Agent skill

Implementing Attack Path Analysis With Xm Cyber

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Deploys XM Cyber's continuous exposure management platform to build attack graphs that chain vulnerabilities, misconfigurations, identity risks, and credential weaknesses toward critical assets…

Apache-2.0Auto-check passedSecurity

Install Implementing Attack Path Analysis With Xm Cyber

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-attack-path-analysis-with-xm-cyber -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-attack-path-analysis-with-xm-cyber --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-attack-path-analysis-with-xm-cyber .claude/skills/implementing-attack-path-analysis-with-xm-cyber && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-attack-path-analysis-with-xm-cyber
GitHub stars
34k
Token cost
~2.7k tokens
SKILL.md length
617 words
Files
8 (incl. scripts, references, assets)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploys XM Cyber's continuous exposure management platform to build attack graphs that chain vulnerabilities, misconfigurations, identity risks, and credential weaknesses toward critical assets…

  • Works in 5 steps: Define Critical Assets (Business Context) → Deploy XM Cyber Sensors → Configure Attack Scenarios → …
  • Mapping attack paths across an environment
  • SKILL.md covers Overview, When to Use, Prerequisites and Core Concepts, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Implementing Attack Path Analysis With Xm Cyber is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys XM Cyber's continuous exposure management platform to build attack graphs that chain vulnerabilities, misconfigurations, identity risks, and credential weaknesses toward critical assets, identifying the small fraction of exposures sitting on converging "choke points". Use when mapping attack paths across an environment or prioritizing remediation within a continuous threat exposure management (CTEM) program.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Mapping attack paths across an environment
  • Prioritizing remediation within a continuous threat exposure management (CTEM) program

Example prompts

  • “choke points”
  • “Use the implementing-attack-path-analysis-with-xm-cyber skill to deploy XM Cyber's continuous exposure management platform to build attack graphs…”
  • “/implementing-attack-path-analysis-with-xm-cyber”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Define Critical Assets (Business Context)
  2. Deploy XM Cyber Sensors
  3. Configure Attack Scenarios
  4. Analyze Attack Path Results
  5. Prioritize Remediation by Impact

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Attack Path Analysis With Xm Cyber loads about 2.7k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 117 tokens; SKILL.md has 617 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 617 words, ~2,736 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-attack-path-analysis-with-xm-cyber/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-attack-path-analysis-with-xm-cyber
description
Deploys XM Cyber's continuous exposure management platform to build attack graphs that chain vulnerabilities, misconfigurations, identity risks, and credential weaknesses toward critical assets, identifying the small fraction of exposures sitting on converging "choke points". Use when mapping attack paths across an environment or prioritizing remediation within a continuous threat exposure management (CTEM) program.
domain
cybersecurity
subdomain
vulnerability-management
tags
xm-cyber, attack-path-analysis, exposure-management, ctem, choke-points, breach-simulation, attack-surface
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
ID.RA-01, ID.RA-02, ID.IM-02, ID.RA-06
mitre_attack
T1190, T1203, T1068

Implementing Attack Path Analysis with XM Cyber

Overview

XM Cyber is a continuous exposure management platform that uses attack graph analysis to identify how adversaries can chain together exposures -- vulnerabilities, misconfigurations, identity risks, and credential weaknesses -- to reach critical business assets. According to XM Cyber's 2024 research analyzing over 40 million exposures across 11.5 million entities, organizations typically have around 15,000 exploitable exposures, but traditional CVEs account for less than 1% of total exposures. The platform identifies that only 2% of exposures reside on "choke points" of converging attack paths, enabling security teams to focus on fixes that eliminate the most risk with the least effort.

When to Use

  • When deploying or configuring implementing attack path analysis with xm cyber capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • XM Cyber platform license and tenant access
  • Network connectivity to monitored environments (on-premises, cloud, hybrid)
  • Administrative access for agent deployment or agentless integration
  • Cloud provider API access (AWS, Azure, GCP) for cloud attack path analysis
  • Active Directory read access for identity-based attack path modeling
  • CMDB or asset inventory defining critical business assets

Core Concepts

Attack Graph Analysis

Unlike point-in-time vulnerability scanning, XM Cyber continuously models all possible attack paths across the entire environment:

Traditional ScanningXM Cyber Attack Path Analysis
Lists individual vulnerabilitiesMaps chained attack paths
Scores by CVSS severityScores by reachability to critical assets
Point-in-time assessmentContinuous real-time modeling
No context of lateral movementModels full lateral movement chains
Treats each vuln independentlyShows how vulns chain together
Key Metrics from XM Cyber Research (2024)
FindingStatistic
Average exposures per organization~15,000
CVE-based exposures< 1% of total
Misconfiguration-based exposures~80% of total
Exposures on critical choke points2%
Orgs where attackers can pivot on-prem to cloud70%
Cloud critical assets compromisable in 2 hops93%
Critical asset exposures in cloud platforms56%
Choke Point Concept

A choke point is a single entity (host, identity, credential, misconfiguration) that sits at the intersection of multiple attack paths leading to critical assets. Fixing a choke point eliminates many attack paths simultaneously, providing maximum risk reduction per remediation effort.

