Agent skill

Breach Patterns

by briiirussell in briiirussell/cybersecurity-skills

Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

MITAuto-check: notesDatabases

Install Breach Patterns

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill breach-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills breach-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/breach-patterns .claude/skills/breach-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
breach-patterns
GitHub stars
413
Token cost
~3.5k tokens
SKILL.md length
1,733 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

  • Works in 4 steps: Read the one-paragraph summary of the… → Ask the audit question(s) it implies for… → Map to specific checks in the existing… → …
  • The user mentions breach analysis
  • SKILL.md covers How to use this skill, Pattern 1 — IMDS abuse…, Pattern 2 — Supplier… and Pattern 3 — Vault exfiltration…, plus 11 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Breach Patterns is an agent skill from briiirussell/cybersecurity-skills. Learn from public breach disclosures — extract the audit question each one implies and check your own stack. Capital One IMDS abuse, LastPass vault exfiltration, Okta Lapsus$, Snowflake credential reuse, MOVEit, SolarWinds, Equifax, Target POS, Codecov, Uber, Twilio — what would you check now if your boss said 'could that happen to us?' Use when the user mentions 'breach analysis,' 'lessons learned,' 'security postmortem,' 'breach patterns,' 'breach lessons,' 'has this happened to us,' 'apply breach lessons,'…

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering Retrospectives, Data warehousing and Runbooks and postmortems. It works with Snowflake, Okta and Twilio. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions breach analysis
  • Lessons learned
  • Security postmortem
  • Breach patterns

Example prompts

  • “could that happen to us?”
  • “breach analysis,”
  • “lessons learned,”
  • “/breach-patterns”

Requirements

  • Docker
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, WebSearch, WebFetch

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read the one-paragraph summary of the breach
  2. Ask the audit question(s) it implies for your environment
  3. Map to specific checks in the existing audit skills
  4. Decide disposition — "we've confirmed this can't happen," "we have a gap, here's the plan," or "we accept-risk for these reasons"

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • WebSearch
    • WebFetch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Breach Patterns loads about 3.5k tokens when it runs. Until then it costs about 166 tokens; SKILL.md has 1,733 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~166
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, WebSearch, WebFetch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,733 words, ~3,518 tokens.

Download SKILL.mdSave it as .claude/skills/breach-patterns/SKILL.md (or your agent's skills folder).
name
breach-patterns
description
Learn from public breach disclosures — extract the audit question each one implies and check your own stack. Capital One IMDS abuse, LastPass vault exfiltration, Okta Lapsus$, Snowflake credential reuse, MOVEit, SolarWinds, Equifax, Target POS, Codecov, Uber, Twilio — what would you check now if your boss said 'could that happen to us?' Use when the user mentions 'breach analysis,' 'lessons learned,' 'security postmortem,' 'breach patterns,' 'breach lessons,' 'has this happened to us,' 'apply breach lessons,' 'preempt breaches,' 'security retrospective,' 'real-world security incidents,' or wants to harden against known attacker playbooks.
allowed-tools
Read, Grep, Glob, Bash, WebSearch, WebFetch

Breach Patterns — Preemptive Hardening from Public Breach Disclosures

The inverse of incident-triage. That skill is "we're on fire, what now." This skill is "go read the breach writeups, extract the audit question each one implies, and check your own stack."

Breaches catalogued here are public, well-documented, and pattern-bearing. Each pattern surfaces a control or check that often falls between OWASP categories — IMDS abuse, supplier credential blast radius, secrets-in-CI, single-sign-on lateral movement, log-tampering pre-breach. These are the controls people add after their first incident; reading other people's breaches is cheaper than writing your own.

Cross-references: every audit skill in this repo. Use this skill to surface "have we considered X?" questions, then pivot to the relevant audit skill for the deep dive. When a breach pattern surfaces a regulatory implication — health data exposure, payment card data exposure, PII exposure — also reach for hipaa-audit, pci-audit, or privacy-engineering to understand the regulatory clock and notification obligations that come with that breach class.

How to use this skill

For each breach pattern below:

  1. Read the one-paragraph summary of the breach
  2. Ask the audit question(s) it implies for your environment
  3. Map to specific checks in the existing audit skills
  4. Decide disposition — "we've confirmed this can't happen," "we have a gap, here's the plan," or "we accept-risk for these reasons"

The output is a "breach-pattern coverage" document — not a fixed report, an evergreen checklist you re-run against your evolving stack.

Pattern 1 — IMDS abuse (Capital One, 2019)

What happened: A misconfigured WAF allowed SSRF. An attacker used SSRF to reach the EC2 instance metadata service (IMDSv1, no token requirement), pulled temporary IAM credentials, and used them to enumerate and exfiltrate S3 buckets containing 100M+ records.

Audit question: Does any service that takes a URL from user input also have IAM credentials reachable via IMDS?

