Agent skill

RAG Security First

by lyonzin in lyonzin/knowledge-rag

For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the…

MITAuto-check passedAI & LLM Engineering

Install RAG Security First

skills CLI
$ npx skills add lyonzin/knowledge-rag --skill rag-security-first -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install lyonzin/knowledge-rag rag-security-first --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/lyonzin/knowledge-rag.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/domain/rag-security-first .claude/skills/rag-security-first && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rag-security-first
GitHub stars
290
Token cost
~2.3k tokens
SKILL.md length
461 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the…

  • Works in 4 steps: Search the corpus before hitting any… → Use the query-expansion mappings (sqli →… → Cite the MITRE technique ID + the… → …
  • Tasks that involve Retrieval-augmented generation
  • SKILL.md covers When to use this skill, What this skill commits to, Steps and Examples
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

RAG Security First is an agent skill from lyonzin/knowledge-rag. For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the local corpus first. Assumes the RAG is loaded with security content (cybersecurity preset, MITRE data, threat reports, runbooks). Prevents wasted external threat-intel calls and grounds recommendations in the team's actual playbooks.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering Retrieval-augmented generation, Vulnerability scanning and Runbooks and postmortems. It works with Model Context Protocol. The repository describes itself as: Local RAG MCP server for Claude Code — hybrid search (semantic + BM25), cross-encoder reranking, 13 MCP tools, 20 format parsers. Zero external servers, zero API keys. The licence is MIT.

When your agent uses it

  • Tasks that involve Retrieval-augmented generation
  • Tasks that involve Vulnerability scanning
  • Tasks that involve Runbooks and postmortems

Example prompts

  • “/rag-security-first”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Search the corpus before hitting any external threat-intel MCP (mcpcti*, mcpvirustotal*, mcpshodan*).
  2. Use the query-expansion mappings (sqli → SQL injection) — they exist for a reason.
  3. Cite the MITRE technique ID + the internal runbook link.
  4. Only escalate to external threat-intel when the corpus does not cover the specific IOC / CVE / technique in enough depth.

What it can do on your machine

Read from SKILL.md and the folder at commit df9cccb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

RAG Security First loads about 2.3k tokens when it runs. Until then it costs about 112 tokens; SKILL.md has 461 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from lyonzin/knowledge-rag at commit df9cccb, republished under its MIT licence (© lyonzin). 461 words, ~2,325 tokens.

Download SKILL.mdSave it as .claude/skills/rag-security-first/SKILL.md (or your agent's skills folder).
name
rag-security-first
description
For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the local corpus first. Assumes the RAG is loaded with security content (cybersecurity preset, MITRE data, threat reports, runbooks). Prevents wasted external threat-intel calls and grounds recommendations in the team's actual playbooks.
metadata.type
rag-workflow
metadata.kind
domain
metadata.target
any-mcp-client

rag-security-first — RAG-driven security workflow

When to use this skill

Trigger this skill for any security-flavored task:

  • Threat triage or incident response
  • MITRE ATT&CK technique mapping (T1078, T1055, …)
  • CVE lookup or vulnerability analysis
  • Exploit / payload / attacker-technique questions
  • Red team / blue team / purple team exercises
  • CTF challenge analysis
  • Detection engineering (Sigma / Snort / YARA / KQL / SPL / LQL rules)
  • Defensive control validation
  • Compliance / hardening questions

Prerequisite: the RAG should be loaded with security-relevant content. The cybersecurity preset is optimized for this — it ships 8 categories, 200+ routing keywords, and 69 query expansions covering sqli → SQL injection, privesc → privilege escalation, etc.


What this skill commits to

For security tasks, the corpus is primary:

  1. Search the corpus before hitting any external threat-intel MCP (mcp__cti__*, mcp__virustotal__*, mcp__shodan__*).
  2. Use the query-expansion mappings (sqli → SQL injection) — they exist for a reason.
  3. Cite the MITRE technique ID + the internal runbook link.
  4. Only escalate to external threat-intel when the corpus does not cover the specific IOC / CVE / technique in enough depth.

