Anthropic-Cybersecurity-Skills
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·
Anthropic Cybersecurity Skills is an open-source library of 817 structured cybersecurity agent skills mapped to six industry frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF, and MITRE Fight Fraud Framework. Each skill provides step-by-step workflows, prerequisites, verification steps, and framework mappings in YAML frontmatter plus Markdown format, enabling AI agents to execute security analyst tasks across 29 domains including threat hunting, digital forensics, cloud security, and malware analysis. It works with Claude Code, GitHub Copilot, Cursor, Gemini CLI, and 20+ agentskills.io-compatible platforms.
Key Features
Use Cases
- 01Memory forensics analysis: agent scans skills, identifies Volatility3 workflow, executes credential-dumping detection procedures mapped to ATT&CK T1003
- 02Incident response automation: agent loads breach containment playbooks with NIST CSF alignment and framework-validated response steps
- 03Threat hunting workflows: hypothesis-driven hunt execution using EVTX analysis, LOTL detection, and fleet-wide hunting procedures
- 04Cloud security assessment: AWS/Azure/GCP hardening workflows with CSPM controls and cloud attack emulation techniques
- 05Red team operation planning: agent sequences ADCS exploitation, BloodHound enumeration, and C2 setup detection mapped to 15 ATT&CK tactics
- 06Compliance validation: NIST 800-30/RMF, CMMC, HIPAA, and GDPR assessment workflows with Govern/Identify/Protect/Detect/Respond/Recover functions
Related Skills
View moresuperpowers
An agentic skills framework & software development methodology that works.
skills
Skills for Real Engineers. Straight from my .agents directory.
skills
Public repository for Agent Skills
ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
Anthropic-Cybersecurity-Skills — FAQ
What is Anthropic Cybersecurity Skills?+
It is an open-source library of 817 structured cybersecurity workflows (called skills) that follow the agentskills.io standard, enabling AI agents to execute security analyst tasks with step-by-step procedures mapped to MITRE ATT&CK, NIST CSF 2.0, and four other frameworks. Each skill encodes real practitioner playbooks covering 29 security domains from threat hunting to digital forensics.
How do I install and use these skills with my AI agent?+
For agentskills.io-compatible platforms, run 'npx skills add mukul975/Anthropic-Cybersecurity-Skills' to install. Alternatively, clone the repository with 'git clone https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git' and point your agent at the skills directory. Agents scan the YAML frontmatter to discover relevant skills, then load the full Markdown workflow on demand.
Which AI clients and platforms work with these skills?+
The skills work with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Windsurf, Gemini CLI, Cline, Aider, Continue, and any platform supporting the agentskills.io standard. Agent frameworks like LangChain, CrewAI, AutoGen, and Semantic Kernel are also compatible.
Do I need API keys or special access to use these skills?+
The skills library itself requires no API keys and is Apache 2.0 licensed. However, individual skills may reference security tools (Volatility3, BloodHound, Nessus, etc.) that require separate installation or licensing. Prerequisites are documented in each skill's frontmatter and Prerequisites section.
Is this library free to use commercially?+
Yes, the library is licensed under Apache License 2.0, allowing free use, modification, and distribution in both personal and commercial projects. You must comply with authorized and lawful use requirements for offensive security techniques.
How are skills mapped to MITRE ATT&CK and other frameworks?+
Each skill's YAML frontmatter contains validated technique IDs for applicable frameworks—ATT&CK uses T1XXX IDs from v19.1 Enterprise/Mobile/ICS, NIST CSF 2.0 uses function/category codes, ATLAS uses AML.TXXXX, D3FEND uses D3-XXX, AI RMF uses function references, and F3 uses F1XXX fraud technique IDs. Mappings are validated against official MITRE STIX bundles and NIST publications.
How do I install Anthropic-Cybersecurity-Skills?+
Open the source repository on GitHub and follow its README. Anthropic-Cybersecurity-Skills is a skill — MCP Agents Market links you directly to the official repo.
Is Anthropic-Cybersecurity-Skills free?+
Anthropic-Cybersecurity-Skills is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.