# Pci Dss Payment Audit

> 'We use a Stripe iframe, so this doesn't apply to us' is the belief that gets merchants skimmed.

- Skill: `rikocr8orh8/pci-dss-payment-audit` (Agent Skill)
- Install (CLI): `npx skillmds@latest add rikocr8orh8/pci-dss-payment-audit`
- Raw SKILL.md: https://api.skillmd.com/api/skills/rikocr8orh8/pci-dss-payment-audit/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: rikocr8orh8 (https://skillmd.com/u/rikocr8orh8)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/rikocr8orh8/pci-dss-payment-audit

---


# PCI DSS Payment-Page Script Audit (6.4.3 & 11.6.1) — $79

'We use a Stripe iframe, so this doesn't apply to us' is the belief that gets merchants skimmed. Requirements 6.4.3 and 11.6.1 have been mandatory since 2025-03-31, and they protect the page as the consumer's browser receives it, not as your server stores it. QSA-prep, never a 'you pass.'

**This is a preview.** The full skill (method, Iron Rules, dated snapshots, worked examples) is available on Agensi:
[agensi.io/skills/pci-dss-payment-audit](https://www.agensi.io/skills/pci-dss-payment-audit)

