Zhang Yiming Perspective
alchaincyf/zhang-yiming-skill
Answers product, organization, globalization, talent and growth questions in the voice of ByteDance founder Zhang Yiming, using a framework built from public material.
AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model
$ npx skills add Hack23/cia --skill information-security-strategy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Hack23/cia information-security-strategy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/information-security-strategy .claude/skills/information-security-strategy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "information-security-strategy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/information-security-strategy into .claude/skills/information-security-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "information-security-strategy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Hack23/cia/tree/master/.github/skills/information-security-strategyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Hack23/cia --skill information-security-strategy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Hack23/cia information-security-strategy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/information-security-strategy .agents/skills/information-security-strategy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "information-security-strategy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/information-security-strategy into .agents/skills/information-security-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "information-security-strategy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill information-security-strategy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Hack23/cia information-security-strategy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/information-security-strategy .cursor/skills/information-security-strategy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "information-security-strategy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/information-security-strategy into .cursor/skills/information-security-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "information-security-strategy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Hack23/cia.git --path .github/skills/information-security-strategy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Hack23/cia --skill information-security-strategy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Hack23/cia information-security-strategy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/information-security-strategy .gemini/skills/information-security-strategy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "information-security-strategy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/information-security-strategy into .gemini/skills/information-security-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "information-security-strategy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Hack23/cia information-security-strategyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Hack23/cia --skill information-security-strategy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/information-security-strategy .github/skills/information-security-strategy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "information-security-strategy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/information-security-strategy into .github/skills/information-security-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "information-security-strategy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill information-security-strategy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Hack23/cia information-security-strategy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/information-security-strategy .opencode/skills/information-security-strategy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "information-security-strategy" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/information-security-strategy into .opencode/skills/information-security-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "information-security-strategy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
information-security-strategyAI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model
Information Security Strategy is an agent skill from Hack23/cia. AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Secure coding, Product strategy and Startup and business strategy. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml and mermaid).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Information Security Strategy loads about 4.1k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 733 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 733 words, ~4,115 tokens.
.claude/skills/information-security-strategy/SKILL.md (or your agent's skills folder).This skill provides strategic security planning guidance aligned with Hack23 AB's AI-augmented operating model and transparent ISMS implementation. It enables security architects and business leaders to align security controls with business impact classifications, demonstrate security excellence through public transparency, and leverage ISMS as competitive advantage for cybersecurity consulting services.
