Process Mapper
alirezarezvani/claude-skills
A skill your agent uses when a BizOps lead, COO, or process-improvement owner needs to document an end-to-end business process (procurement, employee onboarding, incident handoff…
Translate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales.
$ npx skills add briiirussell/cybersecurity-skills --skill security-comms -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install briiirussell/cybersecurity-skills security-comms --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-comms .claude/skills/security-comms && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-comms" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/security-comms into .claude/skills/security-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-comms", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/security-commsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add briiirussell/cybersecurity-skills --skill security-comms -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install briiirussell/cybersecurity-skills security-comms --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-comms .agents/skills/security-comms && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-comms" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/security-comms into .agents/skills/security-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-comms", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add briiirussell/cybersecurity-skills --skill security-comms -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install briiirussell/cybersecurity-skills security-comms --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-comms .cursor/skills/security-comms && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-comms" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/security-comms into .cursor/skills/security-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-comms", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/briiirussell/cybersecurity-skills.git --path skills/security-comms--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add briiirussell/cybersecurity-skills --skill security-comms -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install briiirussell/cybersecurity-skills security-comms --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-comms .gemini/skills/security-comms && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-comms" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/security-comms into .gemini/skills/security-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-comms", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install briiirussell/cybersecurity-skills security-commsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add briiirussell/cybersecurity-skills --skill security-comms -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-comms .github/skills/security-comms && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-comms" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/security-comms into .github/skills/security-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-comms", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add briiirussell/cybersecurity-skills --skill security-comms -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install briiirussell/cybersecurity-skills security-comms --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-comms .opencode/skills/security-comms && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-comms" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/security-comms into .opencode/skills/security-comms/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-comms", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-commsTranslate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales.
Security Comms is an agent skill from briiirussell/cybersecurity-skills. Translate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales. Covers incident communication, post-mortem narrative, audit-findings-for-stakeholders, risk justification, security spend justification, and customer-facing breach disclosure. Use when the user mentions 'security comms,' 'communicate this finding,' 'explain to my boss,' 'board update,' 'executive summary,' 'incident communication,' 'breach…
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Business, Finance & HR, covering Customer success, Vendor and procurement management and Runbooks and postmortems. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteWebSearchFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Comms loads about 3.8k tokens when it runs. Until then it costs about 198 tokens; SKILL.md has 1,427 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,427 words, ~3,757 tokens.
.claude/skills/security-comms/SKILL.md (or your agent's skills folder).The skill that closes the gap every other skill produces. The audit family generates findings; the response family generates incidents; the governance family generates roadmaps. None of those outputs survive contact with a board, a customer, a sales engineer trying to answer a security questionnaire, or a CFO asking "is this going to cost us money."
This skill takes technical security work and turns it into the deliverable that audience can actually use. It's the skill security practitioners reach for two to three times a week and that founders without dedicated security teams reach for whenever a finding has to leave the security context.
Cross-references: feeds from every other skill (audit output, incident write-ups, threat-model summaries, CSF assessments) and produces audience-specific deliverables; pairs especially closely with finding-triage (the disposition writeup) and incident-triage (the response narrative).
Security comms is not one register. Each audience needs a different deliverable; using the wrong register is the most common failure mode.
They need to know: Are we materially exposed? Is the team handling it? Is more investment needed?
They do not need: CVE numbers, file paths, scanner names, technical jargon, the methodology.
Format: One slide or one page. Three sections — current posture in one paragraph, top three risks with one sentence each, named investments / decisions needed. Numbers must be material (in dollars or % impact), not raw counts ("we have 47 vulnerabilities" tells them nothing; "two of our payments-team services have unpatched issues an attacker could use to access customer card data" tells them what to do).
Common mistake: Boards get scored heat maps and 30-row CVE tables. They want the punchline.
They need to know: What decision is being asked of them? What's the trade-off? What's the cost of inaction?
Format: Memo, one to three pages. Lead with the decision; then context, options with trade-offs, recommendation, the cost / time / people / risk if they say no. Quantify where possible (regulatory exposure dollars, customer-trust risk in churn percentage, engineering hours).
Common mistake: Asking for budget without naming the alternative if the budget is denied.
They need to know: What's broken, how to fix it, what's the priority, what's the trade-off in their roadmap.
Format: Ticket or design-doc-shaped writeup. Specific files / endpoints / commits. Reproduction steps. Fix proposal. Verification step. Effort estimate. Engineering leadership respects specificity; vague "you have an XSS somewhere" creates resentment.
