Devops Agent
LeoYeAI/openclaw-master-skills
Your on-call DevOps assistant — one-click deploy, monitoring setup, scheduled backups, and fault diagnosis.
Agent skill
Develops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-ot-incident-response-playbook --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-ot-incident-response-playbook .claude/skills/implementing-ot-incident-response-playbook && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "implementing-ot-incident-response-playbook" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-ot-incident-response-playbook into .claude/skills/implementing-ot-incident-response-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-ot-incident-response-playbook", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-ot-incident-response-playbookType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-ot-incident-response-playbook --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/implementing-ot-incident-response-playbook .agents/skills/implementing-ot-incident-response-playbook && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "implementing-ot-incident-response-playbook" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-ot-incident-response-playbook into .agents/skills/implementing-ot-incident-response-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-ot-incident-response-playbook", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-ot-incident-response-playbook --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/implementing-ot-incident-response-playbook .cursor/skills/implementing-ot-incident-response-playbook && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "implementing-ot-incident-response-playbook" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-ot-incident-response-playbook into .cursor/skills/implementing-ot-incident-response-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-ot-incident-response-playbook", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/implementing-ot-incident-response-playbook--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-ot-incident-response-playbook --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/implementing-ot-incident-response-playbook .gemini/skills/implementing-ot-incident-response-playbook && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "implementing-ot-incident-response-playbook" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-ot-incident-response-playbook into .gemini/skills/implementing-ot-incident-response-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-ot-incident-response-playbook", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-ot-incident-response-playbookInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/implementing-ot-incident-response-playbook .github/skills/implementing-ot-incident-response-playbook && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "implementing-ot-incident-response-playbook" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-ot-incident-response-playbook into .github/skills/implementing-ot-incident-response-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-ot-incident-response-playbook", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-ot-incident-response-playbook --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/implementing-ot-incident-response-playbook .opencode/skills/implementing-ot-incident-response-playbook && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "implementing-ot-incident-response-playbook" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-ot-incident-response-playbook into .opencode/skills/implementing-ot-incident-response-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-ot-incident-response-playbook", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
implementing-ot-incident-response-playbookDevelops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering…
Implementing Ot Incident Response Playbook is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Develops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering, and plant operations, aligned with IEC 62443 and NIST SP 800-82. Use when building ICS/SCADA incident response procedures for the first time, preparing for OT ransomware scenarios, or aligning IR with IEC 62443/NERC CIP reporting requirements.
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in DevOps & Cloud, covering Incident response. It works with Python. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Implementing Ot Incident Response Playbook loads about 4.2k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 121 tokens; SKILL.md has 428 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 428 words, ~4,234 tokens.
.claude/skills/implementing-ot-incident-response-playbook/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Do not use for IT-only incident response without OT components (use standard NIST 800-61 playbooks), for day-to-day OT security monitoring (see implementing-dragos-platform-for-ot-monitoring), or for tabletop exercise design (see performing-ics-tabletop-exercise).
#!/usr/bin/env python3
"""OT Incident Response Playbook Engine.
Implements structured OT incident response procedures following
SANS PICERL lifecycle with ICS-specific considerations for safety,
availability, and cross-team coordination.
