- Home
- Skills
- Finance & Accounting
- pci dss payment audit
Works with the AI tools you already use
pci dss payment audit
Audit e-commerce payment pages for PCI DSS v4.0.1 script integrity and tamper-detection compliance.
$30
pci dss payment audit
Example session with this skill installed
We use an Adyen iframe for payments. Do I still need to worry about PCI DSS 6.4.3 script management, and does my Weekly CSP report satisfy 11.6.1?
- Read your context and instructions
- Compiled the pci dss payment
Yes. The page loading the iframe is the attack surface. 6.4.3 applies to all scripts on that page. Your CSP report only satisfies 11.6.1 if it alerts on unauthorized script changes and header modifications, not just presence. Cadence must be at least every 7 days or backed by a 12.3.1 TRA.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Merchant websites are frequently compromised via e-skimming and formjacking that injects malicious code into the browser, even if the server-side code remains clean. Developers often falsely believe that using an iframe or redirect for payments exempts them from the mandatory PCI DSS v4.0.1 requirements that addressed these vulnerabilities starting March 2025.
What it does
- Audits payment pages against PCI DSS v4.0.1 Requirement 6.4.3 for script authorization, integrity, and inventory justification.
- Evaluates change-and-tamper-detection mechanisms against Requirement 11.6.1, including security-impacting HTTP headers and script content.
- Identifies "blind spots" in script monitoring, such as fourth-party scripts loaded by tag managers that never appear in your repository.
- Verifies monitoring cadences and alert triggers to ensure compliance with the seven-day minimum or documented Risk Analysis.
- Maps integration models like Stripe/Adyen iframes to the specific parent-page security obligations required for SAQ A eligibility.
Why this beats prompting it yourself
General LLMs often use outdated PCI DSS v3.2.1 knowledge or fail to grasp that compliance is measured at the browser level, not the server. This skill enforces the distinction between site-as-stored and site-as-delivered, preventing the most common "false pass" in script auditing. It bridges the gap between technical script management and the specific attestation language required for 2025 compliance cycles.
Use cases
- Pre-audit a checkout page before a QSA assessment to find unrecorded third-party tags.
- Review a script-monitoring tool setup to see if it covers both headers and DOM content.
- Validate whether a marketing team's new tag manager scripts break compliance.
- Prepare justification documentation for every script running on a payment surface.
Known limitations
This tool is not a QSA and cannot provide formal PCI certification or sign an AOC. It cannot assess live script behavior without access to the delivered DOM or provided script lists.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- Passed all security checks, Safe to install