Check:

  • IMDSv2 enforced on every EC2 launch template (MetadataOptions.HttpTokens: required) — see cloud-audit
  • SSRF defences on every URL-taking endpoint — see owasp-audit A10 bypass matrix (especially the cloud metadata endpoints row: 169.254.169.254, metadata.google.internal, 169.254.170.2)
  • WAF rules log + alert on metadata-endpoint patterns

Pattern 2 — Supplier credential blast radius (SolarWinds, 2020)

What happened: Attackers compromised SolarWinds' build pipeline and inserted a backdoor (Sunburst) into the Orion product. Customers who installed legitimate Orion updates received the backdoored binary. The backdoor enabled lateral movement into customer networks, including the US federal government.

Audit questions:

  • Which suppliers have credentials in your environment that could similarly compromise you if the supplier was breached?
  • Do your CI / CD systems have credentials that could move laterally into prod?
  • Are software updates verified against signatures, or trusted by source URL?

Check:

  • CI/CD secrets minimized to scope (read-only deploy tokens, not full admin)
  • Signed commit / signed artifact enforcement where critical
  • Third-party JavaScript pinned to specific versions or SHA-pinned via SRI
  • Vendor-managed services audited for blast radius — see iam-audit for cross-account trust patterns

Pattern 3 — Vault exfiltration via developer endpoint (LastPass, 2022)

What happened: Attackers initially compromised an engineer's home computer via a vulnerable third-party media plugin. That gave them access to the engineer's corporate vault. Months later, they used that access to exfiltrate customer vault data — including unencrypted URLs that helped target customers for phishing.

Audit questions:

  • Which engineering accounts can reach production data, and what device posture is required?
  • Are device security policies enforced for personal devices used to access corporate systems?
  • What metadata is stored unencrypted around encrypted user data?

Check:

  • Device-trust requirements for any high-value access (Zero Trust posture — see iam-audit)
  • Privileged access through dedicated workstations / jump hosts, not engineer personal laptops
  • Encrypt the metadata too, not just the "important" payload — URLs are PII

Pattern 4 — SSO push fatigue (Okta / Lapsus$, 2022)

What happened: Attackers obtained credentials for a third-party support engineer (Sitel). They spammed the engineer with push-notification MFA prompts until the engineer approved one out of habit / annoyance. They then used the support engineer's access to view (but not modify) some Okta customer tenants.

Audit questions:

  • Is MFA on your admin accounts phishing-resistant (FIDO2 / hardware key), or just push?
  • Are third-party support / contractor accounts treated with the same controls as employees?
  • What's the blast radius of a support / customer-success role being compromised?

Check:

  • Phishing-resistant MFA (FIDO2 / WebAuthn) for admins and privileged users — see iam-audit
  • "Number matching" enabled on push MFA (where allowed) so users can't approve blindly
  • Push-fatigue detection — repeated push prompts in a short window trigger an alert
  • Third-party access reviewed quarterly with same rigor as employee access

Pattern 5 — Stolen credentials → SaaS lateral movement (Snowflake customers, 2024)

What happened: Attackers used credentials stolen from infostealer malware on personal devices to log into Snowflake customer environments (which had no MFA enforced). They exfiltrated data from Ticketmaster, AT&T, Santander, and others. Snowflake itself wasn't breached — customers were.

Audit questions:

  • Are there SaaS services in your stack where users can authenticate without MFA?
  • Is access to SaaS gated on enterprise SSO with MFA enforcement, or are local accounts allowed?
  • Could credentials stolen from a personal device unlock your business-critical SaaS?

Check:

  • Every SaaS in your environment audited for MFA enforcement and SSO federation
  • Local-account access disabled where SSO is available
  • Conditional Access policies require compliant device — see iam-audit
  • Credential monitoring (HIBP, internal dark-web monitoring) for employee emails

Pattern 6 — Unpatched zero-day in file transfer (MOVEit, 2023)

What happened: Cl0p ransomware group exploited an SQL injection zero-day (CVE-2023-34362) in Progress MOVEit Transfer. They exfiltrated data from hundreds of customers — many of whom were transferring sensitive HR / financial / health data via MOVEit. Patches arrived after the exploitation campaign was already running.

Audit questions:

  • For internet-facing third-party software in your environment, what's your patch SLA when a zero-day surfaces?
  • What sensitive data sits in pre-built / off-the-shelf software you don't control the code of?
  • Do you have detection for unusual data egress from third-party systems?

Check:

  • Inventory of internet-facing third-party software, owners, patch process
  • Network egress monitoring on third-party systems (see siem-detection)
  • CISA KEV monitoring — automatic alerting when listed CVEs apply to your stack (see vuln-research)
  • Data classification — sensitive data minimized in third-party platforms
Show full SKILL.md (739 more words)Show less

Pattern 7 — Compromised CI build artifact (Codecov, 2021)

What happened: A flaw in Codecov's Docker image creation process let attackers extract a credential. They modified Codecov's Bash uploader script to exfiltrate environment variables from every CI run using Codecov. CI environments leak: AWS keys, Stripe keys, npm tokens, GitHub tokens.

