Security Auditor
aiskillstore/marketplace
Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace find-cybersecurity-firm --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/mcp/servicegraph/skills/find-cybersecurity-firm .claude/skills/find-cybersecurity-firm && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "find-cybersecurity-firm" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/mcp/servicegraph/skills/find-cybersecurity-firm into .claude/skills/find-cybersecurity-firm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-cybersecurity-firm", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/mcp/servicegraph/skills/find-cybersecurity-firmType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace find-cybersecurity-firm --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/mcp/servicegraph/skills/find-cybersecurity-firm .agents/skills/find-cybersecurity-firm && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "find-cybersecurity-firm" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/mcp/servicegraph/skills/find-cybersecurity-firm into .agents/skills/find-cybersecurity-firm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-cybersecurity-firm", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace find-cybersecurity-firm --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/mcp/servicegraph/skills/find-cybersecurity-firm .cursor/skills/find-cybersecurity-firm && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "find-cybersecurity-firm" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/mcp/servicegraph/skills/find-cybersecurity-firm into .cursor/skills/find-cybersecurity-firm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-cybersecurity-firm", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path plugins/mcp/servicegraph/skills/find-cybersecurity-firm--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace find-cybersecurity-firm --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/mcp/servicegraph/skills/find-cybersecurity-firm .gemini/skills/find-cybersecurity-firm && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "find-cybersecurity-firm" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/mcp/servicegraph/skills/find-cybersecurity-firm into .gemini/skills/find-cybersecurity-firm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-cybersecurity-firm", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace find-cybersecurity-firmInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/mcp/servicegraph/skills/find-cybersecurity-firm .github/skills/find-cybersecurity-firm && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "find-cybersecurity-firm" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/mcp/servicegraph/skills/find-cybersecurity-firm into .github/skills/find-cybersecurity-firm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-cybersecurity-firm", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace find-cybersecurity-firm --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/mcp/servicegraph/skills/find-cybersecurity-firm .opencode/skills/find-cybersecurity-firm && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "find-cybersecurity-firm" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/plugins/mcp/servicegraph/skills/find-cybersecurity-firm into .opencode/skills/find-cybersecurity-firm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "find-cybersecurity-firm", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
find-cybersecurity-firmA skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…
Find Cybersecurity Firm is an agent skill from jeremylongshore/tons-of-skills-marketplace. Use whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed SOC, IAM, cloud security, and AppSec. Triggers on "find me a pen-testing firm for our SOC 2 audit", "shortlist three vCISO services for our healthcare-tech startup", "we need an incident response retainer", or "pull contact info for these 8 security firm domains", even when described indirectly (we got breached, prepare us for the…
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code
It sits in Security, covering SOC 2 and security compliance, Security review and Bug bounty. It works with Model Context Protocol. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(curl:*)mcp__servicegraph__list_fieldsmcp__servicegraph__list_field_valuesmcp__servicegraph__check_filtermcp__servicegraph__translate_intentmcp__servicegraph__search_datasetmcp__servicegraph__get_rowmcp__servicegraph__unlock_rowsmcp__servicegraph__get_credit_balanceFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.servicegraph.comcp.servicegraph.coAlso links to:
servicegraph.cogithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SERVICEGRAPH_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Find Cybersecurity Firm loads about 3.7k tokens when it runs. Until then it costs about 249 tokens; SKILL.md has 1,259 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ICEGRAPH_API_KEY` in the environment or `.env.local` for the RESTLLM context** — never read `.env*` into your context; dispatch via** through a shell wrapper that sources `.env.local`:( set -a; [ -f .env.local ] && . ./.env.local; set +a;and add `SERVICEGRAPH_API_KEY=vk_…` to `.env.local` hereAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,259 words, ~3,651 tokens.
.claude/skills/find-cybersecurity-firm/SKILL.md (or your agent's skills folder).Drive the ServiceGraph API (https://api.servicegraph.co) to find,
shortlist, and enrich US cybersecurity firms via the pro_services
dataset.
