Agent skill

Conducting Phishing Incident Response

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Respond to phishing incidents by analyzing reported emails, extracting indicators, sandboxing URLs/attachments, assessing credential compromise, quarantining malicious messages organization-wide…

Apache-2.0Auto-check passedDevOps & Cloud

Install Conducting Phishing Incident Response

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-phishing-incident-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills conducting-phishing-incident-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/conducting-phishing-incident-response .claude/skills/conducting-phishing-incident-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
conducting-phishing-incident-response
GitHub stars
34k
Token cost
~2.9k tokens
SKILL.md length
1,016 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Respond to phishing incidents by analyzing reported emails, extracting indicators, sandboxing URLs/attachments, assessing credential compromise, quarantining malicious messages organization-wide…

  • Works in 6 steps: Receive and Triage the Phishing Report → Analyze Malicious Content → Determine Scope of Impact → …
  • Investigating a reported phishing
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Conducting Phishing Incident Response is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Respond to phishing incidents by analyzing reported emails, extracting indicators, sandboxing URLs/attachments, assessing credential compromise, quarantining malicious messages organization-wide, and remediating affected accounts. Use when investigating a reported phishing or credential-phishing email, a suspected spearphishing incident, or when a mailbox-wide purge and account remediation is needed.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in DevOps & Cloud, covering Incident response. It works with Microsoft 365. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Investigating a reported phishing
  • Credential-phishing email
  • A suspected spearphishing incident
  • A mailbox-wide purge and account remediation is needed

Example prompts

  • “/conducting-phishing-incident-response”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Receive and Triage the Phishing Report
  2. Analyze Malicious Content
  3. Determine Scope of Impact
  4. Contain the Threat
  5. Eradicate and Recover
  6. Post-Incident Actions

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Conducting Phishing Incident Response loads about 2.9k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 110 tokens; SKILL.md has 1,016 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~110
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,016 words, ~2,947 tokens.

Download SKILL.mdSave it as .claude/skills/conducting-phishing-incident-response/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
conducting-phishing-incident-response
description
Respond to phishing incidents by analyzing reported emails, extracting indicators, sandboxing URLs/attachments, assessing credential compromise, quarantining malicious messages organization-wide, and remediating affected accounts. Use when investigating a reported phishing or credential-phishing email, a suspected spearphishing incident, or when a mailbox-wide purge and account remediation is needed.
domain
cybersecurity
subdomain
incident-response
tags
phishing-response, email-security, credential-compromise, email-header-analysis, mailbox-remediation
mitre_attack
T1566.001, T1566.002, T1204.002, T1204.001, T1114, T1056.003
mitre_f3.version
1.1
mitre_f3.tactics
initial-access, reconnaissance, resource-development, positioning
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
RS.MA-01, RS.MA-02, RS.AN-03, RC.RP-01

Conducting Phishing Incident Response

When to Use

  • A user reports receiving a suspicious email via the phishing report button or abuse mailbox
  • Email gateway detects a malicious email that bypassed initial filtering
  • Threat intelligence indicates an active phishing campaign targeting the organization
  • A user confirms they clicked a link or opened an attachment from a suspicious email
  • Credentials have been entered on a suspected phishing page

Do not use for business email compromise (BEC) involving compromised internal accounts; use BEC response procedures which focus on account takeover investigation.

Prerequisites

  • Email security gateway with message trace and quarantine capabilities (Microsoft Defender for Office 365, Proofpoint, Mimecast)
  • Microsoft 365 admin access or Google Workspace admin for mailbox search and purge
  • Malware sandbox for attachment and URL analysis (ANY.RUN, Joe Sandbox, Hybrid Analysis)
  • Email header analysis tools (MXToolbox Header Analyzer, Google Admin Toolbox)
  • Identity provider access for account remediation (Azure AD, Okta, Duo)
  • Phishing report intake process (dedicated mailbox or integrated report button)

Workflow

Step 1: Receive and Triage the Phishing Report

Evaluate the reported email to determine if it is malicious:

