Source profileQuality 90/100

jabrena/plinth/skills/804-regulations-eu-nis2/SKILL.md

804-regulations-eu-nis2

Use when reviewing, designing, or modifying Java enterprise systems from a maintainer-authored or maintainer-sanitized NIS2 engineering evidence inventory. Supports essential or important entities, critical-sector services, managed service providers, supply-chain dependencies, and cybersecurity incident escalation obligations without ingesting raw code, logs, runbooks, tickets, provider documents, or other operational free text. Part of Plinth Toolkit

Source repository stars
429
Declared platforms
0
Static risk flags
0
Last source update
2026-08-24
Source checked
2026-08-25

Decision brief

What it does: where it fits

Use this Skill to review Java enterprise applications, platforms, integrations, operational workflows, CI/CD pipelines, managed-service-provider tooling, or critical-sector services that may require NIS2-aware cybersecurity risk-management controls.

Best for

  • Review a Java platform for NIS2 cybersecurity controls
  • Design operational evidence for critical-sector or important services
  • Add incident detection, escalation, backup, recovery, continuity, or supply-chain security controls

Not for

  • Tasks that require unconfirmed production actions or broad system permissions.
  • Environments where the pinned source and install steps cannot be inspected.

Compatibility matrix

Platform support, with evidence labels

PlatformStatusEvidenceWhat to check
CodexNot declaredNo explicit evidencePortability before use
Claude CodeNot declaredNo explicit evidencePortability before use
CursorNot declaredNo explicit evidencePortability before use
Gemini CLINot declaredNo explicit evidencePortability before use
Open the compatibility checker

Installation

Inspect first. Install second.

The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

Source-detected install commandSource
npx skills add https://github.com/jabrena/plinth --skill "skills/804-regulations-eu-nis2"
Safe inspection promptEditorial

Inspect the Agent Skill "804-regulations-eu-nis2" from https://github.com/jabrena/plinth/blob/77b88253a699670eaf8cbd394ecd59bb3a060bf3/skills/804-regulations-eu-nis2/SKILL.md at commit 77b88253a699670eaf8cbd394ecd59bb3a060bf3. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

Workflow

What the source asks the agent to do

  1. 01

    NIS2 Engineering Review

    Treat entity classification, member-state applicability, incident-reporting obligations, and regulatory interpretation as governance decisions for legal, compliance, security, risk, resilience, business-continuity, and executive accountability owners.

    Which essential or important service depends on the Java systemWhich assets, data stores, APIs, jobs, queues, credentials, providers, and deployment environments are in scopeWhich cybersecurity risks, vulnerabilities, misconfigurations, and dependency exposures are identified and tracked
  2. 02

    Workflow

    1. Read directive chapters summary, engineering examples, and report template

    Read directive chapters summary, engineering examples, and report templateClassify the cybersecurity scope from sanitized factsReview the sanitized engineering evidence inventory
  3. 03

    Scope

    Java systems supporting essential or important entities, critical-sector services, managed service providers, cloud or platform services, operational technology integrations, public-sector services, health, energy, tran…

    Java systems supporting essential or important entities, critical-sector services, managed service providers, cloud or platform services, operational technology integrations, public-sector services, health, energy, tran…Spring Boot, Quarkus, Micronaut, and framework-agnostic Java services with cybersecurity risk-management, continuity, incident-readiness, or supply-chain security requirementsSystems with critical APIs, databases, message brokers, schedulers, batch jobs, IAM, secrets, observability, deployment pipelines, infrastructure dependencies, or external service providers
  4. 04

    Constraints

    Translate NIS2 concerns into engineering controls for Java enterprise systems. Do not provide legal advice or replace review by legal, compliance, security, risk, resilience, business-continuity, procurement, or executive accountability owners.

