Agent skill

Deploying Cloud Deception With Decoy Resources

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…

Apache-2.0Auto-check passedDevOps & Cloud

Install Deploying Cloud Deception With Decoy Resources

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-cloud-deception-with-decoy-resources -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills deploying-cloud-deception-with-decoy-resources --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deploying-cloud-deception-with-decoy-resources .claude/skills/deploying-cloud-deception-with-decoy-resources && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deploying-cloud-deception-with-decoy-resources
GitHub stars
34k
Token cost
~2.8k tokens
SKILL.md length
1,099 words
Files
5 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…

  • Works in 4 steps: Decide what to mimic → Centralize and de-duplicate → Validate (red-team the decoys) → …
  • Protecting cloud accounts and data stores
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls aws, gcloud and gsutil

What it does

Deploying Cloud Deception With Decoy Resources is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access keys, permission-less decoy users/roles/service principals, honey object-storage buckets, and decoy secrets in Secrets Manager / Key Vault / Secret Manager. Wires detection through CloudTrail + EventBridge, Azure Sentinel honeytoken watchlists + Defender, and GCP Cloud Audit Logs, so any use of a decoy is routed to…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `scripts/process.py`).

It sits in DevOps & Cloud, covering Deployment, Red teaming and adversary simulation and Secrets management. It works with Amazon Web Services, Google Cloud, Microsoft Azure and Amazon S3. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Protecting cloud accounts and data stores
  • An org has only on-prem honeypots and needs cloud coverage
  • Seeding fake AWS keys to catch credential theft and code-leak exposure
  • Detecting cloud reconnaissance and lateral movement

Example prompts

  • “/deploying-cloud-deception-with-decoy-resources”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Decide what to mimic
  2. Centralize and de-duplicate
  3. Validate (red-team the decoys)
  4. Maintain realism and rotate

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • gcloud
    • gsutil

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • canarytokens.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deploying Cloud Deception With Decoy Resources loads about 2.8k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 266 tokens; SKILL.md has 1,099 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~266
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,099 words, ~2,801 tokens.

Download SKILL.mdSave it as .claude/skills/deploying-cloud-deception-with-decoy-resources/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
deploying-cloud-deception-with-decoy-resources
description
Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access keys, permission-less decoy users/roles/service principals, honey object-storage buckets, and decoy secrets in Secrets Manager / Key Vault / Secret Manager. Wires detection through CloudTrail + EventBridge, Azure Sentinel honeytoken watchlists + Defender, and GCP Cloud Audit Logs, so any use of a decoy is routed to the SOC with near-zero false positives. Use when protecting cloud accounts and data stores, when an org has only on-prem honeypots and needs cloud coverage, when seeding fake AWS keys to catch credential theft and code-leak exposure, or when detecting cloud reconnaissance and lateral movement. Keywords: cloud deception, canary token AWS, honey S3 bucket, decoy IAM credentials, CloudTrail alert, GuardDuty, Sentinel honeytoken, decoy secret, honey service account, cloud honeypot, breach detection.
domain
cybersecurity
subdomain
deception-technology
tags
cloud-deception, aws, azure, gcp, canary-token, honeytoken, cloudtrail, breach-detection
version
1.0
author
andrewibrah
license
Apache-2.0
nist_csf
DE.CM-01, DE.CM-06, DE.AE-02, ID.RA-01, RS.MA-01
mitre_attack
T1078, T1552, T1580, T1530, T1619

Deploying Cloud Deception with Decoy Resources

When to Use

  • When cloud accounts (AWS/Azure/GCP) hold crown-jewel data or infrastructure and you need a tripwire that fires the moment an attacker who has gained access starts to operate.
  • When the only deception in place is on-prem honeypots, leaving the cloud control plane uninstrumented.
  • When seeding fake credentials to catch credential theft, accidental code-repo leaks, or secrets exposed in build pipelines.
  • When detecting cloud reconnaissance (enumeration of IAM, storage, or secrets) and lateral movement that legitimate users would never perform.
  • When you want detections that survive into incident response with strong fidelity — a touch on a decoy resource almost always means malicious or unauthorized activity.

