From billy-milligan
PCI DSS compliance: SAQ A vs SAQ D scope, Stripe Elements for card data isolation, tokenization patterns, cardholder data environment (CDE) scoping, network segmentation, encryption in transit/at rest, audit logging requirements. Never store raw card data. Use when implementing payment systems, reviewing card data handling, PCI scope reduction.
npx claudepluginhub rnavarych/alpha-engineer --plugin billy-milliganThis skill is limited to using the following tools:
- Implementing payment card processing
Compares coding agents like Claude Code and Aider on custom YAML-defined codebase tasks using git worktrees, measuring pass rate, cost, time, and consistency.
Designs and optimizes AI agent action spaces, tool definitions, observation formats, error recovery, and context for higher task completion rates.
Designs, implements, and audits WCAG 2.2 AA accessible UIs for Web (ARIA/HTML5), iOS (SwiftUI traits), and Android (Compose semantics). Audits code for compliance gaps.
pm_xxx, tok_xxx); your app never sees raw card numbersreferences/saq-selection.md — SAQ A vs SAQ A-EP vs SAQ D decision tree, control counts, scope criteriareferences/cardholder-data.md — what to store vs what to forbid, tokenization schema, webhook security patternsreferences/network-segmentation.md — CDE boundary design, firewall rules, segmentation testing