Browse Source-Indexed Agent Skills

Find SKILL.md workflows by category, repository, and source date, then inspect the original GitHub file before installing.

Inspect the source before you use a Skill

AI Vitamin indexes original GitHub SKILL.md files and source dates. A listing improves discovery; it does not certify compatibility, security, or requested permissions.

Learn how Agent Skills work

Browse by workflow

1000 source-indexed records across 10 categories.

Source records · Page 19

Only this page of records is included in the HTML response.

mukul975/Anthropic-Cybersecurity-Skills 32.1K stars

building-devsecops-pipeline-with-gitlab-ci

Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security templates. Use when building a shift-left DevSecOps pipeline in GitLab, adding automated vulnerability scanning stages to .gitlab-ci.yml, or triaging scanner findings with GitLab Duo AI before deployment.

Source checked 2026-09-04
mukul975/Anthropic-Cybersecurity-Skills 32.1K stars

building-identity-federation-with-saml-azure-ad

Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync, pass-through auth, third-party IdP) and the SAML authentication flow. Use when extending on-premises authentication authority to cloud resources or designing hybrid identity SSO architecture for Entra ID.

Source checked 2026-09-04
mukul975/Anthropic-Cybersecurity-Skills 32.1K stars

building-identity-governance-lifecycle-process

Design identity governance and lifecycle (IGA) programs on platforms like SailPoint, Saviynt, or Entra ID Governance, covering joiner-mover-leaver (JML) automation, role mining, access requests, periodic recertification, and orphaned-account remediation sourced from an HR feed. Use when automating cross-system JML provisioning, remediating former-employee access, or building lifecycle processes for SOX, HIPAA, or GDPR compliance.

Source checked 2026-09-04
mukul975/Anthropic-Cybersecurity-Skills 32.1K stars

building-incident-response-dashboard

'Builds real-time incident response dashboards in Splunk, Elastic, or

Source checked 2026-09-04
mukul975/Anthropic-Cybersecurity-Skills 32.1K stars

building-incident-response-playbook

Designs and documents structured incident response playbooks with step-by-step

Source checked 2026-09-04
mukul975/Anthropic-Cybersecurity-Skills 32.1K stars

building-incident-timeline-with-timesketch

Build collaborative forensic incident timelines using Timesketch to ingest,

Source checked 2026-09-04
mukul975/Anthropic-Cybersecurity-Skills 32.1K stars

building-ioc-defanging-and-sharing-pipeline

Build an automated pipeline that ingests raw IOCs (URLs, IPs, domains,

Source checked 2026-09-04
mukul975/Anthropic-Cybersecurity-Skills 32.1K stars

building-ioc-enrichment-pipeline-with-opencti

Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native

Source checked 2026-09-04
mukul975/Anthropic-Cybersecurity-Skills 32.1K stars

building-patch-tuesday-response-process

Establish a repeatable operational process for triaging, testing, and

Source checked 2026-09-04
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

achieving-cmmc-level-2-compliance

Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoD contract, when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for or responding to a CMMC assessment, when computing or improving an SPRS score, when building a System Security Plan or POA&M for 800-171, or when scoping which systems are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2, CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment Methodology, 110 controls, defense industrial base, DIB, FedRAMP equivalency.

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

acquiring-disk-image-with-dd-and-dcfldd

Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-api-gateway-access-logs

'Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-apt-group-with-mitre-navigator

Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap analysis. Use to compare threat-actor technique coverage, find gaps in detection engineering, or produce Navigator visualizations for threat-intel reporting.

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-azure-activity-logs-for-threats

'Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-browser-forensics-with-hindsight

Parse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user's web activity from a browser profile.

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-certificate-transparency-for-phishing

Monitor Certificate Transparency logs using crt.sh and Certstream to

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-cobalt-strike-beacon-configuration

Extract and analyze Cobalt Strike beacon configuration from PE files

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-cyber-kill-chain

'Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-disk-image-with-autopsy

Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence.

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-docker-container-forensics

Investigate compromised Docker containers by analyzing images, layers,

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-email-headers-for-phishing-investigation

Parse and analyze email headers (Received chain, Return-Path, Message-ID)

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-ethereum-smart-contract-vulnerabilities

Perform static and symbolic analysis of Solidity smart contracts using

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-indicators-of-compromise

'Analyzes indicators of compromise (IOCs) including IP addresses, domains,

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-ios-app-security-with-objection

Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-kubernetes-audit-logs

Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules from the event patterns. Use when investigating a suspected cluster compromise, reconstructing what an attacker did through the API server, or writing Kubernetes-specific detection content. Keywords: audit policy, audit log, kube-apiserver, exec into pod, RBAC change, anonymous access, detection rules. Do not use for syscall-level detection inside a running container - use detecting-container-runtime-threats-with-falco. '

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-linux-audit-logs-for-intrusion

'Uses the Linux Audit framework (auditd) with ausearch and aureport utilities

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-linux-system-artifacts

Examine Linux system artifacts (auth logs, cron/systemd persistence,

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-lnk-file-and-jump-list-artifacts

Analyze Windows LNK shortcut files and Jump List artifacts with LECmd,

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-memory-forensics-with-lime-and-volatility

'Performs Linux memory acquisition using LiME (Linux Memory Extractor)

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-mft-for-deleted-file-recovery

Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT,

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-network-flow-data-with-netflow

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-network-packets-with-scapy

Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. Use when performing authorized network reconnaissance, protocol-level forensic analysis, or building traffic anomaly detection during security testing.

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-network-traffic-for-incidents

'Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-network-traffic-with-wireshark

'Captures and analyzes network packet data using Wireshark and tshark

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-office365-audit-logs-for-compromise

Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect

Source checked 2026-09-01
mukul975/Anthropic-Cybersecurity-Skills 31.9K stars

analyzing-outlook-pst-for-email-forensics

Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the Recoverable Items folder. Use when conducting email forensic investigations, legal e-discovery, or incident response that requires reconstructing communication patterns or tracing message routing from Outlook archives.

Source checked 2026-09-01