Agent skill

Performing Malware Triage With Yara

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Performs rapid malware triage and classification using YARA rules that match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious…

Apache-2.0Auto-check passedSecurity

Install Performing Malware Triage With Yara

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-malware-triage-with-yara -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-malware-triage-with-yara --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-malware-triage-with-yara .claude/skills/performing-malware-triage-with-yara && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-malware-triage-with-yara
GitHub stars
34k
Token cost
~3.1k tokens
SKILL.md length
610 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Performs rapid malware triage and classification using YARA rules that match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious…

  • Works in 6 steps: Scan Samples with Existing Rule Sets → Write Rules for Unique String Patterns → Write Rules for Byte Patterns → …
  • Classifying a batch of malware samples against known family signatures
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls git, apt and pip; reaches github.com

What it does

Performing Malware Triage With Yara is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs rapid malware triage and classification using YARA rules that match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators, covering rule writing, scanning, and integration into analysis pipelines. Use when classifying a batch of malware samples against known family signatures, writing detection rules for a newly analyzed malware family, or performing signature-based malware triage.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security. It works with Python. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Classifying a batch of malware samples against known family signatures
  • Writing detection rules for a newly analyzed malware family
  • Performing signature-based malware triage

Example prompts

  • “Use the performing-malware-triage-with-yara skill to perform rapid malware triage and classification using YARA rules that match file patterns…”
  • “/performing-malware-triage-with-yara”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Scan Samples with Existing Rule Sets
  2. Write Rules for Unique String Patterns
  3. Write Rules for Byte Patterns
  4. Write Rules with PE Module
  5. Batch Triage with Python
  6. Validate and Optimize Rules

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • apt
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Malware Triage With Yara loads about 3.1k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 126 tokens; SKILL.md has 610 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~126
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 610 words, ~3,150 tokens.

Download SKILL.mdSave it as .claude/skills/performing-malware-triage-with-yara/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
performing-malware-triage-with-yara
description
Performs rapid malware triage and classification using YARA rules that match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators, covering rule writing, scanning, and integration into analysis pipelines. Use when classifying a batch of malware samples against known family signatures, writing detection rules for a newly analyzed malware family, or performing signature-based malware triage.
domain
cybersecurity
subdomain
malware-analysis
tags
malware, YARA, triage, classification, pattern-matching
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
DE.AE-02, RS.AN-03, ID.RA-01, DE.CM-01
mitre_attack
T1027, T1055, T1140, T1497, T0816

Performing Malware Triage with YARA

When to Use

  • Rapidly classifying a large batch of malware samples against known family signatures
  • Writing detection rules for a newly analyzed malware family based on unique byte patterns
  • Scanning file shares, endpoints, or memory dumps for indicators of a specific threat
  • Building automated triage pipelines that classify samples before manual analysis
  • Hunting for variants of a known threat across an enterprise using YARA scans

Do not use as the sole analysis method; YARA triage identifies known patterns but does not reveal new or unknown malware behaviors.

Prerequisites

  • YARA 4.x installed (apt install yara or pip install yara-python)
  • YARA rule repositories (YARA-Rules, awesome-yara, Malpedia rules, Florian Roth's signature-base)
  • Python 3.8+ with yara-python for scripted scanning
  • Sample collection organized in a directory structure for batch scanning
  • Understanding of PE file format, hex patterns, and regular expressions for rule writing

Workflow

Step 1: Scan Samples with Existing Rule Sets

Apply community and commercial YARA rules to classify samples:

bash
# Scan a single file
yara -s malware_rules.yar suspect.exe

# Scan a directory of samples
yara -r malware_rules.yar /path/to/samples/

# Scan with multiple rule files
yara -r rules/apt_rules.yar rules/ransomware_rules.yar rules/trojan_rules.yar suspect.exe

# Scan with timeout (prevent hanging on large files)
yara -t 30 malware_rules.yar suspect.exe

# Scan and show matching strings
yara -s -r malware_rules.yar suspect.exe

# Scan with compiled rules (faster for repeated scans)
yarac malware_rules.yar compiled_rules.yarc
yara compiled_rules.yarc suspect.exe
bash
# Download community rule sets
git clone https://github.com/Yara-Rules/rules.git yara-community-rules
git clone https://github.com/Neo23x0/signature-base.git signature-base

