Security Comms
briiirussell/cybersecurity-skills
Translate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales.
Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…
$ npx skills add haskaomni/serenity-skill --skill serenity-alpha -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install haskaomni/serenity-skill serenity-alpha --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/haskaomni/serenity-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/serenity-alpha .claude/skills/serenity-alpha && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "serenity-alpha" agent skill from https://github.com/haskaomni/serenity-skill/tree/main/skills/serenity-alpha into .claude/skills/serenity-alpha/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "serenity-alpha", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/haskaomni/serenity-skill/tree/main/skills/serenity-alphaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add haskaomni/serenity-skill --skill serenity-alpha -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install haskaomni/serenity-skill serenity-alpha --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/haskaomni/serenity-skill.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/serenity-alpha .agents/skills/serenity-alpha && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "serenity-alpha" agent skill from https://github.com/haskaomni/serenity-skill/tree/main/skills/serenity-alpha into .agents/skills/serenity-alpha/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "serenity-alpha", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add haskaomni/serenity-skill --skill serenity-alpha -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install haskaomni/serenity-skill serenity-alpha --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/haskaomni/serenity-skill.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/serenity-alpha .cursor/skills/serenity-alpha && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "serenity-alpha" agent skill from https://github.com/haskaomni/serenity-skill/tree/main/skills/serenity-alpha into .cursor/skills/serenity-alpha/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "serenity-alpha", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/haskaomni/serenity-skill.git --path skills/serenity-alpha--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add haskaomni/serenity-skill --skill serenity-alpha -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install haskaomni/serenity-skill serenity-alpha --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/haskaomni/serenity-skill.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/serenity-alpha .gemini/skills/serenity-alpha && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "serenity-alpha" agent skill from https://github.com/haskaomni/serenity-skill/tree/main/skills/serenity-alpha into .gemini/skills/serenity-alpha/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "serenity-alpha", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install haskaomni/serenity-skill serenity-alphaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add haskaomni/serenity-skill --skill serenity-alpha -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/haskaomni/serenity-skill.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/serenity-alpha .github/skills/serenity-alpha && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "serenity-alpha" agent skill from https://github.com/haskaomni/serenity-skill/tree/main/skills/serenity-alpha into .github/skills/serenity-alpha/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "serenity-alpha", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add haskaomni/serenity-skill --skill serenity-alpha -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install haskaomni/serenity-skill serenity-alpha --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/haskaomni/serenity-skill.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/serenity-alpha .opencode/skills/serenity-alpha && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "serenity-alpha" agent skill from https://github.com/haskaomni/serenity-skill/tree/main/skills/serenity-alpha into .opencode/skills/serenity-alpha/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "serenity-alpha", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
serenity-alphaTranslate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…
Serenity Alpha is an agent skill from haskaomni/serenity-skill. Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation metrics, downside risks, and position-sizing conditions. Use when the user shares news, product launches, technology breakthroughs, procurement signals, supply-chain changes, earnings-call clues, or asks for Serenity-style alpha analysis, small-cap beneficiaries, or "news to financial statement" translation.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/original-framework.md`).
It sits in Business, Finance & HR, covering Supply chain security, Financial analysis and Translation. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit dedcf8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipuvFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip and uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Serenity Alpha loads about 2.6k tokens when it runs, and up to ~2.8k if it reads all its reference files. Until then it costs about 131 tokens; SKILL.md has 1,155 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from haskaomni/serenity-skill at commit dedcf8f, republished under its MIT licence (© haskaomni). 1,155 words, ~2,568 tokens.
.claude/skills/serenity-alpha/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Do not ask only whether the news is impressive. Ask whether an already-observable demand change can rewrite a smaller company's financial statements.
Use this skill to convert news into a testable alpha hypothesis:
news -> observed demand change -> revenue/profit transmission -> small-cap elasticity -> validation pathTreat outputs as research hypotheses, not investment advice. Verify current prices, market caps, filings, earnings calls, and news from reliable sources before naming securities or making time-sensitive claims.
For U.S.-listed companies, use SEC filings as the factual base for reported fundamentals and management disclosure when available. edgartools is a good optional helper for this step because it can retrieve company filings, XBRL financial statements, filing text, insider transactions, ownership forms, and recent 8-K disclosures.
If the environment does not already have it, install with pip install edgartools or uv pip install edgartools. The import package is edgar, not edgartools. SEC access requires an identity; set EDGAR_IDENTITY="Name email@example.com" in the environment or call from edgar import set_identity; set_identity("name@example.com") before requests.