Always pin service_provided:cybersecurity — that's the only
relevant structured tag in the live catalog. Older docs and the
catalog source mention sub-tags like pen-testing and
security-audit, but in the current release none of those exist as
separate tags — cybersecurity is the broad catch-all and every
sub-type (pen-testing, red-team, vCISO, SOC 2 readiness, IR retainer,
IAM, cloud security, AppSec) is a keyword substring search on firm
text. Confirm via /v1/datasets/pro_services/fields?include_values=1
once per session.
The industry tag also drifts between releases — newer catalogs may
use industry:cybersecurity, older ones used industry:security.
Confirm the value via /fields and pin both industry and
service_provided:cybersecurity for safety.
Any HTTP client works (curl, fetch, requests). Examples below use curl.
https://mcp.servicegraph.co) loaded in
your harness — this plugin's .mcp.json wires it up; OAuth 2.1 + PKCE
keeps credentials in the harness sandbox — orvk_…, minted at
https://servicegraph.co/profile/api-keys) available as
SERVICEGRAPH_API_KEY in the environment or .env.local for the REST
path (setup steps under Auth below).curl.The loop is free-first: discovery, validation, search, and brief reads cost nothing; only unlock after the user confirms the spend.
GET /v1/datasets/pro_services/fields?include_values=1 — confirm the
fields and values you plan to filter on exist.GET /v1/datasets/pro_services/check — or draft it from plain English via
POST /v1/datasets/pro_services/translate-intent.GET /v1/datasets/pro_services/search — present the free brief cards and
let the user pick.POST /v1/datasets/pro_services/unlocks with the chosen apexes; report the
revealed detail.GET /v1/me/credits to report the remaining balance when asked.If your harness has the ServiceGraph MCP server loaded (tools
containing servicegraph), prefer those — OAuth 2.1 + PKCE keeps the
token in the harness sandbox. Otherwise use the REST flow below.
pro_services)Every endpoint requires the bearer (Authorization: Bearer vk_…).
No anonymous tier.
| Endpoint | Cost | Use it for |
|---|---|---|
GET /v1/datasets/pro_services/fields[?include_values=1] | free | Confirm industry value name and cybersecurity is in service_provided. |
GET /v1/datasets/pro_services/check?filter=… | free | Validate filter. |
POST /v1/datasets/pro_services/translate-intent | free | {intent} → DSL filter + sanity count. |
GET /v1/datasets/pro_services/search?filter=…&limit= | free | Brief firm cards + per-row unlock hint + total. |
GET /v1/datasets/pro_services/:apex | free | One row brief; detail only if unlocked. |
POST /v1/datasets/pro_services/unlocks | 10 credits / firm | {apexes:[...]} ≤100; atomic; 30-day TTL on detail. |
GET /v1/me/credits | free | Balance. |
Cost model. Discovery / validation / search / brief reads are
free. Detail (url, phone, email, social, address, full platforms
map) costs 10 credits per firm and lasts 30 days.
vk_* API keys minted in the dashboard. Keep the token out of the
LLM context — never read .env* into your context; dispatch via
shell.
Try the call first through a shell wrapper that sources .env.local:
( set -a; [ -f .env.local ] && . ./.env.local; set +a;
curl -sS -H "Authorization: Bearer $SERVICEGRAPH_API_KEY" \
'https://api.servicegraph.co/v1/datasets/pro_services/fields' )On 401 prompt the user:
"Open https://servicegraph.co/profile/api-keys, create a key, and add
SERVICEGRAPH_API_KEY=vk_…to.env.localhere (or export it). Tell me when done. Please don't paste the key into chat."
Retry after the user signals ready.
GitHub-search-style.
filter := orExpr
orExpr := andExpr ("OR" andExpr)*
andExpr := notExpr (("AND")? notExpr)* # whitespace = implicit AND
notExpr := ("NOT" | "-") notExpr | atom
atom := "(" filter ")" | predicate
predicate:= IDENT op valueOrList | bareword
op := ":" | "=" | ">=" | "<=" | ">" | "<"
valueOrList := value ("," value)*
value := IDENT | NUMBER | tagAtEvidence
tagAtEvidence := IDENT "@" ("low"|"medium"|"high")
bareword := IDENT | NUMBER # → keyword:<bareword>Four rules that bite: AND binds tighter than OR (use parens);
comma list = OR within one predicate; negation is -x or NOT x;
bareword = keyword search (quote multi-word phrases).
