Agent skill

Data Breach Response

by borghei in borghei/Claude-Skills

Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking.

MITAuto-check passedLegal & Compliance

Install Data Breach Response

skills CLI
$ npx skills add borghei/Claude-Skills --skill data-breach-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills data-breach-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/legal/data-breach-response .claude/skills/data-breach-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
data-breach-response
GitHub stars
881
Token cost
~4k tokens
SKILL.md length
1,402 words
Files
5 (incl. scripts, references)
Skills in repo
349
Repo updated
First seen
Licence
MIT

At a glance

Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking.

  • Breach assessment and response
  • SKILL.md covers Table of Contents, Clarify First, Tools and Reference Guides, plus 8 more sections
  • Runs Python scripts from its folder; calls python
  • Tasks that involve Security operations

What it does

Data Breach Response is an agent skill from borghei/Claude-Skills. Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking. Use for breach assessment and response.

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/enisa_methodology.md`, `references/notification_obligations.md` and `scripts/breach_severity_calculator.py`).

It sits in Legal & Compliance, covering Security operations and Incident response. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Breach assessment and response
  • Tasks that involve Security operations
  • Tasks that involve Incident response

Example prompts

  • “/data-breach-response”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Data Breach Response loads about 4k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 42 tokens; SKILL.md has 1,402 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 1,402 words, ~4,024 tokens.

Download SKILL.mdSave it as .claude/skills/data-breach-response/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
data-breach-response
description
Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking. Use for breach assessment and response.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
The Glass Room
metadata.category
legal
metadata.domain
incident-response
metadata.updated
2026-04-10
metadata.tags
data-breach, gdpr, enisa, incident-response, notification

⚠️ EXPERIMENTAL — This skill is provided for educational and informational purposes only. It does NOT constitute legal advice. All responsibility for usage rests with the user. Consult qualified legal professionals before acting on any output.

Data Breach Response

Incident response and legal compliance for personal data breaches under GDPR Art. 33/34, CCPA, HIPAA, NIS2, PCI DSS, and other regulations. Calculates breach severity, tracks notification deadlines, and manages response timelines.


Table of Contents


Clarify First

Before assessing the breach, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • T0 — the moment of awareness — starts the 72h clock; every deadline and "time remaining" in the timeline is calculated from it
  • Your role: controller or processor — determines whether you notify the SA/data subjects (Art. 33/34) or only the controller (Art. 33(2))
  • Data categories, scale, and ease of identification — these are the DPC/EI inputs that drive the ENISA severity score and verdict (LOW/MEDIUM/HIGH/VERY HIGH)
  • Which regulations apply — GDPR, CCPA, HIPAA, PCI DSS, NIS2, AI Act — sets which notification deadlines and authorities the matrix produces

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the assessment.

Tools

Breach Severity Calculator

Calculates ENISA breach severity score from breach parameters. Determines notification obligations based on severity verdict.

bash
# Calculate severity from parameters
python scripts/breach_severity_calculator.py \
  --dpc 3 --ei 0.75 \
  --confidentiality 0.5 --integrity 0.25 --availability 0 \
  --malicious

# JSON output
python scripts/breach_severity_calculator.py \
  --dpc 2 --ei 0.5 --confidentiality 0.5 --json

# With T0 timestamp for countdown
python scripts/breach_severity_calculator.py \
  --dpc 3 --ei 1.0 --confidentiality 0.5 \
  --t0 "2026-04-10T08:00:00" --json

# Generate input template
python scripts/breach_severity_calculator.py --template

Output includes:

  • ENISA severity score (SE)
  • Severity verdict: LOW / MEDIUM / HIGH / VERY HIGH
  • Notification obligations (SA, data subjects, public)
  • Time remaining for GDPR 72h notification from T0

Breach Timeline Tracker

Tracks breach response timeline from T0 (moment of awareness). Records events, monitors deadlines, and generates status dashboards.

bash
# Initialize a new breach timeline
python scripts/breach_timeline_tracker.py init \
  --breach-id "BR-2026-001" --t0 "2026-04-10T08:00:00" \
  --description "Unauthorized database access" \
  --output breach_timeline.json

# Record an event
python scripts/breach_timeline_tracker.py event \
  --timeline breach_timeline.json \
  --action "Containment team activated" --category containment

# View status dashboard
python scripts/breach_timeline_tracker.py status --timeline breach_timeline.json

# Check deadlines
python scripts/breach_timeline_tracker.py deadlines --timeline breach_timeline.json

# JSON status output
python scripts/breach_timeline_tracker.py status --timeline breach_timeline.json --json

Tracks:

  • GDPR 72-hour SA notification deadline
  • DPA contractual deadlines (24h / 48h processor notification)
  • NIS2 24-hour early warning and 72-hour notification
  • Completed vs. pending response actions
  • Time elapsed and time remaining per deadline

Reference Guides

ENISA Methodology

references/enisa_methodology.md

Complete ENISA breach severity methodology:

  • DPC (Data Processing Context) scoring 1-4
  • EI (Ease of Identification) scoring 0.25-1.00
  • CB (Circumstances of Breach) additive scoring
  • Formula: SE = (DPC x EI) + CB
  • Adjustments for encryption, pseudonymization, volume
  • EDPB case matching (18 reference cases)
Notification Obligations

references/notification_obligations.md

Multi-regulation notification requirements:

  • GDPR Art. 33 (SA within 72h) and Art. 34 (data subjects)
  • CCPA, HIPAA, PCI DSS, NIS2, state breach notification
  • Controller vs. Processor obligation matrix
  • Cross-border notification rules
  • AI Act Art. 62 serious incident reporting

Workflows

Workflow 1: Standard Breach Response
Step 1: Emergency check — is there <12h remaining on any deadline?
        → If yes, skip to Step 4 (emergency notification)

Step 2: Initialize breach timeline
        → python scripts/breach_timeline_tracker.py init --breach-id "BR-2026-001" \
          --t0 "2026-04-10T08:00:00" --description "Description"

Step 3: Calculate severity
        → python scripts/breach_severity_calculator.py --dpc N --ei N \
          --confidentiality N --integrity N --availability N [--malicious]

Step 4: Based on severity verdict, determine notifications
        → LOW (<2): Internal log only, no external notification
        → MEDIUM (2 to <3): Notify supervisory authority within 72h
        → HIGH (3 to <4): Notify SA + individual data subjects
        → VERY HIGH (>=4): Notify SA + data subjects + consider public notice

Step 5: Execute containment and record events
        → python scripts/breach_timeline_tracker.py event --timeline breach.json \
          --action "Action taken" --category containment

Step 6: Monitor deadlines continuously
        → python scripts/breach_timeline_tracker.py deadlines --timeline breach.json

Step 7: Complete notification obligations and document
Workflow 2: Emergency Mode (<12h Remaining)
Step 1: Calculate severity immediately
        → python scripts/breach_severity_calculator.py --dpc N --ei N \
          --confidentiality N --t0 "original-t0" --json

Step 2: If MEDIUM or higher, prepare phased notification
        → Art. 33(4) allows phased notification when full information unavailable
        → Initial notification: what is known + promise of update
        → Supplementary notification: full details when available

Step 3: File initial SA notification before deadline expires

Step 4: Initialize timeline for ongoing tracking
        → Continue gathering information for supplementary notification

Step 5: Document emergency timeline and decisions
Workflow 3: Processor Breach Notification
Step 1: Processor becomes aware of breach
        → T0 for processor = moment of awareness

Step 2: Processor must notify controller "without undue delay"
        → Check DPA for specific contractual deadline (24h/48h common)

Step 3: Controller's T0 starts when controller becomes aware
        → Controller's 72h clock starts at this point

Step 4: Controller assesses severity independently
        → python scripts/breach_severity_calculator.py (controller's assessment)

Step 5: Controller makes notification decisions
        → Processor provides information; controller decides on SA/subject notification

ENISA Severity Formula

SE = (DPC x EI) + CB
ComponentRangeDescription
DPC1-4Data Processing Context — nature and sensitivity of data
EI0.25-1.0Ease of Identification — how easily individuals can be identified
CB-0.5 to +1.0Circumstances of Breach — additive factors (malicious intent, volume, loss type)
Severity Verdicts
Score RangeVerdictNotification Obligations
<2LOWInternal log only. No SA or subject notification required
2 to <3MEDIUMNotify supervisory authority within 72h (Art. 33)
3 to <4HIGHNotify SA within 72h + notify individual data subjects (Art. 34)
>=4VERY HIGHNotify SA + data subjects + consider public notice; crisis management

Notification Decision Matrix

Quick reference for notification obligations per regulation and severity.

