Router into 817 Anthropic-Cybersecurity-Skills (MITRE ATT&CK, NIST CSF, ATLAS, D3FEND, AI RMF, F3). Use for security investigations, DFIR, red/blue team playbooks.
Scanned 9/2/2026
Install to Claude Code
npx -y skills add nuroctane/nur-cli --skill cybersecurity --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Cybersecurity?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/nuroctane-cybersecurity)More formats (shields.io, HTML) on the badges page.
---
name: cybersecurity
description: "Router into 817 Anthropic-Cybersecurity-Skills (MITRE ATT&CK, NIST CSF, ATLAS, D3FEND, AI RMF, F3). Use for security investigations, DFIR, red/blue team playbooks."
---
# Cybersecurity skills library
Source: https://github.com/mukul975/Anthropic-Cybersecurity-Skills (Apache-2.0, community).
**Authorized & lawful use only.** Offensive skills are for systems you own or have written permission to test.
## How Meta uses this pack
- Full skill bodies live under `~/.agents/skills/` (and mirrors) after ecosystem ensure.
- Do **not** load all 817 into context. Progressive disclosure:
1. Match the user task to a skill **name** via list/grep of skill dirs or index.
2. `skill(action=read, name=<kebab-name>)` for the full playbook.
3. Execute workflow steps with bash/read tools; map findings to ATT&CK IDs.
## Domains (29)
Cloud · Threat Hunting · Threat Intel · Network · Web App · DFIR · Malware · IAM · SOC · Red Team · Containers · OT/ICS · API · IR · Vuln Mgmt · Pentest · DevSecOps · Zero Trust · Endpoint · Crypto · Phishing · AI Security · Mobile · Ransomware · Compliance · Supply Chain · Deception · Hardware/Firmware
## Example matches
| User ask | Skill to load |
|----------|----------------|
| memory dump credential theft | performing-memory-forensics-with-volatility3 |
| S3 public buckets | auditing-aws-s3-bucket-permissions |
| prompt injection | detecting-ai-model-prompt-injection-attacks |
| kerberoasting | detecting-kerberoasting-attacks |
| Solidity / DeFi / Immunefi | sc-research (then one playbook, `hunting-x-linked-bounties`, or one historical-smart-contract-vulns slice including investigator-ops; this pack's Crypto domain is cryptography, not DeFi) |
Index: https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/main/index.json
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!