Minimal usage pattern:
from edgar import Company
company = Company("AAPL")
filings = company.get_filings(form="10-Q")
financials = company.get_financials()
income = financials.income_statement()Use it to support the analysis, not to replace the framework:
When using SEC data, cite the filing form and filing date in the reasoning, and state when the data is stale relative to the news item.
Start and end with the company that best fits the alpha hypothesis.
最值得优先验证的是:Company / ticker,原因是...暂时没有足够明确的公司,先观察...Identify whether the item is merely narrative or a demand inflection. Prioritize evidence that has already happened:
If demand is not observable, classify the idea as watchlist-only.
Use this sentence structure:
Because X is happening, demand for Y is increasing.
That demand can flow to A/B/C companies through revenue line Z.
Company N may matter because its market cap, revenue base, or business purity is small enough for the demand shock to change reported results.For each candidate, map the mechanism to income-statement or balance-sheet items:
Look for "small shovels," not only obvious mega-cap winners. Rank candidates higher when they have:
Use this rough screen:
alpha elasticity ~= incremental demand impact / current company scaleAsk:
Misclassification creates alpha only when the relabeling can be validated by numbers, not just story.
Convert the thesis into observable checkpoints. Use the most relevant indicators:
Define what would confirm, weaken, or falsify the thesis.
Score each candidate qualitatively or on a 1-5 scale:
| Dimension | Question |
|---|---|
| Demand certainty | Is this already occurring, or only imagined? |
| Transmission clarity | Can the demand clearly flow to named companies? |
| Business purity | Is the company directly exposed? |
| Market-cap elasticity | Is the company small enough for the impact to matter? |
| Market neglect | Is the market missing or mislabeling it? |
| Verification speed | Can filings or calls verify this in 1-4 quarters? |
| Downside risk | What happens if the thesis is wrong? |
Prioritize ideas with high certainty, clear transmission, high purity, high elasticity, and near-term verification.
Frame position posture as conditional research guidance, not a personalized recommendation:
| Thesis state | Posture |
|---|---|
| Demand seems real, transmission unclear | observe / very small exploratory size |
| Demand real, transmission clear, no financial proof yet | small test position if risk fits |
| Financials begin validating and market still underprices | consider adding |
| Thesis becomes consensus and valuation stretches | lower return expectations / trade only |
| Key assumptions are falsified | exit or remove from watchlist |
For a full report, include 2-4 Mermaid diagrams when they materially improve comprehension. A short answer or data-limited analysis may use fewer. Do not create a diagram merely to meet a quota.
Prioritize these views:
flowchart from news to observed demand, financial-statement lines, beneficiaries, and the decisive validation condition.quadrantChart only with a nearby comparison table.Apply these rules to every diagram:
mermaid blocks, match the report language, keep node IDs in simple ASCII, and keep labels short.flowchart, pie, and stateDiagram syntax. Use xychart-beta, quadrantChart, or timeline only as progressive enhancement and retain the adjacent Markdown table as the fallback.When analyzing a news item, use this structure:
## 结论先行:优先验证的公司
点名最值得优先验证的一家公司 / ticker,并用一句话说明为什么它是本次新闻里最有弹性的候选。
## A. 表层新闻
简述新闻表面信息。
## B. 已发生的需求变化
说明已经可观察的需求、采购、使用、价格、排产或供应链变化;如果没有,明确说只是谈资。
## C. 财务翻译
把需求映射到收入项、成本项、利润项、现金流或资产负债表项目。
在这里或下一节加入需求传导 Mermaid flowchart,展示新闻如何进入财务报表并最终影响候选公司。
## D. 受益链条
列出一阶、二阶、三阶受益者,并说明传导距离。
## E. 小市值高弹性标的
列出可能的小盘/高纯度/低关注候选;标注需要核实的市值、收入基数和业务占比。
如果至少三个候选具有可比数据,可加入证据强度—财务弹性矩阵,并保留候选比较表。
## F. 市场误分类
说明市场现在把公司当什么,它可能正在变成什么。
## G. 验证指标
列出未来 1-4 个季度要看的财报、电话会、供应链和价格指标。
加入验证路径图,明确确认、削弱和证伪分支。
## H. 下行风险
列出需求、传导、竞争、估值、时点和流动性风险。
## I. 仓位建议
给出观察、小仓、加仓、放弃的条件;避免承诺收益或给出个性化投资指令。
## 最后一句
再次点名这家公司,并给出最关键的财报验证条件;如果条件不成立,明确说应放弃或降级为观察。When references/original-framework.md is consulted, preserve its analytical intent but follow this SKILL.md's current output and visualization rules when the formats differ.