Cybersecurity examples (validate yours with /check; replace
cybersecurity with whatever /fields returns as the industry value):
industry:cybersecurity service_provided:cybersecurity
service_provided:cybersecurity pen-testing
service_provided:cybersecurity "security audit" "soc 2"
service_provided:cybersecurity vciso
service_provided:cybersecurity "incident response" retainer
service_provided:cybersecurity cloud aws
service_provided:cybersecurity "application security" sast
service_provided:cybersecurity rating>=4 has:clutch
service_provided:cybersecurity hipaaThe live catalog has no separate pen-testing / security-audit /
appsec tags — pin service_provided:cybersecurity and treat all
sub-types as keywords.
Sub-type → keyword mapping (all sub-types are keyword-only):
| User asks for | Use |
|---|---|
| Pen test / red team | pen-testing, "red team" |
| Security audit / assessment | audit, assessment |
| vCISO / fractional CISO | vciso, "fractional ciso" |
| SOC 2 readiness | "soc 2", readiness |
| Incident response / forensics | "incident response", forensics, "ir retainer" |
| Cloud security | "cloud security", aws, gcp, azure |
| Identity / IAM | iam, identity |
| Application security / SAST/DAST | "application security", appsec, sast, dast |
| Compliance frameworks | pci, hipaa, "iso 27001", nist |
apexFirms are identified by their apex domain (mandiant.com, not
www.mandiant.com/about).
All responses are JSON.
apex, name, location, and
rating signals — plus a per-row unlock hint and the match total. Briefs
never include url, phone_primary, email_primary, legal_name,
address_full, or the full platforms map.POST …/unlocks) returns each unlocked firm's detail block —
contact fields, address, socials, the platforms map — plus per-item
billing; detail stays readable for 30 days.{"error": {"code": "…", "message": "…"}} — see Errors below.User: "Pen-testing firm for our SOC 2 audit."
GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+pen-testing+"soc 2"&limit=10
# Present, get pick of 3. "Unlocking 3 = 30 credits, 30-day TTL."
POST /v1/datasets/pro_services/unlocks
{ "apexes": ["firm-a.com", "firm-b.com", "firm-c.com"] }GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+vciso+(healthcare OR hipaa)&limit=10User: "Incident response retainer in case we get breached."
GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+"incident response"+retainer&limit=10If thin, drop retainer — most IR firms offer retainer engagements as standard.
GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+cloud+aws+hipaa&limit=10User: "We got hit with ransomware last week — we need help fast."
That's emergency IR:
GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+"incident response"+ransomware&limit=10Skip validation; present briefs immediately given urgency.
GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+"application security"+(sast OR "code review")&limit=10GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+"soc 2"+(readiness OR preparation)&limit=10User pastes 8–20 cybersecurity firm domains:
GET /v1/datasets/pro_services/:apex per domain — free brief
(404 = not in catalog, no charge).POST /unlocks = 10×N credits,
atomic, detail returned.pen-testing / vciso / appsec keywords leak into IT-services rows that mention security./fields — older catalogs used industry:security, newer ones may use industry:cybersecurity. Don't hardcode."incident response" → one phrase).apex, name, location, ratings. They DON'T include url, phone_primary, email_primary, legal_name, address_full, full platforms — those require an unlock.not_found / not_in_dataset 404 = not in pro_services. Skip; not charged.was_cached:true).JSON envelope: {"error": {"code": "...", "message": "..."}}.
| Status | Code | What to do |
|---|---|---|
| 400 | filter_parse_error | position included; fix and re-validate with /check. |
| 400 | kind_in_filter | Strip any kind: from filter — URL is authoritative. |
| 400 | field_not_in_dataset | Drop the disallowed field. |
| 400 | invalid_apex | Re-normalize. |
| 401 | unauthorized / invalid_audience | Re-prompt for fresh vk_…. |
| 402 | insufficient_credits | needed and balance in payload; nothing charged. |
| 404 | not_found / not_in_dataset | Skip; not charged. |
| 429 | rate_limited | Honor Retry-After. |
User: "Three pen-testing firms for our SOC 2 audit, 4-star ratings, ideally with HIPAA experience for a healthcare-tech context."