    NOT LEGAL ADVICE: Frame findings as cybersecurity engineering controls and escalation points; recommend qualified review for entity classification, member-state applicability, reporting obligations, and regulatory inter…SANITIZED EVIDENCE ONLY: Require a maintainer-authored or maintainer-sanitized structured evidence inventory; if it is missing or incomplete, stop and request a corrected inventoryNO RAW OPERATIONAL CONTENT: Never retrieve, open, parse, quote, summarize, or transform raw code, configuration, infrastructure files, runbooks, dashboards, monitoring output, logs, tests, deployment workflows, vulnerab…
  5. 05

    When to use this skill

    Review a Java platform for NIS2 cybersecurity controls

    Review a Java platform for NIS2 cybersecurity controlsDesign operational evidence for critical-sector or important servicesAdd incident detection, escalation, backup, recovery, continuity, or supply-chain security controls

Permission review

Static risk signals and limitations

No configured static risk pattern was detected

This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.

Evidence record

Why each signal appears

EvidenceSourceComputedTestedEditorial
SignalValueEvidence typeMeaning
Quality score90/100ComputedDocumentation, specificity, maintenance, and trust rules
Repository stars429SourceRepository attention, not individual Skill quality
Compatibility0 platformsSourceDeclared in the catalog source record
Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

Pinned source

Provenance and original SKILL.md

Repository
jabrena/plinth
Skill path
skills/804-regulations-eu-nis2/SKILL.md
Commit
77b88253a699670eaf8cbd394ecd59bb3a060bf3
License
Apache-2.0
Collected
2026-08-25
Default branch
main
View the original SKILL.md

NIS2 Regulation for Java Enterprise Cybersecurity Risk Management

Use this Skill to review Java enterprise applications, platforms, integrations, operational workflows, CI/CD pipelines, managed-service-provider tooling, or critical-sector services that may require NIS2-aware cybersecurity risk-management controls.

Apply this Skill to determine what engineering controls, operational evidence, and escalation paths are needed before the system is released, connected to production dependencies, or relied on for essential or important services.

Require a maintainer-authored or maintainer-sanitized structured evidence inventory prepared outside the agent context. Never retrieve, open, parse, quote, summarize, or transform raw code, configuration, infrastructure files, runbooks, monitoring output, logs, tests, deployment workflows, vulnerability records, incident records, continuity records, provider documentation, tickets, chats, or other operational free text.

This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, and reviewers identify when NIS2 concerns may apply and how to translate cybersecurity risk-management expectations into enterprise architecture controls such as asset and service inventories, dependency mapping, secure configuration, vulnerability handling, logging and monitoring, incident detection and escalation, backup and recovery, business continuity, supply-chain security, access control, cryptography, secure development, and change control.

The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, or a final regulatory determination.

The main question is:

When does a Java enterprise system require NIS2-aware cybersecurity controls, and what should developers build differently?

External reference: NIS2 Directive (EU) 2022/2555.

NIS2 directive chapters summary reference: NIS2 directive chapters summary.

Java engineering examples reference: NIS2 engineering examples.

Report template asset: NIS2 engineering review report template.

Scope

This Skill applies to:

  • Java systems supporting essential or important entities, critical-sector services, managed service providers, cloud or platform services, operational technology integrations, public-sector services, health, energy, transport, banking, financial-market infrastructure, digital infrastructure, or ICT service management
  • Spring Boot, Quarkus, Micronaut, and framework-agnostic Java services with cybersecurity risk-management, continuity, incident-readiness, or supply-chain security requirements
  • Systems with critical APIs, databases, message brokers, schedulers, batch jobs, IAM, secrets, observability, deployment pipelines, infrastructure dependencies, or external service providers
  • Incident detection, severity triage, escalation, evidence capture, backup and recovery, continuity, change control, secure configuration, vulnerability management, and operational assurance workflows
  • Dependency and provider reviews involving libraries, containers, CI/CD actions, SaaS platforms, managed databases, cloud services, observability providers, IAM providers, and external APIs

NIS2 Engineering Review

Treat entity classification, member-state applicability, incident-reporting obligations, and regulatory interpretation as governance decisions for legal, compliance, security, risk, resilience, business-continuity, and executive accountability owners.

