Works with the AI tools you already use

    CClaude CodeCCursorCCodex CLIGGitHub CopilotGGemini CLIVVS CodeWWindsurfMManus+14 more

    Cra Readiness Auditor

    by Nex AI

    1

    Automated EU Cyber Resilience Act (CRA) auditing, SBOM generation, and compliance documentation for software repos.

    $9

    /mo

    Subscription · cancel anytime

    Secure checkout via Stripe

    • Always the latest version
    • Delivered live to your agent via MCP
    • Cancel anytime, access ends at period end
    0 installsSecurity scanned

    See it in action

    You say

    Perform a CRA readiness audit on my current repository and generate the required SBOM and incident runbooks.

    Your agent does

    CRA Audit Summary

    Location: /cra-readiness/

    • SBOM: sbom.cdx.json (CycloneDX 1.5)
    • Status: 12 Met, 5 Open, 2 Partial
    • Top Gaps: Missing 24h ENISA notification procedure, Technical Doc skeleton incomplete. This is a readiness aid and does not constitute legal advice.

    What you get

    Generate CycloneDX 1.5 SBOMs from project manifests automaticallyMap repository security gaps to specific EU CRA Articles and AnnexesCreate ENISA-compliant 24-hour incident reporting runbooksGenerate technical documentation skeletons required for EU market entryPrepare software products for the September 2026 CRA enforcement date

    About this skill

    Audit Your Software for EU CRA Compliance

    The Cyber Resilience Act (CRA) introduces strict cybersecurity requirements for software products in the EU market, starting September 2026. This skill automates the complex task of auditing your repository against these specific legal obligations, saving developers and legal teams weeks of manual mapping.

    What it does

    This skill performs a comprehensive scan of your repository to extract dependency data, security policies, and update mechanisms. It then generates the exact artifacts required for CRA compliance:

    • CycloneDX SBOM: An industry-standard software bill of materials (v1.5).
    • Readiness Report: A detailed audit mapping your repo to specific CRA articles and essential requirements.
    • Compliance Templates: Ready-to-use vulnerability disclosure policies (SECURITY.md) and incident response runbooks mapped to ENISA's 24-hour reporting duty.
    • Technical Documentation: A structured skeleton for the required CRA technical dossiers.

    Why use this skill?

    Unlike generic vulnerability scanners, this tool is specifically tuned to the legal text of the Cyber Resilience Act. It doesn't just find bugs; it identifies gaps in your compliance framework—such as missing incident notification paths or insufficient update documentation—that carry significant regulatory risk.

    Supported Environments

    The auditor supports all major package managers including npm, pip/poetry, go-mod, and cargo. It operates entirely locally for privacy, with an optional path for online vulnerability enrichment.

    Changelog

    1. v1.1LatestJul 13, 2026

      Refreshed audited build: manifest, README, worked examples and security declarations cleaned up.

    2. v1.1Jul 13, 2026

      Quality pass: clearer description, worked examples, packaging standard (manifest, README, license, changelog), tone and formatting cleanup.

    3. v1.0Jun 15, 2026

      Initial release

    How to install

    Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 17 days ago

    Listed1 month ago
    Updated17 days ago

    Creator

    Founder of Nex AI. I build production-grade Claude Skills from systems that actually run: multi-tenant SaaS, Telegram agents, Raspberry Pi infrastructure, 3D multiplayer rooms. Every skill ships battle-tested patterns, not theory. 33+ open source skills published, commercial catalog growing.

    Frequently Asked Questions

    Popular in Security & Compliance