Agent skill

Designing Adversary Engagement With Mitre Engage

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc.

Apache-2.0Auto-check passedDevOps & Cloud

Install Designing Adversary Engagement With Mitre Engage

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills designing-adversary-engagement-with-mitre-engage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/designing-adversary-engagement-with-mitre-engage .claude/skills/designing-adversary-engagement-with-mitre-engage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
designing-adversary-engagement-with-mitre-engage
GitHub stars
34k
Token cost
~3k tokens
SKILL.md length
1,330 words
Files
5 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc.

  • Works in 10 steps: Confirm strategic fit (Prepare) → Define Engagement Goals and Operational… → Build the threat model and select… → …
  • A team has honeypots
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Designing Adversary Engagement With Mitre Engage is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc. Covers the Engage Matrix (Prepare, Expose, Affect, Elicit, Understand), the 10-Step Operational Process, mapping engagement Activities to the ATT&CK techniques they expose, and defining measurable Goals and Operational Objectives. Use when a team has honeypots, honeytokens, or canary tokens but no coordinating strategy, when leadership asks "should…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `scripts/process.py`).

It sits in DevOps & Cloud, covering Deployment. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • A team has honeypots
  • Canary tokens but no coordinating strategy
  • Leadership asks should we engage attackers and how
  • Building a deception/denial program

Example prompts

  • “should we engage attackers and how”
  • “/designing-adversary-engagement-with-mitre-engage”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Confirm strategic fit (Prepare)
  2. Define Engagement Goals and Operational Objectives
  3. Build the threat model and select Approaches
  4. Map ATT&CK techniques to Engagement Activities
  5. Design the engagement environment
  6. Define gating criteria and rules of engagement
  7. Deploy the Activities
  8. Operate and observe
  9. Analyze (Understand)
  10. After-action and feedback

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • engage.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Designing Adversary Engagement With Mitre Engage loads about 3k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 245 tokens; SKILL.md has 1,330 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~245
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,330 words, ~2,952 tokens.

Download SKILL.mdSave it as .claude/skills/designing-adversary-engagement-with-mitre-engage/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
designing-adversary-engagement-with-mitre-engage
description
Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc. Covers the Engage Matrix (Prepare, Expose, Affect, Elicit, Understand), the 10-Step Operational Process, mapping engagement Activities to the ATT&CK techniques they expose, and defining measurable Goals and Operational Objectives. Use when a team has honeypots, honeytokens, or canary tokens but no coordinating strategy, when leadership asks "should we engage attackers and how", when building a deception/denial program, when writing an adversary engagement operation plan, or when deciding which deception Activities to deploy against a specific threat actor. Keywords: MITRE Engage, adversary engagement, cyber deception strategy, denial and deception, Engage Matrix, EAC, EGO, Expose Affect Elicit, deception program, honeypot strategy, engagement operation.
domain
cybersecurity
subdomain
deception-technology
tags
mitre-engage, adversary-engagement, deception, denial-and-deception, engage-matrix, cyber-deception, threat-intelligence, detection-engineering
version
1.0
author
andrewibrah
license
Apache-2.0
nist_csf
GV.RM-01, ID.RA-01, ID.IM-02, DE.CM-01, DE.AE-02
mitre_attack
T1078, T1083, T1021, T1552, T1046

Designing Adversary Engagement with MITRE Engage

When to Use

  • When an organization owns deception tooling (honeypots, honeytokens, canary tokens, decoy files) but deploys it tactically with no unifying strategy or measurable outcome.
  • When leadership asks whether the organization should engage adversaries, and what the legal, operational, and resourcing implications are.
  • When writing a formal adversary engagement operation plan that must justify every deployed deceptive artifact against a strategic goal.
  • When selecting which specific deception Activities to deploy against a known or suspected threat actor based on that actor's ATT&CK TTPs.
  • When building a denial, deception, and adversary engagement (DD&AE) program that must integrate with existing SOC, threat intel, and incident response functions.
  • When a deception deployment generates alerts that nobody knows how to act on, because Expose was never connected to Affect or Elicit goals.

