ACTIVATE on ANY request that involves writing, generating, reviewing, modifying, or outputting source code in any programming language — Python, JavaScript, TypeScript, Go, Java, Rust, C#, SQL, Terraform, or any other. This includes functions, endpoints, scripts, migrations, infrastructure-as-code, config files with logic, and code snippets in responses. Every piece of code the LLM produces must include structured audit logging for security-relevant operations. Also activate when the user asks about audit logs, compliance logging, or traceability. Ensures NIS2 and ISO 27001 compliant logging (structured, no string interpolation, no secrets in logs).
ACTIVATE when making changes that affect critical assets: deployments, database migrations, schema changes, Terraform/IaC modifications, access control or IAM changes, firewall rules, TLS certificates, environment variables on production, or dependency upgrades. Ensures every change is documented, impact-assessed, approved, and reversible per NIS2 Art. 21(2)(e) and ISO 27001 A.8.32.
ACTIVATE when the user asks about centralising compliance records, log collection, audit trail persistence, log retention, SIEM integration, or agent observability. Central collection point for all complisec output: audit logs, incident records, change records, and vendor assessments. Configures immutable cloud storage and optionally connects observability platforms.
../../SKILL.md
ACTIVATE when the user's message contains secrets, credentials, API keys, passwords, tokens, private keys, AWS access keys, connection strings, database URLs, national IDs (BSN/SSN), or any sensitive data — even if the user did not ask about security. Also activate when asked to classify data, scan for PII, or review code for credential exposure. This skill BLOCKS secrets in prompts and enforces EU data protection rules (GDPR, NIS2, ISO 27001).
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Skills for AI agents, built by Eye Security.
| Plugin | Description |
|---|---|
| complisec | EU compliance enforcement — NIS2, GDPR, ISO 27001 |
Each plugin has its own README with details and examples.
/plugin marketplace add eyesecurity/skills
/plugin install <plugin-name>
Clone the repo — Codex reads AGENTS.md automatically:
git clone https://github.com/eyesecurity/skills.git
Clone the repo, then tell your agent:
"Read plugins/<plugin-name>/SKILL.md and follow its instructions."
Download the plugin zip from Releases, upload it to your chat, and say: "Read SKILL.md and follow its instructions."
Eye Security helps EU organisations implement compliance end-to-end — from NIS2 readiness to managed detection and response.
MIT
npx claudepluginhub eyesecurity/skills --plugin complisecGDPR compliance assistant — code and system audits, privacy notice drafting, DPAs, DPIAs, data flow reviews, and authoritative article-cited Q&A.
18 GDPR compliance skills: audit, gap analysis, accountability, DPO, certification, DPA drafting, supervisory authority cooperation
GDPR Plugin - EU General Data Protection Regulation with DPIA, data subject rights, and 72-hour breach notification
Regulatory compliance and governance planning BEFORE development begins. Covers GDPR, HIPAA, PCI-DSS, AI governance (EU AI Act, NIST AI RMF), security frameworks (ISO 27001, SOC 2), open source compliance, and data classification.
Compliance and governance including regulatory mapping, security policies, audit readiness, GDPR, SOC2, and PCI-DSS compliance.
DevsForge Enterprise Compliance Automation Architect delivering comprehensive compliance engineering methodologies, regulatory automation frameworks, and governance optimization strategies that transform compliance management from operational burden into strategic business value creation and trust catalyst