Sast Missingauth
utkusen/sast-skills
Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify…
Agent skill
Deploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-access-control-with-cisco-ise -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-access-control-with-cisco-ise --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-network-access-control-with-cisco-ise .claude/skills/implementing-network-access-control-with-cisco-ise && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "implementing-network-access-control-with-cisco-ise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-access-control-with-cisco-ise into .claude/skills/implementing-network-access-control-with-cisco-ise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-access-control-with-cisco-ise", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-access-control-with-cisco-iseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-access-control-with-cisco-ise -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-access-control-with-cisco-ise --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/implementing-network-access-control-with-cisco-ise .agents/skills/implementing-network-access-control-with-cisco-ise && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "implementing-network-access-control-with-cisco-ise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-access-control-with-cisco-ise into .agents/skills/implementing-network-access-control-with-cisco-ise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-access-control-with-cisco-ise", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-access-control-with-cisco-ise -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-access-control-with-cisco-ise --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/implementing-network-access-control-with-cisco-ise .cursor/skills/implementing-network-access-control-with-cisco-ise && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "implementing-network-access-control-with-cisco-ise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-access-control-with-cisco-ise into .cursor/skills/implementing-network-access-control-with-cisco-ise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-access-control-with-cisco-ise", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/implementing-network-access-control-with-cisco-ise--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-access-control-with-cisco-ise -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-access-control-with-cisco-ise --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/implementing-network-access-control-with-cisco-ise .gemini/skills/implementing-network-access-control-with-cisco-ise && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "implementing-network-access-control-with-cisco-ise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-access-control-with-cisco-ise into .gemini/skills/implementing-network-access-control-with-cisco-ise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-access-control-with-cisco-ise", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-access-control-with-cisco-iseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-access-control-with-cisco-ise -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/implementing-network-access-control-with-cisco-ise .github/skills/implementing-network-access-control-with-cisco-ise && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "implementing-network-access-control-with-cisco-ise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-access-control-with-cisco-ise into .github/skills/implementing-network-access-control-with-cisco-ise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-access-control-with-cisco-ise", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-access-control-with-cisco-ise -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-network-access-control-with-cisco-ise --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/implementing-network-access-control-with-cisco-ise .opencode/skills/implementing-network-access-control-with-cisco-ise && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "implementing-network-access-control-with-cisco-ise" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-network-access-control-with-cisco-ise into .opencode/skills/implementing-network-access-control-with-cisco-ise/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-network-access-control-with-cisco-ise", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
implementing-network-access-control-with-cisco-iseDeploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment…
Implementing Network Access Control With Cisco Ise is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment, downloadable ACLs, and TrustSec Security Group Tags. Use when deploying enterprise NAC with ISE and Active Directory integration, enforcing endpoint posture compliance, or segmenting access with TrustSec instead of a generic 802.1X/PacketFence setup.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Security, covering Authorization and RBAC, Red teaming and adversary simulation and Authentication. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
cisco.comciscolive.comnetworkcomputing.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Implementing Network Access Control With Cisco Ise loads about 2.9k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 123 tokens; SKILL.md has 632 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 632 words, ~2,893 tokens.
.claude/skills/implementing-network-access-control-with-cisco-ise/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Cisco Identity Services Engine (ISE) provides centralized network access control through 802.1X authentication, MAC Authentication Bypass (MAB), posture assessment, and guest access management. ISE acts as a RADIUS policy server that evaluates authentication requests from network devices (switches, wireless controllers) and returns authorization policies including VLAN assignments, downloadable ACLs (dACLs), and Security Group Tags (SGTs). This skill covers deploying ISE for enterprise wired 802.1X authentication with Active Directory integration, MAB fallback, posture compliance enforcement, and TrustSec segmentation.
The 802.1X framework involves three components:
| Component | Role | Example |
|---|---|---|
| Supplicant | Client requesting network access | Windows 802.1X client, AnyConnect NAM |
| Authenticator | Network device controlling port access | Cisco Catalyst switch |
| Authentication Server | Policy decision engine | Cisco ISE (RADIUS) |
1. Endpoint connects to switch port
2. Switch sends EAP-Request/Identity to endpoint
3. Endpoint responds with EAP-Response/Identity
4. Switch forwards credentials to ISE via RADIUS Access-Request
5. ISE authenticates against AD/LDAP/internal store
6. ISE evaluates authorization policy
7. ISE returns RADIUS Access-Accept with attributes (VLAN, dACL, SGT)
8. Switch enforces authorization on the port| Method | Use Case | Security Level |
|---|---|---|
| EAP-TLS | Certificate-based, highest security | High |
| PEAP-MSCHAPv2 | Username/password via AD | Medium |
| EAP-FAST | Cisco proprietary, fast reauthentication | Medium |
| MAB | Non-802.1X devices (printers, IP phones) | Low |
Navigate to Administration > Identity Management > External Identity Sources > Active Directory:
corp.example.com)Domain Users - Standard employee accessDomain Computers - Machine authenticationIT-Admins - Privileged accessBYOD-Users - Personal device accessNavigate to Administration > Network Resources > Network Devices:
Name: SW-ACCESS-01
IP Address: 10.0.1.1/32
RADIUS Shared Secret: C0mpl3x$3cretKey!