Steps

  1. Classify the intent. Is it:

    • Detection — "we saw X in logs, is this bad?"
    • Response — "we confirmed compromise, what now?"
    • Prevention — "how do we harden against X?"
    • Research — "how does X actually work?"
  2. Extract the security signature from the user's message:

    • MITRE ATT&CK ID (T1078, T1078.001, TA0004)
    • CVE ID (CVE-2024-1234)
    • Malware family (Cobalt Strike, Mimikatz, LSASS dump)
    • Attack technique term (Kerberoasting, AS-REP Roasting, pass-the-hash)
    • IOC (hash, domain, IP — treat as verbatim in the search)
  3. Search the corpus with the security preset in mind:

    search_knowledge(query="<signature> <intent>", max_results=5, min_score=0.15)

    Example: search_knowledge(query="LSASS dump credential access detection", max_results=5)

  4. If the RAG has a routing preset, the categories redteam / blueteam / mitre / ctf are likely present. Filter when specificity matters:

    search_knowledge(query="lateral movement WinRM", category="blueteam", max_results=5)
  5. Read the top hits and build the answer around them. Typical outputs to include:

    SectionContent
    TechniqueMITRE ATT&CK ID + name + tactic
    Detectionlog signals, EDR queries (KQL / SPL / LQL), Sigma rules — from corpus
    Responserunbook steps from blueteam category or def-* skills
    Attacker viewtools / commands from redteam category (authorized engagements only)
    Referencescitations to corpus files + MITRE technique URL + CVE URL
  6. Only escalate to external threat-intel MCPs when the corpus is thin on the specific IOC:

    # Only if RAG returns generic-only hits, not IOC-specific:
    mcp__virustotal__vt_file_report(hash=...)
    mcp__cti__ti_check_ioc(ioc=..., ioc_type="hash")
    mcp__shodan__shodan_host(ip=...)
  7. After resolution, chain to rag-index-decisions if the incident produced a new detection rule, runbook entry, or lesson.

Show full SKILL.md (84 more words)Show less

Examples

Example 1 — MITRE-mapped detection question

User: "We saw process creation of rundll32.exe comsvcs.dll MiniDump 632 dump.dmp full on a workstation. Is this bad?"

Agent:

search_knowledge(query="rundll32 comsvcs MiniDump LSASS credential dump",
                 max_results=5, min_score=0.15)
→ 4 hits: mitre-T1003.001-lsass.md (0.94), redteam-cred-dumping.md (0.82),
          blueteam-lsass-detection.md (0.79), edr-tuning-lsass.md (0.71)

Reply: "Yes, high-confidence malicious [mitre-T1003.001-lsass.md].

**Technique:** MITRE ATT&CK T1003.001 (OS Credential Dumping: LSASS Memory)
via the built-in `comsvcs.dll` MiniDump helper. Legitimate use of this
command is extremely rare.

**Detection signals** [blueteam-lsass-detection.md]:
- Process: `rundll32.exe` with cmdline containing `comsvcs.dll` + `MiniDump`
- Parent process: often `cmd.exe` or `powershell.exe` after initial access
- File write: `.dmp` file with LSASS-typical size (~50-500 MB)

**Immediate response** [runbooks/incident-lsass-dump.md]:
1. Isolate the host (network quarantine, do not power off — preserve memory)
2. Capture the dump before attacker retrieves it
3. Rotate credentials of every user logged on to that host (last 24h)
4. Kerberos: krbtgt reset if attacker had time to Golden Ticket

**Related ATT&CK:** T1078 (Valid Accounts, likely next step),
T1550 (Alternate Auth Material)."

Example 2 — CVE lookup

User: "Is CVE-2024-3400 relevant to our infra?"

Agent:

search_knowledge(query="CVE-2024-3400", max_results=5) → 0 hits (specific CVE not indexed)
search_knowledge(query="PAN-OS GlobalProtect vulnerability", max_results=5) → 2 hits
  → asset-inventory-perimeter.md (0.68), vuln-response-playbook.md (0.55)

Reply: "The corpus does not have CVE-2024-3400 specifically indexed. Checking external
sources... [chains to mcp__cti__vuln_cve(cve_id='CVE-2024-3400')]

From external threat intel: CVE-2024-3400 is a critical PAN-OS GlobalProtect command
injection (CVSS 10.0), actively exploited since March 2024.

**Relevance to your infra** [asset-inventory-perimeter.md]:
- Your perimeter inventory lists 2 PAN-OS firewalls in scope.
- Response playbook: [vuln-response-playbook.md] — priority PATCH within 24h
  for internet-facing PAN-OS with GlobalProtect enabled.