RegulationAuthority NotificationIndividual NotificationTrigger
GDPR Art. 33SA within 72hN/AUnless unlikely to result in risk to rights/freedoms
GDPR Art. 34N/AWithout undue delayWhen likely to result in high risk
CCPAState AGAffected consumersUnencrypted personal information compromised
HIPAAHHS within 60 daysAffected individualsUnsecured PHI; >500: notify media
PCI DSSCard brands within 24hCardholders (via issuer)Cardholder data compromised
NIS2 Art. 23CSIRT within 24h (early warning), 72h (notification)N/ASignificant incident
AI Act Art. 62Market surveillance within 15 daysN/ASerious incident involving AI system
Controller vs. Processor Obligations
ObligationControllerProcessor
Notify supervisory authorityYes (Art. 33)No (notify controller only)
Notify data subjectsYes (Art. 34)No
Document all breachesYes (Art. 33(5))Yes (assist controller)
Notify controllerN/AYes, without undue delay (Art. 33(2))
Conduct severity assessmentYesAssist (provide information)
Timeline starts (T0)When controller becomes awareWhen processor becomes aware

Troubleshooting

ProblemPossible CauseResolution
Severity score is borderline between MEDIUM and HIGHParameters are at threshold boundariesScore conservatively — if near 3.0, treat as HIGH and notify data subjects; document the borderline analysis
72-hour deadline approaching with incomplete informationComplex breach requiring ongoing investigationUse Art. 33(4) phased notification — notify SA with available information and supplement later
Processor discovered breach but delayed notifying controllerDPA contractual deadline may have been missedDocument the delay; assess whether processor's delay affected controller's ability to comply; review DPA terms
Cross-border breach — unclear which SA to notifyMulti-jurisdictional processing with unclear lead SANotify the SA of your main establishment (one-stop-shop); if unclear, notify the SA where most affected subjects reside
Breach involves encrypted data — unclear if notification neededEncryption may lower severity or eliminate notificationIf encryption was effective (strong algorithm, key not compromised), this may make notification unnecessary per Art. 34(3)(a); document the analysis
AI system involved in breach — unclear additional obligationsAI Act Art. 62 may apply alongside GDPRAssess whether AI system is high-risk under AI Act; if serious incident, notify market surveillance authority within 15 days in addition to GDPR obligations

Show full SKILL.md (519 more words)Show less

Success Criteria

  • Breach severity calculated within 2 hours of awareness -- ENISA methodology applied with documented parameters and scoring rationale
  • SA notification filed within 72 hours of T0 -- for MEDIUM or higher severity breaches, phased notification used when full information unavailable
  • Data subject notification completed without undue delay -- for HIGH or higher severity breaches, clear communication of impact and protective measures
  • All response actions tracked with timestamps -- breach timeline maintained from T0 through closure with all events recorded
  • Cross-regulation obligations identified and met -- GDPR, CCPA, HIPAA, PCI DSS, NIS2, and AI Act obligations assessed and fulfilled per applicable law
  • Post-breach documentation complete -- internal breach log maintained per Art. 33(5) regardless of notification decision

Scope & Limitations

In Scope:

  • ENISA breach severity calculation with full parameter support
  • GDPR Art. 33/34 notification timeline tracking
  • Multi-regulation notification obligation assessment (GDPR, CCPA, HIPAA, PCI DSS, NIS2, AI Act)
  • Controller vs. processor obligation guidance
  • Cross-border breach notification routing
  • Phased notification guidance per Art. 33(4)
  • Breach response event tracking and deadline monitoring

Out of Scope:

  • Technical incident containment (network isolation, forensics, malware removal)
  • Filing notifications with supervisory authorities (document preparation only)
  • Insurance claim processing or coverage analysis
  • Law enforcement coordination
  • Public relations or crisis communications strategy
  • Forensic investigation methodology

Anti-Patterns

  • Delaying T0 determination to buy more time -- T0 is the moment the controller becomes "aware" of the breach, not when full details are known; deliberately delaying awareness to extend the 72-hour window is a compliance violation and will be treated as such by regulators
  • Defaulting to no notification without documented analysis -- every breach must be documented and assessed, even if the conclusion is that notification is not required; "we decided not to notify" without documented severity analysis is indefensible
  • Treating processor notification as controller notification -- processor notifying its own SA does not satisfy the controller's Art. 33 obligation; the controller must make its own independent notification decision and filing
  • Using encryption as an automatic notification exemption -- Art. 34(3)(a) exemption requires that the encrypted data was rendered unintelligible AND the encryption key was not compromised; weak encryption or compromised keys do not qualify
  • Ignoring AI Act obligations for AI-involved breaches -- if the breach involves a high-risk AI system, Art. 62 serious incident reporting (15 days to market surveillance authority) applies in addition to GDPR; these are separate obligations with different timelines

Tool Reference

breach_severity_calculator.py

Calculates ENISA breach severity score and determines notification obligations.