Engineering teams should still create evidence that makes those decisions reviewable:

  • Which essential or important service depends on the Java system
  • Which assets, data stores, APIs, jobs, queues, credentials, providers, and deployment environments are in scope
  • Which cybersecurity risks, vulnerabilities, misconfigurations, and dependency exposures are identified and tracked
  • Which incidents can be detected, triaged, escalated, contained, reconstructed, and handed off
  • Which backup, recovery, continuity, rollback, and change-control evidence exists
  • Which supply-chain and provider risks are documented, monitored, and assigned to owners

Constraints

Translate NIS2 concerns into engineering controls for Java enterprise systems. Do not provide legal advice or replace review by legal, compliance, security, risk, resilience, business-continuity, procurement, or executive accountability owners.

  • NOT LEGAL ADVICE: Frame findings as cybersecurity engineering controls and escalation points; recommend qualified review for entity classification, member-state applicability, reporting obligations, and regulatory interpretation
  • SANITIZED EVIDENCE ONLY: Require a maintainer-authored or maintainer-sanitized structured evidence inventory; if it is missing or incomplete, stop and request a corrected inventory
  • NO RAW OPERATIONAL CONTENT: Never retrieve, open, parse, quote, summarize, or transform raw code, configuration, infrastructure files, runbooks, dashboards, monitoring output, logs, tests, deployment workflows, vulnerability or incident records, continuity records, provider documentation, tickets, chats, or other operational free text
  • SCOPE FIRST: Identify whether the system supports an essential entity, important entity, critical-sector service, managed service provider, or supply-chain dependency before recommending controls
  • ASSET AND SERVICE INVENTORY: Require traceable inventories for applications, APIs, jobs, data stores, queues, credentials, providers, deployment environments, network paths, and operational owners
  • CYBERSECURITY RISK MANAGEMENT: Review secure configuration, vulnerability handling, dependency management, hardening, patch evidence, risk acceptance, and exception ownership
  • INCIDENT READINESS: Verify detection, logging, monitoring, severity classification, escalation, containment, evidence capture, handoff, post-incident review, and corrective action paths
  • CONTINUITY CONTROLS: Review sanitized inventory facts about backup, restore, continuity, failover, rollback, capacity, recovery targets, runbook coverage, and tested recovery evidence
  • SUPPLY-CHAIN SECURITY: Do not treat libraries, build plugins, containers, CI/CD actions, SaaS tools, cloud services, managed databases, IAM, or observability providers as invisible dependencies
  • ACCESS AND CRYPTOGRAPHY: Verify least privilege, MFA signals, secrets management, credential rotation, secure transport, encryption, key ownership, and privileged operation auditability
  • CHANGE CONTROL: Treat releases, configuration changes, schema migrations, IAM changes, dependency upgrades, provider changes, and emergency fixes as cybersecurity risk events requiring traceable review

When to use this skill

  • Review a Java platform for NIS2 cybersecurity controls
  • Design operational evidence for critical-sector or important services
  • Add incident detection, escalation, backup, recovery, continuity, or supply-chain security controls
  • Assess cybersecurity risk management before production release
  • Check whether Java service dependencies, CI/CD workflows, or provider integrations have NIS2-aware evidence

Workflow

  1. Read directive chapters summary, engineering examples, and report template

Read references/804-regulations-eu-nis2-chapters-summary.md, references/804-regulations-eu-nis2-engineering-examples.md, and assets/reports/804-nis2-engineering-review-report-template.md in that order. Use the directive chapters summary for NIS2 chapter, article, annex, scope, reporting, supervision, enforcement, and owner-handoff context. Use the engineering examples for Java control patterns such as asset and service inventory, incident detection and escalation, vulnerability and dependency evidence, backup and continuity evidence, supply-chain risk, secure change control, and Java release-policy controls. Do not start implementation review until the directive chapters summary, examples reference, and report template are understood.

