Agent skill

Implementing Cloud Security Posture Management

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

Apache-2.0Auto-check passedSecurity

Install Implementing Cloud Security Posture Management

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-cloud-security-posture-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-cloud-security-posture-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-cloud-security-posture-management .claude/skills/implementing-cloud-security-posture-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-cloud-security-posture-management
GitHub stars
34k
Token cost
~3k tokens
SKILL.md length
642 words
Files
5 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

  • Works in 6 steps: Deploy Cloud-Native CSPM Services → Run Prowler for Multi-Cloud Assessment → Run ScoutSuite for Cross-Cloud Comparison → …
  • Cross-cloud posture monitoring
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls aws, az and gcloud

What it does

Implementing Cloud Security Posture Management is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for Cloud, and GCP Security Command Center. Use for cross-cloud posture monitoring, CIS/SOC 2/PCI DSS compliance, or drift-detection workflows; not for runtime workload protection or application security testing.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `SKILL.es.md`, `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Cloud security, Cloud architecture and GitOps. It works with Google Cloud, Amazon Web Services, Microsoft Azure and Microsoft Defender. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Cross-cloud posture monitoring
  • CIS/SOC 2/PCI DSS compliance
  • Drift-detection workflows
  • Not for runtime workload protection

Example prompts

  • “/implementing-cloud-security-posture-management”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Deploy Cloud-Native CSPM Services
  2. Run Prowler for Multi-Cloud Assessment
  3. Run ScoutSuite for Cross-Cloud Comparison
  4. Build Automated Compliance Monitoring Pipeline
  5. Configure Finding Aggregation and Deduplication
  6. Implement Drift Detection and Auto-Remediation

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • az
    • gcloud
    • python3
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, az, gcloud and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Cloud Security Posture Management loads about 3k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 642 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 642 words, ~3,021 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-cloud-security-posture-management/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
implementing-cloud-security-posture-management
description
Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for Cloud, and GCP Security Command Center. Use for cross-cloud posture monitoring, CIS/SOC 2/PCI DSS compliance, or drift-detection workflows; not for runtime workload protection or application security testing.
domain
cybersecurity
subdomain
cloud-security
tags
cloud-security, cspm, multi-cloud, compliance, prowler, scoutsuite
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, ID.AM-08, GV.SC-06, DE.CM-01
mitre_attack
T1078.004, T1530, T1537, T1580

Implementing Cloud Security Posture Management

When to Use

  • When establishing continuous security monitoring across AWS, Azure, and GCP environments
  • When compliance requirements demand automated posture assessment against CIS, SOC 2, or PCI DSS
  • When security teams need visibility into cloud misconfigurations across multiple accounts and subscriptions
  • When building a security operations workflow that detects and remediates drift from security baselines
  • When migrating workloads to the cloud and need to enforce security guardrails

Do not use for runtime workload protection (use CWPP tools like Falco or Aqua), for application security testing (use DAST/SAST tools), or for network intrusion detection (use cloud-native IDS like GuardDuty or Network Watcher).

Prerequisites

  • Multi-cloud credentials with read-only security audit permissions across all target environments
  • Prowler v3+ installed (pip install prowler)
  • ScoutSuite installed (pip install scoutsuite)
  • AWS Config, Azure Policy, and GCP Organization Policy enabled in respective environments
  • Central logging destination (S3 bucket, Log Analytics Workspace, or Cloud Storage) for findings aggregation
  • Notification channels configured (Slack, PagerDuty, email) for critical finding alerts

Workflow

Step 1: Deploy Cloud-Native CSPM Services

Enable the built-in CSPM capabilities in each cloud provider for baseline posture assessment.

bash
# AWS: Enable Security Hub with FSBP and CIS standards
aws securityhub enable-security-hub --enable-default-standards
aws securityhub batch-enable-standards --standards-subscription-requests \
  '[{"StandardsArn":"arn:aws:securityhub:::standards/cis-aws-foundations-benchmark/v/1.4.0"}]'

# Azure: Enable Microsoft Defender for Cloud (CSPM tier)
az security pricing create --name CloudPosture --tier standard
az security auto-provisioning-setting update --name default --auto-provision on

# GCP: Enable Security Command Center Premium
gcloud services enable securitycenter.googleapis.com
gcloud scc settings update --organization=ORG_ID \
  --enable-asset-discovery
Step 2: Run Prowler for Multi-Cloud Assessment

