Agent skill

Find Cybersecurity Firm

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…

MITAuto-check: notesSecurity

Install Find Cybersecurity Firm

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace find-cybersecurity-firm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/mcp/servicegraph/skills/find-cybersecurity-firm .claude/skills/find-cybersecurity-firm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
find-cybersecurity-firm
GitHub stars
2.8k
Token cost
~3.7k tokens
SKILL.md length
1,259 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…

  • Works in 7 steps: Pick the call path — the ServiceGraph… → GET… → Build the filter (Filter DSL below) and… → …
  • The user wants to find
  • SKILL.md covers Overview, When NOT to use this skill, Prerequisites and Instructions, plus 6 more sections
  • Calls curl; reaches api.servicegraph.co and mcp.servicegraph.co; needs SERVICEGRAPH_API_KEY

What it does

Find Cybersecurity Firm is an agent skill from jeremylongshore/tons-of-skills-marketplace. Use whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed SOC, IAM, cloud security, and AppSec. Triggers on "find me a pen-testing firm for our SOC 2 audit", "shortlist three vCISO services for our healthcare-tech startup", "we need an incident response retainer", or "pull contact info for these 8 security firm domains", even when described indirectly (we got breached, prepare us for the…

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code

It sits in Security, covering SOC 2 and security compliance, Security review and Bug bounty. It works with Model Context Protocol. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • The user wants to find
  • Enrich US cybersecurity firms — pen-testing/red team
  • Security audits
  • SOC 2 readiness

Example prompts

  • “find me a pen-testing firm for our SOC 2 audit”
  • “shortlist three vCISO services for our healthcare-tech startup”
  • “we need an incident response retainer”
  • “/find-cybersecurity-firm”

Requirements

  • A credential in SERVICEGRAPH_API_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Bash(curl:*), mcp__servicegraph__list_fields, mcp__servicegraph__list_field_values, mcp__servicegraph__check_filter, mcp__servicegraph__translate_intent, mcp__servicegraph__search_dataset, mcp__servicegraph__get_row, mcp__servicegraph__unlock_rows, mcp__servicegraph__get_credit_balance

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Pick the call path — the ServiceGraph MCP tools if loaded, otherwise the
  2. GET /v1/datasets/pro_services/fields?include_values=1 — confirm the
  3. Build the filter (Filter DSL below) and validate it with
  4. GET /v1/datasets/pro_services/search — present the free brief cards and
  5. Quote the unlock cost (10 credits per row, 30-day TTL) and get an explicit
  6. POST /v1/datasets/pro_services/unlocks with the chosen apexes; report the
  7. GET /v1/me/credits to report the remaining balance when asked.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(curl:*)
    • mcp__servicegraph__list_fields
    • mcp__servicegraph__list_field_values
    • mcp__servicegraph__check_filter
    • mcp__servicegraph__translate_intent
    • mcp__servicegraph__search_dataset
    • mcp__servicegraph__get_row
    • mcp__servicegraph__unlock_rows
    • mcp__servicegraph__get_credit_balance

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.servicegraph.co
    • mcp.servicegraph.co

    Also links to:

    • servicegraph.co
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SERVICEGRAPH_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Find Cybersecurity Firm loads about 3.7k tokens when it runs. Until then it costs about 249 tokens; SKILL.md has 1,259 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~249
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:67
    ICEGRAPH_API_KEY` in the environment or `.env.local` for the REST
  • NoteMentions a .env fileSKILL.md:119
    LLM context** — never read `.env*` into your context; dispatch via
  • NoteMentions a .env fileSKILL.md:122
    ** through a shell wrapper that sources `.env.local`:
  • NoteMentions a .env fileSKILL.md:125
    ( set -a; [ -f .env.local ] && . ./.env.local; set +a;
  • NoteMentions a .env fileSKILL.md:133
    and add `SERVICEGRAPH_API_KEY=vk_…` to `.env.local` here

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,259 words, ~3,651 tokens.

