Agent skill

Implementing Immutable Backup With Restic

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Implements ransomware-resistant backups using restic with S3-compatible Object Lock (AWS S3, MinIO, Backblaze B2), automating backup creation, integrity checks via restic check --read-data…

Apache-2.0Auto-check passedDevOps & Cloud

Install Implementing Immutable Backup With Restic

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-immutable-backup-with-restic -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-immutable-backup-with-restic --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-immutable-backup-with-restic .claude/skills/implementing-immutable-backup-with-restic && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-immutable-backup-with-restic
GitHub stars
34k
Token cost
~1k tokens
SKILL.md length
374 words
Files
4 (incl. scripts, references)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements ransomware-resistant backups using restic with S3-compatible Object Lock (AWS S3, MinIO, Backblaze B2), automating backup creation, integrity checks via restic check --read-data…

  • Works in 4 steps: Initialize Restic Repository with… → Configure Object Lock Retention → Automate Backup and Verification → …
  • Building immutable backup infrastructure
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Implementing Immutable Backup With Restic is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements ransomware-resistant backups using restic with S3-compatible Object Lock (AWS S3, MinIO, Backblaze B2), automating backup creation, integrity checks via restic check --read-data, retention enforcement, and restore testing. Use when building immutable backup infrastructure, adding a WORM copy to a 3-2-1-1-0 strategy, or automating scheduled backup-verification workflows.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in DevOps & Cloud, covering Backup and disaster recovery and File uploads and storage. It works with Amazon S3. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Building immutable backup infrastructure
  • Adding a WORM copy to a 3-2-1-1-0 strategy
  • Automating scheduled backup-verification workflows

Example prompts

  • “Use the implementing-immutable-backup-with-restic skill to implement ransomware-resistant backups using restic with S3-compatible Object Lock (AWS…”
  • “/implementing-immutable-backup-with-restic”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Initialize Restic Repository with Encryption
  2. Configure Object Lock Retention
  3. Automate Backup and Verification
  4. Test Restore Procedures

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • restic.readthedocs.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Immutable Backup With Restic loads about 1k tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 374 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 374 words, ~1,044 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-immutable-backup-with-restic/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-immutable-backup-with-restic
description
Implements ransomware-resistant backups using restic with S3-compatible Object Lock (AWS S3, MinIO, Backblaze B2), automating backup creation, integrity checks via restic check --read-data, retention enforcement, and restore testing. Use when building immutable backup infrastructure, adding a WORM copy to a 3-2-1-1-0 strategy, or automating scheduled backup-verification workflows.
domain
cybersecurity
subdomain
ransomware-defense
tags
restic, backup, immutable, ransomware, s3, object-lock, worm, recovery
version
1.0.0
author
mahipal
license
Apache-2.0
nist_ai_rmf
MEASURE-2.7, MAP-5.1, MANAGE-2.4
atlas_techniques
AML.T0070, AML.T0066, AML.T0082
nist_csf
PR.DS-11, RS.MA-01, RC.RP-01, PR.IR-01
mitre_attack
T1078, T1190, T1059, T1486, T1490

Implementing Immutable Backup with Restic

When to Use

  • Establishing ransomware-resistant backup infrastructure with cryptographic integrity verification
  • Implementing 3-2-1-1-0 backup strategy where the extra 1 is an immutable copy
  • Automating backup verification workflows that test restore capability on a schedule
  • Protecting backup repositories from deletion or modification by compromised admin accounts
  • Meeting compliance requirements for data retention with tamper-proof storage

Do not use as the sole backup solution without also maintaining offline/air-gapped copies. Object lock protects against logical deletion but not physical storage failure.

Prerequisites

  • restic binary installed (https://restic.readthedocs.io/)
  • S3-compatible storage with Object Lock enabled (AWS S3, MinIO, Backblaze B2)
  • Python 3.8+ with subprocess module
  • AWS CLI or MinIO client (mc) configured for bucket access
  • Sufficient storage for backup repository (typically 2-3x source data with deduplication)

Workflow

Step 1: Initialize Restic Repository with Encryption

Create an encrypted restic repository on S3-compatible storage with object lock enabled. Restic uses AES-256-CTR for encryption with Poly1305-AES for authentication, ensuring backup data is both confidential and tamper-evident.

Step 2: Configure Object Lock Retention

Enable S3 Object Lock in Compliance mode on the backup bucket to prevent any principal (including root) from deleting or modifying objects during the retention period. Set retention to match your backup window requirements (typically 30-90 days).

Step 3: Automate Backup and Verification

Schedule backup operations with post-backup integrity verification using restic check --read-data which downloads and verifies every data blob against its stored checksum. Log results and alert on any integrity failures.

Show full SKILL.md (133 more words)Show less
Step 4: Test Restore Procedures

Periodically restore random files from backup snapshots to a temporary location and compare checksums against the original to validate end-to-end backup integrity. Document restore times for RTO planning.