FlagRequiredDescription
--dpc <1-4>YesData Processing Context: 1=Simple demographic, 2=Behavioral/financial, 3=Sensitive personal, 4=Special category/highly sensitive
--ei <0.25-1.0>YesEase of Identification: 0.25=Negligible, 0.5=Limited, 0.75=Significant, 1.0=Maximum
--confidentiality <0/0.25/0.5>NoConfidentiality loss score (default 0)
--integrity <0/0.25/0.5>NoIntegrity loss score (default 0)
--availability <0/0.25/0.5>NoAvailability loss score (default 0)
--maliciousNoFlag for malicious intent (adds +0.5 to CB)
--t0 <ISO datetime>NoT0 timestamp for deadline calculation
--templateNoGenerate input template
--jsonNoOutput in JSON format
breach_timeline_tracker.py

Tracks breach response timeline, events, and regulatory deadlines.

SubcommandDescription
initInitialize breach timeline (--breach-id, --t0, --description required, --output optional)
eventRecord event (--timeline, --action, --category required)
statusView status dashboard (--timeline required, --json optional)
deadlinesCheck deadline status (--timeline required, --json optional)

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in legal/data-breach-response of borghei/Claude-Skills.

  • SKILL.md
  • references/enisa_methodology.md
  • references/notification_obligations.md
  • scripts/breach_severity_calculator.py
  • scripts/breach_timeline_tracker.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Data Breach Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Data Breach Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Data Breach Response this skillborghei/Claude-Skills881—~4kAutomated safety check: PassMIT
Hunting For Persistence Mechanisms In Windowsmukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.0
Hunting For Webshell Activitymukul975/Anthropic-Cybersecurity-Skills34k—~904Automated safety check: PassApache-2.0
Implementing Soar Playbook With Palo Alto Xsoarmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0
Conducting Cloud Incident Responsemukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Detecting Network Anomalies With Zeekmukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: NotesApache-2.0

Similar skills

  • Hunting For Persistence Mechanisms In Windows

    mukul975/Anthropic-Cybersecurity-Skills

    Systematically hunts for adversary persistence mechanisms across Windows endpoints, covering registry Run/RunOnce keys, services, startup folders, scheduled tasks, and WMI event subscriptions.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Hunting For Webshell Activity

    mukul975/Anthropic-Cybersecurity-Skills

    Runs a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server…

    34k GitHub stars~904 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Soar Playbook With Palo Alto Xsoar

    mukul975/Anthropic-Cybersecurity-Skills

    Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise…

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Conducting Cloud Incident Response

    mukul975/Anthropic-Cybersecurity-Skills

    Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Detecting Network Anomalies With Zeek

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy and configure Zeek (formerly Bro) to passively analyze network traffic, generate structured connection/DNS/HTTP/SSL/file logs, detect anomalous behavior, and write custom scripts for…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Implementing Soar Automation With Phantom

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from borghei/Claude-Skills

All 349 skills in this repo
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    881 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    881 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    881 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Brainstorm Okrs

    borghei/Claude-Skills

    OKR brainstorming and validation using the Radical Focus framework — outcome objectives, measurable key results, counter-metrics.

    881 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed

Questions about Data Breach Response

What does Data Breach Response do?

Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking. Data Breach Response is an agent skill from borghei/Claude-Skills. Data breach incident response with ENISA severity scoring, notification timelines, and compliance tracking.

When should I use Data Breach Response?

Data Breach Response fits situations like: breach assessment and response; tasks that involve Security operations; tasks that involve Incident response.

How do I install Data Breach Response in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill data-breach-response -a claude-code`. Or copy the skill folder (legal/data-breach-response in borghei/Claude-Skills) into .claude/skills/data-breach-response in your project. Claude Code loads it when a task matches its description.

How do I install Data Breach Response in Codex?

Run `npx skills add borghei/Claude-Skills --skill data-breach-response -a codex`. Or copy the skill folder (legal/data-breach-response in borghei/Claude-Skills) into .agents/skills/data-breach-response in your project. Codex loads it when a task matches its description.

Can I use Data Breach Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill data-breach-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/data-breach-response, .gemini/skills/data-breach-response, .github/skills/data-breach-response and .opencode/skills/data-breach-response in your project.

What does Data Breach Response need to run?

Going by SKILL.md and its folder, Data Breach Response needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Data Breach Response access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Data Breach Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Data Breach Response use?

Data Breach Response is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Data Breach Response use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.4k tokens, read only when the agent opens those files.

What are the alternatives to Data Breach Response?

Skills that share tags, products or a category with Data Breach Response: Hunting For Persistence Mechanisms In Windows (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Hunting For Webshell Activity (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Soar Playbook With Palo Alto Xsoar (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Conducting Cloud Incident Response (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Data Breach Response?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 881 GitHub stars. The repository holds 349 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.