Apply this skill when:
Do NOT use for:
graph TB
CEO["👨💼 CEO/Founder<br/>Strategic Oversight"]
subgraph AI_AGENTS["🤖 Specialist AI Agent Ecosystem"]
SEC_ARCH["🔐 Security Architect Agent<br/>Architecture design & review"]
DEV_SEC["💻 DevSecOps Agent<br/>CI/CD security integration"]
TEST_SEC["🧪 Security Testing Agent<br/>SAST/DAST/Fuzzing"]
DOC_SEC["📚 Documentation Agent<br/>Policy & procedure creation"]
BIZ_SEC["💼 Business Agent<br/>Risk/value alignment"]
MARKET_SEC["📢 Marketing Agent<br/>Security posture communication"]
end
CEO --> SEC_ARCH
CEO --> DEV_SEC
CEO --> TEST_SEC
CEO --> DOC_SEC
CEO --> BIZ_SEC
CEO --> MARKET_SEC
SEC_ARCH --> ARCH_OUT["📋 SECURITY_ARCHITECTURE.md<br/>THREAT_MODEL.md"]
DEV_SEC --> CICD_OUT["⚙️ GitHub Actions Workflows<br/>Security Gates"]
TEST_SEC --> TEST_OUT["🧪 CodeQL / OWASP ZAP<br/>Vulnerability Reports"]
DOC_SEC --> DOC_OUT["📖 ISMS Policies<br/>Compliance Evidence"]
BIZ_SEC --> BIZ_OUT["💰 Risk Register<br/>Business Impact Analysis"]
MARKET_SEC --> MARKET_OUT["🏆 Security Badges<br/>Public Metrics"]
ARCH_OUT --> EVIDENCE["🎖️ Public Evidence<br/>OpenSSF Scorecard<br/>CII Best Practices<br/>SLSA Level 3"]
CICD_OUT --> EVIDENCE
TEST_OUT --> EVIDENCE
DOC_OUT --> EVIDENCE
BIZ_OUT --> EVIDENCE
MARKET_OUT --> EVIDENCE
EVIDENCE --> CLIENTS["🤝 Client Demonstration<br/>Competitive Advantage"]
style CEO fill:#1565C0,stroke:#0D47A1,stroke-width:3px,color:#fff
style AI_AGENTS fill:#4CAF50,stroke:#2E7D32,stroke-width:2px
style EVIDENCE fill:#FF9800,stroke:#F57C00,stroke-width:2px
style CLIENTS fill:#9C27B0,stroke:#6A1B9A,stroke-width:2pxKey Strategic Principles:
Use this decision tree when designing security controls for new products:
flowchart TD
START["🎯 New Product/Service"] --> CLASS{What is the<br/>Confidentiality<br/>Classification?}
CLASS -->|Low| LOW_CONF["⚪ Low Confidentiality<br/>Public data only"]
CLASS -->|Moderate| MOD_CONF["🟡 Moderate Confidentiality<br/>User accounts/data"]
CLASS -->|High/Very High| HIGH_CONF["🔴 High/Very High<br/>Sensitive operations"]
LOW_CONF --> AUTH_LOW{Does app process<br/>user-specific data?}
AUTH_LOW -->|No| NO_AUTH["❌ No Authentication<br/>✅ TLS 1.3 Required<br/>Example: CIA CM, Black Trigram"]
AUTH_LOW -->|Yes| BASIC_AUTH["🔐 Basic Authentication<br/>Username/Password"]
MOD_CONF --> AUTH_MOD["🔐 Full Authentication Stack"]
AUTH_MOD --> MFA["✅ MFA Required<br/>✅ RBAC<br/>✅ Session Management<br/>✅ Audit Logging"]
HIGH_CONF --> AUTH_HIGH["🔐 Enhanced Security"]
AUTH_HIGH --> ENHANCED["✅ MFA Mandatory<br/>✅ Fine-grained RBAC<br/>✅ Comprehensive Audit<br/>✅ Encryption at Rest<br/>Example: CIA Platform"]
NO_AUTH --> RATIONALE_LOW["📋 Document Risk Acceptance<br/>Update Risk Register<br/>Reference Classification Framework"]
BASIC_AUTH --> RATIONALE_MOD["📋 Document Control Selection<br/>Map to Classification Framework"]
MFA --> RATIONALE_HIGH["📋 Full Security Architecture<br/>SECURITY_ARCHITECTURE.md"]
ENHANCED --> RATIONALE_HIGH
RATIONALE_LOW --> VERIFY["🧪 Verification Required"]
RATIONALE_MOD --> VERIFY
RATIONALE_HIGH --> VERIFY
VERIFY --> V1["✅ SECURITY_ARCHITECTURE.md created"]
VERIFY --> V2["✅ THREAT_MODEL.md completed"]
VERIFY --> V3["✅ Risk Register updated"]
VERIFY --> V4["✅ Classification badges in README"]
style START fill:#1565C0,stroke:#0D47A1,stroke-width:2px,color:#fff
style LOW_CONF fill:#9E9E9E,stroke:#616161,stroke-width:2px
style MOD_CONF fill:#FF9800,stroke:#F57C00,stroke-width:2px
style HIGH_CONF fill:#D32F2F,stroke:#B71C1C,stroke-width:3px,color:#fff
style NO_AUTH fill:#4CAF50,stroke:#2E7D32,stroke-width:2px,color:#fff
style ENHANCED fill:#B71C1C,stroke:#880E4F,stroke-width:3px,color:#fff
style VERIFY fill:#7B1FA2,stroke:#4A148C,stroke-width:2px,color:#fffMap security controls to Classification Framework business impact levels:
CIA Platform - Moderate Confidentiality, High Integrity, Moderate Availability
Required Controls:
authentication:
type: "Multi-factor with RBAC"
implementation: "Spring Security + JWT + MFA"
session: "Server-side with Redis"
audit_logging:
framework: "Javers + AWS CloudTrail"
retention: "7 years (regulatory compliance)"
monitoring: "Real-time with CloudWatch alarms"
encryption:
in_transit: "TLS 1.3 enforced"
at_rest: "PostgreSQL encryption + AWS KMS"
access_control:
model: "Role-Based Access Control (RBAC)"
segregation: "Admin/User/Anonymous roles"Architecture Documentation:
CIA Compliance Manager, Black Trigram - Low Confidentiality, Moderate Integrity
Required Controls:
authentication:
type: "None (intentional risk acceptance)"
rationale: "Public data only, no user-specific operations"
risk_documentation: "Risk_Register.md entry with annual review"
encryption:
in_transit: "TLS 1.3 enforced via CDN"
at_rest: "Not applicable (no backend database)"
session_management:
type: "Browser-only (localStorage/sessionStorage)"
scope: "UI state persistence only"
monitoring:
application: "None (frontend-only, stateless)"
infrastructure: "CDN access logs only"Risk Acceptance Documentation:
The absence of authentication is an intentional architectural decision based on Low confidentiality classification. All data processed is public compliance framework information with no sensitive user data. This risk is documented in the Risk Register with periodic review triggers if feature requirements change.
