Agent skill

Implementing Patch Management For Ot Systems

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based…

Apache-2.0Auto-check passedDevOps & Cloud

Install Implementing Patch Management For Ot Systems

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-patch-management-for-ot-systems --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-patch-management-for-ot-systems .claude/skills/implementing-patch-management-for-ot-systems && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-patch-management-for-ot-systems
GitHub stars
34k
Token cost
~3.2k tokens
SKILL.md length
352 words
Files
4 (incl. scripts, references)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based…

  • Works in 2 steps: Establish OT Patch Management Program → Test Patches in Staging Environment
  • Auditing patching for SCADA
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Implementing Patch Management For Ot Systems is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based prioritization, staged test deployment, maintenance window coordination, rollback procedures, and compensating controls. Use when planning or auditing patching for SCADA, PLCs, or other industrial control systems.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in DevOps & Cloud, covering Prioritization frameworks. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Auditing patching for SCADA
  • Other industrial control systems

Example prompts

  • “Use the implementing-patch-management-for-ot-systems skill to implement a structured patch management program for OT/ICS environments where IT-style…”
  • “/implementing-patch-management-for-ot-systems”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Establish OT Patch Management Program
  2. Test Patches in Staging Environment

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Patch Management For Ot Systems loads about 3.2k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 352 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 352 words, ~3,180 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-patch-management-for-ot-systems/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-patch-management-for-ot-systems
description
Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based prioritization, staged test deployment, maintenance window coordination, rollback procedures, and compensating controls. Use when planning or auditing patching for SCADA, PLCs, or other industrial control systems.
domain
cybersecurity
subdomain
ot-ics-security
tags
ot-security, ics, scada, industrial-control, iec62443, patch-management, vulnerability-management
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, DE.CM-01, ID.AM-05, GV.OC-02
mitre_attack
T1078, T1190, T1059, T0816, T0836

Implementing Patch Management for OT Systems

When to Use

  • When establishing a formal OT patch management program for the first time
  • When responding to critical ICS-CERT advisories affecting deployed OT systems
  • When preparing for NERC CIP-007-6 or IEC 62443 patch management compliance audits
  • When planning patch deployment during limited maintenance windows in continuous operations
  • When evaluating compensating controls for systems that cannot be patched

Do not use for IT-only patch management without OT considerations, for emergency patching during active cyber incidents (see performing-ot-incident-response), or for firmware upgrades that change PLC functionality (requires separate change management).

Prerequisites

  • OT asset inventory with firmware/OS versions for all patchable systems
  • Vendor patch notification subscriptions (Siemens ProductCERT, Rockwell, Schneider, etc.)
  • Test/staging environment mirroring production OT systems for patch validation
  • Maintenance window schedule aligned with process shutdowns and turnarounds
  • Change management board approval process including operations and safety representatives

Workflow

Step 1: Establish OT Patch Management Program

Define the patch management lifecycle adapted for OT environments where availability and safety take priority over immediate vulnerability remediation.

python
#!/usr/bin/env python3
"""OT Patch Management Program Manager.

Tracks patches for OT systems, manages risk-based prioritization,
coordinates testing and deployment, and documents compensating
controls for unpatchable systems.
"""

import json
import sys
from collections import defaultdict
from dataclasses import dataclass, field, asdict
from datetime import datetime, timedelta
from enum import Enum


class PatchStatus(str, Enum):
    IDENTIFIED = "identified"
    EVALUATING = "evaluating"
    TESTING = "testing"
    APPROVED = "approved"
    SCHEDULED = "scheduled"
    DEPLOYED = "deployed"
    DEFERRED = "deferred"
    NOT_APPLICABLE = "not_applicable"


@dataclass
class OTPatch:
    patch_id: str
    vendor: str
    product: str
    affected_versions: str
    cve_ids: list
    cvss_score: float
    ics_cert_advisory: str
    description: str
    status: str = PatchStatus.IDENTIFIED
    identified_date: str = ""
    evaluation_deadline: str = ""  # 35 days per CIP-007
    test_date: str = ""
    deployment_date: str = ""
    affected_assets: list = field(default_factory=list)
    test_results: str = ""
    compensating_controls: str = ""
    risk_rating: str = ""
    maintenance_window: str = ""
    rollback_procedure: str = ""


class OTPatchManager:
    """Manages the OT patch lifecycle."""