This is the cloud counterpart to on-prem honeypot/honeytoken/canary-token deployment skills. For program strategy and how these Activities map to adversary engagement goals, use designing-adversary-engagement-with-mitre-engage.

Prerequisites

  • Cloud admin/IAM permissions to create decoy principals, storage, secrets, and detection wiring, ideally in a dedicated deployment role with least privilege.
  • Cloud audit logging already enabled: AWS CloudTrail (multi-region, with management and relevant data events), Azure Activity log + Microsoft Entra audit/sign-in logs, GCP Cloud Audit Logs (Admin Activity always on; Data Access enabled where needed).
  • A SIEM/alert sink: SNS topic, Microsoft Sentinel workspace, or GCP Pub/Sub + Monitoring, with routing to the SOC.
  • A naming and tagging convention that is plausible to an attacker but unambiguous to defenders internally (e.g., realistic names, plus an internal deception=true tag/label kept out of attacker-visible metadata).
  • Decoy principals must be permission-less (explicit deny-all). The value is the alert, never the access. A decoy that grants real privilege is a liability, not a control.

Workflow

1. Decide what to mimic

Pick decoys that match how your attackers operate: leaked AWS keys (credential theft), an "admin" S3 bucket (data discovery), a prod-db-password secret (secrets harvesting), a privileged-looking service account (cloud lateral movement). Place credential decoys where harvesting tools look: env files, CI variables, code comments, an internal wiki.

2A. AWS — canary access keys on a permission-less user

Create a decoy IAM user with an explicit deny-all policy, then issue an access key to plant:

bash
aws iam create-user --user-name svc-backup-prod --tags Key=deception,Value=true
aws iam put-user-policy --user-name svc-backup-prod \
  --policy-name deny-all \
  --policy-document '{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"*","Resource":"*"}]}'
aws iam create-access-key --user-name svc-backup-prod   # plant the returned AccessKeyId/Secret

Any use of this key appears in CloudTrail (even denied calls, which still log AccessDenied). Wire an EventBridge rule on CloudTrail to alert:

bash
aws events put-rule --name decoy-key-used \
  --event-pattern '{"detail":{"userIdentity":{"userName":["svc-backup-prod"]}}}'
aws events put-targets --rule decoy-key-used \
  --targets "Id"="1","Arn"="arn:aws:sns:us-east-1:111111111111:soc-deception-alerts"
2B. AWS — honey S3 bucket

Create a believable bucket, enable object-level data events, and alert on any read/list:

bash
aws s3api create-bucket --bucket acme-prod-db-backups-2026 --region us-east-1
aws s3api put-bucket-tagging --bucket acme-prod-db-backups-2026 \
  --tagging 'TagSet=[{Key=deception,Value=true}]'
# Ensure CloudTrail captures S3 data events for this bucket, then alert on GetObject/ListBucket
aws events put-rule --name decoy-bucket-access \
  --event-pattern '{"detail":{"eventSource":["s3.amazonaws.com"],"requestParameters":{"bucketName":["acme-prod-db-backups-2026"]}}}'
2C. AWS — decoy secret
bash
aws secretsmanager create-secret --name prod/db/master-password \
  --secret-string '{"username":"dbadmin","password":"DECOY-DO-NOT-USE"}' \
  --tags Key=deception,Value=true
# Alert on GetSecretValue for this secret via EventBridge -> SNS
3A. Azure — honeytoken watchlist + decoy service principal

Microsoft Sentinel natively supports honeytokens via a Watchlist of the HoneyTokens template; tagged decoy accounts/secrets raise analytics alerts on use. Create a permission-less decoy app registration / service principal, then add its identifiers to the HoneyTokens watchlist and enable the related analytics rules. Microsoft Defender for Cloud and Entra ID Protection surface anomalous sign-ins to the decoy identity.

3B. Azure — honey storage + Key Vault decoy secret

Create a decoy Storage account and Key Vault, enable diagnostic logging to the Sentinel workspace, store a decoy secret, and write an analytics rule that fires on any data-plane read of the decoy resources.

