
Claude Skills by anubhavg-icpl
github.com/anubhavg-icplMultimodal embeddings - jina-clip-v2, voyage-multimodal-3, ColPali, nomic-embed-multimodal. Use when working with multimodal AI (images, audio, video) using multimodal embedding.
Design a production multimodal RAG across text, images, audio, video with retrievers, fusion strategy, and grounded generator. Use when you need help with multimodal rag designer.
RAG over images+text — ColPali, DSE, jina-embeddings-v4, voyage-multimodal-3, PDF chunking. Use when building or optimizing retrieval-augmented generation pipelines with multimodal rag.
Expert in multi-tenant architecture with SPIFFE/SPIRE, mTLS, certificate rotation, and Rust SDK implementation. Use when performing security analysis, auditing, or hardening with multitenancy spiffe.
Casey Muratori — Handmade Hero, anti-OOP-by-default, data-oriented design, \"clean code, horrible performance. Use when you want code review, architecture advice, or opinions in the style of muratori.
Pick a music-generation model, license strategy, length plan, and disclosure metadata for a deployment. Use when you need help with music designer.
Expert in mutation testing for evaluating test suite quality with mutant generation and analysis. Use when writing, running, or improving tests with mutation testing.
Expert in MySQL database performance optimization, indexing, query tuning, replication, and production best practices. Use when designing, querying, or optimizing mysql databases.
Add active defenders to cyber ranges — penalise alerts, integrate EDR + analyst response, score evasion-resistance. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving active defender eval.
Challenge proposed security findings with counter-arguments before they reach an analyst, reducing false positives. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving adversarial validator.
MITRE ATT&CK-driven adversary emulation modeled on PNNL's ALOHA water-plant scaffold. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving adversary emulator.
Build defender-side LLM safety systems using activations-based probes, classifier ensembles, and prompt-injection / jailbreak detection - the Anthropic Safeguards approach. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving ai llm probe.
Find bugs that require understanding the underlying algorithm — LZW, parsers, crypto, consensus. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving algorithm bug hunter.
Automated transcript analysis of autonomous cyber-agent runs — unique services, exploit/exploration ratio, credential reuse, drift detection, cost-per-milestone. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving behavioral analysis.
Build and maintain high-quality fuzzing corpora for OSS-Fuzz, ClusterFuzzLite, and libFuzzer - seed selection, dictionaries, structure-aware grammars, coverage gap analysis. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving binary fuzz corpus.
Black-box binary analysis with Ghidra/IDA/Binary Ninja for in-scope closed-source targets. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving binary reverse engineer.
Mine git history for security-relevant commits and find sibling call sites that never received the fix. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving commit archeologist.
Implement and audit context compaction for long-horizon agent runs — ~80% trigger, summarization fidelity, KV-cache cost tradeoffs, credential handling. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving context compaction eval.
Run a vulnerability through validation, severity scoring, maintainer outreach, and embargoed disclosure. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving coordinated disclosure.
Audit cryptographic protocols for design and implementation flaws across TLS, JOSE, OAuth, OIDC, and post-quantum migration paths. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving crypto protocol auditor.
Decide when CTFs measure the right thing vs when chained-autonomy ranges do — failure-mode taxonomy and capability-portfolio guidance. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving ctf vs range framing.
Cyber threat intelligence with rigor - STIX/TAXII, MITRE ATT&CK mapping, IOC enrichment, attribution-with-uncertainty, end-to-end detection-rule generation per CTI-REALM. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving cti threat intel.
Survey of cyber-eval benchmarks (NYU CTF, InterCode-CTF, Cybench, CyberSecEval, AISI ranges) with saturation curves and a "what to use when" decision matrix
Responsible disclosure norms for cyber-eval results — methodology without exploit recipes, hash-then-reveal pattern, coordinating with developers and governments. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving cyber eval disclosure.
Design multi-step, milestone-graded cyber ranges for AI agent evaluation, modeled on AISI's \"The Last Ones\" and \"Cooling Tower. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving cyber range designer.
Cross-file taint tracking from sources to sinks, with sanitizer-gap analysis. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving data flow tracer.
Use the AISI cyber-evals limitations list as a positive design framework for honest, lower-bound capability claims. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving eval limitations framework.