**Next steps:**
1. Confirm PAN-OS version on those 2 firewalls
2. Check if GlobalProtect gateway feature is enabled (only vulnerable if yes)
3. If yes → apply hotfix per PAN advisory; if no → still upgrade but non-emergency
4. Hunt for IOCs from the campaign — chain to mcp__cti__ti_check_ioc"

Example 3 — Red team, authorized engagement

User: "Doing an authorized internal pentest. Need Kerberoasting query and post-exploitation."

Agent:

search_knowledge(query="Kerberoasting SPN request authorized pentest",
                 category="redteam", max_results=5)
→ 4 hits: kerberoasting-technique.md (0.91), rubeus-usage.md (0.83),
          post-exploit-cred-cracking.md (0.75), opsec-considerations.md (0.68)

Reply: "**MITRE ATT&CK T1558.003** (Steal or Forge Kerberos Tickets: Kerberoasting)
[kerberoasting-technique.md].

**Enumeration:**
```powershell
Get-ADUser -Filter {ServicePrincipalName -ne \"$null\"} -Properties ServicePrincipalName
# or Impacket:
GetUserSPNs.py DOMAIN/user:pass -dc-ip <DC>

[kerberoasting-technique.md#enumeration]

Extraction with Rubeus:

Rubeus.exe kerberoast /outfile:hashes.txt /nowrap

[rubeus-usage.md]

Cracking:

hashcat -m 13100 hashes.txt rockyou.txt --force

[post-exploit-cred-cracking.md]

OPSEC [opsec-considerations.md]: EDRs flag Rubeus / GetUserSPNs by default — use only from authorized C2 or bastion. Prefer Rubeus /aes to avoid RC4 detection."


---

## Edge cases

- **Corpus is not security-loaded** — `list_categories()` returns no security-flavored categories. Skill still works but degrades: no runbook citations, more escalation to external threat-intel MCPs.
- **Sensitive engagement content** — never quote client-specific IOCs from one engagement in another. Sanitize before responding.
- **Unauthorized attacker technique request** — if the user is asking how to attack a system without authorization, this skill does NOT help. Refuse per general policy — RAG-first is about *how to search*, not *what to search for*.
- **Live IOC that should not be cached** — if the response includes a live C2 IP or malware hash, do NOT `add_from_url` it into the RAG. Cite once and move on.

---

## Related skills

- **[`rag-check-first`](https://github.com/lyonzin/knowledge-rag/blob/master/skills/foundation/rag-check-first/SKILL.md)** — the base pattern (this is `check-first` with security priorities).
- **[`rag-cite-sources`](https://github.com/lyonzin/knowledge-rag/blob/master/skills/foundation/rag-cite-sources/SKILL.md)** — extra important in security (auditable trail matters).
- **[`rag-troubleshoot`](https://github.com/lyonzin/knowledge-rag/blob/master/skills/workflow/rag-troubleshoot/SKILL.md)** — incident triage often overlaps with debugging.
- **[`rag-index-decisions`](https://github.com/lyonzin/knowledge-rag/blob/master/skills/maintenance/rag-index-decisions/SKILL.md)** — after handling an incident, index the postmortem.

© lyonzin, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/domain/rag-security-first of lyonzin/knowledge-rag.

Open the folder on GitHubat commit df9cccb

Compare with similar skills

RAG Security First next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

RAG Security First compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
RAG Security First this skilllyonzin/knowledge-rag290—~2.3kAutomated safety check: PassMIT
Pgvector Semantic Searchtimescale/pg-aiguide1.9k1 repos~3.8kAutomated safety check: PassApache-2.0
AutoRAG Setup and RepairMarker-Inc-Korea/AutoRAG5.1k—~5.3kAutomated safety check: PassMIT
Sciverseopendatalab/Sciverse-Agent-Tools119—~3kAutomated safety check: PassCustom licence
Postgres Hybrid Text Searchtimescale/pg-aiguide1.9k—~3.1kAutomated safety check: PassApache-2.0
Slm Recallqualixar/superlocalmemory227—~3.3kAutomated safety check: NotesAGPL-3.0

Similar skills

  • Pgvector Semantic Search

    timescale/pg-aiguide

    A skill your agent uses for setting up vector similarity search with pgvector for AI/ML embeddings, RAG applications, or semantic search.

    1.9k GitHub starsUsed in 1 repo~3.8k tokens
    AI & LLM EngineeringAuto-check passed
  • AutoRAG Setup and Repair

    Marker-Inc-Korea/AutoRAG

    Installs, configures, and repairs AutoRAG's search model, approved folders, indexes, and datasources, and registers its Lite MCP server.

    5.1k GitHub stars~5.3k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Sciverse

    opendatalab/Sciverse-Agent-Tools

    A skill your agent uses when the user needs academic paper retrieval — searching scientific literature by author/year/journal, finding paper chunks for RAG-style citations, or expanding original…

    119 GitHub stars~3k tokensUpdated 19 days ago
    AI & LLM EngineeringAuto-check passed
  • Postgres Hybrid Text Search

    timescale/pg-aiguide