Download SKILL.mdSave it as .claude/skills/find-cybersecurity-firm/SKILL.md (or your agent's skills folder).
name
find-cybersecurity-firm
description
Use whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed SOC, IAM, cloud security, and AppSec. Triggers on "find me a pen-testing firm for our SOC 2 audit", "shortlist three vCISO services for our healthcare-tech startup", "we need an incident response retainer", or "pull contact info for these 8 security firm domains", even when described indirectly (we got breached, prepare us for the compliance audit, get us SOC 2 ready). Drives the ServiceGraph API (api.servicegraph.co) — a 100k+ US firm catalog filterable by industry, services, location, size, ratings. Skip in-house security hires, "how do I patch CVE-X" or "configure firewall Y" DIY questions, security-product reviews (CrowdStrike vs SentinelOne, etc.), generic security knowledge questions, consumer/personal security advice, non-US firms, individual freelancers and bug-bounty hunters.
allowed-tools
Bash(curl:*), mcp__servicegraph__list_fields, mcp__servicegraph__list_field_values, mcp__servicegraph__check_filter, mcp__servicegraph__translate_intent, mcp__servicegraph__search_dataset, mcp__servicegraph__get_row, mcp__servicegraph__unlock_rows, mcp__servicegraph__get_credit_balance
compatibility
Designed for Claude Code
version
0.3.0
author
Artur Briugeman <artur@nostr.band>
license
MIT
tags
cybersecurity, service-providers, lead-generation, b2b, servicegraph
metadata.api_base
https://api.servicegraph.co
metadata.dataset_id
pro_services
metadata.service
cybersecurity

find-cybersecurity-firm

Overview

Drive the ServiceGraph API (https://api.servicegraph.co) to find, shortlist, and enrich US cybersecurity firms via the pro_services dataset.

Always pin service_provided:cybersecurity — that's the only relevant structured tag in the live catalog. Older docs and the catalog source mention sub-tags like pen-testing and security-audit, but in the current release none of those exist as separate tags — cybersecurity is the broad catch-all and every sub-type (pen-testing, red-team, vCISO, SOC 2 readiness, IR retainer, IAM, cloud security, AppSec) is a keyword substring search on firm text. Confirm via /v1/datasets/pro_services/fields?include_values=1 once per session.

The industry tag also drifts between releases — newer catalogs may use industry:cybersecurity, older ones used industry:security. Confirm the value via /fields and pin both industry and service_provided:cybersecurity for safety.

Any HTTP client works (curl, fetch, requests). Examples below use curl.

When NOT to use this skill

  • Consumer/personal cybersecurity ("my Gmail got hacked", "how do I secure my home wifi") — the catalog is B2B procurement only.
  • In-house security hires (Security Engineer, CISO, SOC analyst).
  • DIY/configuration questions ("how do I patch CVE-X", "configure firewall rules", "review this Terraform").
  • Security-product comparisons (CrowdStrike vs SentinelOne, EDR vendors, SIEM vendors).
  • Generic security knowledge ("explain zero-trust", "what is OWASP Top 10").
  • Non-US firms / individual freelance pen-testers / bug-bounty hunters.

Prerequisites

  • ServiceGraph access, either:
    • the ServiceGraph MCP server (https://mcp.servicegraph.co) loaded in your harness — this plugin's .mcp.json wires it up; OAuth 2.1 + PKCE keeps credentials in the harness sandbox — or
    • a ServiceGraph API key (vk_…, minted at https://servicegraph.co/profile/api-keys) available as SERVICEGRAPH_API_KEY in the environment or .env.local for the REST path (setup steps under Auth below).
  • An HTTP client for the REST path — the examples use curl.

Instructions

The loop is free-first: discovery, validation, search, and brief reads cost nothing; only unlock after the user confirms the spend.

  1. Pick the call path — the ServiceGraph MCP tools if loaded, otherwise the REST flow (MCP server and Auth sections below).
  2. GET /v1/datasets/pro_services/fields?include_values=1 — confirm the fields and values you plan to filter on exist.
  3. Build the filter (Filter DSL below) and validate it with GET /v1/datasets/pro_services/check — or draft it from plain English via POST /v1/datasets/pro_services/translate-intent.
  4. GET /v1/datasets/pro_services/search — present the free brief cards and let the user pick.
  5. Quote the unlock cost (10 credits per row, 30-day TTL) and get an explicit go-ahead.
  6. POST /v1/datasets/pro_services/unlocks with the chosen apexes; report the revealed detail.
  7. GET /v1/me/credits to report the remaining balance when asked.
MCP server (preferred for authed calls)

If your harness has the ServiceGraph MCP server loaded (tools containing servicegraph), prefer those — OAuth 2.1 + PKCE keeps the token in the harness sandbox. Otherwise use the REST flow below.