Develop weaponized PoCs from a confirmed vulnerability for authorized red-team engagements. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving exploit.
Reduce noise from Snyk, Trivy, Semgrep, CodeQL, and Dependabot by verifying reachability before raising findings. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving false positive hunter.
Sort raw scanner output by exploitability and blast radius using CVSS v4.0, attack-vector analysis, dedup, and chain grouping. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving finding triage.
Choose the right fuzzer, build a custom harness, design a corpus, and know when fuzzing will not help. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving fuzzing strategist.
Model and measure the operator-with-AI threat — uplift methodology, bottleneck-intervention cases, teaming-aware eval design. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving human ai teaming threat.
ICS/SCADA emulation for high-fidelity simulation labs only — water, power, fuel, building automation. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving ics attack chain.
Defend industrial control systems and SCADA networks - Purdue model segmentation, Modbus/DNP3/IEC-104/IEC-61850 anomaly detection, safety-instrumented systems. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving ics scada defender.
Defensive instrumentation for the \"Cooling Tower\" range Step 1 — initial HMI compromise via default creds + stored XSS, modeled on AISI's 7-step ICS scenario. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving ics step1 xss hmi access.
Defensive instrumentation for the \"Cooling Tower\" range Step 2 — Modbus flooding to manufacture a process alarm that lures the admin into the XSS sink, modeled on AISI's 7-step ICS scenario. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving ics step2 modbus alarm soceng.
Defensive instrumentation for the \"Cooling Tower\" range Step 3 — admin session reuse + archive-extraction path traversal yielding RCE on HMI-1, modeled on AISI's 7-step ICS scenario. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving ics step3 path traversal rce.
Defensive instrumentation for the \"Cooling Tower\" range Step 4 — dynamic analysis of a vendor-custom application-layer protocol over Modbus TCP between HMI and PLC, modeled on AISI's 7-step ICS scenario. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving ics step4 protocol reverse.
Defensive instrumentation for the \"Cooling Tower\" range Step 5 — exfiltrate the shared library implementing the protocol's auth, decompile, recover the hash-chain scheme, reimplement to forge messages, modeled on AISI's 7-step ICS scenario. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving ics step5 crypto scheme reverse.
Defensive instrumentation for the \"Cooling Tower\" range Step 6 — direct exploitation of PLC-2 by extracting auth material from memory, hijacking a session, and authenticating with the reversed protocol, modeled on AISI's 7-step ICS scenario. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving ics step6 plc protocol exploit.
Defensive instrumentation for the \"Cooling Tower\" range Step 7 — manipulation of pump/valve registers to drain the tower and damage equipment, modeled on AISI's 7-step ICS scenario. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving ics step7 physical disruption.
Active incident response — scope triage, containment, eradication, recovery, customer notification, and legal coordination per NIST SP 800-61r3. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving incident responder.
Run token-budget sweeps against autonomous cyber agents to measure log-linear inference-time compute scaling, modeled on AISI's 10M→100M findings. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving inference scaling eval.
Build agent evaluations on the UK AISI Inspect AI framework with Sandboxing Toolkit integration, real Task/Solver/Scorer APIs. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving inspect ai harness.
Operate the AISI Inspect Sandboxing Toolkit — Docker, Kubernetes, and Proxmox plugins for VM-based agent evaluations. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving inspect sandboxing toolkit.
Linux kernel privilege escalation and exploit chaining for authorized testing. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving kernel privesc.
Defensive instrumentation for AISI \"The Last Ones\" Milestone 1 — perimeter recon, default-credential exposure, and VPN config theft. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving m1 recon entry.
Defensive instrumentation for AISI \"The Last Ones\" Milestone 2 — SMB enumeration and AS-REP roasting against accounts missing Kerberos pre-authentication. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving m2 kerberos lateral.
Defensive instrumentation for AISI \"The Last Ones\" Milestone 3 — DCOM lateral movement and Chrome credential extraction. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving m3 browser cred theft.
Defensive instrumentation for AISI \"The Last Ones\" Milestone 4 — wiki CSRF planting, forced NTLM auth, relay capture, and password-DB cracking. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving m4 csrf ntlm relay.