This skill is the strategy and operations layer that sits above tactical deployment skills (honeypot, honeytoken, canary-token, and decoy-file deployment). Use those skills to implement the Activities this skill selects and sequences.

Prerequisites

  • Familiarity with MITRE ATT&CK (tactics, techniques, and how to read a technique page), because Engagement Activities are mapped to the ATT&CK techniques they expose.
  • A documented set of critical assets and an understanding of which adversaries plausibly target them (a threat model or prioritized threat actor list).
  • Executive sponsorship and a written legal review. Engagement operations interact with live adversaries and raise entrapment, evidence-handling, and liability questions; never run an engagement operation without legal sign-off.
  • An existing detection and response capability. Engage is an additive strategy, not a replacement for defense-in-depth; if a defense-in-depth control fails, engagement keeps you in control rather than blind.
  • Access to the live matrix at https://engage.mitre.org/matrix/ for canonical Activity names and IDs.

Workflow

Engage operations follow the 10-Step Operational Process. The matrix is linear to read but cyclical to run — you continuously realign Activities toward your Goals as the adversary reacts.

1. Confirm strategic fit (Prepare)

Decide where denial, deception, and adversary engagement fit in the existing cyber strategy. The Prepare goal (a strategic bookend, alongside Understand) defines the inputs to the operation. Document the strategic goal in plain language, e.g. "reduce dwell time of insider threats around the source-code repository" or "generate first-party CTI on the actor targeting our VPN."

2. Define Engagement Goals and Operational Objectives

Select from the three Engagement Goals. Goals set direction; Operational Objectives take measurable steps in that direction.

Engagement Goal (EGO)What it doesExample Operational Objective
ExposeReveal adversary presence with high-fidelity, low-false-positive alerts"Alert within 5 minutes of any touch on a decoy credential"
AffectNegatively change the adversary's cost-value calculation (defender network only)"Redirect the adversary away from 3 unpatchable legacy hosts"
ElicitObserve the adversary to learn TTPs and produce CTI"Obtain a second-stage malware sample" or "identify ≥10 new indicators"

Write objectives as falsifiable, time-bound statements. A goal without an objective is unmeasurable.

3. Build the threat model and select Approaches

For each Goal, pick the Engagement Approaches (EAP) that fit the adversary you modeled:

  • Expose → Collection, Detection
  • Affect → Prevention, Direction, Disruption
  • Elicit → Reassurance, Motivation
4. Map ATT&CK techniques to Engagement Activities

For each technique your target adversary uses, find the Engage Activity that exposes the weakness that technique creates. Example mappings:

Adversary technique (ATT&CK)Weakness exposedEngage Activity (EAC)
T1078 Valid AccountsMust test credentialsDecoy Credentials, Lures
T1083 File & Directory DiscoveryMust enumerate filesDecoy Content, Pocket Litter
T1046 Network Service DiscoveryMust scan the networkNetwork Diversity, Decoy Systems
T1021 Remote ServicesMust move laterallyDecoy Systems, Network Manipulation
T1552 Unsecured CredentialsHarvests secretsDecoy Credentials, Artifact Diversity

Pull the authoritative Activity list and IDs from the live matrix; Engage IDs use the prefixes SGO/EGO (Goals), SAP/EAP (Approaches), and SAC/EAC (Activities).

5. Design the engagement environment

Decide realism and isolation. Choose between standalone, connected, or integrated decoy environments (see D3FEND honeynet types in references/standards.md). Populate it with diverse, believable artifacts — Persona Creation, Pocket Litter, Artifact Diversity, Application Diversity — so the environment survives adversary scrutiny.

6. Define gating criteria and rules of engagement

Document, before deployment: what the adversary is allowed to reach, the maximum blast radius, the trigger for tear-down or hand-off to IR, evidence preservation steps, and who has authority to escalate. Affect Activities are limited to the defender's own network — never act on infrastructure you do not own.

7. Deploy the Activities

Implement the selected Activities using the tactical deployment skills (honeypots, honeytokens, canary tokens, decoy files). Instrument every artifact so a touch produces telemetry routed to the SOC.