Common mistake: Framing security work as urgent without showing the work. Engineers want to verify the finding themselves.
They need to know: What exactly to change, in their code, with verification they can run themselves.
Format: Ticket with code-shaped detail — file path, line number, current code, fixed code, the test that proves the fix held. This is the most concrete register of all.
Common mistake: Pasting the scanner output without context. The engineer doesn't know which of the scanner's 50 fields matter.
They need to know: What to say to customers who ask. What the answer is to common security questionnaire fields. What changed that they need to mention.
Format: Internal FAQ — questions phrased the way a customer would phrase them, answers written for an SE to read aloud or paste into a reply. Avoid security jargon; avoid "we cannot comment" unless legal actually said so.
Common mistake: Drafting customer-facing language and not letting customer-success read it for tone before it ships. Security folks default to language that sounds defensive or evasive.
They need to know: Did my data get accessed? What did you do about it? What do I need to do?
Format: A short letter. Lead with what happened in their terms (not yours). State what data may have been involved. State what's been done. State what they should do. Provide a contact path that works. Avoid corporate-PR softeners; they read as evasive.
Common mistake: Saying "out of an abundance of caution" when you mean "we don't know yet but we have to tell you." Customers can tell.
Disclosure to customers has legal and regulatory dimensions — this skill produces a draft; legal and possibly outside counsel review before it ships.
They need to know: Are we compliant, what's documented, what's the contractual position, do we have evidence?
Format: Structured artifact — questionnaire response, BAA / DPA red-line input, audit-evidence pull. Use the framework language the counterpart is using (CSF Subcategory IDs, ISO controls, PCI requirement numbers, HIPAA safeguard names). Avoid translating into your own framework; they want their language back.
Common mistake: Answering "yes" or "no" without the evidence pointer. Procurement-side reviewers need the evidence inline, not on request.
The skill works in two modes — drafting from a technical input, or reviewing a draft someone else wrote.
# Security Update — [Date]
## To: Board
## From: [CISO / equivalent]
### Bottom line
[One sentence — material exposure yes / no, contained yes / no, action needed yes / no]
### What happened
[Two to four sentences in the board's terms. No file paths or CVE numbers.]
### What's been done
- [Action 1, by date]
- [Action 2, by date]
### What we're asking of the board
[If anything — funding, vendor change, communications approval. If nothing, say so.]
### What we'll know by [next-meeting date]
[Open questions, planned investigations]# Memo: [Decision name]
## From: [author]
## To: [decision-maker]
## Date: [date]
## Decision needed by: [date]
### The decision
[One sentence — what you're asking them to approve.]
### Why now
[Two sentences — what changed, what the regulatory / customer / risk pressure is.]
### Options
1. [Option A — cost, time, residual risk]
2. [Option B — cost, time, residual risk]
3. [Do nothing — what happens]
### Recommendation
[Which option and why.]
### Cost of inaction
[Specific — regulatory fines, customer-trust impact, engineering hours saved elsewhere, etc.]# Security Notice
## Date: [date]
Dear [customer],
On [date], we identified [what happened — in the customer's terms]. Information that may have been involved includes [specific data fields]. Information not involved includes [specific data fields].
We have taken the following steps:
- [Action 1]
- [Action 2]
We recommend you:
- [Action 1 they should take, e.g., reset password]
- [Action 2]
If you have questions, contact [working contact path — not a generic security@].
We are sorry this happened.
[Name and title — not a corporate signature]# Post-mortem: [Incident name]
## Severity: [SEV1 / SEV2 / SEV3]
## Date detected: [date]
## Date resolved: [date]
## Duration: [hh:mm]
## Authors: [names]
### Summary
[One paragraph that someone outside the response can read and understand the incident.]
### Timeline
[Bulleted, with timestamps in one timezone. Detection → triage → containment → eradication → recovery → all-clear.]
### Impact
- [Who was affected — customers, internal users, third parties]
- [What was affected — service availability, data confidentiality, data integrity]
- [Quantify where possible — affected user count, downtime minutes, data records involved]
### Root cause
[The actual root cause — not the proximate trigger. Why did the trigger lead to user impact?]
### What went well
[Two to four items. Be specific.]
### What did not go well
[Two to four items. Be specific. No blame language.]
### Action items
| Item | Owner | Deadline | Status |
|------|-------|----------|--------|
### Lessons for the rest of the org
[What other teams should change based on this incident.]# Security Findings — [Project / sprint]
## Audit source: [owasp-audit / api-audit / etc.]
## Date: [date]
### Summary
[One sentence — N findings, severity breakdown, target resolution window.]