© haskaomni, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in skills/serenity-alpha of haskaomni/serenity-skill.
Open the folder on GitHubat commit dedcf8f
Serenity Alpha next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Serenity Alpha this skillhaskaomni/serenity-skill | 633 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Security Commsbriiirussell/cybersecurity-skills | 413 | — | ~3.8k | Automated safety check: Pass | MIT | |
| Operationstravisjneuman/.claude | 100 | — | ~3.4k | Automated safety check: Pass | MIT | |
| Longbridge Earningshelsome/folio | 271 | 1 repos | ~2.5k | Automated safety check: Pass | None | |
| Financial Analyzinghuangjia2019/claude-code-engineering | 1.1k | — | ~474 | Automated safety check: Pass | None | |
| Earnings AnalysisWind-Alice/AliceMarket | 134 | 3 repos | ~2.2k | Automated safety check: Pass | None |
briiirussell/cybersecurity-skills
Translate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales.
travisjneuman/.claude
Operations excellence expertise for supply chain optimization, process improvement (Lean, Six Sigma), capacity planning, vendor management, quality assurance, and operational efficiency.
helsome/folio
Earnings analysis — pre- and post-earnings. An agent skill from helsome/folio.
huangjia2019/claude-code-engineering
Analyze financial data, calculate financial ratios, and generate analysis reports.
Wind-Alice/AliceMarket
Create professional equity research earnings update reports (8-12 pages, 3,000-5,000 words) analyzing quarterly results for companies already under coverage.
W-Y-P/Serenity-aleabitoreddit-skill
A skill your agent uses when analyzing stocks through @aleabitoreddit/Serenity-style supply-chain chokepoint thinking: AI/semi photonics, scarce physical bottlenecks, small-cap monopoly or duopoly…
haskaomni/serenity-skill
Use a Bayesian intrinsic-growth valuation model to evaluate whether a company's market value sufficiently, excessively, or insufficiently prices its real 3-5 year growth.
haskaomni/serenity-skill
Generate source-backed buy-side equity research memos from a ticker, starting with investment view, target-price scenarios, SEC and IR-backed financial statement analysis, industry chain…
haskaomni/serenity-skill
Score a stock's current valuation/trend health using the GF-DMA Health Index, combining fundamental growth speed, 20/50/100/200DMA trend speed, price-to-DMA divergence, ATR divergence, escape ratio…
haskaomni/serenity-skill
Classify a listed company and its core industry into Juglar fixed-asset investment cycle stages with probabilities, evidence, counter-evidence, migration signals, and investment implications.
haskaomni/serenity-skill
Evaluate a stock's valuation using TAM-Adj-PEG, adjusting traditional PEG by growth runway and quality.
Categories
Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation…. Serenity Alpha is an agent skill from haskaomni/serenity-skill. Translate market-moving news into investable alpha hypotheses by mapping observed demand changes to revenue lines, supply chains, small-cap financial elasticity, market misclassification, validation metrics, downside risks, and position-sizing conditions.
Serenity Alpha fits situations like: the user shares news; product launches; technology breakthroughs; procurement signals.
Run `npx skills add haskaomni/serenity-skill --skill serenity-alpha -a claude-code`. Or copy the skill folder (skills/serenity-alpha in haskaomni/serenity-skill) into .claude/skills/serenity-alpha in your project. Claude Code loads it when a task matches its description.
Run `npx skills add haskaomni/serenity-skill --skill serenity-alpha -a codex`. Or copy the skill folder (skills/serenity-alpha in haskaomni/serenity-skill) into .agents/skills/serenity-alpha in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add haskaomni/serenity-skill --skill serenity-alpha -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/serenity-alpha, .gemini/skills/serenity-alpha, .github/skills/serenity-alpha and .opencode/skills/serenity-alpha in your project.
Going by SKILL.md and its folder, Serenity Alpha needs the command-line tools its instructions call (pip and uv). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Serenity Alpha is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 231 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Serenity Alpha: Security Comms (briiirussell/cybersecurity-skills, 413 stars), Operations (travisjneuman/.claude, 100 stars), Longbridge Earnings (helsome/folio, 271 stars) and Financial Analyzing (huangjia2019/claude-code-engineering, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
haskaomni (a GitHub user) maintains it in haskaomni/serenity-skill, which has 633 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on July 15, 2026.
Source: haskaomni/serenity-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.