Observability Driven Testing
petrkindlmann/qa-skills
Use production telemetry as INPUT to design new tests. An agent skill from petrkindlmann/qa-skills.
Agent skill
Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-patch-management-for-ot-systems --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-patch-management-for-ot-systems .claude/skills/implementing-patch-management-for-ot-systems && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "implementing-patch-management-for-ot-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-patch-management-for-ot-systems into .claude/skills/implementing-patch-management-for-ot-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-patch-management-for-ot-systems", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-patch-management-for-ot-systemsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-patch-management-for-ot-systems --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/implementing-patch-management-for-ot-systems .agents/skills/implementing-patch-management-for-ot-systems && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "implementing-patch-management-for-ot-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-patch-management-for-ot-systems into .agents/skills/implementing-patch-management-for-ot-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-patch-management-for-ot-systems", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-patch-management-for-ot-systems --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/implementing-patch-management-for-ot-systems .cursor/skills/implementing-patch-management-for-ot-systems && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "implementing-patch-management-for-ot-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-patch-management-for-ot-systems into .cursor/skills/implementing-patch-management-for-ot-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-patch-management-for-ot-systems", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/implementing-patch-management-for-ot-systems--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-patch-management-for-ot-systems --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/implementing-patch-management-for-ot-systems .gemini/skills/implementing-patch-management-for-ot-systems && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "implementing-patch-management-for-ot-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-patch-management-for-ot-systems into .gemini/skills/implementing-patch-management-for-ot-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-patch-management-for-ot-systems", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-patch-management-for-ot-systemsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/implementing-patch-management-for-ot-systems .github/skills/implementing-patch-management-for-ot-systems && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "implementing-patch-management-for-ot-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-patch-management-for-ot-systems into .github/skills/implementing-patch-management-for-ot-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-patch-management-for-ot-systems", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-patch-management-for-ot-systems --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/implementing-patch-management-for-ot-systems .opencode/skills/implementing-patch-management-for-ot-systems && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "implementing-patch-management-for-ot-systems" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/implementing-patch-management-for-ot-systems into .opencode/skills/implementing-patch-management-for-ot-systems/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "implementing-patch-management-for-ot-systems", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
implementing-patch-management-for-ot-systemsImplements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based…
Implementing Patch Management For Ot Systems is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based prioritization, staged test deployment, maintenance window coordination, rollback procedures, and compensating controls. Use when planning or auditing patching for SCADA, PLCs, or other industrial control systems.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in DevOps & Cloud, covering Prioritization frameworks. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Implementing Patch Management For Ot Systems loads about 3.2k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 352 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 352 words, ~3,180 tokens.
.claude/skills/implementing-patch-management-for-ot-systems/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Do not use for IT-only patch management without OT considerations, for emergency patching during active cyber incidents (see performing-ot-incident-response), or for firmware upgrades that change PLC functionality (requires separate change management).
Define the patch management lifecycle adapted for OT environments where availability and safety take priority over immediate vulnerability remediation.
#!/usr/bin/env python3
"""OT Patch Management Program Manager.
Tracks patches for OT systems, manages risk-based prioritization,
coordinates testing and deployment, and documents compensating
controls for unpatchable systems.
"""
import json
import sys
from collections import defaultdict
from dataclasses import dataclass, field, asdict
from datetime import datetime, timedelta
from enum import Enum
class PatchStatus(str, Enum):
IDENTIFIED = "identified"
EVALUATING = "evaluating"
TESTING = "testing"
APPROVED = "approved"
SCHEDULED = "scheduled"
DEPLOYED = "deployed"
DEFERRED = "deferred"
NOT_APPLICABLE = "not_applicable"
@dataclass
class OTPatch:
patch_id: str
vendor: str
product: str
affected_versions: str
cve_ids: list
cvss_score: float
ics_cert_advisory: str
description: str
status: str = PatchStatus.IDENTIFIED
identified_date: str = ""
evaluation_deadline: str = "" # 35 days per CIP-007
test_date: str = ""
deployment_date: str = ""
affected_assets: list = field(default_factory=list)
test_results: str = ""
compensating_controls: str = ""
risk_rating: str = ""
maintenance_window: str = ""
rollback_procedure: str = ""
class OTPatchManager:
"""Manages the OT patch lifecycle."""
def __init__(self):
self.patches = []
self.assets = {}
self.vendor_feeds = {}
def add_patch(self, patch: OTPatch):
"""Register a new patch for tracking."""