  • Extract the email as an .EML or .MSG file (preserves headers)
  • Analyze email headers to determine the true sender, relay path, and authentication results
Email Header Analysis Checklist:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Return-Path:     billing@spoofed-domain[.]com
From:            "IT Support" <support@corp-lookalike[.]com>
Reply-To:        attacker@gmail[.]com (different from From)
SPF:             FAIL (sender IP not authorized for domain)
DKIM:            FAIL (signature invalid)
DMARC:           FAIL (policy: none - no enforcement)
Received:        from mail.attacker-infra[.]net [45.33.x.x]
X-Originating-IP: 45.33.x.x
Message-ID:      <random@attacker-infra.net>

Classification criteria:

  • Confirmed Phishing: Malicious URL/attachment, spoofed sender, credential harvesting page
  • Suspicious: Anomalous headers but no confirmed malicious content
  • Spam/Marketing: Unwanted but not malicious
  • Legitimate: Not a phishing email (false report)
Step 2: Analyze Malicious Content

Examine URLs and attachments in a safe environment:

URL Analysis:

  • Check URL against VirusTotal, URLscan.io, and Google Safe Browsing
  • Open URL in a sandbox browser to capture the landing page
  • Check if the URL redirects to a credential harvesting page
  • Identify the phishing kit type (Microsoft 365 login clone, Okta clone, generic)
  • Determine if the phishing page is still active

Attachment Analysis:

  • Calculate file hash (SHA-256) and check against VirusTotal
  • Detonate in sandbox (ANY.RUN, Joe Sandbox)
  • Analyze document for macros (olevba for Office files)
  • Check for embedded exploits (CVE exploitation in document parsers)
Step 3: Determine Scope of Impact

Identify all recipients and assess who interacted with the phishing email:

Scope Assessment:
━━━━━━━━━━━━━━━━
Total Recipients:     47 users
Delivered to Inbox:   38 users (9 caught by email gateway)
Opened Email:         24 users (email tracking pixel data)
Clicked Link:         8 users (proxy/firewall logs)
Entered Credentials:  3 users (phishing page submitted form data)
Opened Attachment:    2 users (EDR process execution telemetry)

Search methods:

  • Microsoft 365: Use Threat Explorer or Content Search to find all instances of the email
  • Google Workspace: Use Admin Console > Investigation tool for message search
  • Proxy logs: Search for connections to the phishing URL from internal IPs
  • EDR: Search for attachment file hash execution across all endpoints
Step 4: Contain the Threat

Execute containment actions based on impact assessment:

Email Containment:

  • Purge the phishing email from all mailboxes using Microsoft 365 Content Search and Purge or Google Workspace Admin delete
  • Block the sender domain at the email gateway
  • Add the phishing URL to the web proxy blocklist
  • Add attachment hash to email gateway and EDR blocklists

Account Containment (for users who entered credentials):

  • Force password reset immediately
  • Revoke all active sessions and OAuth tokens
  • Enable or re-verify MFA enrollment
  • Review mailbox rules for attacker-created forwarding rules
  • Check for unauthorized OAuth application grants
  • Review recent sign-in activity for suspicious locations
powershell
# Microsoft 365: Revoke sessions and reset password
Connect-AzureAD
Revoke-AzureADUserAllRefreshToken -ObjectId "user@corp.com"
Set-AzureADUserPassword -ObjectId "user@corp.com" -ForceChangePasswordNextLogin $true

# Check for mailbox forwarding rules
Get-InboxRule -Mailbox "user@corp.com" | Where-Object {$_.ForwardTo -or $_.RedirectTo}

# Remove suspicious forwarding rules
Remove-InboxRule -Mailbox "user@corp.com" -Identity "Rule Name"
Step 5: Eradicate and Recover

Remove all traces of the phishing attack:

  • Confirm email purge completed successfully across all mailboxes
  • Verify compromised accounts have been secured (password changed, sessions revoked, MFA verified)
  • Remove any malware installed via phishing attachments from affected endpoints
  • Monitor compromised accounts for 72 hours for signs of continued unauthorized access
  • Check for data exfiltration from compromised accounts during the exposure window
Step 6: Post-Incident Actions

