Detecting Insider Threat Behaviors
mukul975/Anthropic-Cybersecurity-Skills
Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.
This skill should be used when the user asks about "insider buying", "Form 4", "insider selling before the readout", "10b5-1", "management conviction", or wants an insider-transaction overlay on a…
$ npx skills add hh-health-AI/healthcare-equity --skill insider-catalyst-patterns -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hh-health-AI/healthcare-equity insider-catalyst-patterns --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hh-health-AI/healthcare-equity.git skills-src && mkdir -p .claude/skills && cp -r skills-src/modules/sec-forensics/skills/insider-catalyst-patterns .claude/skills/insider-catalyst-patterns && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "insider-catalyst-patterns" agent skill from https://github.com/hh-health-AI/healthcare-equity/tree/main/modules/sec-forensics/skills/insider-catalyst-patterns into .claude/skills/insider-catalyst-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insider-catalyst-patterns", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hh-health-AI/healthcare-equity/tree/main/modules/sec-forensics/skills/insider-catalyst-patternsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hh-health-AI/healthcare-equity --skill insider-catalyst-patterns -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hh-health-AI/healthcare-equity insider-catalyst-patterns --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hh-health-AI/healthcare-equity.git skills-src && mkdir -p .agents/skills && cp -r skills-src/modules/sec-forensics/skills/insider-catalyst-patterns .agents/skills/insider-catalyst-patterns && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "insider-catalyst-patterns" agent skill from https://github.com/hh-health-AI/healthcare-equity/tree/main/modules/sec-forensics/skills/insider-catalyst-patterns into .agents/skills/insider-catalyst-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insider-catalyst-patterns", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hh-health-AI/healthcare-equity --skill insider-catalyst-patterns -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hh-health-AI/healthcare-equity insider-catalyst-patterns --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hh-health-AI/healthcare-equity.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/modules/sec-forensics/skills/insider-catalyst-patterns .cursor/skills/insider-catalyst-patterns && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "insider-catalyst-patterns" agent skill from https://github.com/hh-health-AI/healthcare-equity/tree/main/modules/sec-forensics/skills/insider-catalyst-patterns into .cursor/skills/insider-catalyst-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insider-catalyst-patterns", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hh-health-AI/healthcare-equity.git --path modules/sec-forensics/skills/insider-catalyst-patterns--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hh-health-AI/healthcare-equity --skill insider-catalyst-patterns -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hh-health-AI/healthcare-equity insider-catalyst-patterns --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hh-health-AI/healthcare-equity.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/modules/sec-forensics/skills/insider-catalyst-patterns .gemini/skills/insider-catalyst-patterns && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "insider-catalyst-patterns" agent skill from https://github.com/hh-health-AI/healthcare-equity/tree/main/modules/sec-forensics/skills/insider-catalyst-patterns into .gemini/skills/insider-catalyst-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insider-catalyst-patterns", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hh-health-AI/healthcare-equity insider-catalyst-patternsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hh-health-AI/healthcare-equity --skill insider-catalyst-patterns -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hh-health-AI/healthcare-equity.git skills-src && mkdir -p .github/skills && cp -r skills-src/modules/sec-forensics/skills/insider-catalyst-patterns .github/skills/insider-catalyst-patterns && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "insider-catalyst-patterns" agent skill from https://github.com/hh-health-AI/healthcare-equity/tree/main/modules/sec-forensics/skills/insider-catalyst-patterns into .github/skills/insider-catalyst-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insider-catalyst-patterns", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hh-health-AI/healthcare-equity --skill insider-catalyst-patterns -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hh-health-AI/healthcare-equity insider-catalyst-patterns --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hh-health-AI/healthcare-equity.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/modules/sec-forensics/skills/insider-catalyst-patterns .opencode/skills/insider-catalyst-patterns && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "insider-catalyst-patterns" agent skill from https://github.com/hh-health-AI/healthcare-equity/tree/main/modules/sec-forensics/skills/insider-catalyst-patterns into .opencode/skills/insider-catalyst-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insider-catalyst-patterns", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
insider-catalyst-patternsThis skill should be used when the user asks about "insider buying", "Form 4", "insider selling before the readout", "10b5-1", "management conviction", or wants an insider-transaction overlay on a…
Insider Catalyst Patterns is an agent skill from hh-health-AI/healthcare-equity. This skill should be used when the user asks about "insider buying", "Form 4", "insider selling before the readout", "10b5-1", "management conviction", or wants an insider-transaction overlay on a name approaching a clinical or regulatory catalyst.
Its SKILL.md is about 630 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Synthesis engine for buy-side healthcare equity research. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6c7bda8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Insider Catalyst Patterns loads about 626 tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 316 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hh-health-AI/healthcare-equity at commit 6c7bda8, republished under its MIT licence (© hh-health-AI). 316 words, ~626 tokens.
