Agent skill

Implementing Identity Verification For Zero Trust

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Implements continuous, risk-adaptive identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with NIST SP…

Apache-2.0Auto-check passedSecurity

Install Implementing Identity Verification For Zero Trust

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-identity-verification-for-zero-trust -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-identity-verification-for-zero-trust --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-identity-verification-for-zero-trust .claude/skills/implementing-identity-verification-for-zero-trust && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-identity-verification-for-zero-trust
GitHub stars
34k
Token cost
~2.4k tokens
SKILL.md length
808 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements continuous, risk-adaptive identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with NIST SP…

  • Works in 4 steps: Identity Infrastructure → Risk-Based Authentication → Continuous Verification → …
  • Designing zero trust identity controls
  • SKILL.md covers Prerequisites, Overview, When to Use and Prerequisites, plus 5 more sections
  • Runs Python scripts from its folder

What it does

Implementing Identity Verification For Zero Trust is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements continuous, risk-adaptive identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with NIST SP 800-207 and the CISA Zero Trust Maturity Model Identity Pillar. Use when designing zero trust identity controls, deploying phishing-resistant MFA, or building conditional access policies based on device posture, behavior, and location.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Access reviews and audit trails. It works with Microsoft Entra ID and Okta. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Designing zero trust identity controls
  • Deploying phishing-resistant MFA
  • Building conditional access policies based on device posture

Example prompts

  • “Use the implementing-identity-verification-for-zero-trust skill to implement continuous, risk-adaptive identity verification for zero trust using…”
  • “/implementing-identity-verification-for-zero-trust”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identity Infrastructure
  2. Risk-Based Authentication
  3. Continuous Verification
  4. Identity Governance

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Identity Verification For Zero Trust loads about 2.4k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 121 tokens; SKILL.md has 808 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~121
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 808 words, ~2,355 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-identity-verification-for-zero-trust/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-identity-verification-for-zero-trust
description
Implements continuous, risk-adaptive identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with NIST SP 800-207 and the CISA Zero Trust Maturity Model Identity Pillar. Use when designing zero trust identity controls, deploying phishing-resistant MFA, or building conditional access policies based on device posture, behavior, and location.
domain
cybersecurity
subdomain
zero-trust-architecture
tags
zero-trust, identity, authentication, mfa, identity-verification
version
1.0
author
mahipal
license
Apache-2.0
atlas_techniques
AML.T0052
nist_ai_rmf
GOVERN-1.1, GOVERN-1.7, MAP-1.1
nist_csf
PR.AA-01, PR.AA-05, PR.IR-01, GV.PO-01
mitre_attack
T1078, T1190, T1059, T1566, T1598

Implementing Identity Verification for Zero Trust

Prerequisites

  • Understanding of zero trust principles (NIST SP 800-207)
  • Familiarity with identity providers (Azure AD, Okta, Ping Identity)
  • Knowledge of authentication protocols (SAML 2.0, OIDC, FIDO2)
  • Understanding of MFA and passwordless authentication

Overview

Identity is the foundational pillar of zero trust architecture. NIST SP 800-207 mandates that all resource authentication and authorization are dynamic and strictly enforced before access is allowed. Identity verification in zero trust goes beyond traditional username/password by implementing continuous, risk-adaptive authentication using multiple signals including device posture, behavioral biometrics, location, and network context.

This skill covers implementing phishing-resistant MFA, continuous identity verification, risk-based conditional access, and identity governance aligned with the CISA Zero Trust Maturity Model Identity Pillar.

When to Use

  • When deploying or configuring implementing identity verification for zero trust capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with zero trust architecture concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Architecture