# Set evaluation deadline (35 calendar days per NERC CIP-007)
if not patch.evaluation_deadline:
identified = datetime.fromisoformat(patch.identified_date)
patch.evaluation_deadline = (identified + timedelta(days=35)).isoformat()
self.patches.append(patch)
def prioritize_patches(self):
"""Risk-based prioritization for OT patches."""
for patch in self.patches:
if patch.status in (PatchStatus.DEPLOYED, PatchStatus.NOT_APPLICABLE):
continue
# OT-specific risk scoring
score = patch.cvss_score
# Increase priority for actively exploited vulnerabilities
if "CISA KEV" in patch.ics_cert_advisory:
score += 2.0
# Increase priority for network-exposed OT systems
for asset_id in patch.affected_assets:
asset = self.assets.get(asset_id, {})
if asset.get("network_exposed"):
score += 1.0
if asset.get("purdue_level") in ("Level 0-1", "Level 2"):
score += 1.5
score = min(score, 10.0)
if score >= 9.0:
patch.risk_rating = "critical"
elif score >= 7.0:
patch.risk_rating = "high"
elif score >= 4.0:
patch.risk_rating = "medium"
else:
patch.risk_rating = "low"
def get_patches_needing_evaluation(self):
"""Get patches approaching evaluation deadline."""
now = datetime.now()
approaching = []
for patch in self.patches:
if patch.status == PatchStatus.IDENTIFIED:
deadline = datetime.fromisoformat(patch.evaluation_deadline)
days_remaining = (deadline - now).days
if days_remaining <= 7:
approaching.append((patch, days_remaining))
return sorted(approaching, key=lambda x: x[1])
def defer_patch(self, patch_id, reason, compensating_controls):
"""Defer a patch with documented compensating controls."""
for patch in self.patches:
if patch.patch_id == patch_id:
patch.status = PatchStatus.DEFERRED
patch.compensating_controls = compensating_controls
patch.test_results = f"Deferred: {reason}"
break
def generate_report(self):
"""Generate patch management status report."""
self.prioritize_patches()
report = []
report.append("=" * 70)
report.append("OT PATCH MANAGEMENT STATUS REPORT")
report.append(f"Date: {datetime.now().isoformat()}")
report.append("=" * 70)
# Status summary
status_counts = defaultdict(int)
for p in self.patches:
status_counts[p.status] += 1
report.append("\nPATCH STATUS SUMMARY:")
for status, count in status_counts.items():
report.append(f" {status}: {count}")
# Approaching deadlines
approaching = self.get_patches_needing_evaluation()
if approaching:
report.append("\nAPPROACHING EVALUATION DEADLINES:")
for patch, days in approaching:
report.append(f" [{patch.patch_id}] {patch.description} - {days} days remaining")
# Critical/High priority patches
urgent = [p for p in self.patches
if p.risk_rating in ("critical", "high")
and p.status not in (PatchStatus.DEPLOYED, PatchStatus.NOT_APPLICABLE)]
if urgent:
report.append(f"\nURGENT PATCHES ({len(urgent)}):")
for p in urgent:
report.append(f" [{p.patch_id}] [{p.risk_rating.upper()}] {p.description}")
report.append(f" CVEs: {', '.join(p.cve_ids)}")
report.append(f" Status: {p.status}")
report.append(f" Affected Assets: {len(p.affected_assets)}")
# Deferred patches with compensating controls
deferred = [p for p in self.patches if p.status == PatchStatus.DEFERRED]
if deferred:
report.append(f"\nDEFERRED PATCHES ({len(deferred)}):")
for p in deferred:
report.append(f" [{p.patch_id}] {p.description}")
report.append(f" Reason: {p.test_results}")
report.append(f" Compensating Controls: {p.compensating_controls}")
return "\n".join(report)
if __name__ == "__main__":
manager = OTPatchManager()
# Example patches
manager.add_patch(OTPatch(
patch_id="OT-PATCH-001",
vendor="Siemens",
product="SIMATIC S7-1500",
affected_versions="< V3.0.1",
cve_ids=["CVE-2023-44374"],
cvss_score=8.8,
ics_cert_advisory="ICSA-23-348-01",
description="S7-1500 memory corruption via crafted packets",
identified_date="2026-01-15",
affected_assets=["PLC-01", "PLC-02", "PLC-03"],
))
manager.add_patch(OTPatch(
patch_id="OT-PATCH-002",
vendor="Rockwell Automation",
product="FactoryTalk View SE",
affected_versions="< V13.0",
cve_ids=["CVE-2024-21914"],
cvss_score=7.5,
ics_cert_advisory="ICSA-24-046-02",
description="FactoryTalk View remote code execution",
identified_date="2026-02-01",
affected_assets=["HMI-01", "HMI-02"],
))
print(manager.generate_report())Never deploy patches directly to production OT systems. Use a test environment that mirrors production to validate patch compatibility.
