auto-check passed

Works with

Questions about PCI DSS Compliance

What does PCI DSS Compliance do?

Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption. The skill walks through the 12 core PCI DSS requirements, grouped under building a secure network, protecting cardholder data, vulnerability management, access control, monitoring and testing, and keeping a security policy. It also sets out four compliance levels based on yearly transaction volume, from Level 1 with an annual ROC to Level 4 for smaller merchants.

When should I use PCI DSS Compliance?

PCI DSS Compliance fits situations like: building a checkout or payment flow that touches card data; reducing PCI scope with tokenization; preparing for a PCI DSS assessment or audit; reviewing what cardholder data a system stores and how it is encrypted.

How do I install PCI DSS Compliance in Claude Code?

Run `npx skills add wshobson/agents --skill pci-compliance -a claude-code`. Or copy the skill folder (plugins/payment-processing/skills/pci-compliance in wshobson/agents) into .claude/skills/pci-compliance in your project. Claude Code loads it when a task matches its description.

How do I install PCI DSS Compliance in Codex?

Run `npx skills add wshobson/agents --skill pci-compliance -a codex`. Or copy the skill folder (plugins/payment-processing/skills/pci-compliance in wshobson/agents) into .agents/skills/pci-compliance in your project. Codex loads it when a task matches its description.

Can I use PCI DSS Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill pci-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pci-compliance, .gemini/skills/pci-compliance, .github/skills/pci-compliance and .opencode/skills/pci-compliance in your project.

What does PCI DSS Compliance need to run?

SKILL.md names no scripts, command-line tools or credentials: PCI DSS Compliance is instructions for the agent only.

Does PCI DSS Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is PCI DSS Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does PCI DSS Compliance use?

PCI DSS Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does PCI DSS Compliance use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to PCI DSS Compliance?

Skills that share tags, products or a category with PCI DSS Compliance: Payment Testing (petrkindlmann/qa-skills, 170 stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars) and Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PCI DSS Compliance?

wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,314 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.

Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.