GET /v1/datasets/pro_services/fields?include_values=1
GET /v1/datasets/pro_services/check?filter=service_provided:cybersecurity+pen-testing+"soc 2"+hipaa+rating>=4
GET /v1/datasets/pro_services/search?filter=...&limit=10
# Present briefs. "Unlocking 3 = 30 credits, 30-day TTL."
POST /v1/datasets/pro_services/unlocks
{ "apexes": ["firm-a.com", "firm-b.com", "firm-c.com"] }
GET /v1/me/creditsservicegraph (this plugin) — the dataset-agnostic entry point
when the user names ServiceGraph explicitly.© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/mcp/servicegraph/skills/find-cybersecurity-firm of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Find Cybersecurity Firm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Find Cybersecurity Firm this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~3.7k | Automated safety check: Notes | MIT | |
| Security Auditoraiskillstore/marketplace | 433 | 6 repos | ~2.6k | Automated safety check: Pass | None | |
| Securitytravisjneuman/.claude | 100 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 190 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Slowmist Agent Securityslowmist/slowmist-agent-security | 508 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Security Vuln Remediationstacklok/toolhive-studio | 171 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 |
aiskillstore/marketplace
Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
travisjneuman/.claude
Information security expertise for cybersecurity frameworks (NIST, ISO 27001), security architecture, incident response, vulnerability management, identity management, and cloud security.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
slowmist/slowmist-agent-security
Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.
stacklok/toolhive-studio
Remediate security vulnerabilities found by Grype or pnpm audit.
Jeffallan/claude-skills
Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Works with
Categories
A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…. Find Cybersecurity Firm is an agent skill from jeremylongshore/tons-of-skills-marketplace. Use whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed SOC, IAM, cloud security, and AppSec.
Find Cybersecurity Firm fits situations like: the user wants to find; enrich US cybersecurity firms — pen-testing/red team; security audits; SOC 2 readiness.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a claude-code`. Or copy the skill folder (plugins/mcp/servicegraph/skills/find-cybersecurity-firm in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/find-cybersecurity-firm in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a codex`. Or copy the skill folder (plugins/mcp/servicegraph/skills/find-cybersecurity-firm in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/find-cybersecurity-firm in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/find-cybersecurity-firm, .gemini/skills/find-cybersecurity-firm, .github/skills/find-cybersecurity-firm and .opencode/skills/find-cybersecurity-firm in your project.
Going by SKILL.md and its folder, Find Cybersecurity Firm needs the command-line tools its instructions call (curl) and credentials named SERVICEGRAPH_API_KEY. Our summary lists: A credential in SERVICEGRAPH_API_KEY. Its frontmatter pre-approves these tools: Bash(curl:*), mcp__servicegraph__list_fields, mcp__servicegraph__list_field_values, mcp__servicegraph__check_filter, mcp__servicegraph__translate_intent, mcp__servicegraph__search_dataset, mcp__servicegraph__get_row, mcp__servicegraph__unlock_rows, mcp__servicegraph__get_credit_balance. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 4 domains. In commands or code: api.servicegraph.co and mcp.servicegraph.co; the agent is likely to contact these when it follows the instructions. As links in the text: servicegraph.co and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Find Cybersecurity Firm is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Find Cybersecurity Firm: Security Auditor (aiskillstore/marketplace, 433 stars), Security (travisjneuman/.claude, 100 stars), Forensify (alexgreensh/repo-forensics, 190 stars) and Slowmist Agent Security (slowmist/slowmist-agent-security, 508 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.