Execute Prowler to perform comprehensive security checks across all three cloud providers.

bash
# AWS assessment with all CIS checks
prowler aws \
  --profile production \
  -M json-ocsf csv html \
  -o ./prowler-results/aws/ \
  --compliance cis_1.4_aws cis_1.5_aws

# Azure assessment
prowler azure \
  --subscription-ids SUB_ID_1 SUB_ID_2 \
  -M json-ocsf csv html \
  -o ./prowler-results/azure/ \
  --compliance cis_2.0_azure

# GCP assessment
prowler gcp \
  --project-ids project-1 project-2 \
  -M json-ocsf csv html \
  -o ./prowler-results/gcp/ \
  --compliance cis_2.0_gcp

# View summary across all providers
prowler aws --list-compliance
Step 3: Run ScoutSuite for Cross-Cloud Comparison

Use ScoutSuite for a unified multi-cloud security assessment with visual reporting.

bash
# Scan AWS
python3 -m ScoutSuite aws --profile production \
  --report-dir ./scoutsuite/aws/

# Scan Azure
python3 -m ScoutSuite azure --cli \
  --all-subscriptions \
  --report-dir ./scoutsuite/azure/

# Scan GCP
python3 -m ScoutSuite gcp --user-account \
  --all-projects \
  --report-dir ./scoutsuite/gcp/

# Each produces an HTML report with risk-scored findings
Step 4: Build Automated Compliance Monitoring Pipeline

Create a scheduled pipeline that runs CSPM checks daily and routes findings to appropriate channels.

bash
# Create a daily Prowler scan with EventBridge + CodeBuild (AWS)
cat > buildspec.yml << 'EOF'
version: 0.2
phases:
  install:
    commands:
      - pip install prowler
  build:
    commands:
      - prowler aws -M json-ocsf -o s3://security-findings-bucket/prowler/$(date +%Y%m%d)/
      - prowler aws --compliance cis_1.5_aws -M csv -o s3://security-findings-bucket/prowler/compliance/
  post_build:
    commands:
      - |
        CRITICAL=$(cat output/*.json | grep -c '"CRITICAL"')
        if [ "$CRITICAL" -gt 0 ]; then
          aws sns publish --topic-arn arn:aws:sns:us-east-1:ACCOUNT:security-alerts \
            --subject "Prowler: $CRITICAL critical findings" \
            --message "Review at s3://security-findings-bucket/prowler/$(date +%Y%m%d)/"
        fi
EOF

# Schedule with EventBridge
aws events put-rule \
  --name daily-prowler-scan \
  --schedule-expression "cron(0 6 * * ? *)" \
  --state ENABLED
Step 5: Configure Finding Aggregation and Deduplication

Aggregate findings from multiple CSPM tools and cloud providers into a unified view.

python
# findings_aggregator.py - Normalize and deduplicate CSPM findings
import json
import hashlib
from datetime import datetime

def normalize_finding(finding, source):
    """Normalize findings from different CSPM tools to a common format."""
    normalized = {
        'id': hashlib.sha256(f"{finding.get('ResourceId','')}{finding.get('CheckId','')}".encode()).hexdigest()[:16],
        'source': source,
        'cloud': finding.get('Provider', 'unknown'),
        'account': finding.get('AccountId', finding.get('SubscriptionId', '')),
        'region': finding.get('Region', ''),
        'resource_type': finding.get('ResourceType', ''),
        'resource_id': finding.get('ResourceId', ''),
        'severity': finding.get('Severity', 'INFO').upper(),
        'status': finding.get('Status', 'FAIL'),
        'title': finding.get('CheckTitle', finding.get('Title', '')),
        'description': finding.get('StatusExtended', ''),
        'compliance': finding.get('Compliance', {}),
        'remediation': finding.get('Remediation', {}).get('Recommendation', {}).get('Text', ''),
        'timestamp': datetime.utcnow().isoformat()
    }
    return normalized

def aggregate_findings(prowler_file, scoutsuite_file):
    findings = {}
    for file_path, source in [(prowler_file, 'prowler'), (scoutsuite_file, 'scoutsuite')]:
        with open(file_path) as f:
            for line in f:
                raw = json.loads(line)
                normalized = normalize_finding(raw, source)
                if normalized['status'] == 'FAIL':
                    findings[normalized['id']] = normalized
    return sorted(findings.values(), key=lambda x: {'CRITICAL':0,'HIGH':1,'MEDIUM':2,'LOW':3}.get(x['severity'],4))
Step 6: Implement Drift Detection and Auto-Remediation

