By mukul975
Provides structured guidance for executing cybersecurity operations across penetration testing, incident response, threat hunting, cloud security, and malware analysis, with step-by-step procedures and tool usage.
Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM ELF samples. Activates for requests involving Linux malware analysis, ELF binary investigation, Linux server compromise assessment, or container malware analysis.
Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains and anomalous query patterns
Configures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing.
Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.
Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
817 production-grade cybersecurity skills · 29 security domains · 6 framework mappings · 26+ AI platforms
Get Started · What's Inside · Frameworks · Platforms · Contributing
⚠️ Community Project — This is an independent, community-created project. Not affiliated with Anthropic PBC.
🔐 Authorized & lawful use only. This library includes offensive and dual-use techniques (e.g. red-team C2, phishing simulation, exploitation) intended for authorized penetration testing, security research, defense, and education. Only use them against systems you own or have explicit written permission to test, and comply with all applicable laws and rules of engagement. You are solely responsible for how you use these skills. See SECURITY.md and CODE_OF_CONDUCT.md.
A junior analyst knows which Volatility3 plugin to run on a suspicious memory dump, which Sigma rules catch Kerberoasting, and how to scope a cloud breach across three providers. Your AI agent doesn't — unless you give it these skills.
This repo contains 817 structured cybersecurity skills spanning 29 security domains, each following the agentskills.io open standard. Every skill is mapped to six industry frameworks — MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, NIST AI RMF, and the MITRE Fight Fraud Framework (F3) — making this the only open-source skills library with unified cross-framework coverage. Clone it, point your agent at it, and your next security investigation gets expert-level guidance in seconds.
No other open-source skills library maps every skill to all of these frameworks. One skill, six compliance checkboxes.
npx claudepluginhub mukul975/anthropic-cybersecurity-skills --plugin cybersecurity-skillsComplete collection of 282+ privacy and data protection skills covering GDPR, CCPA, HIPAA, LGPD, PIPL, and 15+ regulations
11 healthcare privacy skills: HIPAA Privacy/Security Rules, risk analysis, BAA management, de-identification, telehealth
13 US state privacy law skills: CCPA/CPRA, VCDPA, CPA, CTDPA, TDPSA, multi-state compliance, universal opt-out
14 consent management skills: valid consent, consent withdrawal, preference centers, consent for research, children, mobile apps
13 breach response skills: 72h notification, forensics, remediation, simulation, multi-jurisdiction, credit monitoring
734+ 网络安全技能,涵盖 Web 安全、渗透测试、DFIR、威胁情报、云安全、恶意软件分析等领域。中文版本。
872 on-demand security skills for CTF, pentest, bug bounty, DFIR, detection engineering, cloud, identity, and red/blue team work. Skills are plain Markdown and activate by task without permanently consuming context. Bundles vendored skills under mixed licenses (MIT, Apache-2.0, CC-BY-SA-4.0) — see per-source attribution in .claude/skills/SKILLS.md.
A complete cybersecurity toolkit: 19 skills spanning reconnaissance, vulnerability assessment, exploit development, reverse engineering, malware analysis, threat hunting, incident response, network/web/cloud security, SOC automation, log analysis, cryptography, red and blue team operations, and AI/LLM, mobile, OT/ICS, and GRC security.
Cybersecurity skills for AI agents — code audit, cloud, recon, IR, AI security, and more
🛡️ Security Engineer — Security Engineer + Adversarial Security Specialist
Editorial "Security Engineer" bundle for Claude Code from Antigravity Awesome Skills.