Agent skill

Performing Ransomware Tabletop Exercise

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Plans and facilitates tabletop exercises simulating ransomware incidents, using realistic scenarios based on threat actors like LockBit and ALPHV/BlackCat with injects covering double extortion and…

Apache-2.0Auto-check passedDevOps & Cloud

Install Performing Ransomware Tabletop Exercise

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ransomware-tabletop-exercise -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ransomware-tabletop-exercise --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-ransomware-tabletop-exercise .claude/skills/performing-ransomware-tabletop-exercise && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-ransomware-tabletop-exercise
GitHub stars
34k
Token cost
~2.9k tokens
SKILL.md length
1,095 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Plans and facilitates tabletop exercises simulating ransomware incidents, using realistic scenarios based on threat actors like LockBit and ALPHV/BlackCat with injects covering double extortion and…

  • Works in 5 steps: Design the Exercise Scenario → Prepare Exercise Materials → Facilitate the Exercise → …
  • Running a ransomware tabletop exercise
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Performing Ransomware Tabletop Exercise is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Plans and facilitates tabletop exercises simulating ransomware incidents, using realistic scenarios based on threat actors like LockBit and ALPHV/BlackCat with injects covering double extortion and backup destruction, then evaluates responses against NIST CSF and CISA guidelines. Use when planning or running a ransomware tabletop exercise or incident response readiness drill.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in DevOps & Cloud, covering Incident response. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Running a ransomware tabletop exercise
  • Incident response readiness drill

Example prompts

  • “Use the performing-ransomware-tabletop-exercise skill to plan and facilitates tabletop exercises simulating ransomware incidents, using realistic…”
  • “/performing-ransomware-tabletop-exercise”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Design the Exercise Scenario
  2. Prepare Exercise Materials
  3. Facilitate the Exercise
  4. Evaluate and Score Responses
  5. Document Findings and Remediation Plan

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Ransomware Tabletop Exercise loads about 2.9k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 1,095 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,095 words, ~2,944 tokens.

Download SKILL.mdSave it as .claude/skills/performing-ransomware-tabletop-exercise/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-ransomware-tabletop-exercise
description
Plans and facilitates tabletop exercises simulating ransomware incidents, using realistic scenarios based on threat actors like LockBit and ALPHV/BlackCat with injects covering double extortion and backup destruction, then evaluates responses against NIST CSF and CISA guidelines. Use when planning or running a ransomware tabletop exercise or incident response readiness drill.
domain
cybersecurity
subdomain
ransomware-defense
tags
ransomware, incident-response, tabletop-exercise, defense, preparedness
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.DS-11, RS.MA-01, RC.RP-01, PR.IR-01
mitre_attack
T1078, T1190, T1059, T1486, T1490
mitre_f3.version
1.1
mitre_f3.tactics
positioning, monetization

Performing Ransomware Tabletop Exercise

When to Use

  • Testing organizational ransomware response procedures annually or after major infrastructure changes
  • Validating decision-making processes for ransom payment, regulatory notification, and public disclosure
  • Training executives, IT, legal, PR, and operations teams on their roles during a ransomware incident
  • Meeting cyber insurance policy requirements for documented incident response testing
  • Identifying gaps in recovery playbooks, communication plans, and backup procedures

Do not use as a substitute for technical controls testing. Tabletop exercises validate procedures and decision-making, not technical detection or prevention capabilities.

Prerequisites

  • Documented incident response plan (IRP) that participants should have read before the exercise
  • Identified exercise participants from: executive leadership, IT/security, legal, communications/PR, HR, operations, and external counsel
  • Facilitator who is independent from the IR team (to provide objective evaluation)
  • Ransomware scenario designed with injects that escalate over multiple rounds
  • Evaluation criteria aligned to NIST CSF Respond/Recover functions
  • Conference room or virtual meeting for 2-4 hours with no interruptions

Workflow

Step 1: Design the Exercise Scenario

Build a realistic scenario based on current threat actor TTPs:

Scenario Structure:

