SKILL.md packages that extend Claude Code, Cursor, Copilot, and other AI agents.
Tags

claude-skills
Provides risk-based security strategy and compliance roadmaps (SOC 2, ISO 27001, HIPAA, GDPR), incident response playbooks, and vendor risk assessments for grow

Anthropic Cybersecurity Skills
Use OWASP Threat Dragon to create data-flow diagrams, apply STRIDE/LINDDUN threat classifications, and generate threat-model reports to guide secure design revi

decepticon
High-volume codebase scanner that shards work, ranks suspicious locations, and promotes a concise set of candidates for deeper analysis.

Anthropic Cybersecurity Skills
Guided workflow to identify, validate, and document reflected, stored, and DOM-based XSS using Burp Suite (scanner, repeater, intruder, DOM Invader).

Arcanum Tabletop Exercises
Design and generate CISA-aligned cybersecurity tabletop exercises, facilitator guides, participant materials, technical atomics, and SOP gap analyses for incide

Anthropic Cybersecurity Skills
Collect and analyze ransomware data-leak site (DLS) postings to extract victim, group, sector, and timeline intelligence for threat hunting and risk assessment.

Anthropic Cybersecurity Skills
Detect Cobalt Strike beacon network activity using TLS certificate signatures, JA3/JA3S/JARM fingerprints, HTTP profile matching, and timing analysis in Zeek/Su

xalgorix
Framework and workflow to turn threat intelligence and telemetry into testable, falsifiable threat-hunting hypotheses for proactive detection.

xalgorix
Use sslyze to assess SSL/TLS server configurations: supported protocols, cipher suites, certificate chains, HSTS/OCSP, and common vulnerabilities like Heartblee

antigravity-awesome-workspace-skill
A comprehensive security testing framework for REST and GraphQL APIs, covering auth, rate limiting, and input validation.

Anthropic Cybersecurity Skills
Guides procurement, evaluation, and proof-of-concept testing for Threat Intelligence Platforms (MISP, OpenCTI, ThreatConnect, Anomali, EclecticIQ) based on inte

claude-fuer-deutsches-recht
Assess IAM for users, roles, groups and applications to support NIS2 cybersecurity compliance and operational decisions.

Anthropic Cybersecurity Skills
Guided procedures to identify DCSync-capable accounts and extract Active Directory credential hashes (KRBTGT, admin) for authorized red-team testing and validat

xalgorix
Implement Zero Trust access for GCP services (Compute Engine, App Engine, Cloud Run, GKE) using identity-based verification and context-aware policies.

xalgorix
Comprehensive guide for enumerating and attacking FreeIPA domains, including LDAP leaks, Kerberos ticket abuse, and HBAC analysis.

maverick
Comprehensive security auditing for codebases, offering full-scan reports and diff-based pre-push gates to prevent vulnerability leaks.

Anthropic Cybersecurity Skills
Deploy and configure SailPoint IdentityNow or IdentityIQ for enterprise identity governance, lifecycle management, and compliance reporting.

Anthropic Cybersecurity Skills
Conducts comprehensive cybersecurity risk assessments using the NIST SP 800-30 Rev 1 methodology to identify threats, vulnerabilities, and impact.

asi
Implements ransomware-resistant backup strategies using Restic with S3-compatible object locking for tamper-proof data protection.

MITRE ATT&CK Agent Skills
Analyze and detect the T1074 'Data Staged' technique in enterprise environments, supporting TTP triage and detection engineering.

cybersecurity-skills-zh
Implement Pod-level network segmentation in Kubernetes to enforce least-privilege communication and prevent lateral movement.

bb-huge
Execute Kerberoasting attacks to extract and crack SPN ticket hashes for privilege escalation in Active Directory.

bb-huge
Comprehensive AD security auditing using MITRE ATT&CK, covering ADCS, GPOs, ACLs, and Kerberos attacks.

Analyst AI Pack
Structures actionable malware analysis reports with executive summaries, IOCs, and MITRE ATT&CK mapping for technical and leadership audiences.

vibe-pentest
A multi-agent parallel architecture for automated black-box web application penetration testing and vulnerability reporting.

MITRE ATT&CK Agent Skills
Analyzes the T1583.006 sub-technique (Web Services) for triage, detection engineering, and incident response mapping.

hermes-profiles
Comprehensive guide for identifying security weaknesses in network infrastructure using Tenable Nessus vulnerability scanner.

Anthropic Cybersecurity Skills
Identify and exploit critical JWT vulnerabilities including algorithm confusion, 'none' bypass, and weak secret exploitation.

bb-huge
Expert-level guide for executing Kerberos-based attacks in AD environments, including roasting, ticket forging, and delegation abuse.