This skill should be used when the user asks to "analyze security alerts", "parse vulnerability scan report", "analyze vulnerability scan report", "verify CVE fix", "analyze WAF attack log"…

No licenceAuto-check: notesSecurity

Install Soe

skills CLI
$ npx skills add infometa/workbuddyskills --skill soe -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install infometa/workbuddyskills soe --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/infometa/workbuddyskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/experts/soe/skills/soe .claude/skills/soe && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
soe
GitHub stars
344
Token cost
~2.3k tokens
SKILL.md length
383 words
Files
7 (incl. references)
Skills in repo
212
Repo updated
First seen
Licence
None found

At a glance

This skill should be used when the user asks to "analyze security alerts", "parse vulnerability scan report", "analyze vulnerability scan report", "verify CVE fix", "analyze WAF attack log"…

  • Works in 3 steps: 意图识别 → 能力匹配 → 渐进式加载
  • Asks to analyze security alerts
  • SKILL.md covers 意图路由表, 路由决策流程, 联动编排规则(跨能力协同) and 执行原则, plus 2 more sections
  • Calls bash

What it does

Soe is an agent skill from infometa/workbuddyskills. This skill should be used when the user asks to "analyze security alerts", "parse vulnerability scan report", "analyze vulnerability scan report", "verify CVE fix", "analyze WAF attack log", "analyze CFW firewall log", "analyze cloud firewall alert", "investigate host intrusion", "analyze DDoS traffic", "check host asset", "troubleshoot application logs", "troubleshoot Tencent iOA", "iOA login or intranet access", "iOA policy delivery", or needs security operations analysis covering…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files.

It sits in Security, covering Vulnerability scanning, Security operations and Excel spreadsheets. It works with Wireshark and Microsoft Excel. The repository describes itself as: WorkBuddy skills / connectors / experts archive for offline study.

When your agent uses it

  • Asks to analyze security alerts
  • Parse vulnerability scan report
  • Analyze vulnerability scan report
  • Analyze WAF attack log

Example prompts

  • “analyze security alerts”
  • “parse vulnerability scan report”
  • “analyze vulnerability scan report”
  • “/soe”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. 意图识别
  2. 能力匹配
  3. 渐进式加载

What it can do on your machine

Read from SKILL.md and the folder at commit 75a5ad9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Soe loads about 2.3k tokens when it runs. Until then it costs about 166 tokens; SKILL.md has 383 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~166
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:46
    /scripts/linux/get_log_all_in_one.sh` | `sudo bash get_log_all_in_one.sh` | `log_<IP>_<主机名>_<用户>_<时间戳>.txt` |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 383 words (~2,254 tokens).

name
soe
version
1.0.0

Read the full SKILL.md on GitHub

Files

SKILL.md and 6 other files (references) in experts/soe/skills/soe of infometa/workbuddyskills.

  • SKILL.md
  • references/alert-analysis
  • references/asset-management
  • references/attack-analysis
  • references/general
  • references/intrusion-analysis
  • references/vulnerability-analysis

Open the folder on GitHubat commit 75a5ad9

Compare with similar skills

Soe next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Soe compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Soe this skillinfometa/workbuddyskills344—~2.3kAutomated safety check: NotesNone
Chaitin CLIchaitin/chaitin-cli114—~15kAutomated safety check: NotesGPL-3.0
Security Auditmarketcalls/openalgo2.8k—~1.9kAutomated safety check: PassAGPL-3.0
DefectDojo Vulnerability ManagementAgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassCustom licence
Building Vulnerability Scanning Workflowmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Performing Network Traffic Analysis With Zeekmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: NotesApache-2.0

Similar skills

  • Chaitin CLI

    chaitin/chaitin-cli

    A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

    114 GitHub stars~15k tokensUpdated 9 days ago
    SecurityAuto-check: notes
  • Security Audit

    marketcalls/openalgo

    Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.

    2.8k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check passed
  • DefectDojo Vulnerability Management

    AgentSecOps/SecOpsAgentKit

    Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

    220 GitHub stars~2.3k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Building Vulnerability Scanning Workflow

    mukul975/Anthropic-Cybersecurity-Skills

    Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure.

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Network Traffic Analysis With Zeek

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    562 GitHub stars~1.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from infometa/workbuddyskills

All 212 skills in this repo
  • Campus Event Playbook

    infometa/workbuddyskills

    This skill should be used when planning, coordinating, running, or reviewing student-led campus events, including club recruitment, freshman mixers, welcome activities, small talks, competitions…

    344 GitHub stars~861 tokensUpdated today
    Auto-check passed
  • Teachany

    infometa/workbuddyskills

    K-12 interactive courseware creation. An agent skill from infometa/workbuddyskills.

    344 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check: notes
  • Weight Management HTML

    infometa/workbuddyskills

    A skill your agent uses when the adult weight-management MCP needs to be installed/set up in WorkBuddy (connector) or its result must be rendered as a standalone Chinese HTML plan.

    344 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Agent Browser

    infometa/workbuddyskills

    A skill your agent uses when the user needs browser automation, including opening web pages, taking screenshots, extracting page content, clicking elements, filling forms, or testing web flows.

    344 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • AI Research Radar

    infometa/workbuddyskills

    定时任务:每日研究简报。漏掉重要论文和行业报告?每天帮你盯着,关键信息一条不漏 This skill should be used when the user asks about 定时任务:每日研究简报.

    344 GitHub stars~438 tokensUpdated today
    Auto-check passed
  • Check Deck

    infometa/workbuddyskills

    Investment banking presentation quality checker. An agent skill from infometa/workbuddyskills.

    344 GitHub stars~687 tokensUpdated today
    Auto-check passed

Categories

Questions about Soe

What does Soe do?

This skill should be used when the user asks to "analyze security alerts", "parse vulnerability scan report", "analyze vulnerability scan report", "verify CVE fix", "analyze WAF attack log"…. Soe is an agent skill from infometa/workbuddyskills.

When should I use Soe?

Soe fits situations like: asks to analyze security alerts; parse vulnerability scan report; analyze vulnerability scan report; analyze WAF attack log.

How do I install Soe in Claude Code?

Run `npx skills add infometa/workbuddyskills --skill soe -a claude-code`. Or copy the skill folder (experts/soe/skills/soe in infometa/workbuddyskills) into .claude/skills/soe in your project. Claude Code loads it when a task matches its description.

How do I install Soe in Codex?

Run `npx skills add infometa/workbuddyskills --skill soe -a codex`. Or copy the skill folder (experts/soe/skills/soe in infometa/workbuddyskills) into .agents/skills/soe in your project. Codex loads it when a task matches its description.

Can I use Soe in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add infometa/workbuddyskills --skill soe -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/soe, .gemini/skills/soe, .github/skills/soe and .opencode/skills/soe in your project.

What does Soe need to run?

Going by SKILL.md and its folder, Soe needs the command-line tools its instructions call (bash).

Does Soe access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Soe safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Soe use?

No licence was found for Soe or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Soe use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Soe?

Skills that share tags, products or a category with Soe: Chaitin CLI (chaitin/chaitin-cli, 114 stars), Security Audit (marketcalls/openalgo, 2.8k stars), DefectDojo Vulnerability Management (AgentSecOps/SecOpsAgentKit, 220 stars) and Building Vulnerability Scanning Workflow (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Soe?

infometa (a GitHub user) maintains it in infometa/workbuddyskills, which has 344 GitHub stars. The repository holds 212 skills in this directory. The repository was last updated on October 7, 2026.

Source: infometa/workbuddyskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.