# OT Patch Testing Procedure
patch_testing:
environment:
description: "Staging lab mirroring production OT architecture"
components:
- "Virtual PLC simulators matching production firmware"
- "Test HMI stations with identical software versions"
- "Test historian with representative data"
- "Network configuration matching production VLANs/firewalls"
test_cases:
functional:
- "PLC programs execute correctly after OS patch"
- "HMI displays update with correct process values"
- "Historian data collection continues uninterrupted"
- "Alarm and event handling functions properly"
- "Communication between PLCs maintains cycle time"
- "Safety system trip tests pass (if SIS affected)"
performance:
- "PLC scan time remains within acceptable limits (<50ms increase)"
- "HMI screen refresh rate unchanged"
- "Historian collection interval maintained"
- "Network latency between zones unchanged"
compatibility:
- "Third-party applications function correctly"
- "OPC UA/DA connections establish successfully"
- "Custom scripts and batch processes execute"
- "Backup and restore procedures work"
rollback:
- "System can be reverted to pre-patch state"
- "Rollback procedure documented and tested"
- "Estimated rollback time: [N] minutes"
documentation:
required:
- "Test plan with pass/fail criteria"
- "Test execution results with screenshots"
- "Performance measurements before and after"
- "Sign-off by operations, engineering, and security"| Term | Definition |
|---|---|
| Compensating Control | Alternative security measure applied when a patch cannot be deployed, such as firewall rules, IPS signatures, or network isolation |
| Vendor Compatibility | Confirmation from the OT vendor that a patch (especially OS patches) is compatible with their control system software |
| Maintenance Window | Scheduled period for system modifications, aligned with process shutdowns or reduced-risk operational periods |
| Virtual Patching | Deploying IDS/IPS rules to detect and block exploitation attempts for known vulnerabilities without modifying the target system |
| Evaluation Deadline | NERC CIP-007-6 requires patch evaluation within 35 calendar days of availability |
| Turnaround | Major scheduled shutdown of a process unit for maintenance, providing opportunity for extensive OT patching |
OT Patch Management Report
============================
Reporting Period: YYYY-MM to YYYY-MM
PATCH STATUS:
Identified: [N]
Evaluating: [N]
Testing: [N]
Deployed: [N]
Deferred: [N]
COMPLIANCE:
Evaluated within 35 days: [N]/[N] (CIP-007-6 R2)
Deployed or mitigated: [N]/[N]
Deferred with compensating controls: [N]© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/implementing-patch-management-for-ot-systems of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Implementing Patch Management For Ot Systems next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Implementing Patch Management For Ot Systems this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Observability Driven Testingpetrkindlmann/qa-skills | 165 | — | ~5.5k | Automated safety check: Pass | MIT | |
| Threat Detectionalirezarezvani/claude-skills | 28k | — | ~3.5k | Automated safety check: Pass | MIT | |
| Managing Vulnerabilitiesancoleman/ai-design-components | 526 | — | ~3.8k | Automated safety check: Pass | MIT | |
| Risk Prioritisertransilienceai/communitytools | 562 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Helm Planjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~701 | Automated safety check: Notes | MIT |
petrkindlmann/qa-skills
Use production telemetry as INPUT to design new tests. An agent skill from petrkindlmann/qa-skills.
alirezarezvani/claude-skills
A skill your agent uses when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.
ancoleman/ai-design-components
Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.
transilienceai/communitytools
Risk-based prioritisation of confirmed attack paths. An agent skill from transilienceai/communitytools.
jeremylongshore/tons-of-skills-marketplace
A skill your agent uses when asked to build a product roadmap, prioritize a backlog, decide what to build next, or sequence a list of feature ideas.
nrwl/nx
Run Nx generators with prioritization for workspace-plugin generators.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based…. Implementing Patch Management For Ot Systems is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based prioritization, staged test deployment, maintenance window coordination, rollback procedures, and compensating controls.
Implementing Patch Management For Ot Systems fits situations like: auditing patching for SCADA; other industrial control systems.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a claude-code`. Or copy the skill folder (skills/implementing-patch-management-for-ot-systems in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-patch-management-for-ot-systems in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a codex`. Or copy the skill folder (skills/implementing-patch-management-for-ot-systems in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-patch-management-for-ot-systems in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-patch-management-for-ot-systems, .gemini/skills/implementing-patch-management-for-ot-systems, .github/skills/implementing-patch-management-for-ot-systems and .opencode/skills/implementing-patch-management-for-ot-systems in your project.
Going by SKILL.md and its folder, Implementing Patch Management For Ot Systems needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Implementing Patch Management For Ot Systems is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 744 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Implementing Patch Management For Ot Systems: Observability Driven Testing (petrkindlmann/qa-skills, 165 stars), Threat Detection (alirezarezvani/claude-skills, 28k stars), Managing Vulnerabilities (ancoleman/ai-design-components, 526 stars) and Risk Prioritiser (transilienceai/communitytools, 562 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.