Agent skill

Deploying Software Defined Perimeter

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Deploys a Software-Defined Perimeter per the CSA v2.0 specification, configuring Single Packet Authorization, mutual TLS, and SDP controller/gateway components to enforce zero trust network access.

Apache-2.0Auto-check passedSecurity

Install Deploying Software Defined Perimeter

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-software-defined-perimeter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills deploying-software-defined-perimeter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deploying-software-defined-perimeter .claude/skills/deploying-software-defined-perimeter && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deploying-software-defined-perimeter
GitHub stars
34k
Token cost
~1.9k tokens
SKILL.md length
766 words
Files
8 (incl. scripts, references, assets)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploys a Software-Defined Perimeter per the CSA v2.0 specification, configuring Single Packet Authorization, mutual TLS, and SDP controller/gateway components to enforce zero trust network access.

  • Works in 4 steps: SDP Controller Deployment → SDP Gateway Deployment → Client Deployment → …
  • Hardening zero trust network architecture
  • SKILL.md covers Prerequisites, Overview, When to Use and Prerequisites, plus 5 more sections
  • Runs Python scripts from its folder

What it does

Deploying Software Defined Perimeter is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys a Software-Defined Perimeter per the CSA v2.0 specification, configuring Single Packet Authorization, mutual TLS, and SDP controller/gateway components to enforce zero trust network access. Use when building or hardening zero trust network architecture, implementing SPA-based "invisible" infrastructure that cloaks services from unauthenticated scanning, or meeting compliance requirements for zero trust network access.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Authorization and RBAC. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Hardening zero trust network architecture
  • Implementing SPA-based invisible infrastructure that cloaks services from unauthenticated scanning
  • Meeting compliance requirements for zero trust network access

Example prompts

  • “invisible”
  • “Use the deploying-software-defined-perimeter skill to deploy a Software-Defined Perimeter per the CSA v2.0 specification, configuring Single Packet…”
  • “/deploying-software-defined-perimeter”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. SDP Controller Deployment
  2. SDP Gateway Deployment
  3. Client Deployment
  4. Operational Validation

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deploying Software Defined Perimeter loads about 1.9k tokens when it runs, and up to ~4.4k if it reads all its reference files. Until then it costs about 117 tokens; SKILL.md has 766 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 766 words, ~1,938 tokens.

Download SKILL.mdSave it as .claude/skills/deploying-software-defined-perimeter/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
deploying-software-defined-perimeter
description
Deploys a Software-Defined Perimeter per the CSA v2.0 specification, configuring Single Packet Authorization, mutual TLS, and SDP controller/gateway components to enforce zero trust network access. Use when building or hardening zero trust network architecture, implementing SPA-based "invisible" infrastructure that cloaks services from unauthenticated scanning, or meeting compliance requirements for zero trust network access.
domain
cybersecurity
subdomain
zero-trust-architecture
tags
zero-trust, sdp, software-defined-perimeter, network-access, ztna
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.AA-01, PR.AA-05, PR.IR-01, GV.PO-01
mitre_attack
T1133, T1078, T1021, T1046, T1190

Deploying Software-Defined Perimeter

Prerequisites

  • Understanding of zero trust principles (NIST SP 800-207)
  • Knowledge of CSA Software-Defined Perimeter specification
  • Familiarity with PKI and mutual TLS authentication
  • Experience with network security architecture

Overview

A Software-Defined Perimeter (SDP) implements zero trust by creating a dynamically provisioned, identity-centric perimeter around individual resources. Defined by the Cloud Security Alliance (CSA), SDP makes application infrastructure invisible to unauthorized users through a "dark cloud" approach where services are hidden until authenticated and authorized. Unlike traditional VPN, SDP establishes one-to-one encrypted connections between verified users and specific applications.

This skill covers deploying SDP using the CSA v2.0 specification, implementing Single Packet Authorization (SPA), configuring the SDP controller and gateway, and validating the deployment against NIST SP 800-207 requirements.