Key Concepts

TermDefinition
Object LockS3 feature that prevents object deletion or overwrite for a specified retention period
Compliance ModeObject Lock mode where even the root account cannot delete objects before retention expires
DeduplicationRestic stores data in content-addressable chunks, deduplicating across all snapshots
3-2-1-1-03 copies, 2 media types, 1 offsite, 1 immutable, 0 errors in verification

Tools & Systems

  • restic: Fast, secure, cross-platform backup tool with built-in encryption and deduplication
  • resticpy: Python wrapper for restic CLI operations
  • AWS S3 Object Lock: WORM storage for tamper-proof backup retention
  • MinIO: Self-hosted S3-compatible storage with Object Lock support

Output Format

BACKUP VERIFICATION REPORT
===========================
Repository: s3:s3.amazonaws.com/company-backups-immutable
Snapshots: 45
Total Size: 2.3 TiB (deduplicated from 8.7 TiB)
Last Backup: 2026-03-11T02:00:00Z
Integrity Check: PASSED (all packs verified)
Object Lock: Compliance mode, 90-day retention
Restore Test: PASSED (15 files verified)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-immutable-backup-with-restic of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Immutable Backup With Restic next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Immutable Backup With Restic compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Immutable Backup With Restic this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1kAutomated safety check: PassApache-2.0
Storage S3 Resiliency Expertiseaws/tools-for-devops-agent100—~2.8kAutomated safety check: PassApache-2.0
AWS Essentialsericrisco/rsc-harness167—~2.9kAutomated safety check: NotesMIT
Resticmajiayu000/claude-skill-registry6661 repos~1.8kAutomated safety check: PassMIT
Database Backupssickn33/agentic-awesome-skills47k2 repos~3.1kAutomated safety check: NotesMIT
Storage Fsx Windows Sla Optimizeraws/tools-for-devops-agent100—~3.4kAutomated safety check: PassApache-2.0

Similar skills

  • Storage S3 Resiliency Expertise

    aws/tools-for-devops-agent

    Official

    S3 resiliency, security, and data protection review. An agent skill from aws/tools-for-devops-agent.

    100 GitHub stars~2.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Essentials

    ericrisco/rsc-harness

    A skill your agent uses when standing up the core AWS surface a small product needs: hardening a fresh account, a private S3 bucket, encrypted RDS Postgres, ECS Fargate vs EC2, CloudFront + OAC, or…

    167 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Restic

    majiayu000/claude-skill-registry

    Install, configure, operate, secure, automate, tune, troubleshoot, and recover restic backups across local, SFTP, S3-compatible, cloud, and REST backends.

    666 GitHub starsUsed in 1 repo~1.8k tokens
    DevOps & CloudAuto-check passed
  • Database Backups

    sickn33/agentic-awesome-skills

    Implement database backup strategies. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.1k tokens
    DatabasesAuto-check: notes
  • Storage Fsx Windows Sla Optimizer

    aws/tools-for-devops-agent

    Official

    Read-only SLA-readiness, availability, and cost review of Amazon FSx for Windows File Server.

    100 GitHub stars~3.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • S3 Bucket Policy Generator

    jeremylongshore/tons-of-skills-marketplace

    Generate s3 bucket policy generator operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~571 tokensUpdated today
    Backend & APIsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Implementing Immutable Backup With Restic

What does Implementing Immutable Backup With Restic do?

Implements ransomware-resistant backups using restic with S3-compatible Object Lock (AWS S3, MinIO, Backblaze B2), automating backup creation, integrity checks via restic check --read-data…. Implementing Immutable Backup With Restic is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements ransomware-resistant backups using restic with S3-compatible Object Lock (AWS S3, MinIO, Backblaze B2), automating backup creation, integrity checks via restic check --read-data, retention enforcement, and restore testing.

When should I use Implementing Immutable Backup With Restic?

Implementing Immutable Backup With Restic fits situations like: building immutable backup infrastructure; adding a WORM copy to a 3-2-1-1-0 strategy; automating scheduled backup-verification workflows.

How do I install Implementing Immutable Backup With Restic in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-immutable-backup-with-restic -a claude-code`. Or copy the skill folder (skills/implementing-immutable-backup-with-restic in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-immutable-backup-with-restic in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Immutable Backup With Restic in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-immutable-backup-with-restic -a codex`. Or copy the skill folder (skills/implementing-immutable-backup-with-restic in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-immutable-backup-with-restic in your project. Codex loads it when a task matches its description.

Can I use Implementing Immutable Backup With Restic in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-immutable-backup-with-restic -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-immutable-backup-with-restic, .gemini/skills/implementing-immutable-backup-with-restic, .github/skills/implementing-immutable-backup-with-restic and .opencode/skills/implementing-immutable-backup-with-restic in your project.

What does Implementing Immutable Backup With Restic need to run?

Going by SKILL.md and its folder, Implementing Immutable Backup With Restic needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Immutable Backup With Restic access the network?

SKILL.md names 1 domain. As links in the text: restic.readthedocs.io. This is read from the text; nothing was executed.

Is Implementing Immutable Backup With Restic safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Immutable Backup With Restic use?

Implementing Immutable Backup With Restic is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Immutable Backup With Restic use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 759 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Immutable Backup With Restic?

Skills that share tags, products or a category with Implementing Immutable Backup With Restic: Storage S3 Resiliency Expertise (aws/tools-for-devops-agent, 100 stars), AWS Essentials (ericrisco/rsc-harness, 167 stars), Restic (majiayu000/claude-skill-registry, 666 stars) and Database Backups (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Immutable Backup With Restic?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.