Agent skill

Investigating Phishing Email Incident

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk…

Apache-2.0Auto-check passedSecurity

Install Investigating Phishing Email Incident

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-phishing-email-incident -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills investigating-phishing-email-incident --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/investigating-phishing-email-incident .claude/skills/investigating-phishing-email-incident && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
investigating-phishing-email-incident
GitHub stars
34k
Token cost
~2.8k tokens
SKILL.md length
577 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk…

  • Works in 6 steps: Extract and Analyze Email Headers → Analyze URLs and Attachments → Determine Campaign Scope → …
  • A reported phishing email requires full incident investigation to determine scope and impact
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; reaches urlscan.io and mb-api.abuse.ch

What it does

Investigating Phishing Email Incident is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security. It works with Splunk, Microsoft Defender and Microsoft 365. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • A reported phishing email requires full incident investigation to determine scope and impact

Example prompts

  • “Use the investigating-phishing-email-incident skill to investigate phishing email incidents from initial user report through header analysis…”
  • “/investigating-phishing-email-incident”

Requirements

  • Python 3
  • A credential in YOUR_KEY
  • A credential in YOUR_VT_API_KEY

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Extract and Analyze Email Headers
  2. Analyze URLs and Attachments
  3. Determine Campaign Scope
  4. Identify Impacted Users (Who Clicked)
  5. Containment Actions
  6. Document and Report

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • urlscan.io
    • mb-api.abuse.ch
    • graph.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Investigating Phishing Email Incident loads about 2.8k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 577 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 577 words, ~2,845 tokens.

Download SKILL.mdSave it as .claude/skills/investigating-phishing-email-incident/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
investigating-phishing-email-incident
description
Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.
domain
cybersecurity
subdomain
soc-operations
tags
soc, phishing, incident-response, email-security, splunk, defender, sandbox
mitre_attack
T1078, T1685.002, T1685.005, T1566, T1598
mitre_f3.version
1.1
mitre_f3.tactics
reconnaissance, resource-development, initial-access, stealth, positioning
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
DE.CM-01, DE.AE-02, RS.MA-01, DE.AE-06

Investigating Phishing Email Incident

When to Use

Use this skill when:

  • A user reports a suspicious email via the phishing report button or helpdesk ticket
  • Email security gateway flags a message that bypassed initial filters
  • Automated detection identifies credential harvesting URLs or malicious attachments
  • A phishing campaign targeting the organization requires scope assessment

Do not use for spam or marketing emails without malicious intent — route those to email administration for filter tuning.

Prerequisites

  • Access to email gateway logs (Proofpoint, Mimecast, or Microsoft Defender for Office 365)
  • Splunk or SIEM with email log ingestion (O365 Message Trace, Exchange tracking logs)
  • Sandbox access (Any.Run, Joe Sandbox, or Hybrid Analysis) for URL/attachment detonation
  • Microsoft Graph API or Exchange Admin Center for email search and purge operations
  • URLScan.io and VirusTotal API keys

Workflow

Step 1: Extract and Analyze Email Headers

Obtain the full email headers (.eml file) from the reported message:

python
import email
from email import policy

with open("phishing_sample.eml", "rb") as f:
    msg = email.message_from_binary_file(f, policy=policy.default)

# Extract key headers
print(f"From: {msg['From']}")
print(f"Return-Path: {msg['Return-Path']}")
print(f"Reply-To: {msg['Reply-To']}")
print(f"Subject: {msg['Subject']}")
print(f"Message-ID: {msg['Message-ID']}")
print(f"X-Originating-IP: {msg['X-Originating-IP']}")

# Parse Received headers (bottom-up for true origin)
for header in reversed(msg.get_all('Received', [])):
    print(f"Received: {header[:120]}")

# Check authentication results
print(f"Authentication-Results: {msg['Authentication-Results']}")
print(f"DKIM-Signature: {msg.get('DKIM-Signature', 'NONE')[:80]}")