SNMP Settings: v2c, community string
Device Type: Cisco Switches
Location: Building-A-Floor-1Create a Network Device Group hierarchy:
Device Type:
├── Cisco Switches
│ ├── Access Layer
│ └── Distribution Layer
└── Wireless Controllers
Location:
├── Building-A
└── Building-BApply this configuration to the access switch:
! Enable AAA
aaa new-model
aaa authentication dot1x default group radius
aaa authorization network default group radius
aaa accounting dot1x default start-stop group radius
aaa accounting update newinfo periodic 2880
! Configure RADIUS server
radius server ISE-PRIMARY
address ipv4 10.0.5.10 auth-port 1812 acct-port 1813
key 0 C0mpl3x$3cretKey!
automate-tester username radius-test probe-on
radius server ISE-SECONDARY
address ipv4 10.0.5.11 auth-port 1812 acct-port 1813
key 0 C0mpl3x$3cretKey!
automate-tester username radius-test probe-on
aaa group server radius ISE-GROUP
server name ISE-PRIMARY
server name ISE-SECONDARY
deadtime 15
ip radius source-interface Loopback0
! Enable 802.1X globally
dot1x system-auth-control
! Enable RADIUS CoA (Change of Authorization)
aaa server radius dynamic-author
client 10.0.5.10 server-key C0mpl3x$3cretKey!
client 10.0.5.11 server-key C0mpl3x$3cretKey!
! Enable device tracking for IP-to-MAC mapping
device-tracking tracking auto-source
! Configure access port template
interface range GigabitEthernet1/0/1-48
description 802.1X Access Port
switchport mode access
switchport access vlan 100
! Authentication settings
authentication host-mode multi-auth
authentication order dot1x mab
authentication priority dot1x mab
authentication port-control auto
authentication periodic
authentication timer reauthenticate server
authentication timer inactivity server dynamic
authentication violation restrict
! 802.1X settings
dot1x pae authenticator
dot1x timeout tx-period 10
dot1x max-reauth-req 2
! MAB fallback
mab
! Enable spanning-tree portfast (required for timely auth)
spanning-tree portfast
! Apply pre-auth ACL
ip access-group PRE-AUTH-ACL in
! Pre-authentication ACL (allow DHCP, DNS, ISE portal)
ip access-list extended PRE-AUTH-ACL
permit udp any any eq 67
permit udp any any eq 68
permit udp any any eq 53
permit tcp any host 10.0.5.10 eq 8443
permit tcp any host 10.0.5.11 eq 8443
deny ip any anyNavigate to Policy > Policy Sets:
Authentication Policy:
| Rule Name | Condition | Allowed Protocols | Identity Source |
|---|---|---|---|
| Dot1X-EAP-TLS | Radius:EAP-Type EQUALS EAP-TLS | EAP-TLS | AD with Certificate |
| Dot1X-PEAP | Radius:EAP-Type EQUALS PEAP | PEAP-MSCHAPv2 | Active Directory |
| MAB | Radius:Service-Type EQUALS Call-Check | MAB Lookup | Internal Endpoints |
| Default | Default | Default | Deny Access |
Authorization Policy:
| Rule Name | Condition | Authorization Profile |
|---|---|---|
| IT-Admin-Wired | AD:Group EQUALS IT-Admins AND Dot1X | VLAN10-FullAccess |
| Employee-Compliant | AD:Group EQUALS Domain Users AND Posture:Compliant | VLAN100-Corporate |
| Employee-NonCompliant | AD:Group EQUALS Domain Users AND Posture:NonCompliant | VLAN200-Remediation |
| Printer-MAB | EndpointIdentityGroup EQUALS Printers | VLAN150-Printers |
| IP-Phone-MAB | EndpointIdentityGroup EQUALS IP-Phones | VLAN50-Voice |
| BYOD-Onboarding | AD:Group EQUALS BYOD-Users AND !Registered | BYOD-Portal-Redirect |
| Guest-Access | GuestEndpointGroup EQUALS GuestEndpoints | VLAN300-Guest |
| Default | Default | DenyAccess |
Authorization Profiles:
Profile: VLAN100-Corporate
VLAN: 100
dACL: PERMIT_ALL
SGT: Employees (0x0005)
Reauthentication Timer: 28800
Profile: VLAN200-Remediation
VLAN: 200
dACL: REMEDIATION-ACL (allow only remediation server access)
Web Redirection: Posture Discovery
Reauthentication Timer: 300
Profile: DenyAccess
Access Type: ACCESS_REJECTNavigate to Work Centers > Posture:
Posture Conditions:
- Windows Firewall Enabled (Registry check)
- Antivirus Running and Updated (AV compound condition)
- OS Patch Level Current (Windows Update check)
- Disk Encryption Enabled (BitLocker check)Posture Requirements:
Requirement: Corporate-Windows-Compliance
OS: Windows All
Conditions: Windows Firewall AND Antivirus AND OS Patches
Remediation: Auto-remediate with AnyConnect ISE Posture ModulePosture Policy:
Rule: Windows-Endpoints
Identity Group: Any
OS: Windows All
Requirement: Corporate-Windows-ComplianceEnable SGT-based segmentation:
! On switch - enable CTS
cts credentials id SW-ACCESS-01 password CtsP@ss
cts role-based enforcement
cts role-based sgt-map 10.0.100.0/24 sgt 5
! Download SGT policy from ISE
cts role-based permissionsISE TrustSec Matrix (SGACL):
| Source SGT | Destination SGT | Policy |
|---|---|---|