4A. GCP — decoy service account + honey GCS bucket

Create a service account with no role bindings (permission-less), generate a key to plant, and alert on its use via Cloud Audit Logs:

bash
gcloud iam service-accounts create svc-billing-export \
  --display-name="billing-export"
gcloud iam service-accounts keys create decoy-key.json \
  --iam-account=svc-billing-export@PROJECT.iam.gserviceaccount.com   # plant this key
gsutil mb -b on gs://acme-finance-exports-2026

Create a log-based metric + alerting policy in Cloud Monitoring that triggers on any audit-log entry where the principal is the decoy service account or the resource is the honey bucket.

5. Centralize and de-duplicate

Route all clouds' decoy alerts to one SOC pipeline. Tag each alert as DECEPTION/high-fidelity so it bypasses normal noise filtering and triggers an IR playbook rather than a triage queue.

6. Validate (red-team the decoys)

Have an authorized tester use each decoy (read the bucket, call with the key, fetch the secret) and confirm an alert lands end-to-end within target latency. A decoy you have not tested is assumed broken.

7. Maintain realism and rotate

Refresh decoy names, secrets, and pocket-litter periodically so they age with the real environment. Track every decoy in an inventory so they are never mistaken for real assets during audits or cleanups.

Show full SKILL.md (432 more words)Show less

Key Concepts

ConceptDefinition
Decoy / honey resourceA cloud object created solely to be touched by an attacker; no legitimate user has any reason to use it.
Canary access keyA planted credential whose use generates an audit-log event; carries deny-all permissions.
High-fidelity alertA near-zero-false-positive signal because legitimate workflows never reference the decoy.
Permission-less principalA decoy IAM user/role/service principal/service account with explicit deny-all or no role bindings.
Data eventCloud audit logging of object/data-plane access (e.g., S3 GetObject), required to detect storage decoys.
Pocket litterPlausible supporting artifacts (fake configs, env files, wiki entries) that make a decoy credible.
Decoy inventoryThe authoritative internal record distinguishing decoys from real assets.

Tools & Systems

  • AWS — IAM (decoy users/roles), S3 (honey buckets, data events), Secrets Manager / SSM Parameter Store (decoy secrets), CloudTrail, EventBridge, SNS/Lambda, GuardDuty (correlate anomalous use).
  • Azure — Microsoft Entra ID (decoy app registrations / service principals), Storage / Key Vault decoys, Microsoft Sentinel HoneyTokens watchlist and analytics rules, Microsoft Defender for Cloud, Entra ID Protection.
  • GCP — IAM service accounts (decoys), Cloud Storage (honey buckets), Secret Manager (decoy secrets), Cloud Audit Logs, log-based metrics + Cloud Monitoring alerting, Pub/Sub.
  • Open-source / managed honeytoken systems — Canarytokens (https://canarytokens.org offers AWS API key tokens), Thinkst Canary, SpaceSiren / SpaceCrab (self-hosted AWS honey-token frameworks).
  • SIEM/SOAR — to centralize alerts across clouds and drive an IR playbook on any decoy hit.

Common Scenarios

  • Credential-theft / code-leak detection. Plant a canary AWS key in CI variables, an env file, and a private repo. Any external use (even from a leaked public push) fires within minutes.
  • Crown-jewel data store. Stand up a honey "backups" bucket next to the real one; attackers enumerating storage hit the decoy first and reveal themselves.
  • Cloud lateral movement. A permission-less decoy service principal that "looks" privileged catches adversaries assuming roles during pivoting.
  • Secrets harvesting. Decoy entries in Secrets Manager / Key Vault / Secret Manager detect tools scraping the secrets store.
  • Migrating from on-prem-only deception. Mirror the existing on-prem decoy strategy into the cloud control plane so coverage follows workloads.

Output Format

Produce a Cloud Deception Deployment Record using assets/template.md, containing:

  1. Decoy inventory — per decoy: cloud, type, plausible name, real placement location of any planted credential, internal deception tag/label, owner.
  2. Detection wiring — per decoy: audit-log source → rule/pattern → alert sink → IR playbook reference, with the target alert latency.
  3. Least-privilege proof — evidence each decoy principal is deny-all / no-role-binding.
  4. Validation results — date tested, who tested, end-to-end latency observed, pass/fail.
  5. Maintenance plan — rotation cadence and review owner.

