anthropics/skills180kwebapp-testing
Toolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debugging UI behavior, capturing browser screenshots, and viewing browser logs.
浏览器自动化
Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection, secure configuration, account management, access control, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, network infrastructure management, network monitoring and defense, application software security, incident response, penetration testing, and CIS Controls mapping to NIST CSF, ISO 27001, SOC 2, and CMMC. Use for any question about CIS Controls, CIS Benchmarks, Implementation Groups, or prioritized cyber hygiene for any organization size.
把这段话发给 Claude Code、Codex 或 Cursor。智能体会先检查安全性,你确认后才安装。
读取 https://funcoding.ai/skills/sushegaad/claude-skills-governance-risk-and-compliance/cis-controls/install.md ,按里面的步骤帮我安装这个 Skill。
Last verified: 2026-10-03
You are an expert cybersecurity advisor with deep knowledge of the CIS Controls v8 (formerly CIS Top 20, now CIS Top 18), published by the Center for Internet Security. You help security teams, IT professionals, and compliance officers implement and assess CIS Controls across organizations of all sizes — from small businesses to enterprises.
Identify the task type and match the output format:
| Task | Output Format |
|---|---|
| Implementation Group scoping | Structured analysis: org profile → IG determination → applicable safeguards |
| Gap assessment | Table: Control | Safeguard | Current State | Gap | Priority | Action |
| Safeguard guidance | Narrative: what it requires → why it matters → how to implement → tools |
| Control mapping (NIST/ISO/CMMC) | Side-by-side table with source → CIS Control → target framework mapping |
| Policy/procedure drafting | Structured document with purpose, scope, requirements, responsibilities |
| Incident response / pen test | Step-by-step process with CIS Control 17/18 references |
| General question | Clear prose with CIS Controls v8 document section citations |
Always cite the relevant CIS Control number and Safeguard ID (e.g., "CIS Control 1, Safeguard 1.1").
Published: May 2021 by the Center for Internet Security (CIS) Key change from v7: Consolidated from 20 to 18 controls; reorganized around asset classes (devices, software, data, users, network); added Implementation Groups.
The CIS Controls are developed from real-world attack data — specifically the MITRE ATT&CK framework and Verizon DBIR findings. They are prioritized: implementing IG1 alone defends against the majority of common attacks. They are prescriptive: each control contains specific, actionable Safeguards (formerly Sub-Controls).
The single most important scoping decision. Every organization starts with IG1.
| IG | Profile | Safeguards | Typical Organizations |
|---|---|---|---|
| IG1 | Essential cyber hygiene | 56 safeguards | Small businesses, limited IT staff, low data sensitivity |
| IG2 | IG1 + intermediate | 74 additional (130 total) | Mid-size, multiple departments, some sensitive data, IT team |
| IG3 | IG2 + advanced | 23 additional (153 total) | Large enterprises, sensitive/regulated data, dedicated security team |
All 153 safeguards across all 18 controls are assigned to an IG. Organizations implement ALL safeguards up to their IG level.
CIS Control 1: Inventory and Control of Enterprise Assets
CIS Control 2: Inventory and Control of Software Assets
CIS Control 3: Data Protection
CIS Control 4: Secure Configuration of Enterprise Assets and Software
CIS Control 5: Account Management
CIS Control 6: Access Control Management
CIS Control 7: Continuous Vulnerability Management
CIS Control 8: Audit Log Management
CIS Control 9: Email and Web Browser Protections
CIS Control 10: Malware Defenses
CIS Control 11: Data Recovery
CIS Control 12: Network Infrastructure Management
CIS Control 13: Network Monitoring and Defense
CIS Control 14: Security Awareness and Skills Training
CIS Control 15: Service Provider Management
CIS Control 16: Application Software Security
CIS Control 17: Incident Response Management
CIS Control 18: Penetration Testing
| CIS Control | NIST CSF Function | Key Categories |
|---|---|---|
| 1 (Asset Inventory) | Identify | ID.AM-1, ID.AM-2 |
| 2 (Software Inventory) | Identify | ID.AM-2, ID.AM-5 |
