Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Cyber Engagement Planning

ASecurity

Drafts bounded cybersecurity engagement plans with objectives, scope, exclusions, roles, authorization, runtime controls, evidence, stop criteria, and restart gates. Use when preparing an exercise or assessment plan before execution.

571 stars
0 votes
0 copies
0 views
Added 9/24/2026
developmentrustgosecurity

Security Analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-engagement-planning --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cyber Engagement Planning?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Cyber Engagement Planning
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-cyber-engagement-planning-df5a6fad/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-engagement-planning-df5a6fad)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: cyber-engagement-planning
guardrail: true
description: Drafts bounded cybersecurity engagement plans with objectives, scope, exclusions, roles, authorization, runtime controls, evidence, stop criteria, and restart gates. Use when preparing an exercise or assessment plan before execution.
metadata:
  labels: [cybersecurity, engagement-planning, scope]
  triggers:
    keywords: [engagement plan, rules of engagement, exercise plan, security assessment scope, test exclusions, stop criteria]
---
# Cyber Engagement Planning

## **Priority: P0 (CRITICAL)**

Produce a reviewable plan that separates intended activity from host-enforced permission.

## Structure

```text
cyber-engagement-planning/
├── SKILL.md
├── references/engagement-brief.md
└── evals/evals.json
```

## Workflow

1. State objective, success observation, engagement/scope reference, dates, and accountable owner.
2. List in-scope synthetic assets or explicitly authorized targets; list exclusions and non-goals.
3. Assign requester, approver, operator, exercise control, adjudicator, and escalation roles.
4. Record allowed actions, prohibited actions, data handling, communications, and runtime controls.
5. Define expiry, stop triggers, restart authority, evidence fields, and unresolved decisions.
6. Mark live execution `blocked` and the plan offline-only when required runtime support is absent; never imply production readiness.
7. Restart requires both current authorization and verified host enforcement of scope. Owner approval, risk acceptance, documented exceptions, or proposed compensating controls cannot waive either prerequisite; unverified alternatives keep the live lane blocked.

## Rules

- Plan only; do not include payloads, attack commands, credentials, real targets, or destructive steps.
- Treat production modifications as separately approved actions.
- Reuse [authorization](../cyber-authorization/SKILL.md), [evidence](../cyber-evidence/SKILL.md), and [mapping](../cyber-framework-mapping/SKILL.md).
- Use primary framework sources; mark uncertain mappings explicitly.
Plan evidence fields explicitly: `engagement_scope_ref`, `skill_version`, `source`, `observed_at`, `finding_status`, `evidence_refs`, `limitations`, and `accountable_owner`.

## Anti-Patterns

- **No implied authorization**: A completed plan is not approval.
- **No vague scope**: Name boundaries and exclusions.
- **No hidden runtime dependency**: State unsupported controls and block live work.
- **No team-color shortcut**: Roles do not replace authorization.

## References

- [Engagement brief](references/engagement-brief.md)
- [Canonical review artifact conventions](../../common/common-security-audit/references/trust-review-policy.md)

Attribution

HoangNguyen0403HoangNguyen0403
View sourceSee grades on GitHubMore from HoangNguyen0403 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Clean Code

Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments

304955 votes

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

286712 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Writing Plans

Use when you have a spec or requirements for a multi-step task, before touching code

2927051 votes
View all in development →