# Scan with signature-base
yara -r signature-base/yara/*.yar suspect.exe
Step 2: Write Rules for Unique String Patterns

Create YARA rules based on strings extracted during malware analysis:

rule MalwareX_Strings {
    meta:
        description = "Detects MalwareX based on unique strings"
        author = "analyst"
        date = "2025-09-15"
        reference = "Internal Analysis Report #1547"
        hash = "e3b0c44298fc1c149afbf4c8996fb924"
        tlp = "WHITE"

    strings:
        // C2 URL pattern
        $url1 = "/gate.php?id=" ascii
        $url2 = "/panel/connect.php" ascii

        // Unique mutex name
        $mutex = "Global\\CryptLocker_2025" ascii wide

        // User-Agent string
        $ua = "Mozilla/5.0 (compatible; MSIE 10.0)" ascii

        // Registry persistence path
        $reg = "Software\\Microsoft\\Windows\\CurrentVersion\\Run\\WindowsUpdate" ascii

        // Campaign identifier
        $campaign = "campaign_2025_q3" ascii

    condition:
        uint16(0) == 0x5A4D and      // PE file (MZ header)
        filesize < 500KB and          // Size constraint
        ($url1 or $url2) and          // At least one C2 URL
        ($mutex or $campaign) and     // Campaign identifier
        $ua                           // Specific User-Agent
}
Step 3: Write Rules for Byte Patterns

Create rules matching specific code sequences:

rule MalwareX_Decryptor {
    meta:
        description = "Detects MalwareX XOR decryption routine"
        author = "analyst"
        date = "2025-09-15"

    strings:
        // XOR decryption loop (x86 assembly)
        // mov al, [esi+ecx]
        // xor al, [edi+ecx]
        // mov [esi+ecx], al
        // inc ecx
        // cmp ecx, edx
        // jl loop
        $xor_loop = { 8A 04 0E 32 04 0F 88 04 0E 41 3B CA 7C F3 }

        // RC4 KSA initialization (256-byte loop)
        $rc4_ksa = { 33 C0 88 04 ?8 40 3D 00 01 00 00 7? }

        // Embedded RSA public key marker
        $rsa_key = { 06 02 00 00 00 A4 00 00 52 53 41 31 }  // PUBLICKEYBLOB

    condition:
        uint16(0) == 0x5A4D and
        ($xor_loop or $rc4_ksa) and
        $rsa_key
}
Step 4: Write Rules with PE Module

Leverage YARA's PE module for structural detection:

import "pe"
import "hash"
import "math"

rule MalwareX_PE_Characteristics {
    meta:
        description = "Detects MalwareX by PE structure and imports"
        author = "analyst"

    condition:
        pe.is_pe and

        // Compiled within specific timeframe
        pe.timestamp > 1693526400 and   // After 2023-09-01
        pe.timestamp < 1727740800 and   // Before 2024-10-01

        // Specific import hash
        pe.imphash() == "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6" or

        // Suspicious import combination
        (
            pe.imports("kernel32.dll", "VirtualAllocEx") and
            pe.imports("kernel32.dll", "WriteProcessMemory") and
            pe.imports("kernel32.dll", "CreateRemoteThread") and
            pe.imports("wininet.dll", "InternetOpenA")
        ) or

        // High entropy .text section (packed)
        (
            for any section in pe.sections : (
                section.name == ".text" and
                math.entropy(section.raw_data_offset, section.raw_data_size) > 7.0
            )
        )
}

rule MalwareX_Rich_Header {
    meta:
        description = "Detects MalwareX by Rich header hash"

    condition:
        pe.is_pe and
        hash.md5(pe.rich_signature.clear_data) == "abc123def456abc123def456abc123de"
}
Step 5: Batch Triage with Python

Automate scanning of sample collections:

python
import yara
import os
import json
import hashlib
from datetime import datetime

# Compile all rule files
rule_files = {
    "apt": "rules/apt_rules.yar",
    "ransomware": "rules/ransomware_rules.yar",
    "trojan": "rules/trojan_rules.yar",
    "custom": "rules/custom_rules.yar",
}
rules = yara.compile(filepaths=rule_files)