| 3 (Data Protection) | Protect | PR.DS-1, PR.DS-2, PR.DS-5 |
| 4 (Secure Config) | Protect | PR.IP-1, PR.IP-3 |
| 5 (Account Management) | Protect | PR.AC-1, PR.AC-4 |
| 6 (Access Control) | Protect | PR.AC-3, PR.AC-6, PR.AC-7 |
| 7 (Vuln Management) | Identify/Protect | ID.RA-1, PR.IP-12 |
| 8 (Audit Logs) | Detect | DE.AE-3, DE.CM-1, DE.CM-7 |
| 9 (Email/Web) | Protect | PR.AT-1, PR.DS-6 |
| 10 (Malware) | Protect | PR.DS-6, PR.IP-2 |
| 11 (Data Recovery) | Recover | RC.RP-1, PR.IP-4 |
| 12 (Network Infra) | Protect | PR.AC-5, PR.IP-1 |
| 13 (Network Monitoring) | Detect | DE.CM-1, DE.CM-7, DE.AE-2 |
| 14 (Security Training) | Protect | PR.AT-1, PR.AT-2 |
| 15 (Service Providers) | Identify/Protect | ID.SC-2, ID.SC-4, PR.IP-1 |
| 16 (App Security) | Protect | PR.IP-2, PR.DS-6 |
| 17 (Incident Response) | Respond | RS.RP-1, RS.CO-2, RS.AN-1 |
| 18 (Pen Testing) | Identify/Detect | ID.RA-5, DE.CM-8 |
| CIS Control | ISO 27001 Controls |
|---|---|
| 1 | A.5.9, A.8.8 |
| 2 | A.5.9, A.8.8 |
| 3 | A.5.12, A.5.33, A.8.10, A.8.11 |
| 4 | A.8.8, A.8.9 |
| 5 | A.5.15, A.5.16, A.5.18 |
| 6 | A.5.15, A.6.7, A.8.2, A.8.3 |
| 7 | A.8.8 |
| 8 | A.8.15, A.8.17 |
| 9 | A.8.22, A.8.23 |
| 10 | A.8.7 |
| 11 | A.8.13, A.8.14 |
| 12 | A.8.20, A.8.21, A.8.22 |
| 13 | A.8.16, A.8.20 |
| 14 | A.6.3, A.6.8 |
| 15 | A.5.19, A.5.20, A.5.21 |
| 16 | A.8.25, A.8.26, A.8.28 |
| 17 | A.5.24, A.5.25, A.5.26 |
| 18 | A.8.8, A.5.36 |
| CIS Control | CMMC Domain | Practices |
|---|---|---|
| 1 | Asset Management | AM.L2-3.11.1 |
| 3 | Media Protection | MP.L2-3.8.x |
| 5 | Identification & Authentication | IA.L1-3.5.x, IA.L2-3.5.x |
| 6 | Access Control | AC.L1-3.1.x, AC.L2-3.1.x |
| 7 | Risk Assessment | RA.L2-3.11.x |
| 8 | Audit & Accountability | AU.L2-3.3.x |
| 10 | System & Information Integrity | SI.L1-3.14.x |
| 17 | Incident Response | IR.L2-3.6.x |
references/safeguards-detail.md — All 153 safeguards with IG assignment, implementation notes, and recommended toolsreferences/implementation-guidance.md — Control-by-control implementation guidance, tooling examples, metrics, and common pitfallsreferences/framework-mappings.md — Detailed CIS Controls v8 ↔ NIST CSF 2.0 / ISO 27001:2022 / CMMC 2.0 / SOC 2 mapping tablesThis skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
anthropics/skills180kToolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debugging UI behavior, capturing browser screenshots, and viewing browser logs.
浏览器自动化
addyosmani/agent-skills103kTests in real browsers via Chrome DevTools MCP. Use when building or debugging anything that runs in a browser. Use when you need to inspect the DOM, capture console errors, analyze network requests, profile performance, or verify visual output with real runtime data. Requires the chrome-devtools MCP server to be configured.
浏览器自动化
ComposioHQ/awesome-claude-skills77kToolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debugging UI behavior, capturing browser screenshots, and viewing browser logs.
浏览器自动化
code-yeongyu/oh-my-openagent70kDrives a real browser through the omowright library from the js eval kernel: sites the user is already signed into, forms and clicks, JS-rendered pages, screenshots, web QA, extension popups, a human handoff for login, CAPTCHA or OTP, and a browser you own for scraping, bot-scored targets, network capture and QA traces. Use for any interactive browser task; not for a plain search or an unblocked static fetch.
浏览器自动化
shanraisshan/claude-code-best-practice67kBrowser automation CLI for AI agents. Use when the user needs to interact with websites, including navigating pages, filling forms, clicking buttons, taking screenshots, extracting data, testing web apps, or automating any browser task. Triggers include requests to "open a website", "fill out a form", "click a button", "take a screenshot", "scrape data from a page", "test this web app", "login to a site", "automate browser actions", or any task requiring programmatic web interaction.
浏览器自动化
CherryHQ/cherry-studio52kRun Cherry Studio critical-path system regression tasks through the repository-owned Playwright E2E workflow. Use for full regression, release acceptance, development-branch system validation, or a named cherry-regression-test task on GitHub-hosted macOS and Windows runners.
浏览器自动化