Phase 1: Initial Detection (30 min)
  - SOC receives alert for suspicious process execution on file server
  - EDR detects Cobalt Strike beacon on 3 workstations
  - Inject: External threat intel report links C2 IP to LockBit affiliate

Phase 2: Escalation (30 min)
  - Ransomware executes on 40% of servers during overnight hours
  - Ransom note demands $2M in Bitcoin with 72-hour deadline
  - Inject: Attackers contact media claiming data theft of customer PII

Phase 3: Decision Points (45 min)
  - Backup assessment reveals immutable copies are intact but primary backups encrypted
  - Legal advises on breach notification timeline (72 hours GDPR, varies by US state)
  - Inject: Threat actor publishes sample of stolen data on leak site

Phase 4: Recovery and Communication (45 min)
  - Recovery time estimate: 5-7 days from immutable backups
  - Insurance carrier engages negotiation firm
  - Inject: Major customer threatens contract termination without update within 24 hours

Scenario Variables to Customize:

  • Threat actor group and known TTPs
  • Percentage of infrastructure encrypted
  • Whether backups are intact, partially compromised, or fully destroyed
  • Type of data exfiltrated (PII, PHI, financial, trade secrets)
  • Applicable regulatory frameworks (GDPR, HIPAA, PCI DSS, SEC rules)
  • Ransom amount and payment deadline
Step 2: Prepare Exercise Materials

Create the following documents for participants:

  1. Exercise Overview Briefing - Ground rules, objectives, scope, and participants
  2. Situation Reports (SITREPs) - One per phase, distributed as the exercise progresses
  3. Inject Cards - New information introduced at specific times to force decision-making
  4. Decision Point Worksheets - Structured forms for documenting group decisions
  5. Evaluation Scorecard - Criteria for assessing response quality

Key Decision Points to Include:

  • When to activate the incident response team
  • Whether to shut down systems or contain selectively
  • Whether to engage law enforcement (FBI IC3, CISA)
  • Whether to pay the ransom and under what conditions
  • When and how to notify regulators, customers, and the public
  • How to prioritize system recovery order
Step 3: Facilitate the Exercise

Facilitator Responsibilities:

  • Present each phase scenario and distribute SITREPs
  • Introduce injects at predetermined times to increase pressure
  • Ask probing questions to test decision-making reasoning
  • Ensure all participant groups contribute (prevent IT from dominating)
  • Document all decisions, rationales, and action items
  • Track time management (many teams lose time on early phases)

Probing Questions by Phase:

Phase 1 - Detection:

  • Who makes the call to declare an incident? What criteria trigger it?
  • How do we determine the scope of compromise from initial alerts?
  • Do we have the forensic capability to investigate or do we need external help?

Phase 2 - Escalation:

  • What is our communication plan for employees? Do they know not to turn on affected machines?
  • Have we isolated the network to prevent further encryption?
  • Who authorizes system shutdowns that impact business operations?

Phase 3 - Decision:

  • Under what conditions would we consider paying the ransom?
  • What are the legal obligations for notification at this point?
  • How do we handle the public leak of customer data?

Phase 4 - Recovery:

  • What is the recovery priority order? Is it documented or decided ad hoc?
  • How long until critical business operations resume?
  • What evidence preservation is required for law enforcement and insurance?
Step 4: Evaluate and Score Responses

Score each functional area against defined criteria:

Evaluation AreaScore (1-5)Criteria
Detection & EscalationTimely incident declaration, proper chain of command
ContainmentNetwork isolation, credential reset, scope assessment
Communication - InternalEmployee notification, executive briefing, documented decisions
Communication - ExternalRegulatory notification, customer communication, media response
Recovery PlanningBackup verification, recovery priority, RTO tracking
Legal & ComplianceBreach notification timelines, evidence preservation, law enforcement engagement
Business ContinuityManual operations, customer impact mitigation, revenue loss estimation
Payment DecisionStructured framework, legal review, OFAC sanctions check
Step 5: Document Findings and Remediation Plan

Produce an after-action report (AAR) within 5 business days:

AAR Contents:

