Skip to main content

compliance-pack

Produce the compliance artefacts a regulator, an auditor or a customer's security questionnaire asks for: a CycloneDX or SPDX SBOM, an EU Cyber Resilience Act evidence pack, an OpenVEX reachability statement, and CWE→ASVS 5.0 / PCI DSS 4.0.1 mapping. Use when the user asks for an SBOM, asks "are we CRA compliant", is filling in a vendor security questionnaire, needs a vulnerability register, asks which findings map to a standard, or says "SBOM", "CycloneDX", "SPDX", "VEX", "CRA", "ASVS", "PCI DSS", "compliance report", and Turkish equivalents ("uyumluluk", "denetim raporu", "bağımlılık envanteri"). NOT for finding vulnerabilities — that is the `security-audit` skill. This one turns findings that already exist into documents someone else reads.

Jump to install

Source facts

Repository
mtvrkan/secaudit
Last source activity
August 20, 2026 at 21:05
Detected SKILL.md language
English
Stars
0
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.