Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
Agent skill
Perform OT vulnerability assessments using the Claroty xDome platform for asset discovery, risk scoring, and vulnerability correlation, combining passive traffic-based identification and active safe…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ot-vulnerability-assessment-with-claroty -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ot-vulnerability-assessment-with-claroty --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-ot-vulnerability-assessment-with-claroty .claude/skills/performing-ot-vulnerability-assessment-with-claroty && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "performing-ot-vulnerability-assessment-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ot-vulnerability-assessment-with-claroty into .claude/skills/performing-ot-vulnerability-assessment-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ot-vulnerability-assessment-with-claroty", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ot-vulnerability-assessment-with-clarotyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ot-vulnerability-assessment-with-claroty -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ot-vulnerability-assessment-with-claroty --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/performing-ot-vulnerability-assessment-with-claroty .agents/skills/performing-ot-vulnerability-assessment-with-claroty && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "performing-ot-vulnerability-assessment-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ot-vulnerability-assessment-with-claroty into .agents/skills/performing-ot-vulnerability-assessment-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ot-vulnerability-assessment-with-claroty", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ot-vulnerability-assessment-with-claroty -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ot-vulnerability-assessment-with-claroty --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/performing-ot-vulnerability-assessment-with-claroty .cursor/skills/performing-ot-vulnerability-assessment-with-claroty && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "performing-ot-vulnerability-assessment-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ot-vulnerability-assessment-with-claroty into .cursor/skills/performing-ot-vulnerability-assessment-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ot-vulnerability-assessment-with-claroty", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/performing-ot-vulnerability-assessment-with-claroty--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ot-vulnerability-assessment-with-claroty -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ot-vulnerability-assessment-with-claroty --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/performing-ot-vulnerability-assessment-with-claroty .gemini/skills/performing-ot-vulnerability-assessment-with-claroty && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "performing-ot-vulnerability-assessment-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ot-vulnerability-assessment-with-claroty into .gemini/skills/performing-ot-vulnerability-assessment-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ot-vulnerability-assessment-with-claroty", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ot-vulnerability-assessment-with-clarotyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ot-vulnerability-assessment-with-claroty -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/performing-ot-vulnerability-assessment-with-claroty .github/skills/performing-ot-vulnerability-assessment-with-claroty && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "performing-ot-vulnerability-assessment-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ot-vulnerability-assessment-with-claroty into .github/skills/performing-ot-vulnerability-assessment-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ot-vulnerability-assessment-with-claroty", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ot-vulnerability-assessment-with-claroty -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ot-vulnerability-assessment-with-claroty --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/performing-ot-vulnerability-assessment-with-claroty .opencode/skills/performing-ot-vulnerability-assessment-with-claroty && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "performing-ot-vulnerability-assessment-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ot-vulnerability-assessment-with-claroty into .opencode/skills/performing-ot-vulnerability-assessment-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ot-vulnerability-assessment-with-claroty", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
performing-ot-vulnerability-assessment-with-clarotyPerform OT vulnerability assessments using the Claroty xDome platform for asset discovery, risk scoring, and vulnerability correlation, combining passive traffic-based identification and active safe…
Performing Ot Vulnerability Assessment With Claroty is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Perform OT vulnerability assessments using the Claroty xDome platform for asset discovery, risk scoring, and vulnerability correlation, combining passive traffic-based identification and active safe device querying with CVE/ICS-CERT advisory correlation for remediation prioritization. Use for scheduled IEC 62443 or NERC CIP OT vulnerability assessments, initial xDome deployment, or generating CIP-010-4 compliance evidence; not for active PLC scanning or penetration testing.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Security, covering Vulnerability scanning. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
cisa.govFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Performing Ot Vulnerability Assessment With Claroty loads about 3.1k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 133 tokens; SKILL.md has 351 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 351 words, ~3,133 tokens.
.claude/skills/performing-ot-vulnerability-assessment-with-claroty/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Do not use for active vulnerability scanning of PLCs and safety systems (see performing-ot-network-security-assessment for passive approaches), for IT-only vulnerability management (see standard vulnerability scanners), or for penetration testing (see performing-ics-penetration-testing).
Configure Claroty to perform passive and active-safe discovery to build complete asset inventory with firmware versions for vulnerability correlation.
#!/usr/bin/env python3
"""OT Vulnerability Assessment Manager.
Correlates OT asset inventory with ICS-CERT advisories and CVE data
to identify, prioritize, and track OT vulnerabilities. Designed to
integrate with Claroty xDome API or standalone operation.
