Campaign Attribution Evidence Analysis
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
Black box flight recorder for the server. An agent skill from bolivian-peru/os-moda.
$ npx skills add bolivian-peru/os-moda --skill flight-recorder -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install bolivian-peru/os-moda flight-recorder --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/bolivian-peru/os-moda.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/flight-recorder .claude/skills/flight-recorder && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "flight-recorder" agent skill from https://github.com/bolivian-peru/os-moda/tree/main/skills/flight-recorder into .claude/skills/flight-recorder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flight-recorder", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/bolivian-peru/os-moda/tree/main/skills/flight-recorderType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add bolivian-peru/os-moda --skill flight-recorder -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install bolivian-peru/os-moda flight-recorder --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bolivian-peru/os-moda.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/flight-recorder .agents/skills/flight-recorder && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "flight-recorder" agent skill from https://github.com/bolivian-peru/os-moda/tree/main/skills/flight-recorder into .agents/skills/flight-recorder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flight-recorder", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bolivian-peru/os-moda --skill flight-recorder -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install bolivian-peru/os-moda flight-recorder --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bolivian-peru/os-moda.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/flight-recorder .cursor/skills/flight-recorder && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "flight-recorder" agent skill from https://github.com/bolivian-peru/os-moda/tree/main/skills/flight-recorder into .cursor/skills/flight-recorder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flight-recorder", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/bolivian-peru/os-moda.git --path skills/flight-recorder--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add bolivian-peru/os-moda --skill flight-recorder -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install bolivian-peru/os-moda flight-recorder --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bolivian-peru/os-moda.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/flight-recorder .gemini/skills/flight-recorder && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "flight-recorder" agent skill from https://github.com/bolivian-peru/os-moda/tree/main/skills/flight-recorder into .gemini/skills/flight-recorder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flight-recorder", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install bolivian-peru/os-moda flight-recorderInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add bolivian-peru/os-moda --skill flight-recorder -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/bolivian-peru/os-moda.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/flight-recorder .github/skills/flight-recorder && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "flight-recorder" agent skill from https://github.com/bolivian-peru/os-moda/tree/main/skills/flight-recorder into .github/skills/flight-recorder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flight-recorder", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bolivian-peru/os-moda --skill flight-recorder -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install bolivian-peru/os-moda flight-recorder --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bolivian-peru/os-moda.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/flight-recorder .opencode/skills/flight-recorder && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "flight-recorder" agent skill from https://github.com/bolivian-peru/os-moda/tree/main/skills/flight-recorder into .opencode/skills/flight-recorder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flight-recorder", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
flight-recorderBlack box flight recorder for the server. An agent skill from bolivian-peru/os-moda.
Flight Recorder is an agent skill from bolivian-peru/os-moda. Black box flight recorder for the server. Capture system state snapshots for forensic analysis after incidents. Continuous telemetry ring buffer.
Its SKILL.md is about 620 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Digital forensics. The repository describes itself as: An operating system built for AI agents — talk to your NixOS server instead of SSH-ing in. Typed, audited tool access with atomic rollback on every change. Research-grade; run it… The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b8e418f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Flight Recorder loads about 624 tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 90 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from bolivian-peru/os-moda at commit b8e418f, republished under its Apache-2.0 licence (© bolivian-peru). 90 words, ~624 tokens.
.claude/skills/flight-recorder/SKILL.md (or your agent's skills folder).Continuous state capture for post-incident forensics.
