From cybersecurity-skills
Decode and analyze suspicious scripts and active documents without triggering them. Use for shell, AppleScript, JavaScript, Python, PowerShell, shortcuts, Office files, PDFs, configuration profiles, encoded commands, macros, embedded objects, external templates, staged downloads, or mixed document-to-script payload chains.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersecurity-skills:analyze-suspicious-script-or-documentThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Recover the execution chain as data. Use parsers and text extraction in isolation, avoid native handlers, and make each decoding transformation reproducible.
Recover the execution chain as data. Use parsers and text extraction in isolation, avoid native handlers, and make each decoding transformation reproducible.
Read references/script-document-analysis.md for language and document-specific checks.
Return container identity, recovered layers, execution chain, indicators, activation conditions, likely impact, uncertainty, and safe next step.
Creates, edits, and verifies skills using a test-driven development approach with pressure scenarios and subagents.
npx claudepluginhub gaelic-ghost/socket --plugin cybersecurity-skills