CtrlK
BlogDocsLog inGet started
Tessl Logo

pci-audit

Audit applications and infrastructure handling payment card data against PCI DSS v4.0. Heavy emphasis on scope determination (the single most-leveraged variable) plus the engineering-relevant requirements — Req 3 (storage of CHD), Req 4 (transmission), Req 6 (secure SDLC), Req 7-8 (access), Req 10 (logging), Req 11 (testing), Req 12 (program). Use when the user mentions 'PCI,' 'PCI DSS,' 'PCI DSS 4.0,' 'payment card,' 'cardholder data,' 'CHD,' 'PAN,' 'PCI scope,' 'PCI compliance,' 'SAQ,' 'AoC,' 'attestation of compliance,' 'tokenization,' 'P2PE,' 'network segmentation for PCI,' or audits any system that stores, processes, or transmits payment card data.

71

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable audit skill body that leads with the highest-leverage step (scope), provides concrete grep/regex patterns and a ready checklist, and clearly cross-references sibling skills. It is efficient but slightly padded in places, and being a single long file with no bundle references leaves minor room for progressive disclosure.

Suggestions

Tighten motivational prose (e.g. 'radically less in scope … very different audit', 'creates years of compliance debt') to leaner factual statements to lift conciseness toward 5.

Add an explicit 'verify findings before finalizing' checkpoint in the audit checklist (e.g. confirm each finding against a Luhn/regex re-scan and a severity rubric) to make the workflow's validation loop explicit.

Consider moving the per-requirement grep-pattern catalog and/or the references list into a one-level-deep reference file (e.g. references/grep-patterns.md) so SKILL.md reads as an overview, improving progressive disclosure.

DimensionReasoningScore

Conciseness

Dense and information-rich, assuming Claude's PCI knowledge, with minor motivational padding such as 'radically less in scope' and 'very different audit' that could be trimmed without losing clarity.

4 / 5

Actionability

Provides concrete, copy-paste-ready grep patterns and card-number regexes plus a full audit checklist template; minor gaps where requirement sections only cross-reference other skills instead of giving executable guidance.

4 / 5

Workflow Clarity

Clear sequence — scope determination first, then per-requirement audit, then a structured findings checklist with checkboxes; the destructive-cap does not apply to a read-only audit, but explicit validation/verification checkpoints before finalizing findings are only implicit.

4 / 5

Progressive Disclosure

No bundle files exist; the single SKILL.md is well-organized with clear headers, tables, and signaled cross-skill references, though at ~200 lines some detail (grep patterns, checklist template, references) could be split into one-level-deep reference files.

4 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states the audit capability, comprehensively enumerates the requirement areas in scope, and provides an exhaustive set of natural trigger phrases. It is concise for its breadth and unambiguously distinguishes the skill from related security audit skills.

DimensionReasoningScore

Specificity

Lists multiple concrete audit actions ('Audit applications and infrastructure handling payment card data against PCI DSS v4.0', 'scope determination') and comprehensively enumerates the engineering-relevant requirement areas (Req 3, 4, 6, 7-8, 10, 11, 12).

5 / 5

Completeness

Explicitly answers both what (audit against PCI DSS v4.0 with scope + engineering requirements) and when ('Use when the user mentions … or audits any system that stores, processes, or transmits payment card data') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Comprehensive coverage of natural terms and synonyms/acronyms users would say — 'PCI,' 'PCI DSS,' 'PCI DSS 4.0,' 'payment card,' 'cardholder data,' 'CHD,' 'PAN,' 'PCI scope,' 'PCI compliance,' 'SAQ,' 'AoC,' 'attestation of compliance,' 'tokenization,' 'P2PE,' 'network segmentation for PCI'.

5 / 5

Distinctiveness Conflict Risk

Clear PCI-specific niche with distinct triggers ('PAN,' 'SAQ,' 'AoC,' 'P2PE') and minimal overlap risk with adjacent security skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.