Agent skill

Threat Detection

by borghei in borghei/Claude-Skills

This skill should be used when the user asks to "analyze logs for threats", "detect suspicious activity", "scan for brute force attempts", "identify injection attacks", or "audit access patterns for…

MITAuto-check: notesSecurity

Install Threat Detection

skills CLI
$ npx skills add borghei/Claude-Skills --skill threat-detection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills threat-detection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/threat-detection .claude/skills/threat-detection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
threat-detection
GitHub stars
881
Token cost
~1.3k tokens
SKILL.md length
447 words
Files
3 (incl. scripts, references)
Skills in repo
349
Repo updated
First seen
Licence
MIT

At a glance

This skill should be used when the user asks to "analyze logs for threats", "detect suspicious activity", "scan for brute force attempts", "identify injection attacks", or "audit access patterns for…

  • Works in 5 steps: Collect - Gather logs from auth, access,… → Analyze - Run threat_signal_analyzer.py… → Triage - Review critical and high… → …
  • Asks to analyze logs for threats
  • SKILL.md covers Overview, Clarify First, Quick Start and Tools Overview, plus 3 more sections
  • Runs Python scripts from its folder; calls python

What it does

Threat Detection is an agent skill from borghei/Claude-Skills. This skill should be used when the user asks to "analyze logs for threats", "detect suspicious activity", "scan for brute force attempts", "identify injection attacks", or "audit access patterns for anomalies".

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/threat-indicators.md` and `scripts/threat_signal_analyzer.py`).

It sits in Security. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Asks to analyze logs for threats
  • Detect suspicious activity
  • Scan for brute force attempts
  • Identify injection attacks

Example prompts

  • “analyze logs for threats”
  • “detect suspicious activity”
  • “scan for brute force attempts”
  • “/threat-detection”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Collect - Gather logs from auth, access, application sources
  2. Analyze - Run threat_signal_analyzer.py across log files
  3. Triage - Review critical and high severity findings first
  4. Correlate - Cross-reference findings across log sources
  5. Respond - Block IPs, reset credentials, escalate as needed

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Threat Detection loads about 1.3k tokens when it runs, and up to ~2.3k if it reads all its reference files. Until then it costs about 57 tokens; SKILL.md has 447 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:62
    | Privilege escalation | Detects sudo abuse, role changes, permission modifications |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 447 words, ~1,264 tokens.

Download SKILL.mdSave it as .claude/skills/threat-detection/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
threat-detection
description
This skill should be used when the user asks to "analyze logs for threats", "detect suspicious activity", "scan for brute force attempts", "identify injection attacks", or "audit access patterns for anomalies".
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
borghei
metadata.category
engineering
metadata.domain
security
metadata.updated
2026-04-02
metadata.tags
security, threat-detection, logs, monitoring, incident-response

Threat Detection

Category: Engineering Domain: Security Operations

Overview

The Threat Detection skill provides automated analysis of log files for suspicious patterns including brute force attacks, injection attempts, unusual access patterns, and privilege escalation indicators. It helps security teams triage log data and identify threats before they escalate.

Clarify First

Before analyzing logs, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Log file & source type — auth / access / application logs to analyze (--file; the subject of detection)
  • Threat category — brute force / injection / access anomaly / privilege escalation (--category; focuses the scan)
  • Minimum severity — the reporting/alert threshold (--min-severity; changes which signals surface and any SIEM/CI gate)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.

Quick Start

bash
# Analyze a log file for threat signals
python scripts/threat_signal_analyzer.py --file /var/log/auth.log

# Analyze with specific threat category
python scripts/threat_signal_analyzer.py --file access.log --category injection

# JSON output for SIEM integration
python scripts/threat_signal_analyzer.py --file auth.log --format json

# Set minimum severity
python scripts/threat_signal_analyzer.py --file access.log --min-severity high

Tools Overview

threat_signal_analyzer.py

Analyzes log files for suspicious activity patterns across multiple threat categories.