    A skill your agent uses to implement hybrid search combining BM25 keyword search with semantic vector search using Reciprocal Rank Fusion (RRF).

    1.9k GitHub stars~3.1k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Slm Recall

    qualixar/superlocalmemory

    Search and retrieve facts, decisions, and past context from SuperLocalMemory.

    227 GitHub stars~3.3k tokensUpdated today
    AI & LLM EngineeringAuto-check: notes
  • Upgrade Notes

    getknit/knit

    Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.

    131 GitHub stars~1.2k tokensUpdated 4 days ago
    SecurityAuto-check passed

More from lyonzin/knowledge-rag

All 10 skills in this repo
  • RAG Check First

    lyonzin/knowledge-rag

    Before answering any technical question, code request, architecture decision, or factual claim, call searchknowledge to check the local corpus.

    290 GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed
  • RAG Cite Sources

    lyonzin/knowledge-rag

    Every technical claim drawn from the local corpus must ship with a source citation formatted as path:line or path:section.

    290 GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed
  • RAG Code Review

    lyonzin/knowledge-rag

    When performing code review on a PR, diff, snippet, or "look at this change" request, first consult the corpus for related ADRs, coding standards, prior patterns, and similar files.

    290 GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed
  • RAG Deep Dive

    lyonzin/knowledge-rag

    Three-step multi-tool workflow — search the corpus, fetch the most relevant document in full, then find similar documents.

    290 GitHub stars~1.6k tokensUpdated 4 days ago
    Auto-check passed
  • RAG Troubleshoot

    lyonzin/knowledge-rag

    When the user reports a bug, error message, stack trace, unexpected behavior, or "why is this broken" question, search the corpus first for prior occurrences, known fixes, or related runbooks.

    290 GitHub stars~1.8k tokensUpdated 4 days ago
    Auto-check passed
  • RAG Evaluate Quality

    lyonzin/knowledge-rag

    Measure retrieval quality using evaluateretrieval (MRR@5 and Recall@5) and getindexstats.

    290 GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed

Questions about RAG Security First

What does RAG Security First do?

For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the…. RAG Security First is an agent skill from lyonzin/knowledge-rag. For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the local corpus first.

When should I use RAG Security First?

RAG Security First fits situations like: tasks that involve Retrieval-augmented generation; tasks that involve Vulnerability scanning; tasks that involve Runbooks and postmortems.

How do I install RAG Security First in Claude Code?

Run `npx skills add lyonzin/knowledge-rag --skill rag-security-first -a claude-code`. Or copy the skill folder (skills/domain/rag-security-first in lyonzin/knowledge-rag) into .claude/skills/rag-security-first in your project. Claude Code loads it when a task matches its description.

How do I install RAG Security First in Codex?

Run `npx skills add lyonzin/knowledge-rag --skill rag-security-first -a codex`. Or copy the skill folder (skills/domain/rag-security-first in lyonzin/knowledge-rag) into .agents/skills/rag-security-first in your project. Codex loads it when a task matches its description.

Can I use RAG Security First in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lyonzin/knowledge-rag --skill rag-security-first -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rag-security-first, .gemini/skills/rag-security-first, .github/skills/rag-security-first and .opencode/skills/rag-security-first in your project.

What does RAG Security First need to run?

SKILL.md names no scripts, command-line tools or credentials: RAG Security First is instructions for the agent only.

Does RAG Security First access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is RAG Security First safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does RAG Security First use?

RAG Security First is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does RAG Security First use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to RAG Security First?

Skills that share tags, products or a category with RAG Security First: Pgvector Semantic Search (timescale/pg-aiguide, 1.9k stars), AutoRAG Setup and Repair (Marker-Inc-Korea/AutoRAG, 5.1k stars), Sciverse (opendatalab/Sciverse-Agent-Tools, 119 stars) and Postgres Hybrid Text Search (timescale/pg-aiguide, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains RAG Security First?

lyonzin (a GitHub user) maintains it in lyonzin/knowledge-rag, which has 290 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 4, 2026.

Source: lyonzin/knowledge-rag on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.