.claude/skills/insider-catalyst-patterns/SKILL.md (or your agent's skills folder).Overlay Form 4 activity on a known catalyst calendar and extract the small amount of genuine signal from a very noisy series.
scripts/form4_clusters.py --cik ...).The academic evidence on insider purchases is real but modest, and it is strongest for routine operating businesses over long horizons — not for binary biotech events. Treat this skill as a tie-breaker on position size within an existing thesis. It is not a thesis generator, and a brief from this skill should never be the primary evidence for a position.
Insider activity does not license an inference about non-public trial data. Say this explicitly in every brief from this skill.
Contract: ../../references/evidence-brief.md.
© hh-health-AI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in modules/sec-forensics/skills/insider-catalyst-patterns of hh-health-AI/healthcare-equity.
Open the folder on GitHubat commit 6c7bda8
Insider Catalyst Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Insider Catalyst Patterns this skillhh-health-AI/healthcare-equity | 101 | — | ~626 | Automated safety check: Pass | MIT | |
| Detecting Insider Threat Behaviorsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~897 | Automated safety check: Pass | Apache-2.0 | |
| Performing Insider Threat Investigationmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Investigating Insider Threat Indicatorsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Detecting Insider Threat With Uebamukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~738 | Automated safety check: Pass | Apache-2.0 | |
| Detecting Insider Data Exfiltration Via Dlpmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~623 | Automated safety check: Pass | Apache-2.0 |
mukul975/Anthropic-Cybersecurity-Skills
Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.
mukul975/Anthropic-Cybersecurity-Skills
Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies, combining…
mukul975/Anthropic-Cybersecurity-Skills
Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR…
mukul975/Anthropic-Cybersecurity-Skills
Implement User and Entity Behavior Analytics (UEBA) using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and alert on insider threat…
mukul975/Anthropic-Cybersecurity-Skills
Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs.
ccplugins/awesome-claude-code-plugins
Scan SEC Form 4 insider trades and 13F ownership moves for a ticker or a watchlist using the AlphaAI MCP.
hh-health-AI/healthcare-equity
This skill should be used when the user says "prep the AdCom for [asset]", "what will the advisory committee vote", "analyze the approved label", "label delta vs expectations", or within 48 hours of…
hh-health-AI/healthcare-equity
A skill your agent uses to audit whether medical or scientific claims are supported by their citations, verify references, assess AI-generated biomedical text or identify overstatement in a press…
hh-health-AI/healthcare-equity
A skill your agent uses when checking whether a medical or scientific claim is supported by its cited paper, verifying references, auditing an AI-generated biomedical answer or examining…
hh-health-AI/healthcare-equity
This skill should be used when the user asks about "biosimilar erosion", "Purple Book", "biologic exclusivity", "interchangeability", "how fast will [biologic] erode", "erosion curve", or needs the…
hh-health-AI/healthcare-equity
A skill your agent uses for a defined biotech trial watchlist, registry-version comparisons, catalyst calendars or changed enrollment, status and completion estimates.
hh-health-AI/healthcare-equity
A skill your agent uses to monitor a defined biotech trial watchlist, compare registry versions, build a catalyst calendar or explain changed enrollment, status or completion estimates.
This skill should be used when the user asks about "insider buying", "Form 4", "insider selling before the readout", "10b5-1", "management conviction", or wants an insider-transaction overlay on a…. Insider Catalyst Patterns is an agent skill from hh-health-AI/healthcare-equity. This skill should be used when the user asks about "insider buying", "Form 4", "insider selling before the readout", "10b5-1", "management conviction", or wants an insider-transaction overlay on a name approaching a clinical or regulatory catalyst.
Insider Catalyst Patterns fits situations like: asks about insider buying; insider selling before the readout; management conviction; wants an insider-transaction overlay on a name approaching a clinical.
Run `npx skills add hh-health-AI/healthcare-equity --skill insider-catalyst-patterns -a claude-code`. Or copy the skill folder (modules/sec-forensics/skills/insider-catalyst-patterns in hh-health-AI/healthcare-equity) into .claude/skills/insider-catalyst-patterns in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hh-health-AI/healthcare-equity --skill insider-catalyst-patterns -a codex`. Or copy the skill folder (modules/sec-forensics/skills/insider-catalyst-patterns in hh-health-AI/healthcare-equity) into .agents/skills/insider-catalyst-patterns in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hh-health-AI/healthcare-equity --skill insider-catalyst-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/insider-catalyst-patterns, .gemini/skills/insider-catalyst-patterns, .github/skills/insider-catalyst-patterns and .opencode/skills/insider-catalyst-patterns in your project.
SKILL.md names no scripts, command-line tools or credentials: Insider Catalyst Patterns is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Insider Catalyst Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 626 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Insider Catalyst Patterns: Detecting Insider Threat Behaviors (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Insider Threat Investigation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Investigating Insider Threat Indicators (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting Insider Threat With Ueba (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hh-health-AI (a GitHub user) maintains it in hh-health-AI/healthcare-equity, which has 101 GitHub stars. The repository holds 72 skills in this directory. The repository was last updated on October 8, 2026.
Source: hh-health-AI/healthcare-equity on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.