| Employees (5) | Servers (10) | Permit_HTTP_HTTPS |
| Employees (5) | PCI_Zone (15) | Deny_All |
| IT-Admins (3) | Servers (10) | Permit_All |
| Guest (7) | Internet (99) | Permit_HTTP_HTTPS |
| Guest (7) | Servers (10) | Deny_All |
# On switch - verify authentication status
show authentication sessions
show authentication sessions interface Gi1/0/1 details
show dot1x all
# Check RADIUS connectivity
test aaa server radius ISE-PRIMARY username testuser password testpass
# On ISE - check live logs
# Navigate to Operations > RADIUS > Live Logs
# Filter by MAC address or username
# Review Authentication Details for failure reason
# Common failure reasons:
# 12514 - EAP-TLS handshake failed (certificate issue)
# 22056 - Subject not found in identity store
# 24408 - User not found in Active Directory
# 24454 - User password expiredauthentication open with pre-auth dACLs for gradual rollout© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/implementing-network-access-control-with-cisco-ise of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Implementing Network Access Control With Cisco Ise next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Implementing Network Access Control With Cisco Ise this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Sast Missingauthutkusen/sast-skills | 1.3k | — | ~6k | Automated safety check: Pass | MIT | |
| Security Review ChecklistZeroDeng01/sublinkPro | 1.7k | — | ~2.3k | Automated safety check: Pass | MIT | |
| Identity Access Anomaly Reviewahmadvh/octochains | 376 | — | ~1.3k | Automated safety check: Pass | Custom licence | |
| Security ConvexIgorWarzocha/Opencode-Workflows | 122 | — | ~3.1k | Automated safety check: Pass | None | |
| Authorization Bypass DetectionTencent/AI-Infra-Guard | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 |
utkusen/sast-skills
Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify…
ZeroDeng01/sublinkPro
Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.
ahmadvh/octochains
Analyzes authentication and authorization events for failed-login clustering, privilege-escalation chains, credential-stuffing patterns, and MFA-bypass indicators.
IgorWarzocha/Opencode-Workflows
Review Convex security audit patterns for authentication and authorization.
Tencent/AI-Infra-Guard
Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.
NeoTheCapt/RedteamAgent
Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Deploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment…. Implementing Network Access Control With Cisco Ise is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment, downloadable ACLs, and TrustSec Security Group Tags.
Implementing Network Access Control With Cisco Ise fits situations like: deploying enterprise NAC with ISE and Active Directory integration; enforcing endpoint posture compliance; segmenting access with TrustSec instead of a generic 802.1X/PacketFence setup.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-access-control-with-cisco-ise -a claude-code`. Or copy the skill folder (skills/implementing-network-access-control-with-cisco-ise in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-network-access-control-with-cisco-ise in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-access-control-with-cisco-ise -a codex`. Or copy the skill folder (skills/implementing-network-access-control-with-cisco-ise in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-network-access-control-with-cisco-ise in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-network-access-control-with-cisco-ise -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-network-access-control-with-cisco-ise, .gemini/skills/implementing-network-access-control-with-cisco-ise, .github/skills/implementing-network-access-control-with-cisco-ise and .opencode/skills/implementing-network-access-control-with-cisco-ise in your project.
Going by SKILL.md and its folder, Implementing Network Access Control With Cisco Ise needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md names 3 domains. As links in the text: cisco.com, ciscolive.com and networkcomputing.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Implementing Network Access Control With Cisco Ise is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 401 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Implementing Network Access Control With Cisco Ise: Sast Missingauth (utkusen/sast-skills, 1.3k stars), Security Review Checklist (ZeroDeng01/sublinkPro, 1.7k stars), Identity Access Anomaly Review (ahmadvh/octochains, 376 stars) and Security Convex (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.