  1. Exercise overview and objectives
  2. Scenario summary and injects
  3. Key decisions made and rationale
  4. Strengths observed
  5. Gaps identified with severity rating
  6. Remediation actions with owners and deadlines
  7. Comparison to previous exercise results (if applicable)
Show full SKILL.md (414 more words)Show less

Key Concepts

TermDefinition
Tabletop Exercise (TTX)Discussion-based exercise where participants walk through a simulated incident scenario to test plans and procedures
InjectNew information introduced during the exercise to change the scenario and force additional decision-making
SITREPSituation Report providing current status of the simulated incident at each exercise phase
After-Action Report (AAR)Post-exercise document capturing findings, gaps, strengths, and remediation actions
Double ExtortionRansomware tactic where attackers both encrypt data and threaten to publish stolen data unless ransom is paid
OFAC CheckVerification that ransom payment recipient is not on the US Treasury OFAC sanctions list, which would make payment illegal

Tools & Systems

  • CISA Tabletop Exercise Packages (CTEPs): Free scenario packages from CISA designed for critical infrastructure sectors
  • FEMA Homeland Security Exercise and Evaluation Program (HSEEP): Methodology for designing, conducting, and evaluating exercises
  • Immersive Labs: Platform providing interactive cyber crisis simulations with real-time scoring
  • Tabletop Scenarios (from NCSC UK): Exercise in a Box tool providing free guided tabletop exercises
  • Ransomware Readiness Assessment (CISA): Self-assessment tool for evaluating ransomware preparedness

Common Scenarios

Scenario: Healthcare System Double Extortion Exercise

Context: A 5-hospital healthcare system conducts an annual ransomware tabletop. Previous exercise revealed gaps in HIPAA breach notification and clinical system recovery priority. This year's scenario simulates a double extortion attack targeting the EMR system.

Approach:

  1. Design scenario based on Cl0p MOO (Managed Operations Operator) TTPs: exploitation of MOVEit vulnerability for initial access, data exfiltration of 500,000 patient records, followed by encryption of EMR database servers
  2. Participants: CISO, CIO, CMO (Chief Medical Officer), General Counsel, VP Communications, Director of Clinical Operations, Privacy Officer, External IR firm representative
  3. Phase 1 inject: EMR system down, emergency department diverting patients to neighboring hospital
  4. Phase 2 inject: HHS OCR (Office for Civil Rights) contacts organization about reports of patient data on dark web
  5. Phase 3 inject: Attacker provides decryption key sample for $3.5M, 48-hour deadline
  6. Key finding: Organization lacks documented criteria for ransom payment decision and had not pre-identified an OFAC-compliant payment mechanism
  7. Remediation: Establish payment decision framework, pre-engage ransomware negotiation firm, update HIPAA breach notification procedures with specific timelines

Pitfalls:

  • Designing unrealistic scenarios that do not reflect actual ransomware TTPs, reducing exercise credibility
  • Allowing technical teams to dominate the exercise while business and legal participants remain passive
  • Not testing the communication plan (many organizations discover their notification list is outdated during the actual incident)
  • Failing to follow up on remediation actions identified in the AAR, negating the exercise value

Output Format

## Ransomware Tabletop Exercise - After Action Report

**Exercise Date**: [Date]
**Facilitator**: [Name]
**Scenario**: [Brief description]
**Duration**: [Hours]
**Participants**: [Count by department]

### Exercise Objectives
1. [Objective] - Met / Partially Met / Not Met
2. [Objective] - Met / Partially Met / Not Met

### Key Decisions Log
| Time | Decision Point | Decision Made | Rationale | Assessment |
|------|---------------|--------------|-----------|------------|

### Strengths Observed
1. [Strength]

### Gaps Identified
| Gap | Severity | Affected Area | Current State | Desired State |
|-----|----------|--------------|---------------|---------------|

### Remediation Actions
| Action | Owner | Deadline | Priority | Status |
|--------|-------|----------|----------|--------|

### Comparison to Previous Exercise
| Area | Previous Score | Current Score | Trend |
|------|---------------|--------------|-------|