Architecture Documentation:
Implement security controls across multiple layers aligned with product classification:
graph TB
subgraph LAYER7["🎯 Layer 7: Policies & Governance"]
POLICY[Information Security Policy<br/>Classification Framework<br/>Risk Register]
end
subgraph LAYER6["👥 Layer 6: Application Security"]
APP["Authentication & Authorization<br/>Input Validation<br/>Session Management"]
end
subgraph LAYER5["🔐 Layer 5: Data Security"]
DATA[Encryption at Rest<br/>Encryption in Transit<br/>Data Classification]
end
subgraph LAYER4["🌐 Layer 4: Network Security"]
NETWORK[TLS 1.3 Enforcement<br/>CDN Protection<br/>DDoS Mitigation]
end
subgraph LAYER3["🖥️ Layer 3: Infrastructure Security"]
INFRA[AWS Security Groups<br/>IAM Policies<br/>VPC Configuration]
end
subgraph LAYER2["🛠️ Layer 2: CI/CD Security"]
CICD[SAST: CodeQL/SonarCloud<br/>SCA: Dependabot/FOSSA<br/>DAST: OWASP ZAP]
end
subgraph LAYER1["📊 Layer 1: Monitoring & Response"]
MONITOR[CloudWatch Alarms<br/>Security Hub<br/>Incident Response]
end
POLICY --> APP
APP --> DATA
DATA --> NETWORK
NETWORK --> INFRA
INFRA --> CICD
CICD --> MONITOR
MONITOR -->|Feedback Loop| POLICY
style LAYER7 fill:#D32F2F,stroke:#B71C1C,stroke-width:2px,color:#fff
style LAYER6 fill:#FF5722,stroke:#D84315,stroke-width:2px,color:#fff
style LAYER5 fill:#FF9800,stroke:#F57C00,stroke-width:2px
style LAYER4 fill:#FFC107,stroke:#FFA000,stroke-width:2px
style LAYER3 fill:#4CAF50,stroke:#388E3C,stroke-width:2px,color:#fff
style LAYER2 fill:#2196F3,stroke:#1976D2,stroke-width:2px,color:#fff
style LAYER1 fill:#9C27B0,stroke:#7B1FA2,stroke-width:2px,color:#fffAlign security strategy with competitive advantage:
| Force | Security Implication | Strategic Response |
|---|---|---|
| Buyer Power | Customers demand security evidence | Public badges: OpenSSF Scorecard ≥7.0, CII Best Practices, SLSA Level 3 |
| Supplier Power | Cloud/SaaS vendor dependencies | Multi-vendor flexibility, open source preference, SBOM transparency |
| Entry Barriers | Expertise required for ISMS | Transparent ISMS creates moat—competitors lack documentation maturity |
| Substitute Threat | In-house security teams | Demonstrate AI-augmented efficiency (<1 FTE overhead vs 3-5 FTE teams) |
| Rivalry | Cybersecurity consulting competition | ISMS transparency differentiates—"eat our own dog food" credibility |
Reference: Information Security Strategy § Porter's Five Forces
Map strategic security decisions to compliance frameworks:
| Security Decision | ISO 27001:2022 | NIST CSF 2.0 | CIS Controls v8 |
|---|---|---|---|
| Authentication model | A.5.15, A.5.16 | PR.AC-01 | 5.2, 6.3 |
| Encryption requirements | A.8.24 | PR.DS-01 | 3.10 |
| Risk acceptance process | A.5.7, A.8.3 | GV.RM-01 | 4.1 |
| Security architecture | A.8.1 | PR.IP-01 | 16.1 |
| Monitoring & logging | A.8.15, A.8.16 | DE.AE-01 | 8.2, 8.5 |
Use this checklist when developing security strategy for new initiatives:
Scenario: Educational gaming platform with no user accounts
Security Architecture:
product_name: "Black Trigram Educational Gaming"
classification:
confidentiality: "Low"
integrity: "Moderate"
availability: "Moderate"
security_controls:
authentication: "None (risk accepted)"
authorization: "None (public content)"
encryption_in_transit: "TLS 1.3 via CDN"
encryption_at_rest: "N/A (no backend)"
session_management: "Browser localStorage only"
audit_logging: "None (frontend-only)"
risk_acceptance:
rationale: "All game content is public educational material"
risk_register_entry: "RSK-2025-001"
review_cycle: "Annual"
trigger_conditions:
- "Introduction of user accounts"
- "Addition of user-generated content"
- "Processing of personal data"Required Documentation:
Scenario: Political transparency platform with user accounts
Security Architecture:
product_name: "Citizen Intelligence Agency"
classification:
confidentiality: "Moderate"
integrity: "High"
availability: "Moderate"
security_controls:
authentication: "Multi-factor (TOTP/SMS)"
authorization: "RBAC (Admin/User/Anonymous)"
encryption_in_transit: "TLS 1.3"
encryption_at_rest: "PostgreSQL + AWS KMS"