Set up automated responses to configuration drift that violates security baselines.

bash
# AWS Config auto-remediation for non-compliant S3 buckets
aws configservice put-remediation-configurations --remediation-configurations '[{
  "ConfigRuleName": "s3-bucket-public-read-prohibited",
  "TargetType": "SSM_DOCUMENT",
  "TargetId": "AWS-DisableS3BucketPublicReadWrite",
  "Parameters": {
    "S3BucketName": {"ResourceValue": {"Value": "RESOURCE_ID"}}
  },
  "Automatic": true,
  "MaximumAutomaticAttempts": 3,
  "RetryAttemptSeconds": 60
}]'

# Azure Policy for auto-remediation
az policy assignment create \
  --name "enforce-storage-encryption" \
  --policy "/providers/Microsoft.Authorization/policyDefinitions/404c3081-a854-4457-ae30-26a93ef643f9" \
  --scope "/subscriptions/SUB_ID" \
  --enforcement-mode Default

# GCP Organization Policy constraint
gcloud resource-manager org-policies set-policy policy.yaml --organization=ORG_ID
# policy.yaml: constraint: constraints/storage.publicAccessPrevention, enforcement: true

Key Concepts

TermDefinition
CSPMCloud Security Posture Management, the practice of continuously monitoring cloud infrastructure for misconfigurations and compliance violations
Configuration DriftUnintended changes to cloud resource configurations that deviate from the approved security baseline over time
Security BaselineA documented set of minimum security configuration requirements that all cloud resources must meet
Compliance FrameworkA structured set of security controls and requirements (CIS, SOC 2, PCI DSS, NIST) against which cloud configurations are evaluated
Finding SeverityRisk classification of a misconfiguration based on exploitability and potential impact (Critical, High, Medium, Low, Informational)
Auto-RemediationAutomated corrective action that restores a non-compliant resource to its required configuration without manual intervention
Show full SKILL.md (250 more words)Show less

Tools & Systems

  • Prowler: Open-source multi-cloud security assessment tool with 300+ checks aligned to CIS, PCI DSS, HIPAA, and NIST
  • ScoutSuite: Multi-cloud security auditing tool producing risk-scored HTML reports from API-collected configuration data
  • AWS Security Hub: AWS-native CSPM with aggregated findings and compliance standard evaluation
  • Microsoft Defender for Cloud: Azure-native CSPM with secure score, regulatory compliance, and workload protection
  • GCP Security Command Center: GCP-native security platform with asset inventory, vulnerability scanning, and compliance monitoring

Common Scenarios

Scenario: Establishing CSPM for a Multi-Cloud Enterprise

Context: An enterprise runs production workloads across AWS (primary), Azure (identity and Microsoft services), and GCP (data analytics). The security team needs unified posture visibility.

Approach:

  1. Enable cloud-native CSPM in each provider: Security Hub, Defender for Cloud, SCC
  2. Deploy Prowler scans as daily scheduled jobs in each environment via CI/CD pipelines
  3. Normalize and aggregate findings into a central data lake using the aggregation script
  4. Build dashboards in Grafana or Kibana showing posture scores by cloud, account, and severity
  5. Configure auto-remediation for known-good fixes (public access blocks, encryption enablement)
  6. Route CRITICAL findings to PagerDuty for immediate response and HIGH findings to Jira tickets
  7. Produce weekly compliance reports for executive stakeholders showing trend data

Pitfalls: Running CSPM tools with overly broad permissions creates a high-value target. Use dedicated service accounts with read-only permissions and rotate credentials regularly. Different CSPM tools may report the same misconfiguration differently, so deduplication logic must account for varying resource ID formats and finding titles across tools.