Use scripts/process.py to render the deployment record and a per-decoy detection checklist from a decoy-inventory JSON, and to flag decoys missing detection wiring or validation.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/deploying-cloud-deception-with-decoy-resources of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/standards.md
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Deploying Cloud Deception With Decoy Resources next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deploying Cloud Deception With Decoy Resources compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deploying Cloud Deception With Decoy Resources this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
CD Pipeline GeneratorArabelaTso/Skills-4-SE253—~1.3kAutomated safety check: PassApache-2.0
Kcli Cluster Deploymentkarmab/kcli653—~1.5kAutomated safety check: PassApache-2.0
Cloud Auditbriiirussell/cybersecurity-skills413—~1.3kAutomated safety check: NotesMIT
Cloud Infrastructureaiskillstore/marketplace4301 repos~1.3kAutomated safety check: PassNone
Gamma Deploy Integrationjeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMIT

Similar skills

  • CD Pipeline Generator

    ArabelaTso/Skills-4-SE

    Generate GitHub Actions deployment workflows for automated deployment to staging and production environments on cloud platforms (AWS, GCP, Azure).

    253 GitHub stars~1.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Cloud Infrastructure

    aiskillstore/marketplace

    Cloud infrastructure design and deployment patterns for AWS, Azure, and GCP.

    430 GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Gamma Deploy Integration

    jeremylongshore/tons-of-skills-marketplace

    Deploy Gamma-integrated applications to production environments.

    2.8k GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloud Defense

    transilienceai/communitytools

    Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step.

    562 GitHub stars~476 tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Deploying Cloud Deception With Decoy Resources

What does Deploying Cloud Deception With Decoy Resources do?

Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…. Deploying Cloud Deception With Decoy Resources is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access keys, permission-less decoy users/roles/service principals, honey object-storage buckets, and decoy secrets in Secrets Manager / Key Vault / Secret Manager.

When should I use Deploying Cloud Deception With Decoy Resources?

Deploying Cloud Deception With Decoy Resources fits situations like: protecting cloud accounts and data stores; an org has only on-prem honeypots and needs cloud coverage; seeding fake AWS keys to catch credential theft and code-leak exposure; detecting cloud reconnaissance and lateral movement.

How do I install Deploying Cloud Deception With Decoy Resources in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-cloud-deception-with-decoy-resources -a claude-code`. Or copy the skill folder (skills/deploying-cloud-deception-with-decoy-resources in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/deploying-cloud-deception-with-decoy-resources in your project. Claude Code loads it when a task matches its description.

How do I install Deploying Cloud Deception With Decoy Resources in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-cloud-deception-with-decoy-resources -a codex`. Or copy the skill folder (skills/deploying-cloud-deception-with-decoy-resources in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/deploying-cloud-deception-with-decoy-resources in your project. Codex loads it when a task matches its description.

Can I use Deploying Cloud Deception With Decoy Resources in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-cloud-deception-with-decoy-resources -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deploying-cloud-deception-with-decoy-resources, .gemini/skills/deploying-cloud-deception-with-decoy-resources, .github/skills/deploying-cloud-deception-with-decoy-resources and .opencode/skills/deploying-cloud-deception-with-decoy-resources in your project.

What does Deploying Cloud Deception With Decoy Resources need to run?

Going by SKILL.md and its folder, Deploying Cloud Deception With Decoy Resources needs Python for the scripts in its folder and the command-line tools its instructions call (aws, gcloud and gsutil). Our summary lists: Python 3.

Does Deploying Cloud Deception With Decoy Resources access the network?

SKILL.md names 1 domain. As links in the text: canarytokens.org. This is read from the text; nothing was executed.

Is Deploying Cloud Deception With Decoy Resources safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Deploying Cloud Deception With Decoy Resources use?

Deploying Cloud Deception With Decoy Resources is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deploying Cloud Deception With Decoy Resources use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.

What are the alternatives to Deploying Cloud Deception With Decoy Resources?

Skills that share tags, products or a category with Deploying Cloud Deception With Decoy Resources: CD Pipeline Generator (ArabelaTso/Skills-4-SE, 253 stars), Kcli Cluster Deployment (karmab/kcli, 653 stars), Cloud Audit (briiirussell/cybersecurity-skills, 413 stars) and Cloud Infrastructure (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deploying Cloud Deception With Decoy Resources?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.