Capture a lightweight system snapshot:
system_health()
shell_exec({ command: "ps aux --sort=-%mem | head -10" })
shell_exec({ command: "ss -s" }) # connection summaryStore as a compact memory entry:
memory_store({
summary: "Flight recorder: CPU 12%, RAM 4.1G, load 0.3, 142 connections",
detail: "Top processes: postgres 1.2G, openclaw 380M, node 210M. Net: 142 established, 12 listening.",
category: "system.config",
tags: "flight-recorder,snapshot,telemetry"
})When investigating "what happened at 3 AM":
memory_recall({ query: "flight-recorder snapshot", timeframe: "24h", max_results: 50 })journal_logs({ since: "2 hours ago", priority: "warning", lines: 100 })event_log({ limit: 50 })Present a forensic timeline:
Incident Report — Server Crash at 03:12 UTC
Timeline:
02:00 Flight recorder: CPU 15%, RAM 5.2G (normal)
02:30 Flight recorder: CPU 23%, RAM 5.8G (rising)
02:47 Flight recorder: CPU 89%, RAM 7.1G (critical)
02:47 OOM killer triggered (killed: postgres worker)
02:48 PostgreSQL: 3 connections terminated
02:49 App health check failed → Caddy returned 502
02:51 systemd restarted PostgreSQL automatically
02:52 All services recovered
02:55 Flight recorder: CPU 12%, RAM 4.1G (normal)
Root cause: PostgreSQL autovacuum on users table (12M rows)
during traffic spike. Memory peaked at 7.4/7.6 GB.
Recommendations:
1. Add 2GB swap (NixOS config change)
2. Schedule autovacuum for low-traffic hours
3. Consider 16GB RAM plan ($6/mo more on Hetzner)
All data sourced from flight recorder snapshots,
journal logs, and audit ledger. Chain verified.Flight recorder snapshots are compact (~200 bytes each). At 5-minute intervals: 288/day, ~56KB/day, ~1.7MB/month. Keep 30 days of snapshots. Memory recall handles the rest.
© bolivian-peru, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/flight-recorder of bolivian-peru/os-moda.
Open the folder on GitHubat commit b8e418f
Flight Recorder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Flight Recorder this skillbolivian-peru/os-moda | 119 | — | ~624 | Automated safety check: Pass | Apache-2.0 | |
| Campaign Attribution Evidence Analysismukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Oss ForensicsTommy-yw/RunbookHermes | 546 | 3 repos | ~5k | Automated safety check: Pass | MIT | |
| Ctf Malwareljagiello/ctf-skills | 3.4k | — | ~2.1k | Automated safety check: Notes | MIT | |
| LNK and Jump List Forensicsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Malware Persistence Analysis with Autorunsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 |
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
Tommy-yw/RunbookHermes
Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
transilienceai/communitytools
Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.
bolivian-peru/os-moda
Deploy and manage user applications as managed systemd services
bolivian-peru/os-moda
Deploy and manage AI agent workloads with GPU checks, API key management, and health monitoring
bolivian-peru/os-moda
Detect configuration drift — manual changes that exist outside NixOS management.
bolivian-peru/os-moda
NixOS generation-aware debugging and time-travel. An agent skill from bolivian-peru/os-moda.
bolivian-peru/os-moda
Generate a concise daily infrastructure briefing. An agent skill from bolivian-peru/os-moda.
bolivian-peru/os-moda
Translate natural language requests into NixOS configuration changes.
Categories
Black box flight recorder for the server. An agent skill from bolivian-peru/os-moda. Flight Recorder is an agent skill from bolivian-peru/os-moda. Black box flight recorder for the server.
Flight Recorder fits situations like: tasks that involve Digital forensics.
Run `npx skills add bolivian-peru/os-moda --skill flight-recorder -a claude-code`. Or copy the skill folder (skills/flight-recorder in bolivian-peru/os-moda) into .claude/skills/flight-recorder in your project. Claude Code loads it when a task matches its description.
Run `npx skills add bolivian-peru/os-moda --skill flight-recorder -a codex`. Or copy the skill folder (skills/flight-recorder in bolivian-peru/os-moda) into .agents/skills/flight-recorder in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bolivian-peru/os-moda --skill flight-recorder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/flight-recorder, .gemini/skills/flight-recorder, .github/skills/flight-recorder and .opencode/skills/flight-recorder in your project.
SKILL.md names no scripts, command-line tools or credentials: Flight Recorder is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Flight Recorder is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 624 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Flight Recorder: Campaign Attribution Evidence Analysis (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Oss Forensics (Tommy-yw/RunbookHermes, 546 stars), Ctf Malware (ljagiello/ctf-skills, 3.4k stars) and LNK and Jump List Forensics (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
bolivian-peru (a GitHub user) maintains it in bolivian-peru/os-moda, which has 119 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on June 24, 2026.
Source: bolivian-peru/os-moda on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.