Skip to main content

compliance-pack

Produce the compliance artefacts a regulator, an auditor or a customer's security questionnaire asks for: a CycloneDX or SPDX SBOM, an EU Cyber Resilience Act evidence pack, an OpenVEX reachability statement, and CWE→ASVS 5.0 / PCI DSS 4.0.1 mapping. Use when the user asks for an SBOM, asks "are we CRA compliant", is filling in a vendor security questionnaire, needs a vulnerability register, asks which findings map to a standard, or says "SBOM", "CycloneDX", "SPDX", "VEX", "CRA", "ASVS", "PCI DSS", "compliance report", and Turkish equivalents ("uyumluluk", "denetim raporu", "bağımlılık envanteri"). NOT for finding vulnerabilities — that is the `security-audit` skill. This one turns findings that already exist into documents someone else reads.

설치로 이동

소스 정보

저장소
mtvrkan/secaudit
최근 소스 활동
2026년 8월 20일 21:05
감지된 SKILL.md 언어
영어
스타
0
포크
0

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.