Agent skill

Implementing Aes Encryption For Data At REST

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Guides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores at rest, covering key derivation, IV/nonce management, and authenticated encryption.

Apache-2.0Auto-check passedSecurity

Install Implementing Aes Encryption For Data At REST

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-aes-encryption-for-data-at-rest -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-aes-encryption-for-data-at-rest --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-aes-encryption-for-data-at-rest .claude/skills/implementing-aes-encryption-for-data-at-rest && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-aes-encryption-for-data-at-rest
GitHub stars
34k
Token cost
~1.1k tokens
SKILL.md length
428 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores at rest, covering key derivation, IV/nonce management, and authenticated encryption.

  • Works in 6 steps: Install the cryptography library: pip… → Generate or derive an encryption key → Create a random nonce for each… → …
  • Configuring encryption for data at rest
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder; calls pip

What it does

Implementing Aes Encryption For Data At REST is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Guides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores at rest, covering key derivation, IV/nonce management, and authenticated encryption. Use when deploying or configuring encryption for data at rest, establishing controls to meet compliance requirements, or reviewing an implementation during a security assessment.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Cryptography and Security review. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Configuring encryption for data at rest
  • Establishing controls to meet compliance requirements
  • Reviewing an implementation during a security assessment

Example prompts

  • “Use the implementing-aes-encryption-for-data-at-rest skill to guide implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores…”
  • “/implementing-aes-encryption-for-data-at-rest”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Install the cryptography library: pip install cryptography
  2. Generate or derive an encryption key
  3. Create a random nonce for each encryption operation
  4. Encrypt data using AES-256-GCM with the key and nonce
  5. Store nonce + ciphertext + authentication tag together
  6. For decryption, extract nonce, verify tag, and decrypt

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Aes Encryption For Data At REST loads about 1.1k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 99 tokens; SKILL.md has 428 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 428 words, ~1,056 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-aes-encryption-for-data-at-rest/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-aes-encryption-for-data-at-rest
description
Guides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores at rest, covering key derivation, IV/nonce management, and authenticated encryption. Use when deploying or configuring encryption for data at rest, establishing controls to meet compliance requirements, or reviewing an implementation during a security assessment.
domain
cybersecurity
subdomain
cryptography
tags
cryptography, encryption, aes, data-at-rest, symmetric-encryption
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.DS-01, PR.DS-02, PR.DS-10
mitre_attack
T1600, T1573, T1553, T1486

Implementing AES Encryption for Data at Rest

Overview

AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect classified and sensitive data. This skill covers implementing AES-256 encryption in GCM mode for encrypting files and data stores at rest, including proper key derivation, IV/nonce management, and authenticated encryption.

When to Use

  • When deploying or configuring implementing aes encryption for data at rest capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with cryptography concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Objectives

  • Implement AES-256-GCM encryption and decryption for files
  • Derive encryption keys from passwords using PBKDF2 and Argon2
  • Manage initialization vectors (IVs) and nonces securely
  • Encrypt and decrypt entire directory trees
  • Implement authenticated encryption to detect tampering
  • Handle large files with streaming encryption

Key Concepts

AES Modes of Operation
ModeAuthenticationParallelizableUse Case
GCMYes (AEAD)YesNetwork data, file encryption
CBCNoDecrypt onlyLegacy systems, disk encryption
CTRNoYesStreaming encryption
CCMYes (AEAD)NoIoT, constrained environments
Key Derivation

Never use raw passwords as encryption keys. Always derive keys using:

  • PBKDF2: NIST-approved, widely supported (minimum 600,000 iterations as of 2024)
  • Argon2id: Winner of Password Hashing Competition, memory-hard
  • scrypt: Memory-hard, good alternative to Argon2
Show full SKILL.md (184 more words)Show less
Nonce/IV Management
  • GCM requires a 96-bit (12-byte) nonce that must NEVER be reused with the same key
  • Generate nonces using os.urandom() (CSPRNG)
  • Store nonce alongside ciphertext (it is not secret)

Workflow

  1. Install the cryptography library: pip install cryptography
  2. Generate or derive an encryption key
  3. Create a random nonce for each encryption operation
  4. Encrypt data using AES-256-GCM with the key and nonce
  5. Store nonce + ciphertext + authentication tag together
  6. For decryption, extract nonce, verify tag, and decrypt

Encrypted File Format

[salt: 16 bytes][nonce: 12 bytes][ciphertext: variable][tag: 16 bytes]

