Fla Ascend Performance
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover).
$ npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install briiirussell/cybersecurity-skills csf-mapping --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/csf-mapping .claude/skills/csf-mapping && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "csf-mapping" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/csf-mapping into .claude/skills/csf-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csf-mapping", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/csf-mappingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install briiirussell/cybersecurity-skills csf-mapping --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/csf-mapping .agents/skills/csf-mapping && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "csf-mapping" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/csf-mapping into .agents/skills/csf-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csf-mapping", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install briiirussell/cybersecurity-skills csf-mapping --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/csf-mapping .cursor/skills/csf-mapping && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "csf-mapping" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/csf-mapping into .cursor/skills/csf-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csf-mapping", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/briiirussell/cybersecurity-skills.git --path skills/csf-mapping--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install briiirussell/cybersecurity-skills csf-mapping --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/csf-mapping .gemini/skills/csf-mapping && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "csf-mapping" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/csf-mapping into .gemini/skills/csf-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csf-mapping", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install briiirussell/cybersecurity-skills csf-mappingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/csf-mapping .github/skills/csf-mapping && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "csf-mapping" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/csf-mapping into .github/skills/csf-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csf-mapping", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install briiirussell/cybersecurity-skills csf-mapping --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/csf-mapping .opencode/skills/csf-mapping && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "csf-mapping" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/csf-mapping into .opencode/skills/csf-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "csf-mapping", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
csf-mappingMap your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover).
Csf Mapping is an agent skill from briiirussell/cybersecurity-skills. Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover). Produce a gap analysis, current/target tier assessment, and roadmap in the governance language that boards, auditors, and CISOs actually use. Use when the user mentions 'NIST CSF,' 'CSF 2.0,' 'cybersecurity framework,' 'security posture,' 'governance mapping,' 'CSF gap analysis,' 'CSF tiers,' 'cybersecurity maturity,' 'security roadmap,' 'CISO report,' 'board reporting,' 'security…
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepGlobBashWebSearchFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Csf Mapping loads about 3k tokens when it runs. Until then it costs about 150 tokens; SKILL.md has 1,305 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Grep, Glob, Bash, WebSearchAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,305 words, ~3,038 tokens.
.claude/skills/csf-mapping/SKILL.md (or your agent's skills folder).Translate your security posture into the language every CISO, board, auditor, and insurer already speaks. Distinct from the audit skills (which find specific issues); this skill assesses your program against a recognized framework and produces governance-ready output.
NIST CSF 2.0 is the framework that, as of 2024, replaced CSF 1.1. It added a sixth function — Govern — recognizing that the others can't work without governance backing.
The six functions:
| Function | What it covers |
|---|---|
| Govern (GV) | Cybersecurity strategy, roles, policies, oversight, supply chain risk |
| Identify (ID) | Asset inventory, business environment, risk assessment, supply chain |
| Protect (PR) | Access control, awareness, data security, baseline configurations, maintenance, protective tech |
| Detect (DE) | Continuous monitoring, anomaly detection, adverse event analysis |
| Respond (RS) | Incident management, analysis, mitigation, reporting, comms |
| Recover (RC) | Recovery planning, improvements, communications |
Each function contains Categories (e.g., PR.AA — Identity Management, Authentication, and Access Control), and each category contains Subcategories (e.g., PR.AA-01 — Identities and credentials for authorized users, services, and hardware are managed).
This skill maps your reality to those Subcategories.
Cross-references: every audit skill in this repo (they produce evidence that becomes the "current state" entries here), iam-audit (most of PR.AA), siem-detection (most of DE), incident-triage (most of RS), threat-modeling (informs ID.RA risk assessment), breach-patterns (informs ID.IM improvements from lessons learned).
CSF assessments are scope-bounded. Decide which of these you're assessing:
Write down what's in and what's out. Most CSF assessments fail at scope drift.
CSF 2.0 introduced Organizational Profiles — instead of "score every Subcategory equally," you tailor based on what matters.
For a first-pass assessment, start with a Community Profile if one exists for your sector, then tailor.
For each Subcategory in scope:
| Field | What to record |
|---|---|
| ID | e.g., PR.AA-05 |
| Subcategory text | Verbatim from NIST or paraphrased |
| Current state | What you actually do today (evidence, not aspiration) |
| Evidence | Document / system / process that proves the current state |
| Tier | Partial / Risk-Informed / Repeatable / Adaptive (1-4) |
| Target tier | What you're aiming for |
| Gap | The delta |
| Plan | What closes the gap |
| Owner | Who's accountable |
| Timeline | When |
| Tier | Name | Characteristic |
|---|---|---|
| 1 | Partial | Ad-hoc, reactive, undocumented; awareness is informal |
| 2 | Risk-Informed | Risk management is approved but not org-wide; processes are repeatable for some teams |
| 3 | Repeatable | Documented org-wide policies; consistent processes; risk-informed budgeting |
| 4 | Adaptive | Continuous improvement; quantitative risk; learning from incidents (yours and peers'); cybersecurity culture |
Tier 4 is rare and expensive. Most mature SaaS orgs target Tier 3 across most subcategories. Set targets based on what the business actually needs, not what looks good.
For each gap, ask:
Prioritize by Risk × Cost-to-close — not just by risk. Some critical-risk items take a year and three vendors; some quick wins reduce real risk in a sprint.
