Skip to main content

compliance-pack

Produce the compliance artefacts a regulator, an auditor or a customer's security questionnaire asks for: a CycloneDX or SPDX SBOM, an EU Cyber Resilience Act evidence pack, an OpenVEX reachability statement, and CWE→ASVS 5.0 / PCI DSS 4.0.1 mapping. Use when the user asks for an SBOM, asks "are we CRA compliant", is filling in a vendor security questionnaire, needs a vulnerability register, asks which findings map to a standard, or says "SBOM", "CycloneDX", "SPDX", "VEX", "CRA", "ASVS", "PCI DSS", "compliance report", and Turkish equivalents ("uyumluluk", "denetim raporu", "bağımlılık envanteri"). NOT for finding vulnerabilities — that is the `security-audit` skill. This one turns findings that already exist into documents someone else reads.

Zur Installation springen

Quellinformationen

Repository
mtvrkan/secaudit
Letzte Quellaktivität
20. August 2026 um 21:05
Erkannte Sprache von SKILL.md
Englisch
Sterne
0
Forks
0

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.