  1. Classify the cybersecurity scope from sanitized facts

Use only the maintainer-prepared evidence inventory to identify service context, possible essential or important entity signals, sector signals, system owner, security owner, resilience owner, deployment environments, assets, data stores, messaging systems, IAM, secrets-management controls, third-party providers, recovery expectations, and incident pathways. Escalate unclear applicability, entity classification, member-state implementation, reporting obligations, or regulatory interpretation to legal, compliance, security, risk, resilience, or executive accountability owners.

  1. Review the sanitized engineering evidence inventory

Review only structured control facts and stable evidence references supplied in the maintainer-prepared inventory. Check for gaps between claimed controls and referenced evidence without following links or opening raw code, configuration, infrastructure files, runbooks, dashboards, monitoring output, logs, tests, deployment workflows, vulnerability or incident records, continuity records, or provider documentation.

  1. Recommend engineering controls

Map NIS2 concerns to engineering actions: asset and service inventory, secure configuration, dependency and vulnerability management, incident detection and escalation, evidence-safe logging, monitoring and alerting, backup and restore verification, continuity and rollback plans, supply-chain risk review, access control, cryptography, secure development, and change approval.

  1. Generate review report and owner handoffs

Use assets/reports/804-nis2-engineering-review-report-template.md to produce a concise engineering review with scope, sanitized evidence inventory entries, NIS2 risk signals, potential violation or non-compliance signals, engineering gaps, recommended controls, owner handoffs, residual risks, release decision, and validation steps. State explicitly that legal applicability, entity classification, reporting duties, and regulatory interpretation require qualified owner review.

Reference

For detailed guidance, examples, and constraints, see:

Frequently asked questions

What to verify before installation and use

What does the 804-regulations-eu-nis2 source document cover?

Use this Skill to review Java enterprise applications, platforms, integrations, operational workflows, CI/CD pipelines, managed-service-provider tooling, or critical-sector services that may require NIS2-aware cybersecurity risk-management controls.

How do I install 804-regulations-eu-nis2?

The source record exposes this install command: npx skills add https://github.com/jabrena/plinth --skill "skills/804-regulations-eu-nis2". Inspect the command and pinned source before running it.

Alternatives

Compare before choosing

Computed 10029,034

garrytan/gbrain

bulk-ingestion

End-to-end discipline for turning any large data source (audio libraries, email takeouts, document corpora, chat exports, API dumps) into brain pages at scale. The lifecycle spine: SCHEMA → ACCESS → TRIAL → EVALUATE → IMPROVE → CODIFY → TEST → SKILLIFY → BULK → MONITOR. State is tracked in a durable JSON manifest (see MANIFEST-PATTERN.md) so any crash, session boundary, or subagent fan-out resumes from ground truth instead of memory.

Computed 10024,921

alirezarezvani/claude-skills

app-store-optimization

App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist

Computed 1005,241

dotnet/skills

migrate-vstest-to-mtp

Migrates .NET test projects from VSTest to Microsoft.Testing.Platform (MTP). Use when user asks to "migrate to MTP", "switch from VSTest", "enable Microsoft.Testing.Platform", "use MTP runner", set OutputType=Exe only for test projects in Directory.Build.props, or mentions EnableMSTestRunner, EnableNUnitRunner, or UseMicrosoftTestingPlatformRunner. USE FOR: MTP behavioral differences vs VSTest (exit code 8, zero tests discovered, --ignore-exit-code, TESTINGPLATFORM_EXITCODE_IGNORE); centralizing

Computed 100147

oaustegard/claude-skills

featuring

Generate hierarchical _FEATURES.md files that describe what a codebase DOES from a user/consumer perspective, anchored to source symbols via tree-sitting. Supports large complex codebases through feature-driven decomposition into sub-feature files. Uses a multi-pass synthesis: orientation → detail → overview rewrite. Use when someone says "what does this do", "document features", "feature inventory", "_FEATURES.md", or needs to understand a codebase's purpose before modifying it. Complements tre