When to Use

  • When deploying or configuring deploying software defined perimeter capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with zero trust architecture concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Architecture

SDP Components (CSA Specification)
┌─────────────────────┐
│ SDP Controller       │
│ - Authentication     │
│ - Authorization      │
│ - Policy management  │
│ - Key management     │
└──────────┬──────────┘
           │
    ┌──────┴──────┐
    │             │
    v             v
┌────────┐  ┌────────────┐
│ IH     │  │ AH         │
│(Client)│  │(Gateway)   │
│        │  │            │
│ SPA    │──│ Protected  │
│ mTLS   │  │ Resources  │
└────────┘  └────────────┘

IH = Initiating Host (User Device)
AH = Accepting Host (Application Gateway)
SPA = Single Packet Authorization
SDP Deployment Models
  1. Client-to-Gateway: User device connects through SDP gateway to backend applications
  2. Client-to-Server: Direct connection between user and application server
  3. Server-to-Server: Workload-to-workload communication through SDP
  4. Gateway-to-Gateway: Site-to-site connectivity replacing traditional VPN tunnels

Key Concepts

Single Packet Authorization (SPA)

SPA is a network security mechanism where the SDP gateway drops all TCP/UDP packets by default. A cryptographically signed single packet must be sent before any connection is established. The gateway validates the SPA packet, and only then opens a temporary port for the authenticated session. This makes the gateway invisible to port scanners.

Mutual TLS (mTLS)

After SPA validation, both the client and server authenticate each other using X.509 certificates. This bidirectional authentication prevents man-in-the-middle attacks and ensures both endpoints are verified.

Dynamic Provisioning

SDP connections are provisioned on-demand based on real-time policy evaluation. No persistent network tunnels exist; each session is individually authorized and encrypted.

Workflow

Phase 1: SDP Controller Deployment
  1. Deploy SDP Controller

    • Install SDP controller on hardened, redundant infrastructure
    • Configure PKI integration for certificate issuance
    • Set up authentication backend (LDAP, SAML, OIDC)
    • Configure policy database with application definitions
    • Enable audit logging for all controller decisions
  2. Configure Authentication

    • Integrate with enterprise IdP via SAML 2.0 or OIDC
    • Configure device certificate enrollment (SCEP/EST)
    • Enable multi-factor authentication requirements
    • Set up certificate revocation checking (OCSP/CRL)
  3. Define Access Policies

    • Map users/groups to authorized applications
    • Define device posture requirements per application
    • Configure contextual conditions (location, time, risk level)
    • Set session duration and re-authentication intervals
Show full SKILL.md (322 more words)Show less
Phase 2: SDP Gateway Deployment
  1. Deploy Accepting Hosts (Gateways)

    • Install SDP gateway instances in front of protected applications
    • Configure default-drop firewall rules (deny all inbound)
    • Enable SPA listener on designated ports
    • Configure mTLS with controller-issued certificates
    • Set up health monitoring and failover
  2. Configure Application Definitions

    • Register each protected application with the controller
    • Define backend server IPs, ports, and protocols
    • Configure load balancing for multi-instance applications
    • Set up application health checks
Phase 3: Client Deployment
  1. Deploy Initiating Hosts (Clients)

    • Install SDP client software on user endpoints
    • Enroll device certificates through automated provisioning
    • Configure SPA key material distribution
    • Test authentication flow: SPA → mTLS → application access
  2. Validate End-to-End Flow

    • Verify SPA packets are accepted by gateway
    • Confirm mTLS handshake succeeds with valid certificates
    • Test application access through the SDP tunnel
    • Verify unauthorized access is blocked (no SPA = invisible gateway)
Phase 4: Operational Validation
  1. Security Testing

    • Port scan the SDP gateway to confirm invisibility (all ports show filtered/closed)
    • Attempt connection without valid SPA (must fail silently)
    • Test with revoked client certificate (must be denied)
    • Attempt lateral movement from one authorized app to another unauthorized app
    • Validate audit trail completeness
  2. Monitoring and Maintenance

    • Configure SIEM integration for SDP controller and gateway logs
    • Set up alerting for failed SPA attempts and certificate errors
    • Establish certificate rotation schedule
    • Document incident response procedures for SDP events

Validation Checklist

  • SDP Controller deployed with HA and audit logging
  • IdP integration tested with SAML/OIDC and MFA
  • SDP Gateways deployed with default-drop firewall
  • SPA mechanism validated (gateway invisible to port scans)
  • mTLS established between clients and gateways
  • Access policies enforce least-privilege per user/app
  • Device certificate enrollment automated
  • Unauthorized access attempts blocked silently
  • Lateral movement between apps prevented
  • Logs streaming to SIEM with alerting configured
  • Certificate rotation and revocation procedures tested

