Agent skill

Auditing Uefi Firmware With Chipsec

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for…

Apache-2.0Auto-check: notesSecurity

Install Auditing Uefi Firmware With Chipsec

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-uefi-firmware-with-chipsec -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills auditing-uefi-firmware-with-chipsec --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auditing-uefi-firmware-with-chipsec .claude/skills/auditing-uefi-firmware-with-chipsec && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auditing-uefi-firmware-with-chipsec
GitHub stars
34k
Token cost
~2.3k tokens
SKILL.md length
830 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for…

  • Works in 8 steps: Run the full automated test suite → Run the core firmware-protection modules… → Verify Secure Boot variable protection → …
  • Security work in your project
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder; calls pip, git and python; reaches github.com

What it does

Auditing Uefi Firmware With Chipsec is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for firmware-level threats.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Security. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/auditing-uefi-firmware-with-chipsec”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Run the full automated test suite
  2. Run the core firmware-protection modules individually
  3. Verify Secure Boot variable protection
  4. Inspect SPI flash region access permissions
  5. Dump SPI flash for offline forensics
  6. Enumerate and triage UEFI variables
  7. Limited assessment without a kernel driver
  8. Triage results and report

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • pip
    • git
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • chipsec.github.io
    • media.defense.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auditing Uefi Firmware With Chipsec loads about 2.3k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 830 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:63
    sudo chipsec_main --help
  • NoteRuns commands with sudoSKILL.md:64
    sudo chipsec_util --help
  • NoteRuns commands with sudoSKILL.md:91
    sudo chipsec_main
  • NoteRuns commands with sudoSKILL.md:94
    sudo chipsec_main -j results.json -x results.xml -l chipsec.log
  • NoteRuns commands with sudoSKILL.md:102
    sudo chipsec_main -m common
  • NoteRuns commands with sudoSKILL.md:105
    sudo chipsec_main -m common.bios_wp
  • NoteRuns commands with sudoSKILL.md:108
    sudo chipsec_main -m common.spi_lock
  • NoteRuns commands with sudoSKILL.md:111
    sudo chipsec_main -m common.smrr
  • NoteRuns commands with sudoSKILL.md:114
    sudo chipsec_main -m common.smm
  • NoteRuns commands with sudoSKILL.md:117
    sudo chipsec_main -m common.uefi.s3bootscript

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 830 words, ~2,347 tokens.

Download SKILL.mdSave it as .claude/skills/auditing-uefi-firmware-with-chipsec/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
auditing-uefi-firmware-with-chipsec
description
Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for firmware-level threats.
domain
cybersecurity
subdomain
hardware-firmware-security
tags
hardware-firmware-security, uefi, chipsec, spi-flash, bios-write-protection, secure-boot, firmware-assessment, platform-security
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
ID.AM-02
mitre_attack
T1542.001

Auditing UEFI Firmware with CHIPSEC

Authorized Use Only: CHIPSEC loads a kernel driver and reads/writes low-level hardware registers, SPI flash, and SMM. Run it only on systems you own or are explicitly authorized to assess, ideally on dedicated test hardware. Misuse (especially write/modify modules) can brick a machine. Never run write-capable modules on production systems.

Overview

CHIPSEC is the open-source Platform Security Assessment Framework created by Intel's Advanced Threat Research team. It inspects the low-level security configuration of x86 platform firmware and hardware — the layer below the operating system where bootkits and firmware implants live. CHIPSEC loads a signed kernel driver (Linux, Windows, or it can run from the UEFI shell) to read and write hardware registers, Model-Specific Registers (MSRs), PCI config space, SPI flash, and UEFI variables, then runs an automated test suite that checks whether the platform's defensive locks are actually engaged.

The threat CHIPSEC addresses is MITRE ATT&CK T1542.001 — Pre-OS Boot: System Firmware: adversaries who modify system firmware (the BIOS/UEFI image on SPI flash) to gain stealthy, persistent, OS-survivable control. Firmware implants persist across OS reinstall and disk replacement and are invisible to most EDR. CHIPSEC's value is verifying the prerequisites that prevent such implants: that the SPI flash BIOS region is write-protected (BIOS_CNTL BLE/SMM_BWP, SPI Protected Ranges), that the flash descriptor locks region access, that SMRAM/SMRR are configured, and that Secure Boot variables are protected. It also dumps the SPI flash for offline forensic comparison.

Sources: Intel/CHIPSEC project (https://github.com/chipsec/chipsec), CHIPSEC documentation (https://chipsec.github.io/).