Security Considerations

  • Always use authenticated encryption (GCM, CCM) to prevent tampering
  • Never reuse a nonce with the same key (catastrophic in GCM)
  • Use at least 256-bit keys for long-term data protection
  • Securely wipe keys from memory after use when possible
  • Rotate encryption keys periodically per organizational policy
  • For disk-level encryption, consider XTS mode (AES-XTS)

Validation Criteria

  • AES-256-GCM encryption produces valid ciphertext
  • Decryption recovers original plaintext exactly
  • Authentication tag detects any ciphertext modification
  • Key derivation uses sufficient iterations/parameters
  • Nonces are never reused for the same key
  • Large files (>1GB) can be processed via streaming
  • Encrypted file format includes all necessary metadata

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-aes-encryption-for-data-at-rest of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Aes Encryption For Data At REST next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Aes Encryption For Data At REST compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Aes Encryption For Data At REST this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.1kAutomated safety check: PassApache-2.0
Security Reviewvalory-xyz/open-autonomy129—~11kAutomated safety check: NotesApache-2.0
Security Review Specwarpdotdev/oz-for-oss3131 repos~2.6kAutomated safety check: PassMIT
Performing Security Auditsjeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMIT
Deepgram Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~2.2kAutomated safety check: PassMIT
Security Reviewgetsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Security Review

    valory-xyz/open-autonomy

    Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…

    129 GitHub stars~11k tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Security Review Spec

    warpdotdev/oz-for-oss

    Audit a product or tech spec pull request diff for high-level security concerns (threat surface, authentication and authorization model, trust boundaries, sensitive data handling, secrets and key…

    313 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Performing Security Audits

    jeremylongshore/tons-of-skills-marketplace

    Analyze code, infrastructure, and configurations by conducting comprehensive security audits.

    2.8k GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed
  • Deepgram Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Deepgram security best practices for API key management and data protection.

    2.8k GitHub stars~2.2k tokensUpdated today
    SecurityAuto-check passed
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes
  • Sharp Edges Analysis

    trailofbits/skills

    Official

    Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis.

    7.4k GitHub starsUsed in 3 repos~3k tokens
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Implementing Aes Encryption For Data At REST

What does Implementing Aes Encryption For Data At REST do?

Guides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores at rest, covering key derivation, IV/nonce management, and authenticated encryption. Implementing Aes Encryption For Data At REST is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Guides implementing AES-256 encryption in GCM mode (FIPS 197) for files and data stores at rest, covering key derivation, IV/nonce management, and authenticated encryption.

When should I use Implementing Aes Encryption For Data At REST?

Implementing Aes Encryption For Data At REST fits situations like: configuring encryption for data at rest; establishing controls to meet compliance requirements; reviewing an implementation during a security assessment.

How do I install Implementing Aes Encryption For Data At REST in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-aes-encryption-for-data-at-rest -a claude-code`. Or copy the skill folder (skills/implementing-aes-encryption-for-data-at-rest in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-aes-encryption-for-data-at-rest in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Aes Encryption For Data At REST in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-aes-encryption-for-data-at-rest -a codex`. Or copy the skill folder (skills/implementing-aes-encryption-for-data-at-rest in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-aes-encryption-for-data-at-rest in your project. Codex loads it when a task matches its description.

Can I use Implementing Aes Encryption For Data At REST in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-aes-encryption-for-data-at-rest -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-aes-encryption-for-data-at-rest, .gemini/skills/implementing-aes-encryption-for-data-at-rest, .github/skills/implementing-aes-encryption-for-data-at-rest and .opencode/skills/implementing-aes-encryption-for-data-at-rest in your project.

What does Implementing Aes Encryption For Data At REST need to run?

Going by SKILL.md and its folder, Implementing Aes Encryption For Data At REST needs Python for the scripts in its folder and the command-line tools its instructions call (pip). Our summary lists: Python 3.

Does Implementing Aes Encryption For Data At REST access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Implementing Aes Encryption For Data At REST safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Aes Encryption For Data At REST use?

Implementing Aes Encryption For Data At REST is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Aes Encryption For Data At REST use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Aes Encryption For Data At REST?

Skills that share tags, products or a category with Implementing Aes Encryption For Data At REST: Security Review (valory-xyz/open-autonomy, 129 stars), Security Review Spec (warpdotdev/oz-for-oss, 313 stars), Performing Security Audits (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Deepgram Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Aes Encryption For Data At REST?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.