# Scan sample directory
results = []
sample_dir = "/path/to/samples"

for filename in os.listdir(sample_dir):
    filepath = os.path.join(sample_dir, filename)
    if not os.path.isfile(filepath):
        continue

    with open(filepath, "rb") as f:
        data = f.read()
        sha256 = hashlib.sha256(data).hexdigest()

    matches = rules.match(filepath)

    result = {
        "filename": filename,
        "sha256": sha256,
        "size": len(data),
        "matches": [],
        "classification": "UNKNOWN",
    }

    for match in matches:
        result["matches"].append({
            "rule": match.rule,
            "namespace": match.namespace,
            "tags": match.tags,
            "strings": [(hex(s[0]), s[1], s[2].decode("utf-8", errors="replace")[:100])
                       for s in match.strings] if match.strings else []
        })

    if result["matches"]:
        result["classification"] = result["matches"][0]["namespace"].upper()

    results.append(result)

# Summary
classified = sum(1 for r in results if r["classification"] != "UNKNOWN")
print(f"Scanned: {len(results)} samples")
print(f"Classified: {classified} ({classified/len(results)*100:.1f}%)")
print(f"Unknown: {len(results)-classified}")

# Export results
with open("triage_results.json", "w") as f:
    json.dump(results, f, indent=2)
Step 6: Validate and Optimize Rules

Test rules for false positives and performance:

bash
# Test rule syntax
yara -C custom_rules.yar

# Scan known-clean directory to check false positives
yara -r custom_rules.yar /path/to/clean_files/ > false_positives.txt
wc -l false_positives.txt

# Benchmark rule performance
time yara -r custom_rules.yar /path/to/large_sample_collection/

# Profile individual rule performance
yara -p custom_rules.yar suspect.exe

Key Concepts

TermDefinition
YARA RulePattern matching rule defining strings, byte sequences, and conditions that identify a specific file or malware family
ConditionBoolean expression combining string matches, file properties, and module functions to determine if a rule matches
Hex StringByte pattern with optional wildcards (??) and jumps ([N-M]) for matching machine code or binary data
PE ModuleYARA module providing access to PE file properties (imports, sections, timestamps, resources) for structural matching
ImphashMD5 hash of a PE file's import table; samples from the same family often share import hashes
Rich HeaderUndocumented PE structure containing compiler/linker metadata; consistent within malware build environments
YARA-CCompiled YARA rule format enabling faster scanning by pre-compiling rules for repeated use
Show full SKILL.md (261 more words)Show less

Tools & Systems

  • YARA: Pattern matching engine for identifying and classifying malware based on text, hex, and structural patterns
  • yara-python: Python bindings for YARA enabling scripted scanning, rule compilation, and integration with analysis pipelines
  • yarGen: Automatic YARA rule generator that creates rules from malware samples by identifying unique strings and opcodes
  • YARA-Rules (GitHub): Community-maintained repository of YARA rules covering malware families, exploits, and suspicious indicators
  • Malpedia YARA: Curated YARA rules from the Malpedia malware encyclopedia with high-quality family-specific rules

Common Scenarios

Scenario: Creating Detection Rules for a New Malware Family

Context: Reverse engineering of a new malware sample has identified unique strings, byte patterns, and PE characteristics. YARA rules are needed for enterprise-wide hunting and ongoing detection.

Approach:

  1. Extract unique strings from the unpacked binary (C2 URLs, mutex names, registry paths)
  2. Identify unique byte sequences from the encryption routine or C2 protocol (from Ghidra analysis)
  3. Record PE characteristics (imphash, Rich header hash, section names, compilation timestamp range)
  4. Write a YARA rule combining string, byte pattern, and PE module conditions
  5. Test against the known malware samples to confirm true positive detection
  6. Test against a clean file corpus (Windows system files, common applications) to verify zero false positives
  7. Deploy to enterprise scanning infrastructure and threat intelligence platform

Pitfalls:

  • Writing rules too specific to a single sample (will not detect variants with minor changes)
  • Writing rules too generic (matching legitimate software, causing false positives)
  • Using strings that appear in common libraries or frameworks (e.g., OpenSSL strings)
  • Not testing on a sufficiently large clean corpus before deployment

Output Format

YARA TRIAGE RESULTS
=====================
Scan Date:        2025-09-15
Rule Sets:        apt_rules (847 rules), ransomware_rules (312 rules),
                  trojan_rules (1,204 rules), custom_rules (45 rules)
Samples Scanned:  2,500
Processing Time:  47 seconds

CLASSIFICATION SUMMARY
APT:              12 samples (0.5%)
Ransomware:       187 samples (7.5%)
Trojan:           423 samples (16.9%)
Unknown:          1,878 samples (75.1%)