Output Format

Cloud Security Posture Management Dashboard
==============================================
Organization: Acme Corp
Assessment Date: 2026-02-23
Environments: AWS (12 accounts), Azure (8 subscriptions), GCP (5 projects)

POSTURE SCORES:
  AWS:   82/100  (+3 from last week)
  Azure: 76/100  (-1 from last week)
  GCP:   79/100  (+5 from last week)
  Overall: 79/100

FINDINGS BY SEVERITY:
  Critical:  18 (AWS: 7, Azure: 8, GCP: 3)
  High:      67 (AWS: 28, Azure: 24, GCP: 15)
  Medium:   234 (AWS: 98, Azure: 87, GCP: 49)
  Low:      412 (AWS: 178, Azure: 134, GCP: 100)

TOP FAILING CATEGORIES:
  1. IAM overly permissive policies     (43 findings)
  2. Encryption not enabled at rest      (38 findings)
  3. Public network exposure             (29 findings)
  4. Logging and monitoring gaps         (24 findings)
  5. Unused credentials and keys         (19 findings)

AUTO-REMEDIATION (Last 7 Days):
  Findings auto-remediated:  34
  Manual remediation pending: 51
  Exceptions approved:        8

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/implementing-cloud-security-posture-management of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • SKILL.es.md
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Cloud Security Posture Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Cloud Security Posture Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Cloud Security Posture Management this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Cloud Securityborghei/Claude-Skills874—~3.5kAutomated safety check: PassMIT
Defender For Cloud Hardeningvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Cloud Auditbriiirussell/cybersecurity-skills412—~1.3kAutomated safety check: NotesMIT
Configuring Firewallsancoleman/ai-design-components526—~3.5kAutomated safety check: NotesMIT
Hardening Cloud Posturetrilwu/secskills156—~1.9kAutomated safety check: PassMIT

Similar skills

  • Cloud Security

    borghei/Claude-Skills

    Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails.

    874 GitHub stars~3.5k tokensUpdated today
    SecurityAuto-check passed
  • Defender For Cloud Hardening

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    412 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Configuring Firewalls

    ancoleman/ai-design-components

    Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.

    526 GitHub stars~3.5k tokensUpdated 10 mo ago
    SecurityAuto-check: notes
  • Hardening Cloud Posture

    trilwu/secskills

    Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

    156 GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Cloud Misconfig Auditor

    criptogus/agent-evolve-network

    Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging.

    288 GitHub stars~965 tokensUpdated 28 days ago
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing Cloud Security Posture Management

What does Implementing Cloud Security Posture Management do?

Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…. Implementing Cloud Security Posture Management is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for Cloud, and GCP Security Command Center.

When should I use Implementing Cloud Security Posture Management?

Implementing Cloud Security Posture Management fits situations like: cross-cloud posture monitoring; CIS/SOC 2/PCI DSS compliance; drift-detection workflows; not for runtime workload protection.

How do I install Implementing Cloud Security Posture Management in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-cloud-security-posture-management -a claude-code`. Or copy the skill folder (skills/implementing-cloud-security-posture-management in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-cloud-security-posture-management in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Cloud Security Posture Management in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-cloud-security-posture-management -a codex`. Or copy the skill folder (skills/implementing-cloud-security-posture-management in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-cloud-security-posture-management in your project. Codex loads it when a task matches its description.

Can I use Implementing Cloud Security Posture Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-cloud-security-posture-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-cloud-security-posture-management, .gemini/skills/implementing-cloud-security-posture-management, .github/skills/implementing-cloud-security-posture-management and .opencode/skills/implementing-cloud-security-posture-management in your project.

What does Implementing Cloud Security Posture Management need to run?

Going by SKILL.md and its folder, Implementing Cloud Security Posture Management needs Python for the scripts in its folder and the command-line tools its instructions call (aws, az, gcloud, python3 and pip). Our summary lists: Python 3.

Does Implementing Cloud Security Posture Management access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Implementing Cloud Security Posture Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Cloud Security Posture Management use?

Implementing Cloud Security Posture Management is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Cloud Security Posture Management use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 487 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Cloud Security Posture Management?

Skills that share tags, products or a category with Implementing Cloud Security Posture Management: Cloud Security (borghei/Claude-Skills, 874 stars), Defender For Cloud Hardening (vinayaklatthe/microsoft-security-skills, 175 stars), Cloud Audit (briiirussell/cybersecurity-skills, 412 stars) and Configuring Firewalls (ancoleman/ai-design-components, 526 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Cloud Security Posture Management?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.