8. Operate and observe

Run the operation. Triage Expose alerts as high-fidelity (a touch on a decoy almost always means malicious or unauthorized activity). Feed observations back into Approach selection — realign Affect/Elicit Activities as the adversary behaves.

Show full SKILL.md (544 more words)Show less
9. Analyze (Understand)

The Understand goal (the output bookend) turns observations into decisions: new detections for production, CTI for sharing, and validated or invalidated threat-model assumptions.

10. After-action and feedback

Score the operation against the Operational Objectives from Step 2. Capture what intel was gained, what Activities triggered, dwell time, and lessons learned. Update the threat model and feed the next cycle.

Key Concepts

ConceptDefinition
Goal (SGO/EGO)High-level outcome of the operation. Prepare/Understand are strategic bookends; Expose/Affect/Elicit are the engagement goals.
Approach (SAP/EAP)The method used to make progress toward a Goal (e.g., Detection, Direction, Motivation).
Activity (SAC/EAC)The concrete denial/deception action deployed (e.g., Decoy Credentials, Network Manipulation).
OperateThe default matrix view = Expose + Affect + Elicit, the three engagement goals.
Operational ObjectiveA measurable, time-bound target that operationalizes a Goal.
Gating CriteriaPre-defined boundaries and triggers that constrain the operation's blast radius.
High-fidelity alertAn alert from a decoy that legitimate users have no reason to touch, yielding near-zero false positives.
Denial vs. DeceptionDenial blocks the adversary's access to real information; deception feeds plausible false information.

Tools & Systems

  • MITRE Engage Matrix and Starter Kit (https://engage.mitre.org) — canonical Goals/Approaches/Activities, the 10-Step Process, and operation-planning worksheets.
  • MITRE ATT&CK Navigator — to lay out the target adversary's techniques and overlay selected Engagement Activities.
  • MITRE D3FEND — the Deceive tactic provides defensive countermeasure naming (Decoy Environment, Decoy Object, honeynet types) that complements Engage.
  • Deception platforms / open tooling — OpenCanary, T-Pot, Cowrie (honeypots); Canarytokens, Thinkst Canary (honeytokens); to implement selected Activities.
  • SIEM/SOAR — to route decoy telemetry to high-priority detections and automate Expose → IR hand-off.
  • CTI platform (MISP, OpenCTI) — to store and share the first-party intelligence produced under the Elicit goal.

Common Scenarios

  • "We have honeypots but no value." Map existing honeypots to the Expose goal, define an Operational Objective (alert latency, dwell-time reduction), and connect alerts to an IR hand-off so the deployment produces decisions, not noise.
  • "Targeted by a specific actor." Build the actor's ATT&CK technique set, map each to the Activity that exposes it, and prioritize the smallest set of Activities that covers the actor's likely kill chain.
  • "Protect unpatchable legacy systems." Use Affect Activities (Direction, Network Manipulation, decoys) to steer adversaries away from systems that cannot be remediated.
  • "Tired of CVE whack-a-mole." Use the Elicit goal to generate a first-party CTI feed so defense is driven by observed adversary TTPs rather than the vulnerability of the week.
  • "Insider threat near critical data." Seed Expose Activities (Decoy Content, Decoy Credentials, Pocket Litter) around the crown-jewel asset for high-fidelity detection of unauthorized internal access.

Output Format

Produce an Adversary Engagement Operation Plan using assets/template.md, containing:

  1. Strategic context — where DD&AE fits the cyber strategy; executive sponsor; legal sign-off reference.
  2. Engagement Goals + Operational Objectives — each objective falsifiable and time-bound.
  3. Threat model — target adversary, prioritized ATT&CK techniques.
  4. Activity selection matrix — technique → exposed weakness → selected Engage Activity (with EAC IDs) → tactical deployment owner.
  5. Engagement environment design — realism, isolation/honeynet type, artifact diversity plan.
  6. Gating criteria and rules of engagement — blast radius, tear-down triggers, evidence handling, escalation authority.
  7. Measurement plan — metrics per objective (alert latency, dwell time, indicators gained, samples obtained).
  8. After-action report — objectives met/missed, intel produced, detections promoted to production, threat-model updates.

