CtrlK
BlogDocsLog inGet started
Tessl Logo

pci-compliance

Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card security measures.

77

1.94x
Quality

72%

Does it follow best practices?

Impact

99%

1.94x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./tests/ext_conformance/artifacts/agents-wshobson/payment-processing/skills/pci-compliance/SKILL.md

The canonical home for this skill is pci-compliance in wshobson/agents

SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is rich in concrete, mostly executable security code, but it is a monolithic ~480-line document whose referenced bundle files (references/, assets/, scripts/) do not exist, breaking its own progressive-disclosure structure. It also lacks a sequenced compliance workflow with validation checkpoints.

Suggestions

Fix progressive disclosure: either actually provide the promised bundle files (references/tokenization.md, references/encryption.md, references/access-control.md, references/audit-logging.md, references/data-minimization.md, assets/pci-compliance-checklist.md, assets/encrypted-storage.py, scripts/audit-payment-system.sh) or remove the Resources section and instead split the inlined checklist and full class implementations into real files the SKILL.md points to.

Add a sequenced workflow with validation checkpoints, e.g.: 1. Determine transaction volume and SAQ level; 2. Choose a scope-reduction strategy (hosted payments or tokenization); 3. Implement the controls; 4. Validate no prohibited data is stored (validate_no_prohibited_storage) and confirm TLS 1.2+; 5. Run the compliance checklist. Tie the existing validation helpers into this sequence.

Trim conciseness losses: remove the empty sanitize_input stub, move the JavaScript token-creation example out of the Python docstring into a proper code block, and delete narrating comments that restate the adjacent code.

DimensionReasoningScore

Conciseness

The ~480-line body is mostly useful, actionable code, but includes unnecessary padding: a JavaScript snippet embedded inside a Python docstring, narrating comments that restate the code ("# Extract nonce and ciphertext", "# Decrypt"), and an empty sanitize_input stub with comment-only pseudocode. It fits anchor 3 (mostly efficient but could be tightened) rather than 2, since the bulk is concrete guidance rather than concept re-explanation, and not 4 because several sections need trimming.

3 / 5

Actionability

Concrete, mostly executable code covers PAN masking, tokenization, AES-256-GCM encryption, Luhn validation, role-based access decorators, and audit logging. It falls short of anchor 5 because several snippets reference undefined symbols (SecurityError, json, request, audit_log, app) and one function is an empty stub; it is well above anchor 3 since the code is real and executable rather than pseudocode.

4 / 5

Workflow Clarity

The body is organized topically rather than as a sequenced process: there is no ordered workflow (e.g., determine SAQ level, tokenize, encrypt, validate, audit) and validation is ad hoc. Validation helpers exist (validate_no_prohibited_storage, validate_card_number) but are not tied into a sequence, matching anchor 3 (sequence/checkpoints implicit or missing) rather than 4.

3 / 5

Progressive Disclosure

The Resources section promises files like references/tokenization.md, references/encryption.md, assets/pci-compliance-checklist.md, and scripts/audit-payment-system.sh, but none of these exist — the bundle contains only SKILL.md. Combined with a ~480-line monolithic body that inlines the full compliance checklist and complete class implementations, this matches anchor 2 (content that belongs in separate files is inlined; references broken) rather than 3, because the disclosure promise is factually unfulfilled.

2 / 5

Total

12

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly answers both what the skill does and when to use it, with natural trigger phrases. Its main gaps are limited enumeration of specific capabilities and missing common synonyms such as "cardholder data" or "credit card security".

DimensionReasoningScore

Specificity

"Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems" names the domain and 1-2 concrete actions (implement compliance requirements, secure handling of card data), but does not enumerate specific capabilities like tokenization, encryption, or audit logging. It matches anchor 3 (domain plus 1-2 concrete actions, not comprehensive) rather than 4, which requires several specific actions listed.

3 / 5

Completeness

Both parts are explicit: a clear "what" ("Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems") and an explicit "Use when..." clause with three concrete trigger phrases. This mirrors the anchor-5 example structure and is well above anchor 4, where the "when" would be less specific.

5 / 5

Trigger Term Quality

The "Use when" clause provides natural phrases users would say: "securing payment processing", "achieving PCI compliance", "implementing payment card security measures". It stops short of anchor 5 because common synonyms and variations are missing, e.g. "cardholder data", "credit card security", or "PCI DSS" as a bare term.

4 / 5

Distinctiveness Conflict Risk

PCI DSS compliance is a clear niche with distinct triggers, but phrases like "securing payment processing" have minor overlap risk with closely related skills (general application-security or payment-integration skills). This fits anchor 4 (mostly distinct, minor overlap risk) rather than 5 (minimal conflict risk).

4 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 8 missing

Warning

Total

15

/

16

Passed

Repository
Dicklesworthstone/pi_agent_rust
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.