"""
import json
import sys
from collections import defaultdict
from dataclasses import dataclass, field, asdict
from datetime import datetime
import requests
@dataclass
class OTAsset:
asset_id: str
name: str
vendor: str
model: str
firmware_version: str
asset_type: str # PLC, HMI, RTU, historian, switch, etc.
purdue_level: str
ip_address: str
protocol: str
criticality: str # critical, high, medium, low
zone: str
@dataclass
class OTVulnerability:
vuln_id: str
cve_id: str
title: str
severity: str # critical, high, medium, low
cvss_score: float
affected_vendor: str
affected_product: str
affected_versions: str
description: str
ics_cert_advisory: str = ""
remediation: str = ""
patch_available: bool = False
compensating_controls: str = ""
@dataclass
class RiskAssessment:
asset: OTAsset
vulnerability: OTVulnerability
risk_score: float = 0.0
risk_rating: str = ""
exploitability: str = ""
operational_impact: str = ""
compensating_controls: list = field(default_factory=list)
remediation_priority: int = 0
class OTVulnerabilityAssessment:
"""OT vulnerability assessment and prioritization engine."""
def __init__(self):
self.assets = []
self.vulnerabilities = []
self.risk_assessments = []
def load_assets(self, assets_data):
"""Load asset inventory from Claroty export or manual inventory."""
for a in assets_data:
self.assets.append(OTAsset(**a))
print(f"[*] Loaded {len(self.assets)} OT assets")
def fetch_ics_advisories(self):
"""Fetch latest ICS-CERT advisories from CISA."""
print("[*] Fetching ICS-CERT advisories from CISA...")
try:
# CISA Known Exploited Vulnerabilities catalog
url = "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
resp = requests.get(url, timeout=30)
resp.raise_for_status()
data = resp.json()
ics_vulns = []
for vuln in data.get("vulnerabilities", []):
# Filter for ICS-relevant vendors
ics_vendors = [
"siemens", "schneider", "rockwell", "honeywell",
"abb", "ge", "emerson", "yokogawa", "omron",
"mitsubishi", "phoenix", "moxa", "advantech",
]
vendor = vuln.get("vendorProject", "").lower()
if any(v in vendor for v in ics_vendors):
ics_vulns.append(vuln)
print(f" Found {len(ics_vulns)} ICS-relevant known exploited vulnerabilities")
return ics_vulns
except Exception as e:
print(f"[WARN] Could not fetch advisories: {e}")
return []
def correlate_vulnerabilities(self):
"""Match vulnerabilities to assets based on vendor/model/firmware."""
print("[*] Correlating vulnerabilities to assets...")
for asset in self.assets:
for vuln in self.vulnerabilities:
if (vuln.affected_vendor.lower() in asset.vendor.lower() and
vuln.affected_product.lower() in asset.model.lower()):
# Check firmware version if specified
ra = RiskAssessment(asset=asset, vulnerability=vuln)
self._calculate_risk_score(ra)
self.risk_assessments.append(ra)
print(f" Correlated {len(self.risk_assessments)} asset-vulnerability pairs")
def _calculate_risk_score(self, ra):
"""Calculate OT-specific risk score considering operational impact."""
# Base score from CVSS
base = ra.vulnerability.cvss_score
# Criticality multiplier based on asset function
criticality_weights = {
"critical": 1.5, # SIS, safety systems
"high": 1.3, # PLCs, primary control
"medium": 1.0, # HMIs, historians
"low": 0.7, # non-critical support systems
}
criticality = criticality_weights.get(ra.asset.criticality, 1.0)
# Purdue level proximity factor (lower levels = higher risk)
level_weights = {
"Level 0-1": 1.5,
"Level 2": 1.3,
"Level 3": 1.0,
"Level 3.5": 0.8,
"Level 4": 0.6,
}
level_factor = level_weights.get(ra.asset.purdue_level, 1.0)
# Network exposure reduction if compensating controls exist
comp_reduction = 0.8 if ra.compensating_controls else 1.0
ra.risk_score = round(base * criticality * level_factor * comp_reduction, 1)
ra.risk_score = min(ra.risk_score, 10.0)
if ra.risk_score >= 9.0:
ra.risk_rating = "critical"
ra.remediation_priority = 1
elif ra.risk_score >= 7.0:
ra.risk_rating = "high"
ra.remediation_priority = 2
elif ra.risk_score >= 4.0:
ra.risk_rating = "medium"
ra.remediation_priority = 3
else:
ra.risk_rating = "low"
ra.remediation_priority = 4
def generate_report(self):
"""Generate vulnerability assessment report."""
# Sort by risk score descending
sorted_ra = sorted(self.risk_assessments, key=lambda x: -x.risk_score)
report = []
report.append("=" * 70)
report.append("OT VULNERABILITY ASSESSMENT REPORT")
report.append(f"Date: {datetime.now().isoformat()}")
report.append(f"Assets: {len(self.assets)} | Vulnerabilities: {len(self.vulnerabilities)}")
report.append(f"Risk Assessments: {len(self.risk_assessments)}")
report.append("=" * 70)
for sev in ["critical", "high", "medium", "low"]:
findings = [ra for ra in sorted_ra if ra.risk_rating == sev]
if findings:
report.append(f"\n--- {sev.upper()} RISK ({len(findings)}) ---")
for ra in findings[:10]:
report.append(f"\n Risk Score: {ra.risk_score}/10.0")
report.append(f" Asset: {ra.asset.name} ({ra.asset.vendor} {ra.asset.model})")
report.append(f" Zone: {ra.asset.zone} ({ra.asset.purdue_level})")
report.append(f" CVE: {ra.vulnerability.cve_id} (CVSS: {ra.vulnerability.cvss_score})")
report.append(f" Title: {ra.vulnerability.title}")
if ra.vulnerability.patch_available:
report.append(f" Patch: Available - schedule for next maintenance window")
else:
report.append(f" Patch: Not available - apply compensating controls")
return "\n".join(report)
def export_json(self, output_file):
"""Export assessment to JSON."""