Use scripts/process.py to validate technique→Activity coverage and generate the operation-plan skeleton from a threat-model input.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/designing-adversary-engagement-with-mitre-engage of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/standards.md
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Designing Adversary Engagement With Mitre Engage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Designing Adversary Engagement With Mitre Engage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Designing Adversary Engagement With Mitre Engage this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
KubeShark for KubernetesLukasNiessen/kubernetes-skill446—~1.2kAutomated safety check: PassMIT
Dependency Auditoralirezarezvani/claude-code-tresor777—~1.2kAutomated safety check: NotesMIT
CI/CD Pipeline Principlesirahardianto/awesome-agv156—~2.7kAutomated safety check: NotesMIT
Robotics Securityarpitg1304/robotics-agent-skills369—~7.8kAutomated safety check: WarnApache-2.0
Canary Tripwire Responsedeonmenezes/mantishack503—~376Automated safety check: PassApache-2.0

Similar skills

  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    446 GitHub stars~1.2k tokensUpdated 28 days ago
    DevOps & CloudAuto-check passed
  • Dependency Auditor

    alirezarezvani/claude-code-tresor

    Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.

    777 GitHub stars~1.2k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: notes
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    156 GitHub stars~2.7k tokensUpdated 6 days ago
    DevOps & CloudAuto-check: notes
  • Robotics Security

    arpitg1304/robotics-agent-skills

    Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.

    369 GitHub stars~7.8k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: warnings
  • Canary Tripwire Response

    deonmenezes/mantishack

    What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result

    503 GitHub stars~376 tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Atmos CI

    cloudposse/atmos

    Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs…

    1.4k GitHub stars~4.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Designing Adversary Engagement With Mitre Engage

What does Designing Adversary Engagement With Mitre Engage do?

Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc. Designing Adversary Engagement With Mitre Engage is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Plan, run, and measure an adversary engagement operation using the MITRE Engage framework so that deployed deception is driven by strategy instead of deployed ad hoc.

When should I use Designing Adversary Engagement With Mitre Engage?

Designing Adversary Engagement With Mitre Engage fits situations like: A team has honeypots; canary tokens but no coordinating strategy; leadership asks should we engage attackers and how; building a deception/denial program.

How do I install Designing Adversary Engagement With Mitre Engage in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a claude-code`. Or copy the skill folder (skills/designing-adversary-engagement-with-mitre-engage in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/designing-adversary-engagement-with-mitre-engage in your project. Claude Code loads it when a task matches its description.

How do I install Designing Adversary Engagement With Mitre Engage in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a codex`. Or copy the skill folder (skills/designing-adversary-engagement-with-mitre-engage in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/designing-adversary-engagement-with-mitre-engage in your project. Codex loads it when a task matches its description.

Can I use Designing Adversary Engagement With Mitre Engage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill designing-adversary-engagement-with-mitre-engage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/designing-adversary-engagement-with-mitre-engage, .gemini/skills/designing-adversary-engagement-with-mitre-engage, .github/skills/designing-adversary-engagement-with-mitre-engage and .opencode/skills/designing-adversary-engagement-with-mitre-engage in your project.

What does Designing Adversary Engagement With Mitre Engage need to run?

Going by SKILL.md and its folder, Designing Adversary Engagement With Mitre Engage needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Designing Adversary Engagement With Mitre Engage access the network?

SKILL.md names 1 domain. As links in the text: engage.mitre.org. This is read from the text; nothing was executed.

Is Designing Adversary Engagement With Mitre Engage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Designing Adversary Engagement With Mitre Engage use?

Designing Adversary Engagement With Mitre Engage is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Designing Adversary Engagement With Mitre Engage use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Designing Adversary Engagement With Mitre Engage?

Skills that share tags, products or a category with Designing Adversary Engagement With Mitre Engage: KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 446 stars), Dependency Auditor (alirezarezvani/claude-code-tresor, 777 stars), CI/CD Pipeline Principles (irahardianto/awesome-agv, 156 stars) and Robotics Security (arpitg1304/robotics-agent-skills, 369 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Designing Adversary Engagement With Mitre Engage?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.