API surface (dataset id: pro_services)

Every endpoint requires the bearer (Authorization: Bearer vk_…). No anonymous tier.

EndpointCostUse it for
GET /v1/datasets/pro_services/fields[?include_values=1]freeConfirm industry value name and cybersecurity is in service_provided.
GET /v1/datasets/pro_services/check?filter=…freeValidate filter.
POST /v1/datasets/pro_services/translate-intentfree{intent} → DSL filter + sanity count.
GET /v1/datasets/pro_services/search?filter=…&limit=freeBrief firm cards + per-row unlock hint + total.
GET /v1/datasets/pro_services/:apexfreeOne row brief; detail only if unlocked.
POST /v1/datasets/pro_services/unlocks10 credits / firm{apexes:[...]} ≤100; atomic; 30-day TTL on detail.
GET /v1/me/creditsfreeBalance.

Cost model. Discovery / validation / search / brief reads are free. Detail (url, phone, email, social, address, full platforms map) costs 10 credits per firm and lasts 30 days.

Auth

vk_* API keys minted in the dashboard. Keep the token out of the LLM context — never read .env* into your context; dispatch via shell.

  1. Try the call first through a shell wrapper that sources .env.local:

    bash
    ( set -a; [ -f .env.local ] && . ./.env.local; set +a;
      curl -sS -H "Authorization: Bearer $SERVICEGRAPH_API_KEY" \
           'https://api.servicegraph.co/v1/datasets/pro_services/fields' )
  2. On 401 prompt the user:

    "Open https://servicegraph.co/profile/api-keys, create a key, and add SERVICEGRAPH_API_KEY=vk_… to .env.local here (or export it). Tell me when done. Please don't paste the key into chat."

  3. Retry after the user signals ready.

Filter DSL

GitHub-search-style.

filter   := orExpr
orExpr   := andExpr ("OR" andExpr)*
andExpr  := notExpr (("AND")? notExpr)*    # whitespace = implicit AND
notExpr  := ("NOT" | "-") notExpr | atom
atom     := "(" filter ")" | predicate
predicate:= IDENT op valueOrList | bareword
op       := ":" | "=" | ">=" | "<=" | ">" | "<"
valueOrList := value ("," value)*
value    := IDENT | NUMBER | tagAtEvidence
tagAtEvidence := IDENT "@" ("low"|"medium"|"high")
bareword := IDENT | NUMBER          # → keyword:<bareword>

Four rules that bite: AND binds tighter than OR (use parens); comma list = OR within one predicate; negation is -x or NOT x; bareword = keyword search (quote multi-word phrases).

Cybersecurity examples (validate yours with /check; replace cybersecurity with whatever /fields returns as the industry value):

industry:cybersecurity service_provided:cybersecurity
service_provided:cybersecurity pen-testing
service_provided:cybersecurity "security audit" "soc 2"
service_provided:cybersecurity vciso
service_provided:cybersecurity "incident response" retainer
service_provided:cybersecurity cloud aws
service_provided:cybersecurity "application security" sast
service_provided:cybersecurity rating>=4 has:clutch
service_provided:cybersecurity hipaa

The live catalog has no separate pen-testing / security-audit / appsec tags — pin service_provided:cybersecurity and treat all sub-types as keywords.

Sub-type → keyword mapping (all sub-types are keyword-only):

User asks forUse
Pen test / red teampen-testing, "red team"
Security audit / assessmentaudit, assessment
vCISO / fractional CISOvciso, "fractional ciso"
SOC 2 readiness"soc 2", readiness
Incident response / forensics"incident response", forensics, "ir retainer"
Cloud security"cloud security", aws, gcp, azure
Identity / IAMiam, identity
Application security / SAST/DAST"application security", appsec, sast, dast
Compliance frameworkspci, hipaa, "iso 27001", nist
Show full SKILL.md (509 more words)Show less
Identifying firms — apex

Firms are identified by their apex domain (mandiant.com, not www.mandiant.com/about).

Output

All responses are JSON.