    def __init__(self):
        self.patches = []
        self.assets = {}
        self.vendor_feeds = {}

    def add_patch(self, patch: OTPatch):
        """Register a new patch for tracking."""
        # Set evaluation deadline (35 calendar days per NERC CIP-007)
        if not patch.evaluation_deadline:
            identified = datetime.fromisoformat(patch.identified_date)
            patch.evaluation_deadline = (identified + timedelta(days=35)).isoformat()

        self.patches.append(patch)

    def prioritize_patches(self):
        """Risk-based prioritization for OT patches."""
        for patch in self.patches:
            if patch.status in (PatchStatus.DEPLOYED, PatchStatus.NOT_APPLICABLE):
                continue

            # OT-specific risk scoring
            score = patch.cvss_score

            # Increase priority for actively exploited vulnerabilities
            if "CISA KEV" in patch.ics_cert_advisory:
                score += 2.0

            # Increase priority for network-exposed OT systems
            for asset_id in patch.affected_assets:
                asset = self.assets.get(asset_id, {})
                if asset.get("network_exposed"):
                    score += 1.0
                if asset.get("purdue_level") in ("Level 0-1", "Level 2"):
                    score += 1.5

            score = min(score, 10.0)

            if score >= 9.0:
                patch.risk_rating = "critical"
            elif score >= 7.0:
                patch.risk_rating = "high"
            elif score >= 4.0:
                patch.risk_rating = "medium"
            else:
                patch.risk_rating = "low"

    def get_patches_needing_evaluation(self):
        """Get patches approaching evaluation deadline."""
        now = datetime.now()
        approaching = []
        for patch in self.patches:
            if patch.status == PatchStatus.IDENTIFIED:
                deadline = datetime.fromisoformat(patch.evaluation_deadline)
                days_remaining = (deadline - now).days
                if days_remaining <= 7:
                    approaching.append((patch, days_remaining))
        return sorted(approaching, key=lambda x: x[1])

    def defer_patch(self, patch_id, reason, compensating_controls):
        """Defer a patch with documented compensating controls."""
        for patch in self.patches:
            if patch.patch_id == patch_id:
                patch.status = PatchStatus.DEFERRED
                patch.compensating_controls = compensating_controls
                patch.test_results = f"Deferred: {reason}"
                break

    def generate_report(self):
        """Generate patch management status report."""
        self.prioritize_patches()

        report = []
        report.append("=" * 70)
        report.append("OT PATCH MANAGEMENT STATUS REPORT")
        report.append(f"Date: {datetime.now().isoformat()}")
        report.append("=" * 70)

        # Status summary
        status_counts = defaultdict(int)
        for p in self.patches:
            status_counts[p.status] += 1

        report.append("\nPATCH STATUS SUMMARY:")
        for status, count in status_counts.items():
            report.append(f"  {status}: {count}")

        # Approaching deadlines
        approaching = self.get_patches_needing_evaluation()
        if approaching:
            report.append("\nAPPROACHING EVALUATION DEADLINES:")
            for patch, days in approaching:
                report.append(f"  [{patch.patch_id}] {patch.description} - {days} days remaining")

        # Critical/High priority patches
        urgent = [p for p in self.patches
                  if p.risk_rating in ("critical", "high")
                  and p.status not in (PatchStatus.DEPLOYED, PatchStatus.NOT_APPLICABLE)]
        if urgent:
            report.append(f"\nURGENT PATCHES ({len(urgent)}):")
            for p in urgent:
                report.append(f"  [{p.patch_id}] [{p.risk_rating.upper()}] {p.description}")
                report.append(f"    CVEs: {', '.join(p.cve_ids)}")
                report.append(f"    Status: {p.status}")
                report.append(f"    Affected Assets: {len(p.affected_assets)}")