Strengthen defenses against similar phishing attacks:

  • Report the phishing URL to Google Safe Browsing and Microsoft SmartScreen
  • Submit the phishing domain for takedown via the domain registrar abuse contact
  • Update email gateway filtering rules based on observed evasion techniques
  • Send targeted security awareness notification to affected users
  • Update phishing simulation program to include the observed technique
Show full SKILL.md (391 more words)Show less

Key Concepts

TermDefinition
Spear PhishingTargeted phishing attack crafted for a specific individual or organization using personalized content
Credential HarvestingPhishing technique that mimics a legitimate login page to capture usernames and passwords
SPF (Sender Policy Framework)Email authentication protocol that specifies which mail servers are authorized to send email for a domain
DKIM (DomainKeys Identified Mail)Email authentication method using cryptographic signatures to verify that an email was not altered in transit
DMARCPolicy framework that uses SPF and DKIM to determine email authenticity and instructs receivers on handling failures
OAuth Consent PhishingAttack that tricks users into granting malicious OAuth applications access to their email and data
Email HeaderMetadata embedded in every email containing routing, authentication, and sender information used for forensic analysis

Tools & Systems

  • Microsoft Defender for Office 365: Email threat protection with Threat Explorer for investigation and automated purge
  • Proofpoint TAP (Targeted Attack Protection): Email security platform with URL rewriting and attachment sandboxing
  • URLscan.io: Online service that scans URLs and captures screenshots of phishing pages for evidence
  • PhishTool: Phishing analysis platform that automates header analysis, URL inspection, and IOC extraction
  • GoPhish: Open-source phishing simulation platform for security awareness testing

Common Scenarios

Scenario: Microsoft 365 Credential Phishing via QR Code

Context: Users report an email claiming to be from IT requiring MFA re-enrollment. The email contains a QR code that links to a convincing Microsoft 365 login page clone hosted on a compromised WordPress site.

Approach:

  1. Scan the QR code in a sandbox to extract the URL
  2. Analyze the phishing page: captures credentials and MFA tokens (adversary-in-the-middle attack)
  3. Search email gateway for all recipients using message subject and sender as search criteria
  4. Cross-reference with proxy logs to identify users who visited the phishing URL
  5. Force password reset and revoke sessions for all users who visited the URL
  6. Purge the email from all mailboxes and block the sender domain
  7. Notify users about the specific campaign with visual examples of the phishing email

Pitfalls:

  • Not checking for adversary-in-the-middle (AiTM) capability that captures session tokens even with MFA
  • Only resetting passwords without revoking active sessions (attacker retains access via stolen session cookies)
  • Not searching for mailbox forwarding rules created by the attacker after compromising an account
  • Missing QR code phishing (quishing) because URL scanning tools cannot decode QR code images

Output Format

PHISHING INCIDENT RESPONSE REPORT
===================================
Incident:          INC-2025-1602
Date Reported:     2025-11-16T09:15:00Z
Reported By:       jdoe@corp.example.com
Classification:    Credential Phishing (AiTM)

EMAIL ANALYSIS
Subject:       "Action Required: MFA Re-enrollment"
Sender:        it-support@corp-security[.]com (spoofed)
SPF:           FAIL | DKIM: FAIL | DMARC: FAIL
Phishing URL:  hxxps://compromised-site[.]com/ms365/login
Phishing Type: Microsoft 365 AiTM credential harvester

IMPACT ASSESSMENT
Recipients:        47
Clicked Link:      8
Credentials Entered: 3 (confirmed via proxy POST data)

CONTAINMENT ACTIONS
[x] Email purged from all 47 mailboxes
[x] Phishing domain blocked at web proxy
[x] Sender domain blocked at email gateway
[x] 3 compromised accounts: passwords reset, sessions revoked
[x] Mailbox forwarding rules reviewed (1 malicious rule removed)
[x] OAuth app grants reviewed (no unauthorized grants found)