"""
import json
import sys
from datetime import datetime
from enum import Enum
from typing import Dict, List, Optional
class OTIncidentSeverity(Enum):
SEV1_SAFETY = "SEV1-SAFETY" # Safety system compromise
SEV2_PROCESS = "SEV2-PROCESS" # Active process manipulation
SEV3_ACCESS = "SEV3-ACCESS" # Unauthorized OT access
SEV4_RECON = "SEV4-RECON" # Reconnaissance in OT network
SEV5_IT_SPILLOVER = "SEV5-IT-SPILLOVER" # IT incident with OT exposure
class OTIncidentCategory(Enum):
RANSOMWARE = "ransomware"
MALWARE_ICS = "malware_ics_specific"
UNAUTHORIZED_ACCESS = "unauthorized_ot_access"
PROCESS_MANIPULATION = "process_manipulation"
SIS_COMPROMISE = "safety_system_compromise"
DATA_EXFILTRATION = "ot_data_exfiltration"
SUPPLY_CHAIN = "supply_chain_compromise"
INSIDER_THREAT = "insider_threat"
# PICERL phase definitions for OT
PICERL_PHASES = {
"preparation": {
"description": "Readiness activities before an incident occurs",
"ot_specific": [
"Maintain offline backups of all PLC programs and HMI configurations",
"Document safe shutdown procedures for each process area",
"Establish out-of-band communication (satellite phone, analog radio)",
"Pre-stage forensic tools that work in air-gapped OT networks",
"Maintain spare PLCs and engineering workstations",
"Conduct quarterly OT tabletop exercises",
],
},
"identification": {
"description": "Detect and confirm the OT security incident",
"ot_specific": [
"Correlate OT IDS alerts with process anomalies from historian data",
"Verify if process deviations are cyber-caused vs operational",
"Check Safety Instrumented Systems (SIS) status and integrity",
"Review engineering workstation logs for unauthorized access",
"Examine PLC mode changes (RUN/STOP/PROGRAM transitions)",
"Assess whether the incident is IT-only or has crossed into OT",
],
},
"containment": {
"description": "Limit the spread and impact of the incident",
"ot_specific": [
"NEVER shut down OT systems without plant operations approval",
"Isolate affected segments at the industrial firewall (not by powering off)",
"Switch PLCs to LOCAL/MANUAL mode if remote manipulation is suspected",
"Disconnect IT-OT conduits at the DMZ while maintaining intra-OT communication",
"Preserve forensic evidence before any remediation actions",
"Maintain safety system operation throughout containment",
],
},
"eradication": {
"description": "Remove the threat from OT systems",
"ot_specific": [
"Compare running PLC programs against known-good backups",
"Rebuild compromised engineering workstations from golden images",
"Verify historian data integrity for evidence of manipulation",
"Check for persistence mechanisms in OT-specific locations (startup scripts, scheduled tasks on HMIs)",
"Validate firmware integrity on PLCs and RTUs",
"Coordinate with ICS vendor for rootkit-level remediation if needed",
],
},
"recovery": {
"description": "Restore OT operations to normal",
"ot_specific": [
"Restore PLC programs from verified offline backups",
"Bring processes back online in stages with engineering oversight",
"Monitor process variables closely during restart for anomalies",
"Validate safety system functionality before resuming automatic operation",
"Re-enable IT-OT connectivity only after OT is verified clean",
"Document any process variable drift during the incident",
],
},
"lessons_learned": {
"description": "Post-incident review and improvement",
"ot_specific": [
"Conduct joint IT/OT post-incident review within 2 weeks",
"Update detection rules based on observed attack techniques",
"Revise network segmentation if lateral movement was successful",
"Update PLC backup schedules based on recovery time experienced",
"Report to CISA ICS-CERT and sector ISAC as required",
"Test updated playbook within 90 days",
],
},
}
class OTIncident:
"""Represents an active OT security incident."""
def __init__(self, title: str, severity: OTIncidentSeverity,
category: OTIncidentCategory, affected_systems: List[str]):
self.id = f"OT-IR-{datetime.now().strftime('%Y%m%d-%H%M%S')}"
self.title = title
self.severity = severity
self.category = category
self.affected_systems = affected_systems
self.created = datetime.now().isoformat()
self.current_phase = "identification"
self.timeline = []
self.decisions = []
self.containment_actions = []
def log_event(self, phase: str, action: str, actor: str, notes: str = ""):
"""Log an incident response action."""
entry = {
"timestamp": datetime.now().isoformat(),
"phase": phase,
"action": action,
"actor": actor,
"notes": notes,
}
self.timeline.append(entry)
return entry
def log_decision(self, decision: str, rationale: str, approved_by: str):
"""Log a critical decision during incident response."""
entry = {
"timestamp": datetime.now().isoformat(),
"decision": decision,
"rationale": rationale,
"approved_by": approved_by,
}
self.decisions.append(entry)
return entry
class OTPlaybookEngine:
"""Executes OT incident response playbooks."""
def __init__(self):
self.playbooks = self._build_playbooks()
def _build_playbooks(self) -> Dict:
"""Build category-specific OT IR playbooks."""