Key checks:

  • SPF: Does Return-Path domain match sending IP? Look for spf=pass or spf=fail
  • DKIM: Is the signature valid? dkim=pass confirms the email was not modified in transit
  • DMARC: Does the From domain align with SPF/DKIM domains? dmarc=fail indicates spoofing
Step 2: Analyze URLs and Attachments

URL Analysis:

python
import requests

# Submit URL to URLScan.io
url_to_scan = "https://evil-login.example.com/office365"
response = requests.post(
    "https://urlscan.io/api/v1/scan/",
    headers={"API-Key": "YOUR_KEY", "Content-Type": "application/json"},
    json={"url": url_to_scan, "visibility": "unlisted"}
)
scan_id = response.json()["uuid"]
print(f"Scan URL: https://urlscan.io/result/{scan_id}/")

# Check VirusTotal for URL reputation
import vt
client = vt.Client("YOUR_VT_API_KEY")
url_id = vt.url_id(url_to_scan)
url_obj = client.get_object(f"/urls/{url_id}")
print(f"VT Score: {url_obj.last_analysis_stats}")
client.close()

Attachment Analysis:

python
import hashlib

# Calculate file hashes
with open("attachment.docx", "rb") as f:
    content = f.read()
    md5 = hashlib.md5(content).hexdigest()
    sha256 = hashlib.sha256(content).hexdigest()

print(f"MD5: {md5}")
print(f"SHA256: {sha256}")

# Submit to MalwareBazaar for lookup
response = requests.post(
    "https://mb-api.abuse.ch/api/v1/",
    data={"query": "get_info", "hash": sha256}
)
print(response.json()["query_status"])

Submit to sandbox (Any.Run or Joe Sandbox) for dynamic analysis of macros, PowerShell execution, and C2 callbacks.

Step 3: Determine Campaign Scope

Search for all recipients of the same phishing email in Splunk:

spl
index=email sourcetype="o365:messageTrace"
(SenderAddress="attacker@evil-domain.com" OR Subject="Urgent: Password Reset Required"
 OR MessageId="<phishing-message-id@evil.com>")
earliest=-7d
| stats count by RecipientAddress, DeliveryStatus, MessageTraceId
| sort - count

Alternatively, use Microsoft Graph API:

python
import requests

headers = {"Authorization": f"Bearer {access_token}"}
params = {
    "$filter": f"subject eq 'Urgent: Password Reset Required' and "
               f"receivedDateTime ge 2024-03-14T00:00:00Z",
    "$select": "sender,toRecipients,subject,receivedDateTime",
    "$top": 100
}
response = requests.get(
    "https://graph.microsoft.com/v1.0/users/admin@company.com/messages",
    headers=headers, params=params
)
messages = response.json()["value"]
print(f"Found {len(messages)} matching messages")
Step 4: Identify Impacted Users (Who Clicked)

Check proxy/web logs for users who visited the phishing URL:

spl
index=proxy dest="evil-login.example.com" earliest=-7d
| stats count, values(action) AS actions, latest(_time) AS last_access
  by src_ip, user
| lookup asset_lookup_by_cidr ip AS src_ip OUTPUT owner, category
| sort - count
| table user, src_ip, owner, actions, count, last_access

Check if credentials were submitted (POST requests to phishing domain):

spl
index=proxy dest="evil-login.example.com" http_method=POST earliest=-7d
| stats count by src_ip, user, url, status
Step 5: Containment Actions

Purge emails from all mailboxes:

powershell
# Microsoft 365 Compliance Search and Purge
New-ComplianceSearch -Name "Phishing_Purge_2024_0315" `
    -ExchangeLocation All `
    -ContentMatchQuery '(From:attacker@evil-domain.com) AND (Subject:"Urgent: Password Reset Required")'

Start-ComplianceSearch -Identity "Phishing_Purge_2024_0315"