IOCs EXTRACTED
Domain:  corp-security[.]com
URL:     hxxps://compromised-site[.]com/ms365/login
IP:      104.21.x.x (Cloudflare-hosted)
Sender:  it-support@corp-security[.]com

RECOMMENDATIONS
1. Implement DMARC enforcement (p=reject) for corp domain
2. Deploy QR code scanning in email gateway
3. Send targeted awareness notification to all 47 recipients
4. Request domain takedown via registrar abuse contact

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/conducting-phishing-incident-response of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Conducting Phishing Incident Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Conducting Phishing Incident Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Conducting Phishing Incident Response this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Responding To Incidentstrilwu/secskills157—~3.9kAutomated safety check: NotesMIT
Sentinelvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Kubernetes Network Root Cause Analysiskubeshark/kubeshark12k—~5.3kAutomated safety check: PassApache-2.0
UModel Root Cause Analysisalibaba/UnifiedModel415—~1.9kAutomated safety check: PassCustom licence
Learningskortix-ai/suna20k—~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Responding To Incidents

    trilwu/secskills

    Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…

    157 GitHub stars~3.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Sentinel

    vinayaklatthe/microsoft-security-skills

    Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.

    12k GitHub stars~5.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • UModel Root Cause Analysis

    alibaba/UnifiedModel

    Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments.

    415 GitHub stars~1.9k tokensUpdated 17 days ago
    DevOps & CloudAuto-check passed
  • Learnings

    kortix-ai/suna

    The project's episodic memory: a timestamped ledger of rules paid for with real outages and near-misses, one entry per incident.

    20k GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Nix Config Debug

    ryan4yin/nix-config

    A skill your agent uses when something here is broken or stops working: an eval or build error, a failed activation, a dead or restarting unit, a mihomo or DNS outage, an unreachable host or MicroVM…

    2.1k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Conducting Phishing Incident Response

What does Conducting Phishing Incident Response do?

Respond to phishing incidents by analyzing reported emails, extracting indicators, sandboxing URLs/attachments, assessing credential compromise, quarantining malicious messages organization-wide…. Conducting Phishing Incident Response is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Respond to phishing incidents by analyzing reported emails, extracting indicators, sandboxing URLs/attachments, assessing credential compromise, quarantining malicious messages organization-wide, and remediating affected accounts.

When should I use Conducting Phishing Incident Response?

Conducting Phishing Incident Response fits situations like: investigating a reported phishing; credential-phishing email; A suspected spearphishing incident; A mailbox-wide purge and account remediation is needed.

How do I install Conducting Phishing Incident Response in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-phishing-incident-response -a claude-code`. Or copy the skill folder (skills/conducting-phishing-incident-response in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/conducting-phishing-incident-response in your project. Claude Code loads it when a task matches its description.

How do I install Conducting Phishing Incident Response in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-phishing-incident-response -a codex`. Or copy the skill folder (skills/conducting-phishing-incident-response in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/conducting-phishing-incident-response in your project. Codex loads it when a task matches its description.

Can I use Conducting Phishing Incident Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-phishing-incident-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/conducting-phishing-incident-response, .gemini/skills/conducting-phishing-incident-response, .github/skills/conducting-phishing-incident-response and .opencode/skills/conducting-phishing-incident-response in your project.

What does Conducting Phishing Incident Response need to run?

Going by SKILL.md and its folder, Conducting Phishing Incident Response needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Conducting Phishing Incident Response access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Conducting Phishing Incident Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Conducting Phishing Incident Response use?

Conducting Phishing Incident Response is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Conducting Phishing Incident Response use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 503 tokens, read only when the agent opens those files.

What are the alternatives to Conducting Phishing Incident Response?

Skills that share tags, products or a category with Conducting Phishing Incident Response: Responding To Incidents (trilwu/secskills, 157 stars), Sentinel (vinayaklatthe/microsoft-security-skills, 175 stars), Kubernetes Network Root Cause Analysis (kubeshark/kubeshark, 12k stars) and UModel Root Cause Analysis (alibaba/UnifiedModel, 415 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Conducting Phishing Incident Response?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.