Audit questions:

  • What third-party tools run inside your CI with access to env vars?
  • Are CI env vars scoped to just what each job needs, or do all jobs see everything?
  • Would you notice if a CI step started phoning home?

Check:

  • CI secrets scoped per-job and per-workflow, not global — see secrets-audit and iam-audit
  • Third-party CI integrations reviewed (every uploader, scanner, deployer that has access to env vars)
  • CI network egress monitored where feasible
  • Build artifact provenance — SLSA framework, signed builds, sigstore

Pattern 8 — Insider access misuse (Twitter / X internal tool abuse, 2020)

What happened: Attackers social-engineered Twitter employees to access an internal admin tool with broad customer-account powers. They used it to hijack high-profile accounts and run a Bitcoin scam.

Audit questions:

  • Which employees have access to powerful internal admin tools?
  • Is access logged and reviewed?
  • Could one employee take a high-impact action without a second party?

Check:

  • Internal admin tooling treated as high-trust — strong auth, JIT access, audit log
  • Two-person rule for sensitive actions (account takeover, mass data export)
  • Quarterly review of who has admin tool access — see iam-audit
  • Honeypot accounts that alert on access

Pattern 9 — Long-standing breach undetected (Equifax, 2017)

What happened: Attackers exploited unpatched Apache Struts CVE-2017-5638 (a known vulnerability with a 2-month-old patch available). They were inside for 76 days before detection, exfiltrating 147M credit records. Patch had been available; vulnerability scanning didn't find it because scan target lists were stale.

Audit questions:

  • How long would it take you to detect an attacker with valid credentials sitting in your environment?
  • Is your patch SLA enforced in practice, or only on paper?
  • Does your vuln-scan inventory match your actual asset inventory?

Check:

  • Asset inventory cross-checked against vuln-scan targets quarterly
  • Patch SLA per severity is measured, not just stated (vuln-research)
  • Detection coverage for post-exploitation behavior (lateral movement, data staging, exfil) — see siem-detection
  • MTTD (Mean Time To Detect) measured for representative scenarios

What happened: Attackers compromised a contractor's credentials, used MFA-prompt-fatigue to get in, and then explored. They found PowerShell scripts on a network share containing privileged credentials, and from there accessed AWS, GCP, Google Workspace, and Slack. Among the goodies: a Privileged Access Management tool that the attackers could use to grant themselves more access.

Audit questions:

  • What credentials are sitting on network shares?
  • If an attacker got to your network share, what would they find?
  • What's the blast radius of contractor accounts?

Check:

  • Credential discovery scan on every internal file share, wiki, ticketing system — see secrets-audit
  • Contractor accounts subject to same MFA and review as employees
  • Privileged Access Management (PAM) systems themselves audited as crown-jewel assets

Patterns to add (your job)

This skill should grow with each major public breach. Process:

  1. Read the post-mortem (vendor, news writeup, regulatory filing)
  2. Extract the one-sentence pattern that generalizes beyond the specific vendor
  3. Phrase it as an audit question your stack should be able to answer "no" to
  4. Map to specific checks in existing audit skills
  5. Add to this skill

Good post-mortem sources:

  • Vendor security blogs (the breached company's own writeup is usually most accurate)
  • SEC 8-K filings for public companies (legal-grade detail)
  • "BleepingComputer," "Risky.Biz News," "Krebs on Security" — solid breach coverage
  • The Verizon DBIR (annual) — patterns across the year aggregated
  • The MITRE ATT&CK in the wild reports

Output Format

markdown
# Breach Pattern Coverage Assessment
## Environment: [name]
## Date: [date]

### Coverage status
| Pattern | Audit question | Status | Owner |
|---------|----------------|--------|-------|
| IMDS abuse (Capital One) | SSRF-to-metadata reachable? | Clean | sec |
| Supplier blast radius (SolarWinds) | CI/CD blast radius? | Gap — plan attached | platform |
| ... | | | |

### Gaps with plans
[For each Gap row above — what's the plan, by when]

### Patterns not yet evaluated
[Patterns where you don't yet have data to mark Clean / Gap]

This is a quarterly-rerunable document — not one-and-done. Industry patterns evolve.