Identity Verification Flow
User Access Request
    │
    v
┌───────────────────────┐
│ Primary Authentication │
│ - FIDO2/WebAuthn key  │
│ - Certificate-based    │
│ - Passwordless         │
└──────────┬────────────┘
           v
┌───────────────────────┐
│ Contextual Assessment  │
│ - Device posture       │
│ - Network location     │
│ - Geo-velocity check   │
│ - Time of access       │
│ - Behavioral baseline  │
└──────────┬────────────┘
           v
┌───────────────────────┐
│ Risk Scoring Engine    │
│ - Aggregate signals    │
│ - Calculate risk score │
│ - Compare to threshold │
└───┬──────────┬────────┘
    │          │
 Low Risk   High Risk
    │          │
    v          v
┌────────┐  ┌──────────────┐
│ Grant  │  │ Step-up Auth  │
│ Access │  │ - Hardware key│
│        │  │ - Biometric   │
│        │  │ - Manager OK  │
└────────┘  └──────────────┘
Identity Provider Architecture
  1. Primary IdP: Azure AD / Okta / Ping Identity for centralized identity management
  2. FIDO2 Authenticators: Hardware security keys (YubiKey) or platform authenticators (Windows Hello, Touch ID)
  3. Risk Engine: Adaptive access using identity threat detection (Microsoft Entra ID Protection, Okta ThreatInsight)
  4. Identity Governance: Lifecycle management, access reviews, just-in-time provisioning
  5. Privileged Identity: Separate verification for elevated access (CyberArk, BeyondTrust)

Key Concepts

Phishing-Resistant MFA

FIDO2/WebAuthn eliminates phishable credentials by binding authentication to the origin domain. Hardware security keys and platform authenticators provide cryptographic proof of identity without transmitting secrets.

Continuous Identity Verification

Rather than authenticating once at session start, zero trust requires ongoing verification through session token evaluation, behavioral analytics, and periodic re-authentication challenges based on risk signals.

Risk-Based Conditional Access

Conditional access policies evaluate multiple signals (user risk level, sign-in risk, device compliance, location) to dynamically adjust authentication requirements and access grants.

Identity Threat Detection

AI-driven analytics detect compromised identities through impossible travel detection, anomalous sign-in patterns, credential stuffing detection, and token replay attacks.

Workflow

Phase 1: Identity Infrastructure
  1. Consolidate Identity Providers

    • Audit all identity sources across the organization
    • Federate to a single authoritative IdP using SAML 2.0 or OIDC
    • Configure SCIM for automated provisioning and deprovisioning
    • Eliminate local accounts and shared credentials
  2. Deploy Phishing-Resistant MFA

    • Enroll all users in FIDO2/WebAuthn with hardware security keys
    • Configure platform authenticators (Windows Hello for Business, macOS Touch ID)
    • Disable SMS and voice call as MFA methods (phishable)
    • Create conditional access policy requiring phishing-resistant methods for all sign-ins
  3. Configure Conditional Access Policies

    • Require compliant device for access to sensitive applications
    • Block legacy authentication protocols (basic auth, IMAP, POP3)
    • Require MFA for all users from untrusted locations
    • Enforce session time limits with re-authentication
    • Block or require additional verification for high-risk sign-ins
Show full SKILL.md (320 more words)Show less
Phase 2: Risk-Based Authentication
  1. Enable Identity Threat Detection

    • Activate Microsoft Entra ID Protection or Okta ThreatInsight
    • Configure risk levels: low (allow), medium (require MFA), high (block and investigate)
    • Enable impossible travel detection and anomalous token alerts
    • Integrate identity risk signals with SIEM/SOAR
  2. Implement Step-Up Authentication

    • For sensitive operations (privilege elevation, financial transactions), require additional verification
    • Configure step-up policies: re-authenticate with hardware key
    • Integrate with PAM for privileged session approval workflows
    • Log all step-up events for audit trail
Phase 3: Continuous Verification
  1. Deploy Continuous Access Evaluation (CAE)

    • Enable Continuous Access Evaluation Protocol (CAEP) for real-time token revocation
    • Configure critical event triggers: user disabled, password changed, location change
    • Test that token revocation occurs within minutes (not hours) of security event
    • Monitor CAE event logs for operational health
  2. Implement Session Controls

    • Configure session duration limits based on application sensitivity
    • Enable sign-in frequency controls (re-authenticate every N hours)
    • Implement persistent browser session controls
    • Configure app-enforced restrictions for unmanaged devices
Phase 4: Identity Governance
  1. Automate Identity Lifecycle

    • Configure joiner-mover-leaver workflows with HR system integration
    • Automate access provisioning based on role and department
    • Enable just-in-time access for temporary elevated permissions
    • Configure automatic access expiration for contractors and guests
  2. Implement Access Reviews

    • Schedule quarterly access certification campaigns
    • Configure automated reminders and escalation
    • Require manager approval for continued access
    • Auto-revoke access for unreviewed certifications

