Agent skill

Implementing Cloud Workload Protection

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances.

Apache-2.0Auto-check passedData & Analytics

Install Implementing Cloud Workload Protection

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-cloud-workload-protection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-cloud-workload-protection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-cloud-workload-protection .claude/skills/implementing-cloud-workload-protection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-cloud-workload-protection
GitHub stars
34k
Token cost
~578 tokens
SKILL.md length
134 words
Files
4 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances.

  • Works in 5 steps: Process monitoring for cryptominers and… → File integrity monitoring on critical… → Network connection auditing for C2… → …
  • Building runtime security controls for cloud compute workloads
  • SKILL.md covers When to Use, Prerequisites, Instructions and Examples
  • Runs Python scripts from its folder

What it does

Implementing Cloud Workload Protection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. Scans for cryptomining, reverse shells, and unauthorized binaries. Use when building runtime security controls for cloud compute workloads.

Its SKILL.md is about 580 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Data & Analytics, covering Anomaly detection. It works with Google Cloud. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Building runtime security controls for cloud compute workloads
  • Tasks that involve Anomaly detection

Example prompts

  • “Use the implementing-cloud-workload-protection skill to implement cloud workload protection using boto3 and google-cloud APIs for runtime security…”
  • “/implementing-cloud-workload-protection”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Process monitoring for cryptominers and reverse shells
  2. File integrity monitoring on critical system files
  3. Network connection auditing for C2 callbacks
  4. Resource utilization anomaly detection (CPU spikes)
  5. Unauthorized binary detection via hash comparison

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Cloud Workload Protection loads about 578 tokens when it runs, and up to ~1k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 134 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~578
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 134 words, ~578 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-cloud-workload-protection/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-cloud-workload-protection
description
Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. Scans for cryptomining, reverse shells, and unauthorized binaries. Use when building runtime security controls for cloud compute workloads.
domain
cybersecurity
subdomain
cloud-security
tags
cloud-security, cwpp, workload-protection, boto3, runtime-security, process-anomaly-detection
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, ID.AM-08, GV.SC-06, DE.CM-01
mitre_attack
T1078.004, T1530, T1537, T1580, T1071

Implementing Cloud Workload Protection

When to Use

  • When deploying or configuring implementing cloud workload protection capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with cloud security concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Instructions

Monitor cloud workloads for runtime threats by checking process lists, network connections, file integrity, and resource utilization anomalies.

python
import boto3

ssm = boto3.client("ssm")
# Run command on EC2 instances to check for suspicious processes
response = ssm.send_command(
    InstanceIds=["i-1234567890abcdef0"],
    DocumentName="AWS-RunShellScript",
    Parameters={"commands": ["ps aux | grep -E 'xmrig|minerd|cryptonight'"]},
)

Key protection areas:

  1. Process monitoring for cryptominers and reverse shells
  2. File integrity monitoring on critical system files
  3. Network connection auditing for C2 callbacks
  4. Resource utilization anomaly detection (CPU spikes)
  5. Unauthorized binary detection via hash comparison

Examples

python
# Check for unauthorized outbound connections
ssm.send_command(
    InstanceIds=instances,
    DocumentName="AWS-RunShellScript",
    Parameters={"commands": ["ss -tlnp | grep ESTABLISHED"]},
)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-cloud-workload-protection of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Cloud Workload Protection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Cloud Workload Protection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Cloud Workload Protection this skillmukul975/Anthropic-Cybersecurity-Skills34k—~578Automated safety check: PassApache-2.0
Anomalib Tiled Ensembleopen-edge-platform/anomalib6.2k—~1.4kAutomated safety check: PassApache-2.0
Dt Obs HostsDynatrace/dynatrace-for-ai161—~5.5kAutomated safety check: PassApache-2.0
TimesFM Forecastinggoogle-research/timesfm34k—~4.7kAutomated safety check: PassApache-2.0
Anomalib Adding A Modelopen-edge-platform/anomalib6.2k—~1.9kAutomated safety check: PassApache-2.0
Kqlmicrosoft/fabric-rti-mcp131—~6.2kAutomated safety check: PassMIT

Similar skills

  • Anomalib Tiled Ensemble

    open-edge-platform/anomalib

    Runs and configures the anomalib tiled-ensemble pipeline, which trains/evaluates one model per image tile and merges results (with optional seam smoothing) for high-resolution anomaly detection.

    6.2k GitHub stars~1.4k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Dt Obs Hosts

    Dynatrace/dynatrace-for-ai

    Host and process metrics including CPU, memory, disk, network, containers, and process-level telemetry.

    161 GitHub stars~5.5k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • TimesFM Forecasting

    google-research/timesfm

    Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.

    34k GitHub stars~4.7k tokensUpdated 7 days ago
    Data & AnalyticsAuto-check passed
  • Anomalib Adding A Model

    open-edge-platform/anomalib

    Adds a new anomaly-detection model to anomalib under src/anomalib/models/.

    6.2k GitHub stars~1.9k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Kql

    microsoft/fabric-rti-mcp

    Official

    KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools.

    131 GitHub stars~6.2k tokensUpdated 6 days ago
    Data & AnalyticsAuto-check passed
  • Time Series Analytics User

    open-edge-platform/edge-ai-libraries

    Build a new time-series analytics use case on top of the deployed Time Series Analytics microservice — bring it up with Docker Compose (from a repo clone, or by fetching the compose files from…

    168 GitHub stars~3.1k tokensUpdated today
    Data & AnalyticsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Implementing Cloud Workload Protection

What does Implementing Cloud Workload Protection do?

Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. Implementing Cloud Workload Protection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances.

When should I use Implementing Cloud Workload Protection?

Implementing Cloud Workload Protection fits situations like: building runtime security controls for cloud compute workloads; tasks that involve Anomaly detection.

How do I install Implementing Cloud Workload Protection in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-cloud-workload-protection -a claude-code`. Or copy the skill folder (skills/implementing-cloud-workload-protection in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-cloud-workload-protection in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Cloud Workload Protection in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-cloud-workload-protection -a codex`. Or copy the skill folder (skills/implementing-cloud-workload-protection in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-cloud-workload-protection in your project. Codex loads it when a task matches its description.

Can I use Implementing Cloud Workload Protection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-cloud-workload-protection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-cloud-workload-protection, .gemini/skills/implementing-cloud-workload-protection, .github/skills/implementing-cloud-workload-protection and .opencode/skills/implementing-cloud-workload-protection in your project.

What does Implementing Cloud Workload Protection need to run?

Going by SKILL.md and its folder, Implementing Cloud Workload Protection needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Cloud Workload Protection access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Cloud Workload Protection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Cloud Workload Protection use?

Implementing Cloud Workload Protection is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Cloud Workload Protection use?

About 578 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 426 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Cloud Workload Protection?

Skills that share tags, products or a category with Implementing Cloud Workload Protection: Anomalib Tiled Ensemble (open-edge-platform/anomalib, 6.2k stars), Dt Obs Hosts (Dynatrace/dynatrace-for-ai, 161 stars), TimesFM Forecasting (google-research/timesfm, 34k stars) and Anomalib Adding A Model (open-edge-platform/anomalib, 6.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Cloud Workload Protection?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.