TOP MATCHING RULES
Rule                         Matches  Family
MalwareX_C2_Beacon           45       MalwareX
LockBit3_Ransom_Note         38       LockBit 3.0
Emotet_Epoch5_Loader         32       Emotet
CobaltStrike_Beacon_Config   28       Cobalt Strike
QakBot_DLL_Loader            25       QakBot

SAMPLE DETAIL
File:    suspect.exe
SHA-256: e3b0c44298fc1c149afbf4c8996fb924...
Matches:
  [1] MalwareX_Strings (custom)
      - $url1 at 0x4A20: "/gate.php?id="
      - $mutex at 0x5100: "Global\\CryptLocker_2025"
  [2] MalwareX_Decryptor (custom)
      - $xor_loop at 0x401200: { 8A 04 0E 32 04 0F ... }
  [3] MalwareX_PE_Characteristics (custom)
      - PE import combination matched
Classification: MALWAREX (HIGH CONFIDENCE)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/performing-malware-triage-with-yara of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Malware Triage With Yara next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Malware Triage With Yara compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Malware Triage With Yara this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
C To AstNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Security AuditTheDecipherist/claude-code-mastery551—~1.3kAutomated safety check: NotesMIT
Vpn Security CheckSergei-thinker/vpn-setup189—~1.5kAutomated safety check: NotesMIT
Banditalpha-omega-security/scrutineer245—~615Automated safety check: NotesMIT
Python Reviewliuyanghejerry/Clausura204—~164Automated safety check: PassMIT

Similar skills

  • C To Ast

    Narwhal-Lab/MagicSkills

    Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

    316 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Vpn Security Check

    Sergei-thinker/vpn-setup

    Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.

    189 GitHub stars~1.5k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Bandit

    alpha-omega-security/scrutineer

    Run bandit against the Python source in the repository and map its hits into the findings shape.

    245 GitHub stars~615 tokensUpdated today
    SecurityAuto-check: notes
  • Python Review

    liuyanghejerry/Clausura

    Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura.

    204 GitHub stars~164 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Case Review

    zhaoxuya520/reverse-skill

    Reviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.

    41k GitHub starsUsed in 1 repo~1.6k tokens
    SecurityAuto-check: warnings

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Performing Malware Triage With Yara

What does Performing Malware Triage With Yara do?

Performs rapid malware triage and classification using YARA rules that match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious…. Performing Malware Triage With Yara is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs rapid malware triage and classification using YARA rules that match file patterns, strings, byte sequences, and structural characteristics against known malware families and suspicious indicators, covering rule writing, scanning, and integration into analysis pipelines.

When should I use Performing Malware Triage With Yara?

Performing Malware Triage With Yara fits situations like: classifying a batch of malware samples against known family signatures; writing detection rules for a newly analyzed malware family; performing signature-based malware triage.

How do I install Performing Malware Triage With Yara in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-malware-triage-with-yara -a claude-code`. Or copy the skill folder (skills/performing-malware-triage-with-yara in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-malware-triage-with-yara in your project. Claude Code loads it when a task matches its description.

How do I install Performing Malware Triage With Yara in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-malware-triage-with-yara -a codex`. Or copy the skill folder (skills/performing-malware-triage-with-yara in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-malware-triage-with-yara in your project. Codex loads it when a task matches its description.

Can I use Performing Malware Triage With Yara in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-malware-triage-with-yara -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-malware-triage-with-yara, .gemini/skills/performing-malware-triage-with-yara, .github/skills/performing-malware-triage-with-yara and .opencode/skills/performing-malware-triage-with-yara in your project.

What does Performing Malware Triage With Yara need to run?

Going by SKILL.md and its folder, Performing Malware Triage With Yara needs Python for the scripts in its folder and the command-line tools its instructions call (git, apt and pip). Our summary lists: Python 3.

Does Performing Malware Triage With Yara access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Performing Malware Triage With Yara safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Malware Triage With Yara use?

Performing Malware Triage With Yara is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Malware Triage With Yara use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 407 tokens, read only when the agent opens those files.

What are the alternatives to Performing Malware Triage With Yara?

Skills that share tags, products or a category with Performing Malware Triage With Yara: C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Security Audit (TheDecipherist/claude-code-mastery, 551 stars), Vpn Security Check (Sergei-thinker/vpn-setup, 189 stars) and Bandit (alpha-omega-security/scrutineer, 245 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Malware Triage With Yara?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.