When to Use

  • Baseline firmware-security assessment of a new laptop/server platform or fleet image
  • Verifying that BIOS write protection and SPI flash locks are correctly enabled by the OEM
  • Firmware forensics: dumping SPI flash to compare against a known-good image
  • Validating Secure Boot variable protection and S3 boot-script protection
  • Hunting for evidence of a firmware implant or misconfiguration enabling one

Prerequisites

  • Physical or admin/root access to the target x86 platform (Intel or AMD)
  • Linux (root) or Windows (Administrator), or a UEFI shell environment
  • Ability to load a kernel driver (Secure Boot may need to allow the CHIPSEC driver, or use --no_driver for limited checks)
  • Python 3.8+ and a C compiler/build tools for the kernel module on Linux
  • Dedicated test hardware strongly recommended

Install CHIPSEC:

bash
# From PyPI
pip install chipsec

# Or from source (builds the kernel helper/driver)
git clone https://github.com/chipsec/chipsec
cd chipsec
python setup.py install        # builds and installs, including the Linux driver

# Verify
sudo chipsec_main --help
sudo chipsec_util --help

Objectives

  • Run the full automated platform-security test suite and interpret PASS/FAIL/WARNING
  • Verify BIOS write protection (BIOS_CNTL) and SPI Protected Ranges
  • Verify the SPI flash descriptor locks region read/write access
  • Verify SMRAM/SMRR and SMI handler protections
  • Verify Secure Boot variable protection and S3 boot-script protection
  • Dump SPI flash and decode it for offline analysis
  • Enumerate UEFI variables and detect anomalous/unexpected entries

MITRE ATT&CK Mapping

Technique IDNameTactic
T1542.001Pre-OS Boot: System FirmwarePersistence / Defense Evasion

CHIPSEC defends against T1542.001 by verifying that the controls preventing unauthorized firmware modification are enabled. A FAIL on common.bios_wp (BIOS not write-protected) or chipsec.modules.common.spi_lock (flash descriptor unlocked) means an attacker with OS privileges could rewrite the SPI flash and implant persistent firmware — exactly the precondition for this technique.

Workflow

Show full SKILL.md (336 more words)Show less
Step 1: Run the full automated test suite

chipsec_main with no module argument runs every applicable security check for the detected platform and prints a summary of PASS/FAIL/WARNING/INFORMATION results.

bash
sudo chipsec_main

# Save machine-readable output for reporting / diffing
sudo chipsec_main -j results.json -x results.xml -l chipsec.log
Step 2: Run the core firmware-protection modules individually

The common module group contains the OEM-independent security checks. Run the group or specific modules:

bash
# Run the whole common group
sudo chipsec_main -m common

# BIOS write protection: checks BIOS_CNTL BLE/SMM_BWP and SPI protected ranges
sudo chipsec_main -m common.bios_wp

# SPI flash descriptor lock (FLOCKDN) — are flash region accesses locked?
sudo chipsec_main -m common.spi_lock

# SMRR programming — protects SMRAM from cache-based attacks
sudo chipsec_main -m common.smrr

# SMM BIOS write protection
sudo chipsec_main -m common.smm

# S3 resume boot-script protection (against bootscript table attacks)
sudo chipsec_main -m common.uefi.s3bootscript
Step 3: Verify Secure Boot variable protection
bash
# Checks that Secure Boot UEFI variables are properly protected
sudo chipsec_main -m common.secureboot.variables

# To actively test write protection of the variables (test hardware ONLY):
sudo chipsec_main -m common.secureboot.variables -a modify
Step 4: Inspect SPI flash region access permissions
bash
# Report SPI flash regions, descriptor, and access permissions
sudo chipsec_util spi info

# Check the SPI access-control module
sudo chipsec_main -m common.spi_access
Step 5: Dump SPI flash for offline forensics

Dumping the flash lets you decode the firmware volumes and compare against a known-good OEM image.

bash
# Dump the entire SPI flash to a file
sudo chipsec_util spi dump rom.bin

# Decode the dumped image: extracts firmware volumes, files, NVRAM variables, etc.
sudo chipsec_util decode rom.bin
Step 6: Enumerate and triage UEFI variables
bash
# List all UEFI variables from the runtime interface
sudo chipsec_util uefi var-list

# List variables directly from the SPI image (offline)
sudo chipsec_util uefi var-find PK
sudo chipsec_util uefi var-read db <GUID> db.bin

# Decode the UEFI firmware structure
sudo chipsec_util uefi decode rom.bin
Step 7: Limited assessment without a kernel driver

Where loading the driver is impossible (locked-down Secure Boot), some checks still run read-only.

bash
sudo chipsec_main -n            # --no_driver: skip checks that need the driver
sudo chipsec_main -p <PLATFORM> # force platform code if auto-detect fails
Step 8: Triage results and report
  • FAIL on bios_wp / spi_lock → firmware is rewritable from the OS: high risk for T1542.001.
  • FAIL on secureboot.variables → Secure Boot policy can be tampered.
  • Compare the spi dump against the OEM's known-good image (hash firmware volumes) to detect unauthorized modification.
  • Record platform, BIOS version, and every FAIL/WARNING with the relevant register values for the report.