References

  • CSA Software-Defined Perimeter Architecture Guide v3
  • CSA SDP Specification v2.0
  • NIST SP 800-207: Zero Trust Architecture
  • CISA Zero Trust Maturity Model v2.0
  • fwknop: Single Packet Authorization implementation

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/deploying-software-defined-perimeter of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Deploying Software Defined Perimeter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deploying Software Defined Perimeter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deploying Software Defined Perimeter this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
Google Cloud PAM Helpergoogle/skills21k—~3.2kAutomated safety check: PassApache-2.0
Absolute Auditmaddhruv/absolute2181 repos~1.2kAutomated safety check: PassMIT
Warden Security ReviewUsefulSoftwareCo/executor4.1k—~1.3kAutomated safety check: PassMIT
Codewhale Security Reviewcodewhale-hq/Codewhale41k—~844Automated safety check: PassMIT
Iamitsmostafa/aws-agent-skills1.2k—~1.8kAutomated safety check: PassMIT

Similar skills

  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    SecurityAuto-check passed
  • Absolute Audit

    maddhruv/absolute

    Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without…

    218 GitHub starsUsed in 1 repo~1.2k tokens
    SecurityAuto-check passed
  • Warden Security Review

    UsefulSoftwareCo/executor

    Run Warden security scans in this repo using Sentry's warden-skills.

    4.1k GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check passed
  • Codewhale Security Review

    codewhale-hq/Codewhale

    Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix.

    41k GitHub stars~844 tokensUpdated today
    SecurityAuto-check passed
  • Iam

    itsmostafa/aws-agent-skills

    AWS Identity and Access Management for users, roles, policies, and permissions.

    1.2k GitHub stars~1.8k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • User Management

    sickn33/agentic-awesome-skills

    Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.8k tokens
    SecurityAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Deploying Software Defined Perimeter

What does Deploying Software Defined Perimeter do?

Deploys a Software-Defined Perimeter per the CSA v2.0 specification, configuring Single Packet Authorization, mutual TLS, and SDP controller/gateway components to enforce zero trust network access. Deploying Software Defined Perimeter is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.0 specification, configuring Single Packet Authorization, mutual TLS, and SDP controller/gateway components to enforce zero trust network access.

When should I use Deploying Software Defined Perimeter?

Deploying Software Defined Perimeter fits situations like: hardening zero trust network architecture; implementing SPA-based invisible infrastructure that cloaks services from unauthenticated scanning; meeting compliance requirements for zero trust network access.

How do I install Deploying Software Defined Perimeter in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-software-defined-perimeter -a claude-code`. Or copy the skill folder (skills/deploying-software-defined-perimeter in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/deploying-software-defined-perimeter in your project. Claude Code loads it when a task matches its description.

How do I install Deploying Software Defined Perimeter in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-software-defined-perimeter -a codex`. Or copy the skill folder (skills/deploying-software-defined-perimeter in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/deploying-software-defined-perimeter in your project. Codex loads it when a task matches its description.

Can I use Deploying Software Defined Perimeter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-software-defined-perimeter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deploying-software-defined-perimeter, .gemini/skills/deploying-software-defined-perimeter, .github/skills/deploying-software-defined-perimeter and .opencode/skills/deploying-software-defined-perimeter in your project.

What does Deploying Software Defined Perimeter need to run?

Going by SKILL.md and its folder, Deploying Software Defined Perimeter needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Deploying Software Defined Perimeter access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Deploying Software Defined Perimeter safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Deploying Software Defined Perimeter use?

Deploying Software Defined Perimeter is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deploying Software Defined Perimeter use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Deploying Software Defined Perimeter?

Skills that share tags, products or a category with Deploying Software Defined Perimeter: Google Cloud PAM Helper (google/skills, 21k stars), Absolute Audit (maddhruv/absolute, 218 stars), Warden Security Review (UsefulSoftwareCo/executor, 4.1k stars) and Codewhale Security Review (codewhale-hq/Codewhale, 41k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deploying Software Defined Perimeter?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.