Agent skill

Data Breach Response

by mohitagw15856 in mohitagw15856/pm-claude-skills

Respond to your data being breached — triage by what actually leaked, the freeze/rotate/monitor ladder in the right order, and the calibrated watchfulness that follows, without panic or paralysis.

MITAuto-check passedSecurity

Install Data Breach Response

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill data-breach-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills data-breach-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/data-breach-response .claude/skills/data-breach-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
data-breach-response
GitHub stars
1.4k
Token cost
~1.5k tokens
SKILL.md length
778 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Respond to your data being breached — triage by what actually leaked, the freeze/rotate/monitor ladder in the right order, and the calibrated watchfulness that follows, without panic or paralysis.

  • Works in 5 steps: Passwords leaked → today: change it,… → Card numbers → today: freeze/reissue via… → Government ID / SSN → this week, and… → …
  • Someone asks my data was in a breach what do I do
  • SKILL.md covers What This Skill Produces, Required Inputs, Framework: The Leak-to-Ladder… and Output Format, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Data Breach Response is an agent skill from mohitagw15856/pm-claude-skills. Respond to your data being breached — triage by what actually leaked, the freeze/rotate/monitor ladder in the right order, and the calibrated watchfulness that follows, without panic or paralysis. Use when someone asks my data was in a breach what do I do, I got a breach notification letter, my SSN/ID number leaked, or should I freeze my credit. Produces the leaked-data triage, the ordered response ladder with the do-today items, the monitoring plan, and the breach-letter decode (including what the free credit…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Someone asks my data was in a breach what do I do
  • I got a breach notification letter
  • My SSN/ID number leaked
  • Should I freeze my credit

Example prompts

  • “/data-breach-response”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Passwords leaked → today: change it, then everywhere it was reused (the breach's real payload is credential-stuffing every other site)…
  2. Card numbers → today: freeze/reissue via the bank app, review recent transactions, set transaction alerts. Painless, fast, and the bank's…
  3. Government ID / SSN → this week, and it's the big one: a credit freeze at the bureaus (the strongest single move where available — free in…
  4. Email + context leaked → the phishing upgrade: breach data fuels targeted scams that reference real details ("your recent order at…")…
  5. The letter decode: "no evidence of misuse" means "we haven't seen it yet," not "you're safe" · the free credit monitoring is worth…

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Data Breach Response loads about 1.5k tokens when it runs. Until then it costs about 142 tokens; SKILL.md has 778 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~142
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 778 words, ~1,535 tokens.

Download SKILL.mdSave it as .claude/skills/data-breach-response/SKILL.md (or your agent's skills folder).
name
data-breach-response
description
Respond to your data being breached — triage by what actually leaked, the freeze/rotate/monitor ladder in the right order, and the calibrated watchfulness that follows, without panic or paralysis. Use when someone asks my data was in a breach what do I do, I got a breach notification letter, my SSN/ID number leaked, or should I freeze my credit. Produces the leaked-data triage, the ordered response ladder with the do-today items, the monitoring plan, and the breach-letter decode (including what the free credit monitoring offer is and isn't).

Data Breach Response Skill

The breach notification letter arrives months late, written by lawyers to minimize alarm and liability in the same paragraph — and the reader's real question is buried: what did they get, and what do I actually do? The answer depends entirely on the first part: a leaked password and a leaked government ID number are different emergencies with different ladders. This skill triages by what leaked, orders the response (some steps are today, most aren't), and decodes the letter itself — including the free-monitoring offer, which is worth taking and worth understanding.

What This Skill Produces

  • The triage — what leaked, mapped to what it enables: account takeover, financial fraud, identity theft, targeted phishing
  • The ladder — do-today / this-week / ongoing, ordered by damage-prevented-per-minute
  • The monitoring plan — what to watch, where, at what cadence — calibrated, not paranoid
  • The letter decode — what the notification actually admits, and what the monitoring offer covers

Required Inputs

Ask for these if not provided:

  • What leaked — from the letter or breach-lookup: email? passwords (hashed or plain — the letter usually says)? card numbers? government ID / SSN? medical? The whole response keys off this list
  • The account's blast radius — was that password reused? (The honest answer decides half the ladder) Is the breached account an identity anchor (primary email)?
  • Jurisdiction, loosely — credit freezes, fraud alerts, and ID-theft reporting are country-specific; the ladder names the step types with verify-locally flags
  • What's been noticed — any weird charges, logins, or mail already? That upgrades the response from preventive to active-incident

Framework: The Leak-to-Ladder Map

  1. Passwords leaked → today: change it, then everywhere it was reused (the breach's real payload is credential-stuffing every other site), enable 2FA on the anchors (email first — it resets everything else), and check the account's forwarding/recovery settings if it's email (persistence tricks outlive password changes).
  2. Card numbers → today: freeze/reissue via the bank app, review recent transactions, set transaction alerts. Painless, fast, and the bank's problem-handling here is mature.
  3. Government ID / SSN → this week, and it's the big one: a credit freeze at the bureaus (the strongest single move where available — free in many jurisdictions, verify locally; it blocks new-account fraud at the source), fraud alerts as the lighter alternative, tax-filing and benefits-fraud awareness where relevant. The ID number can't be rotated like a password — which is why the freeze, monitoring, and calibrated long-term watchfulness are the response.
  4. Email + context leaked → the phishing upgrade: breach data fuels targeted scams that reference real details ("your recent order at…") — the ladder includes the expectation-setting line: incoming messages referencing this breach are now more suspicious, not more credible (route to scam-message-decoder).
  5. The letter decode: "no evidence of misuse" means "we haven't seen it yet," not "you're safe" · the free credit monitoring is worth activating (it's detection, not prevention — it tells you after something happened; the freeze is prevention) · class-action notices are separate and slow · and the offer's enrollment deadline is a real date worth catching.
Show full SKILL.md (290 more words)Show less