# After search completes, execute purge
New-ComplianceSearchAction -SearchName "Phishing_Purge_2024_0315" -Purge -PurgeType SoftDelete

Block indicators:

  • Add sender domain to email gateway block list
  • Add phishing URL domain to web proxy block list
  • Add attachment hash to endpoint detection block list
  • Create DNS sinkhole entry for phishing domain

Reset compromised credentials:

powershell
# Force password reset for impacted users
$impactedUsers = @("user1@company.com", "user2@company.com")
foreach ($user in $impactedUsers) {
    Set-MsolUserPassword -UserPrincipalName $user -ForceChangePassword $true
    Revoke-AzureADUserAllRefreshToken -ObjectId (Get-AzureADUser -ObjectId $user).ObjectId
}
Step 6: Document and Report

Create incident report with full timeline, IOCs, impacted users, and remediation actions taken.

spl
| makeresults
| eval incident_id="PHI-2024-0315",
       reported_time="2024-03-15 09:12:00",
       sender="attacker@evil-domain[.]com",
       subject="Urgent: Password Reset Required",
       url="hxxps://evil-login[.]example[.]com/office365",
       recipients_count=47,
       clicked_count=5,
       credentials_submitted=2,
       emails_purged=47,
       passwords_reset=2,
       domains_blocked=1,
       disposition="True Positive - Credential Phishing Campaign"
| table incident_id, reported_time, sender, subject, url, recipients_count,
        clicked_count, credentials_submitted, emails_purged, passwords_reset, disposition
Show full SKILL.md (251 more words)Show less

Key Concepts

TermDefinition
SPF (Sender Policy Framework)DNS TXT record specifying which mail servers are authorized to send on behalf of a domain
DKIMDomainKeys Identified Mail — cryptographic signature proving email content was not altered in transit
DMARCDomain-based Message Authentication, Reporting and Conformance — policy combining SPF and DKIM alignment
Credential HarvestingPhishing technique using fake login pages to capture username/password combinations
Business Email Compromise (BEC)Social engineering attack using compromised or spoofed executive email for financial fraud
Message TraceO365/Exchange log showing email routing, delivery status, and filtering actions for forensic analysis

Tools & Systems

  • Microsoft Defender for Office 365: Email security platform with Safe Links, Safe Attachments, and Threat Explorer for investigation
  • URLScan.io: Free URL analysis service capturing screenshots, DOM, cookies, and network requests
  • Any.Run: Interactive sandbox for detonating malicious files and URLs with real-time behavior analysis
  • Proofpoint TAP: Targeted Attack Protection dashboard showing clicked URLs and delivered threats per user
  • PhishTool: Dedicated phishing email analysis platform automating header parsing and IOC extraction

Common Scenarios

  • Credential Phishing: Fake O365 login page — check proxy for POST requests, force password resets for submitters
  • Macro-Enabled Document: Word doc with VBA macro — sandbox shows PowerShell download cradle, check endpoints for execution
  • QR Code Phishing (Quishing): Email contains QR code linking to credential harvester — decode QR, submit URL to sandbox
  • Thread Hijacking: Attacker uses compromised mailbox to reply in existing threads — check for impossible travel or new inbox rules
  • Voicemail Phishing: Fake voicemail notification with HTML attachment — analyze attachment for redirect chains

Output Format

PHISHING INCIDENT REPORT — PHI-2024-0315
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Reported:     2024-03-15 09:12 UTC by jsmith (Finance)
Sender:       attacker@evil-domain[.]com (SPF: FAIL, DKIM: NONE, DMARC: FAIL)
Subject:      Urgent: Password Reset Required
Payload:      Credential harvesting URL

IOCs:
  URL:        hxxps://evil-login[.]example[.]com/office365
  Domain:     evil-login[.]example[.]com (registered 2024-03-14, Namecheap)
  IP:         185.234.xx.xx (VT: 12/90 malicious)

