Agent skill

Ransomware Analysis

by infometa in infometa/workbuddyskills

勒索病毒分析 Skill - 基于勒索信、文件扩展名、系统行为特征识别勒索家族、分析入侵路径、评估数据恢复可能性. An agent skill from infometa/workbuddyskills.

No licenceAuto-check passed

Install Ransomware Analysis

skills CLI
$ npx skills add infometa/workbuddyskills --skill ransomware-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install infometa/workbuddyskills ransomware-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/infometa/workbuddyskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/experts/soe/skills/soe/references/attack-analysis/ransomware-analysis .claude/skills/ransomware-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ransomware-analysis
GitHub stars
346
Token cost
~1.3k tokens
SKILL.md length
239 words
Files
11 (incl. scripts, references, assets)
Skills in repo
218
Repo updated
First seen
Licence
None found

At a glance

勒索病毒分析 Skill - 基于勒索信、文件扩展名、系统行为特征识别勒索家族、分析入侵路径、评估数据恢复可能性. An agent skill from infometa/workbuddyskills.

  • Works in 5 steps: 扩展名匹配(10 家族 YAML):加密文件后缀 → 家族 → high… → 扩展名回退匹配(mthcht 700+):10… → 勒索信文件名匹配:勒索信文件名 → 家族 → …
  • SKILL.md covers 角色定位, 能力范围, 工作流程 and 在线情报查询(零 Key), plus 3 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Ransomware Analysis is an agent skill from infometa/workbuddyskills. 勒索病毒分析 Skill - 基于勒索信、文件扩展名、系统行为特征识别勒索家族、分析入侵路径、评估数据恢复可能性

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including scripts, reference files and assets (for example `assets/decryptors.yaml`, `assets/intrusion_vectors.yaml` and `assets/ransomware_families.yaml`).

The repository describes itself as: WorkBuddy skills / connectors / experts archive for offline study.

Example prompts

  • “/ransomware-analysis”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 扩展名匹配(10 家族 YAML):加密文件后缀 → 家族 → high confidence
  2. 扩展名回退匹配(mthcht 700+):10 家族未命中时先联网获取,失败回退到 assets/cache/ransomware_extensions.yaml;均不可用则不命中 → medium confidence(仅扩展名单维度)
  3. 勒索信文件名匹配:勒索信文件名 → 家族
  4. 关键词匹配:勒索信文本关键词 → 家族
  5. IOC 匹配:提取的 BTC/Tor/邮箱等 → 家族

What it can do on your machine

Read from SKILL.md and the folder at commit 692b3eb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ransomware Analysis loads about 1.3k tokens when it runs, and up to ~2.8k if it reads all its reference files. Until then it costs about 19 tokens; SKILL.md has 239 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 239 words (~1,274 tokens).

name
ransomware-analysis
version
0.1.1
triggers
勒索病毒, 勒索信, 勒索软件, ransomware, 勒索家族识别, 文件被加密, ransom note, 勒索应急响应, 解密工具

Read the full SKILL.md on GitHub

Files

SKILL.md and 10 other files (scripts, references, assets) in experts/soe/skills/soe/references/attack-analysis/ransomware-analysis of infometa/workbuddyskills.

  • SKILL.md
  • assets/cache/.gitignore
  • assets/decryptors.yaml
  • assets/intrusion_vectors.yaml
  • assets/ransomware_families.yaml
  • assets/report_template.md
  • references/family_profiles.md
  • scripts/__init__.py
  • scripts/ioc_extractor.py
  • scripts/online_query.py
  • scripts/ransomware_analyzer.py

Open the folder on GitHubat commit 692b3eb

Compare with similar skills

Ransomware Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ransomware Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ransomware Analysis this skillinfometa/workbuddyskills346—~1.3kAutomated safety check: PassNone
Investigating Ransomware Attack Artifactsmukul975/Anthropic-Cybersecurity-Skills34k—~4.1kAutomated safety check: NotesApache-2.0
Deploying Ransomware Canary Filesmukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.0
Performing Ransomware Responsemukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Recovering From Ransomware Attackmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Testing Ransomware Recovery Proceduresmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Investigating Ransomware Attack Artifacts

    mukul975/Anthropic-Cybersecurity-Skills

    Forensically preserve memory and disk, collect ransom notes and encrypted file samples, and identify the ransomware variant using tools such as ID Ransomware, Volatility, and Chainsaw/Hayabusa to…