session_management: "Server-side JWT with Redis"
audit_logging: "Javers + CloudWatch (7-year retention)"
defense_in_depth:
layer_7_governance: "Information Security Policy"
layer_6_application: "Spring Security + MFA"
layer_5_data: "Field-level encryption for PII"
layer_4_network: "VPC + Security Groups"
layer_3_infrastructure: "AWS IAM + GuardDuty"
layer_2_cicd: "CodeQL + SonarCloud + ZAP"
layer_1_monitoring: "CloudWatch + Security Hub"Required Documentation:
Core Hack23 ISMS Policies:
All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC
© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. 1 hidden character (zero-width or bidirectional) removed. Raw file
Just SKILL.md in .github/skills/information-security-strategy of Hack23/cia.
Open the folder on GitHubat commit bbed538
Information Security Strategy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Information Security Strategy this skillHack23/cia | 239 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| Zhang Yiming Perspectivealchaincyf/zhang-yiming-skill | 173 | 2 repos | ~3.2k | Automated safety check: Pass | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Humble Header Report Analystrfc-st/humble | 379 | — | ~3.7k | Automated safety check: Pass | MIT | |
| Startup Designferdinandobons/startup-skill | 1.2k | — | ~8.1k | Automated safety check: Pass | MIT | |
| Pre-Commit Security Scanzereight/gitlab-mcp | 2k | 1 repos | ~859 | Automated safety check: Notes | MIT |
alchaincyf/zhang-yiming-skill
Answers product, organization, globalization, talent and growth questions in the voice of ByteDance founder Zhang Yiming, using a framework built from public material.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
rfc-st/humble
Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.
ferdinandobons/startup-skill
Design, validate, and plan a startup from scratch. An agent skill from ferdinandobons/startup-skill.
zereight/gitlab-mcp
Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.
sandgardenhq/sgai
A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally…
Hack23/cia
WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms
Hack23/cia
Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
Hack23/cia
External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs
Hack23/cia
AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform
Hack23/cia
AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment
Categories
AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model. Information Security Strategy is an agent skill from Hack23/cia.
Information Security Strategy fits situations like: tasks that involve Secure coding; tasks that involve Product strategy; tasks that involve Startup and business strategy.
Run `npx skills add Hack23/cia --skill information-security-strategy -a claude-code`. Or copy the skill folder (.github/skills/information-security-strategy in Hack23/cia) into .claude/skills/information-security-strategy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Hack23/cia --skill information-security-strategy -a codex`. Or copy the skill folder (.github/skills/information-security-strategy in Hack23/cia) into .agents/skills/information-security-strategy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill information-security-strategy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/information-security-strategy, .gemini/skills/information-security-strategy, .github/skills/information-security-strategy and .opencode/skills/information-security-strategy in your project.
SKILL.md names no scripts, command-line tools or credentials: Information Security Strategy is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Information Security Strategy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Information Security Strategy: Zhang Yiming Perspective (alchaincyf/zhang-yiming-skill, 173 stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Humble Header Report Analyst (rfc-st/humble, 379 stars) and Startup Design (ferdinandobons/startup-skill, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.
Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.