data = {
"assessment_date": datetime.now().isoformat(),
"asset_count": len(self.assets),
"vulnerability_count": len(self.vulnerabilities),
"risk_assessments": [
{
"asset_name": ra.asset.name,
"asset_ip": ra.asset.ip_address,
"cve": ra.vulnerability.cve_id,
"risk_score": ra.risk_score,
"risk_rating": ra.risk_rating,
"priority": ra.remediation_priority,
}
for ra in sorted(self.risk_assessments, key=lambda x: -x.risk_score)
],
}
with open(output_file, "w") as f:
json.dump(data, f, indent=2)
if __name__ == "__main__":
assessment = OTVulnerabilityAssessment()
advisories = assessment.fetch_ics_advisories()
print(f"Fetched {len(advisories)} ICS advisories from CISA KEV catalog")| Term | Definition |
|---|---|
| Claroty xDome | Cyber-physical systems protection platform providing asset discovery, vulnerability management, and threat detection for OT/IoT environments |
| Passive Discovery | Identifying OT assets by analyzing network traffic without sending any packets, safe for production environments |
| Safe Active Query | Querying OT devices using native industrial protocols at safe rates to collect detailed asset information without disrupting operations |
| OT Risk Score | Risk rating that factors CVSS base score, asset criticality, Purdue level, and compensating controls for OT-appropriate prioritization |
| ICS-CERT Advisory | CISA-published security advisories for industrial control system vulnerabilities with vendor-specific remediation guidance |
| Virtual Patching | Deploying IPS/firewall rules to block exploitation of known vulnerabilities when firmware patches cannot be immediately applied |
OT Vulnerability Assessment Report
=====================================
Tool: Claroty xDome / Manual Assessment
Date: YYYY-MM-DD
Assets Scanned: [N]
RISK SUMMARY:
Critical Risk: [N] vulnerabilities on [N] assets
High Risk: [N] vulnerabilities on [N] assets
Medium Risk: [N] vulnerabilities on [N] assets
Low Risk: [N] vulnerabilities on [N] assets
TOP RISKS:
[Risk Score] [CVE-ID] on [Asset Name] ([Zone])
Remediation: [Patch/Compensating Control]
Timeline: [Next maintenance window / Immediate]© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/performing-ot-vulnerability-assessment-with-claroty of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Performing Ot Vulnerability Assessment With Claroty next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Performing Ot Vulnerability Assessment With Claroty this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Shiro Attack CLISummerSec/ShiroAttack2 | 2.6k | — | ~945 | Automated safety check: Pass | MIT | |
| Cve Remediationrundeck/rundeck | 6.3k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 190 | — | ~2.5k | Automated safety check: Notes | Custom licence |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
rundeck/rundeck
Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
evdenis/cvehound
Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Perform OT vulnerability assessments using the Claroty xDome platform for asset discovery, risk scoring, and vulnerability correlation, combining passive traffic-based identification and active safe…. Performing Ot Vulnerability Assessment With Claroty is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Perform OT vulnerability assessments using the Claroty xDome platform for asset discovery, risk scoring, and vulnerability correlation, combining passive traffic-based identification and active safe device querying with CVE/ICS-CERT advisory correlation for remediation prioritization.
Performing Ot Vulnerability Assessment With Claroty fits situations like: scheduled IEC 62443; NERC CIP OT vulnerability assessments; initial xDome deployment; generating CIP-010-4 compliance evidence.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ot-vulnerability-assessment-with-claroty -a claude-code`. Or copy the skill folder (skills/performing-ot-vulnerability-assessment-with-claroty in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-ot-vulnerability-assessment-with-claroty in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ot-vulnerability-assessment-with-claroty -a codex`. Or copy the skill folder (skills/performing-ot-vulnerability-assessment-with-claroty in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-ot-vulnerability-assessment-with-claroty in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ot-vulnerability-assessment-with-claroty -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-ot-vulnerability-assessment-with-claroty, .gemini/skills/performing-ot-vulnerability-assessment-with-claroty, .github/skills/performing-ot-vulnerability-assessment-with-claroty and .opencode/skills/performing-ot-vulnerability-assessment-with-claroty in your project.
Going by SKILL.md and its folder, Performing Ot Vulnerability Assessment With Claroty needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: cisa.gov; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Performing Ot Vulnerability Assessment With Claroty is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 292 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Performing Ot Vulnerability Assessment With Claroty: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Cve Remediation (rundeck/rundeck, 6.3k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.