        # Deferred patches with compensating controls
        deferred = [p for p in self.patches if p.status == PatchStatus.DEFERRED]
        if deferred:
            report.append(f"\nDEFERRED PATCHES ({len(deferred)}):")
            for p in deferred:
                report.append(f"  [{p.patch_id}] {p.description}")
                report.append(f"    Reason: {p.test_results}")
                report.append(f"    Compensating Controls: {p.compensating_controls}")

        return "\n".join(report)


if __name__ == "__main__":
    manager = OTPatchManager()

    # Example patches
    manager.add_patch(OTPatch(
        patch_id="OT-PATCH-001",
        vendor="Siemens",
        product="SIMATIC S7-1500",
        affected_versions="< V3.0.1",
        cve_ids=["CVE-2023-44374"],
        cvss_score=8.8,
        ics_cert_advisory="ICSA-23-348-01",
        description="S7-1500 memory corruption via crafted packets",
        identified_date="2026-01-15",
        affected_assets=["PLC-01", "PLC-02", "PLC-03"],
    ))

    manager.add_patch(OTPatch(
        patch_id="OT-PATCH-002",
        vendor="Rockwell Automation",
        product="FactoryTalk View SE",
        affected_versions="< V13.0",
        cve_ids=["CVE-2024-21914"],
        cvss_score=7.5,
        ics_cert_advisory="ICSA-24-046-02",
        description="FactoryTalk View remote code execution",
        identified_date="2026-02-01",
        affected_assets=["HMI-01", "HMI-02"],
    ))

    print(manager.generate_report())
Step 2: Test Patches in Staging Environment

Never deploy patches directly to production OT systems. Use a test environment that mirrors production to validate patch compatibility.

yaml
# OT Patch Testing Procedure
patch_testing:
  environment:
    description: "Staging lab mirroring production OT architecture"
    components:
      - "Virtual PLC simulators matching production firmware"
      - "Test HMI stations with identical software versions"
      - "Test historian with representative data"
      - "Network configuration matching production VLANs/firewalls"

  test_cases:
    functional:
      - "PLC programs execute correctly after OS patch"
      - "HMI displays update with correct process values"
      - "Historian data collection continues uninterrupted"
      - "Alarm and event handling functions properly"
      - "Communication between PLCs maintains cycle time"
      - "Safety system trip tests pass (if SIS affected)"

    performance:
      - "PLC scan time remains within acceptable limits (<50ms increase)"
      - "HMI screen refresh rate unchanged"
      - "Historian collection interval maintained"
      - "Network latency between zones unchanged"

    compatibility:
      - "Third-party applications function correctly"
      - "OPC UA/DA connections establish successfully"
      - "Custom scripts and batch processes execute"
      - "Backup and restore procedures work"

    rollback:
      - "System can be reverted to pre-patch state"
      - "Rollback procedure documented and tested"
      - "Estimated rollback time: [N] minutes"

  documentation:
    required:
      - "Test plan with pass/fail criteria"
      - "Test execution results with screenshots"
      - "Performance measurements before and after"
      - "Sign-off by operations, engineering, and security"
Show full SKILL.md (156 more words)Show less

Key Concepts

TermDefinition
Compensating ControlAlternative security measure applied when a patch cannot be deployed, such as firewall rules, IPS signatures, or network isolation
Vendor CompatibilityConfirmation from the OT vendor that a patch (especially OS patches) is compatible with their control system software
Maintenance WindowScheduled period for system modifications, aligned with process shutdowns or reduced-risk operational periods
Virtual PatchingDeploying IDS/IPS rules to detect and block exploitation attempts for known vulnerabilities without modifying the target system
Evaluation DeadlineNERC CIP-007-6 requires patch evaluation within 35 calendar days of availability
TurnaroundMajor scheduled shutdown of a process unit for maintenance, providing opportunity for extensive OT patching

Tools & Systems

  • WSUS/SCCM: Microsoft patch management for Windows-based OT systems (HMIs, historians, engineering workstations)
  • Siemens ProductCERT: Siemens security advisory service for industrial products
  • Claroty xDome: OT vulnerability management with patch availability tracking and risk scoring
  • Tripwire Enterprise: Configuration monitoring detecting unauthorized changes and tracking patch status

Output Format

OT Patch Management Report
============================
Reporting Period: YYYY-MM to YYYY-MM