### Findings (prioritized)
| ID | Severity | File / endpoint | Effort estimate | Sprint candidate |
|----|----------|-----------------|-----------------|------------------|
### Per-finding detail
[Per-finding entries with file:line, reproduction, fix proposal, verification step, effort estimate.]
### Not findings (FYI)
[Items the scanner / audit flagged that we've determined are not real — with one line each on why. This builds engineering trust that we're not crying wolf.]# Customer Q&A — [Topic, e.g., recent vulnerability disclosure]
## Internal — for SE use; not customer-facing
**Q: Were we affected by [CVE / event]?**
A: [Straight answer. Yes / no / partially with which part.]
**Q: What did you do about it?**
A: [Specific actions with dates.]
**Q: Should I be doing anything on my end?**
A: [Customer-facing recommendation, or "no action required, here's why."]
**Q: When can I expect a written notice?**
A: [Date / not applicable / "you're reading the only one, you can quote it."]
**Q: [Other anticipated question]**
A: [...]
**If asked something not on this list:** [Escalation path — to whom, with what info, how fast.]A specific note because this skill is itself used by AI agents:
When an AI generates a security comm, do not ship it without a human reviewer for that audience. Specifically:
AI-drafted security comms are most useful as the first draft, not the final draft. The skill cuts the time-to-first-draft from 90 minutes to 10; it does not eliminate the review loop.
© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/security-comms of briiirussell/cybersecurity-skills.
Open the folder on GitHubat commit c9ade03
Security Comms next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Comms this skillbriiirussell/cybersecurity-skills | 413 | — | ~3.8k | Automated safety check: Pass | MIT | |
| Process Mapperalirezarezvani/claude-skills | 28k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Autopilot Statusindranilbanerjee/digital-marketing-pro | 859 | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Partnerships EcosystemLeoYeAI/openclaw-master-skills | 2.2k | — | ~5k | Automated safety check: Pass | MIT | |
| Board Meeting Prepw95/awesome-claude-corporate-skills | 239 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Serenity Alphahaskaomni/serenity-skill | 633 | — | ~2.6k | Automated safety check: Pass | MIT |
alirezarezvani/claude-skills
A skill your agent uses when a BizOps lead, COO, or process-improvement owner needs to document an end-to-end business process (procurement, employee onboarding, incident handoff…
indranilbanerjee/digital-marketing-pro
Campaign autopilot operations dashboard — 0-100 health scores for all active campaigns, a chronological log of auto-corrections taken (bid, budget, audience, creative, pause) with before/after…
LeoYeAI/openclaw-master-skills
World-Class Partnerships & Ecosystem Playbook. An agent skill from LeoYeAI/openclaw-master-skills.
w95/awesome-claude-corporate-skills
ACTIVATE when preparing for board meetings, creating board decks, drafting board materials, developing executive summaries for directors, writing talking points, crafting board agendas, addressing…
haskaomni/serenity-skill
Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…
github/awesome-copilot
Board meeting preparation, investor updates, and executive communication.
briiirussell/cybersecurity-skills
Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
briiirussell/cybersecurity-skills
Learn from public breach disclosures — extract the audit question each one implies and check your own stack.
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
briiirussell/cybersecurity-skills
Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.
briiirussell/cybersecurity-skills
Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.
Categories
Translate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales. Security Comms is an agent skill from briiirussell/cybersecurity-skills. Translate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales.
Security Comms fits situations like: the user mentions security comms; communicate this finding; explain to my boss; executive summary.
Run `npx skills add briiirussell/cybersecurity-skills --skill security-comms -a claude-code`. Or copy the skill folder (skills/security-comms in briiirussell/cybersecurity-skills) into .claude/skills/security-comms in your project. Claude Code loads it when a task matches its description.
Run `npx skills add briiirussell/cybersecurity-skills --skill security-comms -a codex`. Or copy the skill folder (skills/security-comms in briiirussell/cybersecurity-skills) into .agents/skills/security-comms in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill security-comms -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-comms, .gemini/skills/security-comms, .github/skills/security-comms and .opencode/skills/security-comms in your project.
SKILL.md names no scripts, command-line tools or credentials: Security Comms is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, WebSearch.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Comms is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Comms: Process Mapper (alirezarezvani/claude-skills, 28k stars), Autopilot Status (indranilbanerjee/digital-marketing-pro, 859 stars), Partnerships Ecosystem (LeoYeAI/openclaw-master-skills, 2.2k stars) and Board Meeting Prep (w95/awesome-claude-corporate-skills, 239 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.
Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.