Output Format

Breach Response: [breach/company] — leaked: [the list]

What This Enables

[The leaked items → the specific risks, plainly — no vague "your data may be at risk"]

The Ladder

Today: [the leak-keyed items] · This week: [freeze/alerts (verify-locally), monitoring enrollment before its deadline] · Ongoing: [the calibrated watch: statements cadence, credit-report cadence, the phishing expectation]

The Letter, Decoded

["No evidence of misuse" translation · what the monitoring offer does and doesn't do · deadlines in the letter, extracted]

If Something's Already Wrong

[Active-fraud branch: dispute processes, the ID-theft report path (jurisdiction-flagged), the paper trail to start]

Freeze mechanics, fraud-alert rules, and identity-theft reporting vary by country — verify the flagged steps locally. A freeze blocks new credit, not existing-account fraud; the ladder covers both for that reason.

Quality Checks

  • Every response item traces to a specific leaked data type — no generic hygiene dump
  • The reuse question was asked and its answer shaped the ladder
  • Freeze vs. monitoring is explained as prevention vs. detection
  • Jurisdiction-specific mechanisms are typed and flagged, not asserted
  • The active-incident branch exists and upgrades the response when triggered

Anti-Patterns

  • Do not respond to every breach identically — a forum password and an ID number are different events
  • Do not present the monitoring offer as protection — it's a smoke detector, not a lock; take it anyway
  • Do not induce panic or dismiss — the calibrated middle is the product
  • Do not skip the email-anchor check — the account that resets all others is the one that matters most
  • Do not let "no evidence of misuse" close the case — the ladder runs on what leaked, not on the letter's comfort

Example Trigger Phrases

  • "My data was in a breach what do I do."
  • "I got a breach notification letter."
  • "My SSN/ID number leaked."
  • "Should I freeze my credit?"

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/data-breach-response of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Data Breach Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Data Breach Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Data Breach Response this skillmohitagw15856/pm-claude-skills1.4k—~1.5kAutomated safety check: PassMIT
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Security Detection Rule Managementelastic/agent-skills5921 repos~3.9kAutomated safety check: NotesApache-2.0
Chaitin CLIchaitin/chaitin-cli114—~15kAutomated safety check: NotesGPL-3.0
GatesNebulock-Inc/agentic-threat-hunting-framework388—~12kAutomated safety check: PassMIT

Similar skills

  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check: notes
  • Chaitin CLI

    chaitin/chaitin-cli

    A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

    114 GitHub stars~15k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Gates

    Nebulock-Inc/agentic-threat-hunting-framework

    GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

    388 GitHub stars~12k tokensUpdated yesterday
    SecurityAuto-check passed
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Data Breach Response

What does Data Breach Response do?

Respond to your data being breached — triage by what actually leaked, the freeze/rotate/monitor ladder in the right order, and the calibrated watchfulness that follows, without panic or paralysis. Data Breach Response is an agent skill from mohitagw15856/pm-claude-skills. Respond to your data being breached — triage by what actually leaked, the freeze/rotate/monitor ladder in the right order, and the calibrated watchfulness that follows, without panic or paralysis.

When should I use Data Breach Response?

Data Breach Response fits situations like: someone asks my data was in a breach what do I do; I got a breach notification letter; my SSN/ID number leaked; should I freeze my credit.

How do I install Data Breach Response in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill data-breach-response -a claude-code`. Or copy the skill folder (skills/data-breach-response in mohitagw15856/pm-claude-skills) into .claude/skills/data-breach-response in your project. Claude Code loads it when a task matches its description.

How do I install Data Breach Response in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill data-breach-response -a codex`. Or copy the skill folder (skills/data-breach-response in mohitagw15856/pm-claude-skills) into .agents/skills/data-breach-response in your project. Codex loads it when a task matches its description.

Can I use Data Breach Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill data-breach-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/data-breach-response, .gemini/skills/data-breach-response, .github/skills/data-breach-response and .opencode/skills/data-breach-response in your project.

What does Data Breach Response need to run?

SKILL.md names no scripts, command-line tools or credentials: Data Breach Response is instructions for the agent only.

Does Data Breach Response access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Data Breach Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Data Breach Response use?

Data Breach Response is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Data Breach Response use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Data Breach Response?

Skills that share tags, products or a category with Data Breach Response: Security Alert Triage (elastic/agent-skills, 592 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Security Detection Rule Management (elastic/agent-skills, 592 stars) and Chaitin CLI (chaitin/chaitin-cli, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Data Breach Response?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,433 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 8, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.