Attack Path 1:  Web Server -> SQL Injection -> DB Admin Creds
                                                    \
Attack Path 2:  VPN -> Stolen Creds -> File Server   -> Domain Controller
                                                    /     (Critical Asset)
Attack Path 3:  Workstation -> Mimikatz -> Cached Creds
                                    ^
                              CHOKE POINT
                     (Cached Domain Admin credential)
Show full SKILL.md (249 more words)Show less
Exposure Categories
Category% of ExposuresExamples
Identity & Credentials40%Cached credentials, over-privileged accounts, Kerberoastable SPNs
Misconfigurations38%Open shares, weak permissions, missing hardening
Network Exposures12%Open ports, flat networks, missing segmentation
Software Vulnerabilities8%Unpatched CVEs, outdated software
Cloud Exposures2%IAM misconfig, public storage, overly permissive roles

Workflow

Step 1: Define Critical Assets (Business Context)
Critical Asset Definition:
    Tier 1 - Crown Jewels:
        - Domain Controllers (Active Directory)
        - Database servers with PII/financial data
        - ERP systems (SAP, Oracle)
        - Certificate Authority servers
        - Backup infrastructure (Veeam, Commvault)

    Tier 2 - High Value:
        - Email servers (Exchange)
        - File servers with IP/trade secrets
        - CI/CD pipeline servers
        - Jump servers / PAM vaults

    Tier 3 - Supporting Infrastructure:
        - DNS/DHCP servers
        - Monitoring systems
        - Logging infrastructure
Step 2: Deploy XM Cyber Sensors
Deployment Architecture:
    On-Premises:
        - Install XM Cyber sensor on management server
        - Configure AD integration (read-only service account)
        - Enable network discovery protocols
        - Set scanning scope (IP ranges, AD OUs)

    Cloud (AWS):
        - Deploy XM Cyber CloudConnect via CloudFormation
        - Configure IAM role with read-only permissions
        - Enable cross-account scanning for multi-account orgs

    Cloud (Azure):
        - Deploy via Azure Marketplace
        - Configure Entra ID (Azure AD) integration
        - Grant Reader role on subscriptions

    Hybrid:
        - Configure cross-environment path analysis
        - Map on-premises to cloud trust relationships
        - Enable identity correlation across environments
Step 3: Configure Attack Scenarios
Scenario 1: External Attacker to Domain Admin
    Starting Point:  Internet-facing assets
    Target:          Domain Admin privileges
    Attack Techniques: Exploit public CVEs, credential theft,
                      lateral movement, privilege escalation

Scenario 2: Insider Threat to Financial Data
    Starting Point:  Any corporate workstation
    Target:          Financial database servers
    Attack Techniques: Credential harvesting, share enumeration,
                      privilege escalation, data access

Scenario 3: Cloud Account Takeover
    Starting Point:  Compromised cloud IAM user
    Target:          Production cloud infrastructure
    Attack Techniques: IAM privilege escalation, cross-account
                      pivot, storage access, compute compromise

Scenario 4: Ransomware Propagation
    Starting Point:  Phished workstation
    Target:          Maximum host compromise (lateral spread)
    Attack Techniques: Credential reuse, SMB exploitation,
                      PsExec/WMI lateral movement
Step 4: Analyze Attack Path Results
python
# Interpreting XM Cyber attack path analysis results
def analyze_choke_points(attack_graph_results):
    """Analyze attack graph results for priority remediation."""

    choke_points = []
    for entity in attack_graph_results.get("entities", []):
        if entity.get("is_choke_point"):
            choke_points.append({
                "entity_name": entity["name"],
                "entity_type": entity["type"],
                "attack_paths_blocked": entity["paths_through"],
                "critical_assets_protected": entity["protects_assets"],
                "remediation_complexity": entity["fix_complexity"],
                "exposure_type": entity["exposure_category"],
            })

    # Sort by impact (paths blocked * assets protected)
    choke_points.sort(
        key=lambda x: x["attack_paths_blocked"] * len(x["critical_assets_protected"]),
        reverse=True
    )

    print(f"Total choke points identified: {len(choke_points)}")
    print(f"\nTop 10 choke points for maximum risk reduction:")
    for i, cp in enumerate(choke_points[:10], 1):
        print(f"  {i}. {cp['entity_name']} ({cp['entity_type']})")
        print(f"     Paths blocked: {cp['attack_paths_blocked']}")
        print(f"     Assets protected: {len(cp['critical_assets_protected'])}")
        print(f"     Exposure type: {cp['exposure_type']}")
        print(f"     Fix complexity: {cp['remediation_complexity']}")

    return choke_points
Step 5: Prioritize Remediation by Impact
Remediation Priority Matrix:

Priority 1 (Immediate - 48h):
    - Choke points on paths to Tier 1 assets
    - Identity exposures (cached Domain Admin creds)
    - Internet-facing vulnerabilities with attack paths

Priority 2 (Urgent - 7 days):
    - Choke points on paths to Tier 2 assets
    - Cloud IAM misconfigurations with privilege escalation
    - Network segmentation gaps enabling lateral movement

Priority 3 (Important - 30 days):
    - Remaining choke points
    - Misconfigurations reducing defense depth
    - Non-critical software vulnerabilities on attack paths

Priority 4 (Standard - 90 days):
    - Exposures NOT on any attack path to critical assets
    - Informational findings
    - Hardening recommendations

Best Practices

  1. Define critical assets before deploying the platform; attack paths without target context are meaningless
  2. Focus remediation on choke points first; fixing 2% of exposures can eliminate the majority of risk
  3. Use attack path context to justify remediation urgency to IT teams (show the chain, not just the vuln)
  4. Re-run attack path analysis after each remediation to verify paths are truly eliminated
  5. Include cloud environments in analysis; 56% of critical asset exposures exist in cloud platforms
  6. Monitor for new attack paths created by infrastructure changes (new servers, permission changes)
  7. Integrate findings with ticketing systems for automated remediation tracking

Common Pitfalls

  • Focusing solely on CVEs when 80% of exposures come from misconfigurations
  • Not defining critical assets, leading to unfocused attack path analysis
  • Treating all exposures equally instead of focusing on choke points
  • Ignoring identity-based attack paths (cached credentials, Kerberoastable accounts)
  • Not correlating on-premises and cloud attack paths in hybrid environments
  • Running analysis once instead of continuously
  • implementing-continuous-security-validation-with-bas
  • performing-asset-criticality-scoring-for-vulns
  • detecting-lateral-movement-in-network
  • exploiting-active-directory-with-bloodhound

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-attack-path-analysis-with-xm-cyber of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Attack Path Analysis With Xm Cyber next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Attack Path Analysis With Xm Cyber compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Attack Path Analysis With Xm Cyber this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4801 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    480 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Implementing Attack Path Analysis With Xm Cyber

What does Implementing Attack Path Analysis With Xm Cyber do?

Deploys XM Cyber's continuous exposure management platform to build attack graphs that chain vulnerabilities, misconfigurations, identity risks, and credential weaknesses toward critical assets…. Implementing Attack Path Analysis With Xm Cyber is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys XM Cyber's continuous exposure management platform to build attack graphs that chain vulnerabilities, misconfigurations, identity risks, and credential weaknesses toward critical assets, identifying the small fraction of exposures sitting on converging "choke points".

When should I use Implementing Attack Path Analysis With Xm Cyber?

Implementing Attack Path Analysis With Xm Cyber fits situations like: mapping attack paths across an environment; prioritizing remediation within a continuous threat exposure management (CTEM) program.

How do I install Implementing Attack Path Analysis With Xm Cyber in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-attack-path-analysis-with-xm-cyber -a claude-code`. Or copy the skill folder (skills/implementing-attack-path-analysis-with-xm-cyber in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-attack-path-analysis-with-xm-cyber in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Attack Path Analysis With Xm Cyber in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-attack-path-analysis-with-xm-cyber -a codex`. Or copy the skill folder (skills/implementing-attack-path-analysis-with-xm-cyber in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-attack-path-analysis-with-xm-cyber in your project. Codex loads it when a task matches its description.

Can I use Implementing Attack Path Analysis With Xm Cyber in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-attack-path-analysis-with-xm-cyber -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-attack-path-analysis-with-xm-cyber, .gemini/skills/implementing-attack-path-analysis-with-xm-cyber, .github/skills/implementing-attack-path-analysis-with-xm-cyber and .opencode/skills/implementing-attack-path-analysis-with-xm-cyber in your project.

What does Implementing Attack Path Analysis With Xm Cyber need to run?

Going by SKILL.md and its folder, Implementing Attack Path Analysis With Xm Cyber needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Attack Path Analysis With Xm Cyber access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Attack Path Analysis With Xm Cyber safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Attack Path Analysis With Xm Cyber use?

Implementing Attack Path Analysis With Xm Cyber is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Attack Path Analysis With Xm Cyber use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Attack Path Analysis With Xm Cyber?

Skills that share tags, products or a category with Implementing Attack Path Analysis With Xm Cyber: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Attack Path Analysis With Xm Cyber?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.