  • Search returns free brief firm cards — apex, name, location, and rating signals — plus a per-row unlock hint and the match total. Briefs never include url, phone_primary, email_primary, legal_name, address_full, or the full platforms map.
  • Unlock (POST …/unlocks) returns each unlocked firm's detail block — contact fields, address, socials, the platforms map — plus per-item billing; detail stays readable for 30 days.
  • Errors arrive as a JSON envelope {"error": {"code": "…", "message": "…"}} — see Errors below.

Examples

A. Pen test for SOC 2

User: "Pen-testing firm for our SOC 2 audit."

GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+pen-testing+"soc 2"&limit=10
# Present, get pick of 3. "Unlocking 3 = 30 credits, 30-day TTL."
POST /v1/datasets/pro_services/unlocks
  { "apexes": ["firm-a.com", "firm-b.com", "firm-c.com"] }
B. vCISO for a healthcare-tech startup
GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+vciso+(healthcare OR hipaa)&limit=10
C. Incident response retainer

User: "Incident response retainer in case we get breached."

GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+"incident response"+retainer&limit=10

If thin, drop retainer — most IR firms offer retainer engagements as standard.

D. Cloud security + AWS + HIPAA
GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+cloud+aws+hipaa&limit=10
E. Indirect intent — "we got breached"

User: "We got hit with ransomware last week — we need help fast."

That's emergency IR:

GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+"incident response"+ransomware&limit=10

Skip validation; present briefs immediately given urgency.

F. AppSec / SAST
GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+"application security"+(sast OR "code review")&limit=10
G. SOC 2 readiness ahead of enterprise sales
GET /v1/datasets/pro_services/search?filter=service_provided:cybersecurity+"soc 2"+(readiness OR preparation)&limit=10
H. BYO apex list — enrich domains

User pastes 8–20 cybersecurity firm domains:

  1. GET /v1/datasets/pro_services/:apex per domain — free brief (404 = not in catalog, no charge).
  2. User picks N to fully enrich. POST /unlocks = 10×N credits, atomic, detail returned.
  3. Re-runs within 30-day TTL are free.

Gotchas

  • Always pin the cybersecurity service tag. Without it, pen-testing / vciso / appsec keywords leak into IT-services rows that mention security.
  • Confirm the industry value name via /fields — older catalogs used industry:security, newer ones may use industry:cybersecurity. Don't hardcode.
  • Refuse consumer-personal asks. "My Gmail got hacked", "how do I secure my home wifi", "should I use a VPN" — not B2B procurement.
  • DIY/configuration questions ("patch CVE-X", "configure firewall rules", "review this Terraform") are NOT procurement.
  • Security-product comparisons (EDR, SIEM, identity providers) are NOT procurement either.
  • "Hire a security engineer / CISO" is recruiting, not procurement of a firm. Refuse.
  • Bug-bounty / freelance pen-testers are out of scope (catalog is firm-level only).
  • Sub-types are keyword-only. Multi-word sub-types split into ANDed barewords unless quoted ("incident response" → one phrase).
  • Briefs DO include apex, name, location, ratings. They DON'T include url, phone_primary, email_primary, legal_name, address_full, full platforms — those require an unlock.
  • not_found / not_in_dataset 404 = not in pro_services. Skip; not charged.
  • Unlock is atomic. N apexes either all charge (up to 10×N credits) or none on 402.
  • Within-TTL re-views are free (was_cached:true).

Errors

JSON envelope: {"error": {"code": "...", "message": "..."}}.

StatusCodeWhat to do
400filter_parse_errorposition included; fix and re-validate with /check.
400kind_in_filterStrip any kind: from filter — URL is authoritative.
400field_not_in_datasetDrop the disallowed field.
400invalid_apexRe-normalize.
401unauthorized / invalid_audienceRe-prompt for fresh vk_….
402insufficient_creditsneeded and balance in payload; nothing charged.
404not_found / not_in_datasetSkip; not charged.
429rate_limitedHonor Retry-After.

End-to-end example

User: "Three pen-testing firms for our SOC 2 audit, 4-star ratings, ideally with HIPAA experience for a healthcare-tech context."