CSF roadmaps usually run in quarters with annual targets. A useful structure:
Each item on the roadmap names: the Subcategory it closes, the owner, the budget, the success metric, the review date.
A useful shortcut — these are the audit skills that produce evidence for which CSF Subcategories.
| CSF Subcategory | Audit skill | Type of evidence |
|---|---|---|
GV.SC (Supply Chain Risk) | dependency-audit | CVE inventory, vendor list, supply chain risk register |
ID.AM (Asset Management) | cloud-audit, container-audit, recon | Asset inventory output |
ID.RA (Risk Assessment) | threat-modeling, breach-patterns | Threat models, breach-pattern coverage doc |
ID.IM (Improvement from past incidents) | incident-triage post-mortems, breach-patterns | Post-incident reviews, lessons-learned applied |
PR.AA (Identity & Access Control) | iam-audit | IAM audit reports, role inventory |
PR.DS (Data Security) | crypto-audit, secrets-audit | Crypto posture, secrets management posture |
PR.PS (Platform Security) | container-audit, cloud-audit | K8s hardening, cloud posture |
PR.IR (Infrastructure Resilience) | container-audit, cloud-audit | Network policy, segmentation, backup posture |
DE.CM (Continuous Monitoring) | siem-detection, soc-operations | SIEM coverage, ATT&CK Navigator export |
DE.AE (Anomaly & Event Analysis) | siem-detection, threat-hunting | Detection rule inventory, hunt findings |
RS.MA (Incident Management) | incident-triage, soc-operations | IR plan, runbooks, recent incident reports |
RS.AN (Analysis) | disk-forensics, incident-triage | Forensic analysis outputs |
RS.MI (Mitigation) | finding-triage, incident-triage | Triage decisions, mitigation tracking |
RC.RP (Recovery Plan) | (not directly covered — separate BCP/DR work) | BCP / DR plans, tested recovery |
For Subcategories without direct skill coverage, the gap is usually "we have technical depth but not the program-level artifact." E.g., RC.RP-01 (Recovery plan is executed during or after an incident) needs an actual documented and tested BCP/DR plan — running incident-triage doesn't automatically produce one.
Patterns I see repeatedly in CSF assessments. Not universal, but starting points:
# NIST CSF 2.0 Posture Assessment
## Organization: [name]
## Scope: [what's in / out]
## Date: [date]
## Assessor: [name]
## Executive summary
[2-3 paragraphs in plain English — overall posture, top 3 risks, top 3 wins, recommended 90-day priorities]
## Profile
### Tier summary across functions
| Function | Current tier | Target tier |
|----------|--------------|-------------|
| GV | 2 | 3 |
| ID | 2 | 3 |
| PR | 3 | 3 |
| DE | 2 | 3 |
| RS | 3 | 3 |
| RC | 1 | 2 |
### Per-Subcategory detail
| Subcategory | Current state | Evidence | Tier | Target | Gap | Owner | Timeline |
|-------------|---------------|----------|------|--------|-----|-------|----------|
## Prioritized roadmap
### Next 30 days
- [Item, owner, success metric]
### Next 90 days
- [Item, owner, success metric]
### Next 12 months
- [Item, owner, success metric]
## Cross-references
[Links to evidence — audit reports, IR plans, IAM reports, etc.]Boards don't want Subcategory IDs. They want answers to three questions:
Use the CSF assessment as the backing detail. The board view is a one-page heatmap and three slides of priorities. The assessment goes in the appendix.
incident-triage or the relevant audit skillnist.gov/cyberframework)© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/csf-mapping of briiirussell/cybersecurity-skills.
Open the folder on GitHubat commit c9ade03
Csf Mapping next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Csf Mapping this skillbriiirussell/cybersecurity-skills | 413 | — | ~3k | Automated safety check: Notes | MIT | |
| Fla Ascend Performancefla-org/flash-linear-attention | 5.8k | — | ~6.3k | Automated safety check: Pass | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 481 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Security Alert Triageelastic/agent-skills | 592 | 1 repos | ~3.5k | Automated safety check: Notes | Apache-2.0 |
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
briiirussell/cybersecurity-skills
Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
briiirussell/cybersecurity-skills
Learn from public breach disclosures — extract the audit question each one implies and check your own stack.
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
briiirussell/cybersecurity-skills
Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.
briiirussell/cybersecurity-skills
Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.
Categories
Map your security posture against the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover). Csf Mapping is an agent skill from briiirussell/cybersecurity-skills.0 (Govern, Identify, Protect, Detect, Respond, Recover).
Csf Mapping fits situations like: the user mentions NIST CSF; cybersecurity framework; security posture; governance mapping.
Run `npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a claude-code`. Or copy the skill folder (skills/csf-mapping in briiirussell/cybersecurity-skills) into .claude/skills/csf-mapping in your project. Claude Code loads it when a task matches its description.
Run `npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a codex`. Or copy the skill folder (skills/csf-mapping in briiirussell/cybersecurity-skills) into .agents/skills/csf-mapping in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill csf-mapping -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/csf-mapping, .gemini/skills/csf-mapping, .github/skills/csf-mapping and .opencode/skills/csf-mapping in your project.
SKILL.md names no scripts, command-line tools or credentials: Csf Mapping is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, WebSearch.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Csf Mapping is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Csf Mapping: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.
Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.