Boundaries

  • This skill is preemptive ("does this happen to us?"), not exploitive ("could we do what Lapsus$ did")
  • Public breach details are public; use them. Do not seek leaked credential dumps or non-public details
  • If your assessment surfaces an active issue (not "could happen" but "is happening"), pivot to incident-triage
  • Do not generate attack patterns or detailed attacker playbooks beyond what's necessary to assess defensive coverage

References

  • "Cyber Incident Reporting and Analysis Methods" — DHS / CISA
  • Verizon Data Breach Investigations Report (DBIR) — annual industry breach analysis
  • MITRE ATT&CK in the wild reports
  • CISA cybersecurity advisories
  • Krebs on Security (krebsonsecurity.com)
  • "Risky.Biz" news podcast / newsletter
  • Project Zero — Google's offensive security team writeups
  • Mandiant / CrowdStrike threat reports
  • "Tracing Stolen Bitcoin" — investigative writeups on attacker workflows

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/breach-patterns of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Breach Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Breach Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Breach Patterns this skillbriiirussell/cybersecurity-skills413—~3.5kAutomated safety check: NotesMIT
Caspian DiscordTryCaspian/caspian-sdk973—~323Automated safety check: PassApache-2.0
Simplywallstgauss314/skills248—~2.9kAutomated safety check: PassMIT
Write Script Snowflakewindmill-labs/windmill18k—~2.2kAutomated safety check: PassCustom licence
Pure Lsp Execute Parallelfinos/legend-engine113—~927Automated safety check: PassApache-2.0
Plot Structuredanjdewhurst/story-skills2861 repos~4kAutomated safety check: NotesMIT

Similar skills

  • Caspian Discord

    TryCaspian/caspian-sdk

    Post a Discord message via Caspian to a channel snowflake id.

    973 GitHub stars~323 tokensUpdated 1 mo ago
    DatabasesAuto-check passed
  • Simplywallst

    gauss314/skills

    Data financiera de 120K+ stocks globales: snowflake scores, valuation, financial health, dividend analysis, insider transactions.

    248 GitHub stars~2.9k tokensUpdated 3 mo ago
    DatabasesAuto-check passed
  • Write Script Snowflake

    windmill-labs/windmill

    MUST use when writing Snowflake queries. An agent skill from windmill-labs/windmill.

    18k GitHub stars~2.2k tokensUpdated today
    DatabasesAuto-check passed
  • Pure Lsp Execute Parallel

    finos/legend-engine

    Runs 2 to 30 Pure functions or tests concurrently on the warm LSP daemon via pure-lsp execute-parallel, or every test in a package or .pure file with --package/--source.

    113 GitHub stars~927 tokensUpdated today
    DatabasesAuto-check passed
  • Plot Structure

    danjdewhurst/story-skills

    This skill should be used when the user asks to "create a plot arc", "story structure", "add a plot point", "story timeline", "track foreshadowing", "pacing", "sagging middle", "act structure"…

    286 GitHub starsUsed in 1 repo~4k tokens
    DatabasesAuto-check: notes
  • Snowflake

    adobe/skills

    Use this when converting an AI-generated static HTML page (Stardust, Mobirise, Relume, Lovable, v0, Figma-derived, etc.) into an Edge Delivery Services page while preserving the original design and…

    197 GitHub stars~3.7k tokensUpdated today
    DatabasesAuto-check passed

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Csf Mapping

    briiirussell/cybersecurity-skills

    Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover).

    413 GitHub stars~3k tokensUpdated 4 mo ago
    Auto-check: notes

Questions about Breach Patterns

What does Breach Patterns do?

Learn from public breach disclosures — extract the audit question each one implies and check your own stack. Breach Patterns is an agent skill from briiirussell/cybersecurity-skills. Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

When should I use Breach Patterns?

Breach Patterns fits situations like: the user mentions breach analysis; lessons learned; security postmortem; breach patterns.

How do I install Breach Patterns in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill breach-patterns -a claude-code`. Or copy the skill folder (skills/breach-patterns in briiirussell/cybersecurity-skills) into .claude/skills/breach-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Breach Patterns in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill breach-patterns -a codex`. Or copy the skill folder (skills/breach-patterns in briiirussell/cybersecurity-skills) into .agents/skills/breach-patterns in your project. Codex loads it when a task matches its description.

Can I use Breach Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill breach-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/breach-patterns, .gemini/skills/breach-patterns, .github/skills/breach-patterns and .opencode/skills/breach-patterns in your project.

What does Breach Patterns need to run?

SKILL.md names no scripts, command-line tools or credentials: Breach Patterns is instructions for the agent only. Our summary lists: Docker. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, WebSearch, WebFetch.

Does Breach Patterns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Breach Patterns safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Breach Patterns use?

Breach Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Breach Patterns use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Breach Patterns?

Skills that share tags, products or a category with Breach Patterns: Caspian Discord (TryCaspian/caspian-sdk, 973 stars), Simplywallst (gauss314/skills, 248 stars), Write Script Snowflake (windmill-labs/windmill, 18k stars) and Pure Lsp Execute Parallel (finos/legend-engine, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Breach Patterns?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.