Tools and Resources

ToolPurposeSource
chipsec_mainAutomated platform-security test suitehttps://github.com/chipsec/chipsec
chipsec_utilManual hardware/firmware access (spi, uefi, decode)https://chipsec.github.io/
UEFIToolGUI/CLI parsing of dumped UEFI imageshttps://github.com/LongSoft/UEFITool
Binarly fwhuntFirmware vulnerability/implant hunting ruleshttps://github.com/binarly-io/fwhunt-scan
NSA UEFI Secure Boot guidanceHardening referencehttps://media.defense.gov/

Core Module Reference

ModuleChecks
common.bios_wpBIOS_CNTL BLE / SMM_BWP and SPI Protected Ranges
common.spi_lockSPI flash descriptor FLOCKDN
common.spi_accessSPI flash region read/write permissions
common.smrrSystem Management Range Registers programming
common.smmSMM BIOS write protection
common.secureboot.variablesSecure Boot variable protection
common.uefi.s3bootscriptS3 resume boot-script protection

Validation Criteria

  • CHIPSEC installed and driver loads (or -n documented if not)
  • Full chipsec_main suite executed with JSON/XML/log output saved
  • common.bios_wp result interpreted (write protection state)
  • common.spi_lock / spi_access result interpreted (descriptor lock)
  • SMRR/SMM module results recorded
  • Secure Boot variable protection checked
  • SPI flash dumped and decoded for offline analysis
  • UEFI variables enumerated and triaged
  • All FAIL/WARNING findings documented with platform/BIOS version
  • Write/modify modules NOT run on production hardware

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/auditing-uefi-firmware-with-chipsec of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Auditing Uefi Firmware With Chipsec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auditing Uefi Firmware With Chipsec compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auditing Uefi Firmware With Chipsec this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: NotesApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Auditing Uefi Firmware With Chipsec

What does Auditing Uefi Firmware With Chipsec do?

Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for…. Auditing Uefi Firmware With Chipsec is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI variables for firmware-level threats.

When should I use Auditing Uefi Firmware With Chipsec?

Auditing Uefi Firmware With Chipsec fits situations like: security work in your project.

How do I install Auditing Uefi Firmware With Chipsec in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-uefi-firmware-with-chipsec -a claude-code`. Or copy the skill folder (skills/auditing-uefi-firmware-with-chipsec in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/auditing-uefi-firmware-with-chipsec in your project. Claude Code loads it when a task matches its description.

How do I install Auditing Uefi Firmware With Chipsec in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-uefi-firmware-with-chipsec -a codex`. Or copy the skill folder (skills/auditing-uefi-firmware-with-chipsec in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/auditing-uefi-firmware-with-chipsec in your project. Codex loads it when a task matches its description.

Can I use Auditing Uefi Firmware With Chipsec in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-uefi-firmware-with-chipsec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-uefi-firmware-with-chipsec, .gemini/skills/auditing-uefi-firmware-with-chipsec, .github/skills/auditing-uefi-firmware-with-chipsec and .opencode/skills/auditing-uefi-firmware-with-chipsec in your project.

What does Auditing Uefi Firmware With Chipsec need to run?

Going by SKILL.md and its folder, Auditing Uefi Firmware With Chipsec needs Python for the scripts in its folder and the command-line tools its instructions call (pip, git and python). Our summary lists: Python 3.

Does Auditing Uefi Firmware With Chipsec access the network?

SKILL.md names 3 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: chipsec.github.io and media.defense.gov. This is read from the text; nothing was executed.

Is Auditing Uefi Firmware With Chipsec safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Auditing Uefi Firmware With Chipsec use?

Auditing Uefi Firmware With Chipsec is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auditing Uefi Firmware With Chipsec use?

About 2.3k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 930 tokens, read only when the agent opens those files.

What are the alternatives to Auditing Uefi Firmware With Chipsec?

Skills that share tags, products or a category with Auditing Uefi Firmware With Chipsec: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars) and Security Alert Triage (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auditing Uefi Firmware With Chipsec?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.