return {
OTIncidentCategory.RANSOMWARE: {
"name": "OT Ransomware Response",
"reference": "SANS ICS Ransomware Defense Playbook",
"immediate_actions": [
"DO NOT pay ransom without executive and legal approval",
"Disconnect IT-OT conduit at DMZ firewalls immediately",
"Verify SIS/safety systems are operating independently",
"Switch critical processes to manual/local control",
"Preserve ransom note and encrypted file samples for forensics",
"Assess if ransomware has reached Level 2 or below",
],
"containment_steps": [
"Block lateral movement by disabling SMB/RDP between OT hosts",
"Isolate affected VLANs while maintaining critical process communication",
"Disable remote access VPN to OT environment",
"Check if backup infrastructure is intact (ransomware targets backups)",
"Inventory which OT systems are encrypted vs still operational",
],
"recovery_priority": [
"1. Safety Instrumented Systems (SIS)",
"2. Critical process controllers (PLCs in continuous process)",
"3. HMIs for operator visibility",
"4. Historian for data continuity",
"5. Engineering workstations",
"6. IT-OT connectivity (last)",
],
"reporting": [
"CISA: report within 72 hours per CIRCIA",
"Sector ISAC: share IOCs within 24 hours",
"NERC (if applicable): report within 1 hour for BES impact",
],
},
OTIncidentCategory.SIS_COMPROMISE: {
"name": "Safety System Compromise Response",
"reference": "TRITON/TRISIS Incident Lessons Learned",
"immediate_actions": [
"IMMEDIATELY alert Process Safety team",
"Verify physical safety devices are functional (relief valves, rupture discs)",
"Consider controlled process shutdown if SIS integrity is uncertain",
"Isolate SIS network from all other networks",
"Check if SIS is in bypass mode or has been disarmed",
"Engage SIS vendor emergency support (Schneider Triconex, HIMA, etc)",
],
"containment_steps": [
"Physically disconnect the SIS engineering workstation from network",
"Capture forensic image of SIS engineering workstation",
"Verify SIS controller firmware and logic against factory baseline",
"Check for unauthorized TriStation/safety protocol connections",
"Inspect all engineering workstations for TRITON indicators",
],
"recovery_priority": [
"1. Verify all physical safety barriers are intact",
"2. Reload SIS logic from offline backup (verified against vendor baseline)",
"3. Full SIS proof test before returning to service",
"4. Independent verification by process safety engineer",
],
"reporting": [
"CISA ICS-CERT: immediate notification for SIS-targeting attack",
"Process safety regulator (OSHA, HSE): as required by jurisdiction",
"SIS vendor: engage for root cause analysis",
],
},
}
def execute_playbook(self, incident: OTIncident):
"""Execute the appropriate playbook for an incident."""
playbook = self.playbooks.get(incident.category)
if not playbook:
print(f"[!] No specific playbook for {incident.category.value}. Using generic OT IR procedures.")
return
print(f"\n{'='*70}")
print(f"OT INCIDENT RESPONSE PLAYBOOK ACTIVATED")
print(f"{'='*70}")
print(f"Incident ID: {incident.id}")
print(f"Title: {incident.title}")
print(f"Severity: {incident.severity.value}")
print(f"Category: {incident.category.value}")
print(f"Playbook: {playbook['name']}")
print(f"Reference: {playbook['reference']}")
print(f"Activated: {incident.created}")
print(f"Affected Systems: {', '.join(incident.affected_systems)}")
print(f"\n--- IMMEDIATE ACTIONS (Execute within first 15 minutes) ---")
for i, action in enumerate(playbook["immediate_actions"], 1):
print(f" {i}. {action}")
print(f"\n--- CONTAINMENT STEPS ---")
for i, step in enumerate(playbook["containment_steps"], 1):
print(f" {i}. {step}")
print(f"\n--- RECOVERY PRIORITY ORDER ---")
for item in playbook["recovery_priority"]:
print(f" {item}")
print(f"\n--- REPORTING REQUIREMENTS ---")
for req in playbook["reporting"]:
print(f" - {req}")
# Print PICERL phase guidance
print(f"\n--- PICERL PHASE CHECKLIST ---")
for phase, info in PICERL_PHASES.items():
print(f"\n [{phase.upper()}] {info['description']}")
for item in info["ot_specific"][:3]:
print(f" - {item}")
if __name__ == "__main__":
engine = OTPlaybookEngine()
# Example: OT Ransomware incident
incident = OTIncident(
title="Ransomware detected on Level 3 historian servers",
severity=OTIncidentSeverity.SEV2_PROCESS,
category=OTIncidentCategory.RANSOMWARE,
affected_systems=["HIST-01", "HIST-02", "ENG-WS-03", "HMI-AREA1"],
)
engine.execute_playbook(incident)| Term | Definition |
|---|---|
| PICERL | SANS incident response lifecycle: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned |
| ICS4ICS | Incident Command System for Industrial Control Systems -- adapts FEMA ICS to OT cybersecurity response |
| Safety Instrumented System (SIS) | Independent safety controller that prevents hazardous conditions; compromising SIS can cause physical harm |
| Manual/Local Mode | Operating PLCs with local panel controls instead of remote SCADA; used when remote access is compromised |
| CIRCIA | Cyber Incident Reporting for Critical Infrastructure Act requiring reporting to CISA within 72 hours |
| Known-Good Backup | Verified, offline copy of PLC programs and configurations used as the trusted baseline for recovery |
Context: Ransomware encrypts enterprise IT systems and spreads through an inadequately protected IT/OT conduit to Level 3 historian servers. HMIs at Level 2 begin showing connectivity errors.