FeatureDescription
Brute force detectionIdentifies repeated failed login attempts from same source
Injection scanningDetects SQL injection, XSS, command injection in requests
Access anomaliesFlags unusual access times, forbidden paths, admin probes
Privilege escalationDetects sudo abuse, role changes, permission modifications
Rate analysisIdentifies request flooding and denial-of-service patterns
IP reputationFlags known-bad patterns (scanners, bots, TOR indicators)

Workflows

Log Analysis Workflow
  1. Collect - Gather logs from auth, access, application sources
  2. Analyze - Run threat_signal_analyzer.py across log files
  3. Triage - Review critical and high severity findings first
  4. Correlate - Cross-reference findings across log sources
  5. Respond - Block IPs, reset credentials, escalate as needed
Show full SKILL.md (191 more words)Show less
Incident Investigation Workflow
  1. Scope - Identify time window and affected systems
  2. Scan - Run analyzer on all relevant log files
  3. Timeline - Build timeline from threat signals
  4. Impact - Assess what was accessed or modified
  5. Contain - Block threat actors and patch vulnerabilities
Continuous Monitoring
bash
# Cron job: analyze auth logs every hour
python scripts/threat_signal_analyzer.py --file /var/log/auth.log --format json --min-severity high > /tmp/threat_report.json

# CI/CD: scan application logs on deployment
python scripts/threat_signal_analyzer.py --file app.log --category injection --format json

Reference Documentation

  • Threat Indicators - Common attack patterns, indicators of compromise, response playbooks

Common Patterns Quick Reference

Threat Categories
CategorySignalsSeverity
Brute force5+ failed logins from same IP in 5 minHigh
SQL injectionUNION SELECT, OR 1=1, DROP TABLE in requestsCritical
XSSscript tags, javascript: URIs, event handlers in inputHigh
Path traversal../ sequences, /etc/passwd access attemptsHigh
Command injection; cat /etc/passwd,nc, backtick usage
Admin probing/admin, /wp-admin, /phpmyadmin access attemptsMedium
Rate flooding100+ requests/minute from single IPHigh
Severity Levels
  • CRITICAL - Active exploitation attempt (injection, RCE)
  • HIGH - Likely attack in progress (brute force, privilege escalation)
  • MEDIUM - Suspicious activity requiring investigation
  • LOW - Informational, possible false positive
Response Actions
SeverityImmediate ActionFollow-Up
CriticalBlock IP, alert SOCIncident report, forensics
HighRate limit, monitorReview access, check damage
MediumLog and monitorWeekly review
LowLog onlyMonthly trend analysis

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in engineering/threat-detection of borghei/Claude-Skills.

  • SKILL.md
  • references/threat-indicators.md
  • scripts/threat_signal_analyzer.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Threat Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Threat Detection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Threat Detection this skillborghei/Claude-Skills881—~1.3kAutomated safety check: NotesMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4801 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    480 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from borghei/Claude-Skills

All 349 skills in this repo
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    881 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    881 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    881 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Brainstorm Okrs

    borghei/Claude-Skills

    OKR brainstorming and validation using the Radical Focus framework — outcome objectives, measurable key results, counter-metrics.

    881 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Threat Detection

What does Threat Detection do?

This skill should be used when the user asks to "analyze logs for threats", "detect suspicious activity", "scan for brute force attempts", "identify injection attacks", or "audit access patterns for…. Threat Detection is an agent skill from borghei/Claude-Skills. This skill should be used when the user asks to "analyze logs for threats", "detect suspicious activity", "scan for brute force attempts", "identify injection attacks", or "audit access patterns for anomalies".

When should I use Threat Detection?

Threat Detection fits situations like: asks to analyze logs for threats; detect suspicious activity; scan for brute force attempts; identify injection attacks.

How do I install Threat Detection in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill threat-detection -a claude-code`. Or copy the skill folder (engineering/threat-detection in borghei/Claude-Skills) into .claude/skills/threat-detection in your project. Claude Code loads it when a task matches its description.

How do I install Threat Detection in Codex?

Run `npx skills add borghei/Claude-Skills --skill threat-detection -a codex`. Or copy the skill folder (engineering/threat-detection in borghei/Claude-Skills) into .agents/skills/threat-detection in your project. Codex loads it when a task matches its description.

Can I use Threat Detection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill threat-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/threat-detection, .gemini/skills/threat-detection, .github/skills/threat-detection and .opencode/skills/threat-detection in your project.

What does Threat Detection need to run?

Going by SKILL.md and its folder, Threat Detection needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Threat Detection access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Threat Detection safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Threat Detection use?

Threat Detection is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Threat Detection use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.

What are the alternatives to Threat Detection?

Skills that share tags, products or a category with Threat Detection: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Threat Detection?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 881 GitHub stars. The repository holds 349 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.