Scope:
  Recipients: 47 users across Finance and HR departments
  Clicked:    5 users visited phishing URL
  Submitted:  2 users entered credentials (confirmed via POST in proxy logs)

Containment:
  [DONE] 47 emails purged via Compliance Search
  [DONE] Domain blocked on proxy and DNS sinkhole
  [DONE] 2 user passwords reset, sessions revoked
  [DONE] MFA enforced for both compromised accounts
  [DONE] Inbox rules audited — no forwarding rules found

Status:       RESOLVED — No evidence of lateral movement post-compromise

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/investigating-phishing-email-incident of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Investigating Phishing Email Incident next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Investigating Phishing Email Incident compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Investigating Phishing Email Incident this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Cloud App Security Posturevinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Sentinelvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Defender Xdrvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
AI Agent ActivitySCStelz/security-investigator249—~17kAutomated safety check: PassMIT
Detection SigmaAgentSecOps/SecOpsAgentKit2201 repos~4kAutomated safety check: PassCustom licence

Similar skills

  • Cloud App Security Posture

    vinayaklatthe/microsoft-security-skills

    Guidance for cloud and SaaS security posture management - combining Defender for Cloud CSPM (IaaS/PaaS) and Defender for Cloud Apps SSPM (SaaS) to assess and harden posture across cloud and SaaS apps.

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Sentinel

    vinayaklatthe/microsoft-security-skills

    Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Defender Xdr

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with…

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • AI Agent Activity

    SCStelz/security-investigator

    Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield…

    249 GitHub stars~17k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Detection Sigma

    AgentSecOps/SecOpsAgentKit

    Generic detection rule creation and management using Sigma, the universal SIEM rule format.

    220 GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Azure Network Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall…

    175 GitHub stars~1.8k tokensUpdated 3 mo ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Investigating Phishing Email Incident

What does Investigating Phishing Email Incident do?

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk…. Investigating Phishing Email Incident is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms.

When should I use Investigating Phishing Email Incident?

Investigating Phishing Email Incident fits situations like: A reported phishing email requires full incident investigation to determine scope and impact.

How do I install Investigating Phishing Email Incident in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-phishing-email-incident -a claude-code`. Or copy the skill folder (skills/investigating-phishing-email-incident in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/investigating-phishing-email-incident in your project. Claude Code loads it when a task matches its description.

How do I install Investigating Phishing Email Incident in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-phishing-email-incident -a codex`. Or copy the skill folder (skills/investigating-phishing-email-incident in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/investigating-phishing-email-incident in your project. Codex loads it when a task matches its description.

Can I use Investigating Phishing Email Incident in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill investigating-phishing-email-incident -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/investigating-phishing-email-incident, .gemini/skills/investigating-phishing-email-incident, .github/skills/investigating-phishing-email-incident and .opencode/skills/investigating-phishing-email-incident in your project.

What does Investigating Phishing Email Incident need to run?

Going by SKILL.md and its folder, Investigating Phishing Email Incident needs Python for the scripts in its folder. Our summary lists: Python 3; A credential in YOUR_KEY; A credential in YOUR_VT_API_KEY.

Does Investigating Phishing Email Incident access the network?

SKILL.md names 3 domains. In commands or code: urlscan.io, mb-api.abuse.ch and graph.microsoft.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Investigating Phishing Email Incident safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Investigating Phishing Email Incident use?

Investigating Phishing Email Incident is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Investigating Phishing Email Incident use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 629 tokens, read only when the agent opens those files.

What are the alternatives to Investigating Phishing Email Incident?

Skills that share tags, products or a category with Investigating Phishing Email Incident: Cloud App Security Posture (vinayaklatthe/microsoft-security-skills, 175 stars), Sentinel (vinayaklatthe/microsoft-security-skills, 175 stars), Defender Xdr (vinayaklatthe/microsoft-security-skills, 175 stars) and AI Agent Activity (SCStelz/security-investigator, 249 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Investigating Phishing Email Incident?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.