Approach:
Pitfalls: Do not shut down PLCs to "protect" them from ransomware -- PLCs run firmware, not Windows, and are typically unaffected by ransomware. Shutting down PLCs disrupts the physical process. Never reconnect IT-OT conduit until the IT side is fully remediated.
OT INCIDENT RESPONSE REPORT
==============================
Incident ID: OT-IR-YYYYMMDD-HHMMSS
Severity: SEV[1-5]
Category: [category]
Status: [Active/Contained/Eradicated/Recovered/Closed]
TIMELINE:
[timestamp] - [phase] - [action] - [actor]
AFFECTED SYSTEMS:
Safety Systems: [status]
Process Controllers: [status]
HMI/SCADA: [status]
Historian: [status]
DECISIONS LOG:
[timestamp] - [decision] - [rationale] - [approver]
CONTAINMENT ACTIONS TAKEN:
1. [action and timestamp]
RECOVERY STATUS:
[system] - [restored/pending] - [ETA]© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/implementing-ot-incident-response-playbook of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Implementing Ot Incident Response Playbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Implementing Ot Incident Response Playbook this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Devops AgentLeoYeAI/openclaw-master-skills | 2.2k | — | ~5.3k | Automated safety check: Notes | MIT | |
| Security Setupluongnv89/skills | 131 | — | ~4.5k | Automated safety check: Pass | MIT | |
| AWS Cdk Developmentzxkane/aws-skills | 367 | 2 repos | ~2.5k | Automated safety check: Pass | MIT | |
| Reproduce macOS Python FlavorsNuitka/Nuitka | 15k | — | ~1.7k | Automated safety check: Pass | AGPL-3.0 | |
| Env Var Conventionssgl-project/sglang | 37k | 2 repos | ~2.9k | Automated safety check: Pass | Apache-2.0 |
LeoYeAI/openclaw-master-skills
Your on-call DevOps assistant — one-click deploy, monitoring setup, scheduled backups, and fault diagnosis.
luongnv89/skills
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
Nuitka/Nuitka
Reproduce macOS Nuitka issues across Python distributions and GitHub Actions Python packaging.
sgl-project/sglang
Conventions for SGLang environment variables — where to define, how to access, how to name, and how to deprecate.
doronz88/pymobiledevice3
Operate iOS and iPadOS devices with pymobiledevice3, from a local checkout or straight from PyPI via uvx on a fresh workstation.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Works with
Categories
Develops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering…. Implementing Ot Incident Response Playbook is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Develops OT-specific incident response playbooks using a SANS PICERL-based Python engine that classifies incident severity (safety, process, access, recon) and coordinates IT SOC, OT engineering, and plant operations, aligned with IEC 62443 and NIST SP 800-82.
Implementing Ot Incident Response Playbook fits situations like: building ICS/SCADA incident response procedures for the first time; preparing for OT ransomware scenarios; aligning IR with IEC 62443/NERC CIP reporting requirements.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a claude-code`. Or copy the skill folder (skills/implementing-ot-incident-response-playbook in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-ot-incident-response-playbook in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a codex`. Or copy the skill folder (skills/implementing-ot-incident-response-playbook in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-ot-incident-response-playbook in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-ot-incident-response-playbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-ot-incident-response-playbook, .gemini/skills/implementing-ot-incident-response-playbook, .github/skills/implementing-ot-incident-response-playbook and .opencode/skills/implementing-ot-incident-response-playbook in your project.
Going by SKILL.md and its folder, Implementing Ot Incident Response Playbook needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Implementing Ot Incident Response Playbook is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 660 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Implementing Ot Incident Response Playbook: Devops Agent (LeoYeAI/openclaw-master-skills, 2.2k stars), Security Setup (luongnv89/skills, 131 stars), AWS Cdk Development (zxkane/aws-skills, 367 stars) and Reproduce macOS Python Flavors (Nuitka/Nuitka, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.