    34k GitHub stars~4.1k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Deploying Ransomware Canary Files

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys and monitors ransomware canary files using Python's watchdog library, placing decoy files mimicking high-value targets (financial records, credentials, database exports) where ransomware…

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Performing Ransomware Response

    mukul975/Anthropic-Cybersecurity-Skills

    Executes a structured ransomware incident response from detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening, covering ransom negotiation…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Recovering From Ransomware Attack

    mukul975/Anthropic-Cybersecurity-Skills

    Executes structured ransomware incident recovery following NIST/CISA frameworks: environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized restoration from…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Testing Ransomware Recovery Procedures

    mukul975/Anthropic-Cybersecurity-Skills

    Tests and validates ransomware recovery procedures - backup restore operations (e.g.

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Honeypot For Ransomware Detection

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys canary files, honeypot shares, and decoy systems to detect ransomware activity at the earliest possible stage.

    34k GitHub stars~3.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from infometa/workbuddyskills

All 218 skills in this repo
  • Campus Event Playbook

    infometa/workbuddyskills

    This skill should be used when planning, coordinating, running, or reviewing student-led campus events, including club recruitment, freshman mixers, welcome activities, small talks, competitions…

    346 GitHub stars~861 tokensUpdated today
    Auto-check passed
  • Teachany

    infometa/workbuddyskills

    K-12 interactive courseware creation. An agent skill from infometa/workbuddyskills.

    346 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check: notes
  • Weight Management HTML

    infometa/workbuddyskills

    A skill your agent uses when the adult weight-management MCP needs to be installed/set up in WorkBuddy (connector) or its result must be rendered as a standalone Chinese HTML plan.

    346 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Agent Browser

    infometa/workbuddyskills

    A skill your agent uses when the user needs browser automation, including opening web pages, taking screenshots, extracting page content, clicking elements, filling forms, or testing web flows.

    346 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • AI Research Radar

    infometa/workbuddyskills

    定时任务:每日研究简报。漏掉重要论文和行业报告?每天帮你盯着,关键信息一条不漏 This skill should be used when the user asks about 定时任务:每日研究简报.

    346 GitHub stars~438 tokensUpdated today
    Auto-check passed
  • Check Deck

    infometa/workbuddyskills

    Investment banking presentation quality checker. An agent skill from infometa/workbuddyskills.

    346 GitHub stars~687 tokensUpdated today
    Auto-check passed

Questions about Ransomware Analysis

What does Ransomware Analysis do?

勒索病毒分析 Skill - 基于勒索信、文件扩展名、系统行为特征识别勒索家族、分析入侵路径、评估数据恢复可能性. An agent skill from infometa/workbuddyskills. Ransomware Analysis is an agent skill from infometa/workbuddyskills.

How do I install Ransomware Analysis in Claude Code?

Run `npx skills add infometa/workbuddyskills --skill ransomware-analysis -a claude-code`. Or copy the skill folder (experts/soe/skills/soe/references/attack-analysis/ransomware-analysis in infometa/workbuddyskills) into .claude/skills/ransomware-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Ransomware Analysis in Codex?

Run `npx skills add infometa/workbuddyskills --skill ransomware-analysis -a codex`. Or copy the skill folder (experts/soe/skills/soe/references/attack-analysis/ransomware-analysis in infometa/workbuddyskills) into .agents/skills/ransomware-analysis in your project. Codex loads it when a task matches its description.

Can I use Ransomware Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add infometa/workbuddyskills --skill ransomware-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ransomware-analysis, .gemini/skills/ransomware-analysis, .github/skills/ransomware-analysis and .opencode/skills/ransomware-analysis in your project.

What does Ransomware Analysis need to run?

Going by SKILL.md and its folder, Ransomware Analysis needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Ransomware Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ransomware Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Ransomware Analysis use?

No licence was found for Ransomware Analysis or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Ransomware Analysis use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Ransomware Analysis?

Skills that share tags, products or a category with Ransomware Analysis: Investigating Ransomware Attack Artifacts (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Deploying Ransomware Canary Files (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Ransomware Response (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Recovering From Ransomware Attack (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ransomware Analysis?

infometa (a GitHub user) maintains it in infometa/workbuddyskills, which has 346 GitHub stars. The repository holds 218 skills in this directory. The repository was last updated on October 8, 2026.

Source: infometa/workbuddyskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.