All skills
wshobson avatar

/pci-compliance

@be57c0b
by Seth Hobsonwshobson/agents40k stars
4,281

Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card security measures.

Use this Skill: https://skilld.dev/gh/wshobson/agents/pci-compliance

This session only. Nothing lands on disk.

referencesdetails.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

pci-compliance — additional patterns and templates

Access Control

from functools import wraps
from flask import session

def require_pci_access(f):
    """Decorator to restrict access to cardholder data."""
    @wraps(f)
    def decorated_function(*args, **kwargs):
        user = session.get('user')

        # Check if user has PCI access role
        if not user or 'pci_access' not in user.get('roles', []):
            return {'error': 'Unauthorized access to cardholder data'}, 403

        # Log access attempt
        audit_log(
            user=user['id'],
            action='access_cardholder_data',
            resource=f.__name__
        )

        return f(*args, **kwargs)

    return decorated_function

@app.route('/api/payment-methods')
@require_pci_access
def get_payment_methods():
    """Retrieve payment methods (restricted access)."""
    # Only accessible to users with pci_access role
    pass

Audit Logging

import logging
from datetime import datetime

class PCIAuditLogger:
    """PCI-compliant audit logging."""

    def __init__(self):
        self.logger = logging.getLogger('pci_audit')
        # Configure to write to secure, append-only log

    def log_access(self, user_id, resource, action, result):
        """Log access to cardholder data."""
        entry = {
            'timestamp': datetime.utcnow().isoformat(),
            'user_id': user_id,
            'resource': resource,
            'action': action,
            'result': result,
            'ip_address': request.remote_addr
        }

        self.logger.info(json.dumps(entry))

    def log_authentication(self, user_id, success, method):
        """Log authentication attempt."""
        entry = {
            'timestamp': datetime.utcnow().isoformat(),
            'user_id': user_id,
            'event': 'authentication',
            'success': success,
            'method': method,
            'ip_address': request.remote_addr
        }

        self.logger.info(json.dumps(entry))

# Usage
audit = PCIAuditLogger()
audit.log_access(user_id=123, resource='payment_methods', action='read', result='success')

Security Best Practices

Input Validation

import re

def validate_card_number(card_number):
    """Validate card number format (Luhn algorithm)."""
    # Remove spaces and dashes
    card_number = re.sub(r'[\s-]', '', card_number)

    # Check if all digits
    if not card_number.isdigit():
        return False

    # Luhn algorithm
    def luhn_checksum(card_num):
        def digits_of(n):
            return [int(d) for d in str(n)]

        digits = digits_of(card_num)
        odd_digits = digits[-1::-2]
        even_digits = digits[-2::-2]
        checksum = sum(odd_digits)
        for d in even_digits:
            checksum += sum(digits_of(d * 2))
        return checksum % 10

    return luhn_checksum(card_number) == 0

def sanitize_input(user_input):
    """Sanitize user input to prevent injection."""
    # Remove special characters
    # Validate against expected format
    # Escape for database queries
    pass

PCI DSS SAQ (Self-Assessment Questionnaire)

SAQ A (Least Requirements)

  • E-commerce using hosted payment page
  • No card data on your systems
  • ~20 questions

SAQ A-EP

  • E-commerce with embedded payment form
  • Uses JavaScript to handle card data
  • ~180 questions

SAQ D (Most Requirements)

  • Store, process, or transmit card data
  • Full PCI DSS requirements
  • ~300 questions

Compliance Checklist

PCI_COMPLIANCE_CHECKLIST = {
    'network_security': [
        'Firewall configured and maintained',
        'No vendor default passwords',
        'Network segmentation implemented'
    ],
    'data_protection': [
        'No storage of CVV, track data, or PIN',
        'PAN encrypted when stored',
        'PAN masked when displayed',
        'Encryption keys properly managed'
    ],
    'vulnerability_management': [
        'Anti-virus installed and updated',
        'Secure development practices',
        'Regular security patches',
        'Vulnerability scanning performed'
    ],
    'access_control': [
        'Access restricted by role',
        'Unique IDs for all users',
        'Multi-factor authentication',
        'Physical security measures'
    ],
    'monitoring': [
        'Audit logs enabled',
        'Log review process',
        'File integrity monitoring',
        'Regular security testing'
    ],
    'policy': [
        'Security policy documented',
        'Risk assessment performed',
        'Security awareness training',
        'Incident response plan'
    ]
}

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides safe and compliant implementations, templates, and best practices for achieving PCI DSS compliance, including tokenization, data encryption, access control, and audit logging. No security risks or malicious behaviors were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    1/1 file flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at be57c0b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 4 months ago
  • Security
  • pci-dss
  • payment-processing
  • compliance
  • encryption
  • tokenization
  • cardholder-data
  • fraud-prevention

README badge

README badge for wshobson/agents/pci-compliance

Guides implementation of PCI DSS compliance for payment processing systems, covering the 12 core requirements, data storage restrictions, tokenization, and encryption patterns. Use this skill when building secure payment flows, handling cardholder data, or preparing for PCI compliance audits.

Generated from the current SKILL.md.

Does this skill cover all 12 PCI DSS requirements?
The skill outlines all 12 core PCI DSS requirements but focuses primarily on data handling patterns (tokenization, encryption, data minimization). Firewall configuration, physical access controls, and audit logging require infrastructure decisions outside the skill's scope.
Can I store credit card numbers if I encrypt them?
Yes, you can store encrypted PANs (Primary Account Numbers), cardholder names, expiration dates, and service codes. You must never store CVV, PIN, or full track data, even encrypted.
Does this skill include Stripe integration?
Yes. The skill shows how to use Stripe's tokenization to avoid handling raw card data on your server, and includes server-side charge examples using tokens.
What encryption standard does this recommend?
The skill uses AES-256-GCM for data at rest and requires TLS 1.2 or higher for data in transit.
Is custom tokenization recommended over payment processor tokens?
No. The skill recommends using payment processor tokens (like Stripe) by default. Custom tokenization is marked as advanced and should only be used if you have a specific reason to build your own vault.

Generated from the current SKILL.md. These answers refresh after source changes.