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/performing-ransomware-tabletop-exercise of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Ransomware Tabletop Exercise next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Ransomware Tabletop Exercise compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Ransomware Tabletop Exercise this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Kubernetes Network Root Cause Analysiskubeshark/kubeshark12k—~5.3kAutomated safety check: PassApache-2.0
UModel Root Cause Analysisalibaba/UnifiedModel415—~1.9kAutomated safety check: PassCustom licence
Learningskortix-ai/suna20k—~1.1kAutomated safety check: PassCustom licence
Oncallpigweed-project/pigweed548—~992Automated safety check: PassApache-2.0
Loop Triage Reportcobusgreyling/loop-engineering11k—~500Automated safety check: PassMIT

Similar skills

  • Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.

    12k GitHub stars~5.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • UModel Root Cause Analysis

    alibaba/UnifiedModel

    Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments.

    415 GitHub stars~1.9k tokensUpdated 15 days ago
    DevOps & CloudAuto-check passed
  • Learnings

    kortix-ai/suna

    The project's episodic memory: a timestamped ledger of rules paid for with real outages and near-misses, one entry per incident.

    20k GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Oncall

    pigweed-project/pigweed

    Pigweed oncall rotation runbooks and maintenance workflows (such as rolling CIPD client tools for b/315378787).

    548 GitHub stars~992 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Loop Triage Report

    cobusgreyling/loop-engineering

    Turns CI failures, open issues, recent commits and chat threads into a prioritized markdown report that an automation loop can act on without inventing architecture work.

    11k GitHub stars~500 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Axiom SRE Investigator

    openclaw/clawhub

    Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.

    9.5k GitHub stars~7.1k tokensUpdated today
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Performing Ransomware Tabletop Exercise

What does Performing Ransomware Tabletop Exercise do?

Plans and facilitates tabletop exercises simulating ransomware incidents, using realistic scenarios based on threat actors like LockBit and ALPHV/BlackCat with injects covering double extortion and…. Performing Ransomware Tabletop Exercise is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Plans and facilitates tabletop exercises simulating ransomware incidents, using realistic scenarios based on threat actors like LockBit and ALPHV/BlackCat with injects covering double extortion and backup destruction, then evaluates responses against NIST CSF and CISA guidelines.

When should I use Performing Ransomware Tabletop Exercise?

Performing Ransomware Tabletop Exercise fits situations like: running a ransomware tabletop exercise; incident response readiness drill.

How do I install Performing Ransomware Tabletop Exercise in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ransomware-tabletop-exercise -a claude-code`. Or copy the skill folder (skills/performing-ransomware-tabletop-exercise in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-ransomware-tabletop-exercise in your project. Claude Code loads it when a task matches its description.

How do I install Performing Ransomware Tabletop Exercise in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ransomware-tabletop-exercise -a codex`. Or copy the skill folder (skills/performing-ransomware-tabletop-exercise in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-ransomware-tabletop-exercise in your project. Codex loads it when a task matches its description.

Can I use Performing Ransomware Tabletop Exercise in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ransomware-tabletop-exercise -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-ransomware-tabletop-exercise, .gemini/skills/performing-ransomware-tabletop-exercise, .github/skills/performing-ransomware-tabletop-exercise and .opencode/skills/performing-ransomware-tabletop-exercise in your project.

What does Performing Ransomware Tabletop Exercise need to run?

Going by SKILL.md and its folder, Performing Ransomware Tabletop Exercise needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Performing Ransomware Tabletop Exercise access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Performing Ransomware Tabletop Exercise safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Ransomware Tabletop Exercise use?

Performing Ransomware Tabletop Exercise is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Ransomware Tabletop Exercise use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Performing Ransomware Tabletop Exercise?

Skills that share tags, products or a category with Performing Ransomware Tabletop Exercise: Kubernetes Network Root Cause Analysis (kubeshark/kubeshark, 12k stars), UModel Root Cause Analysis (alibaba/UnifiedModel, 415 stars), Learnings (kortix-ai/suna, 20k stars) and Oncall (pigweed-project/pigweed, 548 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Ransomware Tabletop Exercise?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.