Validation Checklist

  • Single authoritative IdP with all applications federated
  • FIDO2/WebAuthn enrolled for all users
  • SMS and voice MFA methods disabled
  • Legacy authentication protocols blocked
  • Conditional access policies enforced for all applications
  • Identity threat detection active with risk-based policies
  • Continuous Access Evaluation enabled and tested
  • Step-up authentication configured for sensitive operations
  • Identity lifecycle automated with HR integration
  • Quarterly access reviews scheduled and operational
  • Identity events streaming to SIEM

References

  • NIST SP 800-207: Zero Trust Architecture
  • NIST SP 800-63B: Digital Identity Guidelines - Authentication
  • CISA Zero Trust Maturity Model v2.0 - Identity Pillar
  • FIDO Alliance WebAuthn Specification
  • Microsoft Entra Conditional Access Documentation

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-identity-verification-for-zero-trust of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Identity Verification For Zero Trust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Identity Verification For Zero Trust compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Identity Verification For Zero Trust this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0
Access Review TriageGRCEngClub/claude-grc-engineering420—~2.4kAutomated safety check: NotesCustom licence
Azure Pimvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Entra Id Governancevinayaklatthe/microsoft-security-skills175—~2kAutomated safety check: PassMIT
Identity Access Managementsickn33/agentic-awesome-skills47k1 repos~2.9kAutomated safety check: PassMIT
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT

Similar skills

  • Access Review Triage

    GRCEngClub/claude-grc-engineering

    Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export.

    420 GitHub stars~2.4k tokensUpdated 5 days ago
    Documents & OfficeAuto-check: notes
  • Azure Pim

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Entra Id Governance

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Entra ID Governance — automating identity lifecycle and access with entitlement management (access packages), access reviews, lifecycle workflows for joiner-mover-leaver…

    175 GitHub stars~2k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Identity Access Management

    sickn33/agentic-awesome-skills

    Set up and manage SSO, SCIM provisioning, and MFA for startup teams using Google Workspace, Okta, or Azure AD.

    47k GitHub starsUsed in 1 repo~2.9k tokens
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Cursor Sso Integration

    jeremylongshore/tons-of-skills-marketplace

    Configure SAML 2.0 and OIDC SSO for Cursor with Okta, Microsoft Entra ID, and Google Workspace.

    2.8k GitHub stars~2k tokensUpdated today
    Backend & APIsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing Identity Verification For Zero Trust

What does Implementing Identity Verification For Zero Trust do?

Implements continuous, risk-adaptive identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with NIST SP…. Implementing Identity Verification For Zero Trust is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements continuous, risk-adaptive identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with NIST SP 800-207 and the CISA Zero Trust Maturity Model Identity Pillar.

When should I use Implementing Identity Verification For Zero Trust?

Implementing Identity Verification For Zero Trust fits situations like: designing zero trust identity controls; deploying phishing-resistant MFA; building conditional access policies based on device posture.

How do I install Implementing Identity Verification For Zero Trust in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-identity-verification-for-zero-trust -a claude-code`. Or copy the skill folder (skills/implementing-identity-verification-for-zero-trust in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-identity-verification-for-zero-trust in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Identity Verification For Zero Trust in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-identity-verification-for-zero-trust -a codex`. Or copy the skill folder (skills/implementing-identity-verification-for-zero-trust in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-identity-verification-for-zero-trust in your project. Codex loads it when a task matches its description.

Can I use Implementing Identity Verification For Zero Trust in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-identity-verification-for-zero-trust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-identity-verification-for-zero-trust, .gemini/skills/implementing-identity-verification-for-zero-trust, .github/skills/implementing-identity-verification-for-zero-trust and .opencode/skills/implementing-identity-verification-for-zero-trust in your project.

What does Implementing Identity Verification For Zero Trust need to run?

Going by SKILL.md and its folder, Implementing Identity Verification For Zero Trust needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Identity Verification For Zero Trust access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Identity Verification For Zero Trust safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Identity Verification For Zero Trust use?

Implementing Identity Verification For Zero Trust is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Identity Verification For Zero Trust use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Identity Verification For Zero Trust?

Skills that share tags, products or a category with Implementing Identity Verification For Zero Trust: Access Review Triage (GRCEngClub/claude-grc-engineering, 420 stars), Azure Pim (vinayaklatthe/microsoft-security-skills, 175 stars), Entra Id Governance (vinayaklatthe/microsoft-security-skills, 175 stars) and Identity Access Management (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Identity Verification For Zero Trust?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.