GET /v1/datasets/pro_services/fields?include_values=1
GET /v1/datasets/pro_services/check?filter=service_provided:cybersecurity+pen-testing+"soc 2"+hipaa+rating>=4
GET /v1/datasets/pro_services/search?filter=...&limit=10
# Present briefs. "Unlocking 3 = 30 credits, 30-day TTL."
POST /v1/datasets/pro_services/unlocks
  { "apexes": ["firm-a.com", "firm-b.com", "firm-c.com"] }
GET /v1/me/credits

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/mcp/servicegraph/skills/find-cybersecurity-firm of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Find Cybersecurity Firm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Find Cybersecurity Firm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Find Cybersecurity Firm this skilljeremylongshore/tons-of-skills-marketplace2.8k—~3.7kAutomated safety check: NotesMIT
Security Auditoraiskillstore/marketplace4336 repos~2.6kAutomated safety check: PassNone
Securitytravisjneuman/.claude100—~3.3kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence
Slowmist Agent Securityslowmist/slowmist-agent-security508—~1.4kAutomated safety check: PassMIT
Security Vuln Remediationstacklok/toolhive-studio171—~2.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    433 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Security

    travisjneuman/.claude

    Information security expertise for cybersecurity frameworks (NIST, ISO 27001), security architecture, incident response, vulnerability management, identity management, and cloud security.

    100 GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 14 days ago
    SecurityAuto-check: notes
  • Slowmist Agent Security

    slowmist/slowmist-agent-security

    Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.

    508 GitHub stars~1.4k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Security Vuln Remediation

    stacklok/toolhive-studio

    Remediate security vulnerabilities found by Grype or pnpm audit.

    171 GitHub stars~2.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 7 days ago
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Find Cybersecurity Firm

What does Find Cybersecurity Firm do?

A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…. Find Cybersecurity Firm is an agent skill from jeremylongshore/tons-of-skills-marketplace. Use whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed SOC, IAM, cloud security, and AppSec.

When should I use Find Cybersecurity Firm?

Find Cybersecurity Firm fits situations like: the user wants to find; enrich US cybersecurity firms — pen-testing/red team; security audits; SOC 2 readiness.

How do I install Find Cybersecurity Firm in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a claude-code`. Or copy the skill folder (plugins/mcp/servicegraph/skills/find-cybersecurity-firm in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/find-cybersecurity-firm in your project. Claude Code loads it when a task matches its description.

How do I install Find Cybersecurity Firm in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a codex`. Or copy the skill folder (plugins/mcp/servicegraph/skills/find-cybersecurity-firm in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/find-cybersecurity-firm in your project. Codex loads it when a task matches its description.

Can I use Find Cybersecurity Firm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill find-cybersecurity-firm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/find-cybersecurity-firm, .gemini/skills/find-cybersecurity-firm, .github/skills/find-cybersecurity-firm and .opencode/skills/find-cybersecurity-firm in your project.

What does Find Cybersecurity Firm need to run?

Going by SKILL.md and its folder, Find Cybersecurity Firm needs the command-line tools its instructions call (curl) and credentials named SERVICEGRAPH_API_KEY. Our summary lists: A credential in SERVICEGRAPH_API_KEY. Its frontmatter pre-approves these tools: Bash(curl:*), mcp__servicegraph__list_fields, mcp__servicegraph__list_field_values, mcp__servicegraph__check_filter, mcp__servicegraph__translate_intent, mcp__servicegraph__search_dataset, mcp__servicegraph__get_row, mcp__servicegraph__unlock_rows, mcp__servicegraph__get_credit_balance. Compatibility (from SKILL.md): Designed for Claude Code.

Does Find Cybersecurity Firm access the network?

SKILL.md names 4 domains. In commands or code: api.servicegraph.co and mcp.servicegraph.co; the agent is likely to contact these when it follows the instructions. As links in the text: servicegraph.co and github.com. This is read from the text; nothing was executed.

Is Find Cybersecurity Firm safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Find Cybersecurity Firm use?

Find Cybersecurity Firm is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Find Cybersecurity Firm use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Find Cybersecurity Firm?

Skills that share tags, products or a category with Find Cybersecurity Firm: Security Auditor (aiskillstore/marketplace, 433 stars), Security (travisjneuman/.claude, 100 stars), Forensify (alexgreensh/repo-forensics, 190 stars) and Slowmist Agent Security (slowmist/slowmist-agent-security, 508 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Find Cybersecurity Firm?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.