PATCH STATUS:
  Identified: [N]
  Evaluating: [N]
  Testing: [N]
  Deployed: [N]
  Deferred: [N]

COMPLIANCE:
  Evaluated within 35 days: [N]/[N] (CIP-007-6 R2)
  Deployed or mitigated: [N]/[N]
  Deferred with compensating controls: [N]

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-patch-management-for-ot-systems of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Patch Management For Ot Systems next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Patch Management For Ot Systems compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Patch Management For Ot Systems this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Observability Driven Testingpetrkindlmann/qa-skills165—~5.5kAutomated safety check: PassMIT
Threat Detectionalirezarezvani/claude-skills28k—~3.5kAutomated safety check: PassMIT
Managing Vulnerabilitiesancoleman/ai-design-components526—~3.8kAutomated safety check: PassMIT
Risk Prioritisertransilienceai/communitytools562—~1.5kAutomated safety check: PassMIT
Helm Planjeremylongshore/tons-of-skills-marketplace2.8k—~701Automated safety check: NotesMIT

Similar skills

  • Observability Driven Testing

    petrkindlmann/qa-skills

    Use production telemetry as INPUT to design new tests. An agent skill from petrkindlmann/qa-skills.

    165 GitHub stars~5.5k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Threat Detection

    alirezarezvani/claude-skills

    A skill your agent uses when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.

    28k GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Managing Vulnerabilities

    ancoleman/ai-design-components

    Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.

    526 GitHub stars~3.8k tokensUpdated 10 mo ago
    SecurityAuto-check passed
  • Risk Prioritiser

    transilienceai/communitytools

    Risk-based prioritisation of confirmed attack paths. An agent skill from transilienceai/communitytools.

    562 GitHub stars~1.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Helm Plan

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses when asked to build a product roadmap, prioritize a backlog, decide what to build next, or sequence a list of feature ideas.

    2.8k GitHub stars~701 tokensUpdated today
    Product & Project ManagementAuto-check: notes
  • Run Nx generators with prioritization for workspace-plugin generators.

    29k GitHub starsUsed in 2 repos~592 tokens
    DevelopmentAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing Patch Management For Ot Systems

What does Implementing Patch Management For Ot Systems do?

Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based…. Implementing Patch Management For Ot Systems is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implements a structured patch management program for OT/ICS environments where IT-style patching can cause process disruption or safety hazards, covering vendor compatibility testing, risk-based prioritization, staged test deployment, maintenance window coordination, rollback procedures, and compensating controls.

When should I use Implementing Patch Management For Ot Systems?

Implementing Patch Management For Ot Systems fits situations like: auditing patching for SCADA; other industrial control systems.

How do I install Implementing Patch Management For Ot Systems in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a claude-code`. Or copy the skill folder (skills/implementing-patch-management-for-ot-systems in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-patch-management-for-ot-systems in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Patch Management For Ot Systems in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a codex`. Or copy the skill folder (skills/implementing-patch-management-for-ot-systems in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-patch-management-for-ot-systems in your project. Codex loads it when a task matches its description.

Can I use Implementing Patch Management For Ot Systems in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-patch-management-for-ot-systems -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-patch-management-for-ot-systems, .gemini/skills/implementing-patch-management-for-ot-systems, .github/skills/implementing-patch-management-for-ot-systems and .opencode/skills/implementing-patch-management-for-ot-systems in your project.

What does Implementing Patch Management For Ot Systems need to run?

Going by SKILL.md and its folder, Implementing Patch Management For Ot Systems needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Patch Management For Ot Systems access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Patch Management For Ot Systems safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Patch Management For Ot Systems use?

Implementing Patch Management For Ot Systems is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Patch Management For Ot Systems use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 744 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Patch Management For Ot Systems?

Skills that share tags, products or a category with Implementing Patch Management For Ot Systems: Observability Driven Testing (petrkindlmann/qa-skills, 165 stars), Threat Detection (alirezarezvani/claude-skills, 28k stars), Managing Vulnerabilities (ancoleman/ai-design-components, 526 stars) and Risk Prioritiser (transilienceai/communitytools, 562 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Patch Management For Ot Systems?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.