Agent skill

Triaging Security Incident With Ir Playbook

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the…

Apache-2.0Auto-check passedSecurity

Install Triaging Security Incident With Ir Playbook

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill triaging-security-incident-with-ir-playbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills triaging-security-incident-with-ir-playbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/triaging-security-incident-with-ir-playbook .claude/skills/triaging-security-incident-with-ir-playbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
triaging-security-incident-with-ir-playbook
GitHub stars
34k
Token cost
~2.2k tokens
SKILL.md length
395 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the…

  • Works in 7 steps: Receive and Acknowledge Alert → Enrich Alert Data → Classify Incident Type → …
  • A new SOC alert needs triage
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls curl, jq and python3; reaches virustotal.com and api.abuseipdb.com; needs THEHIVE_API_KEY and VT_API_KEY

What it does

Triaging Security Incident With Ir Playbook is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the appropriate response procedures. Use when a new SOC alert needs triage, multiple concurrent incidents require prioritization, or automated triage rules need validation or tuning.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Security operations. It works with Splunk. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • A new SOC alert needs triage
  • Multiple concurrent incidents require prioritization
  • Automated triage rules need validation

Example prompts

  • “Use the triaging-security-incident-with-ir-playbook skill to classify and prioritizes security incidents using structured IR playbooks and…”
  • “/triaging-security-incident-with-ir-playbook”

Requirements

  • Python 3
  • A credential in THEHIVE_API_KEY
  • A credential in SPLUNK_TOKEN

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Receive and Acknowledge Alert
  2. Enrich Alert Data
  3. Classify Incident Type
  4. Assign Severity Level
  5. Select and Initiate Playbook
  6. Assign Response Team
  7. Document Triage Decision and Hand Off

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • curl
    • jq
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • virustotal.com
    • api.abuseipdb.com
    • attack.mitre.org
    • pagerduty.com
    • events.pagerduty.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • THEHIVE_API_KEY
    • VT_API_KEY
    • SPLUNK_TOKEN
    • ABUSEIPDB_KEY
    • CMDB_TOKEN
    • PD_TOKEN
    • PD_ROUTING_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Triaging Security Incident With Ir Playbook loads about 2.2k tokens when it runs, and up to ~4.5k if it reads all its reference files. Until then it costs about 103 tokens; SKILL.md has 395 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 395 words, ~2,209 tokens.

Download SKILL.mdSave it as .claude/skills/triaging-security-incident-with-ir-playbook/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
triaging-security-incident-with-ir-playbook
description
Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the appropriate response procedures. Use when a new SOC alert needs triage, multiple concurrent incidents require prioritization, or automated triage rules need validation or tuning.
domain
cybersecurity
subdomain
incident-response
tags
incident-response, triage, playbook, severity-classification, soc
mitre_attack
T1486, T1490, T1070, T1078
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
RS.MA-01, RS.MA-02, RS.AN-03, RC.RP-01

Triaging Security Incidents with IR Playbooks

When to Use

  • New security alert received from SIEM, EDR, or other detection sources
  • SOC analyst needs to determine if an alert is a true positive requiring response
  • Incident needs severity classification and team assignment
  • Multiple concurrent incidents require prioritization
  • Automated triage rules need validation or tuning

Prerequisites

  • SIEM platform with alert correlation (Splunk, Elastic, QRadar, Sentinel)
  • Incident response playbook library (by incident type)
  • Severity classification matrix approved by CISO
  • On-call rotation and escalation procedures
  • Ticketing system for incident tracking (ServiceNow, Jira, TheHive)
  • Threat intelligence feeds for IOC enrichment

Workflow

Step 1: Receive and Acknowledge Alert
bash
# Query Splunk for new critical/high severity alerts
index=notable status=new severity IN ("critical","high")
| table _time, rule_name, src, dest, severity, description
| sort -_time

# Query TheHive for new cases
curl -s -H "Authorization: Bearer $THEHIVE_API_KEY" \
  "https://thehive.local/api/v1/query?name=list-alerts" \
  -H "Content-Type: application/json" \
  -d '{"query":[{"_name":"listAlert"},{"_name":"filter","_field":"status","_value":"New"}]}'

# Acknowledge alert in SIEM to prevent duplicate triage
curl -X POST "https://splunk.local:8089/services/notable_update" \
  -H "Authorization: Bearer $SPLUNK_TOKEN" \
  -d "ruleUIDs=$RULE_UID&status=1&comment=Triage+initiated+by+analyst"
Step 2: Enrich Alert Data
bash
# Enrich source IP with VirusTotal
curl -s "https://www.virustotal.com/api/v3/ip_addresses/$SRC_IP" \
  -H "x-apikey: $VT_API_KEY" | jq '.data.attributes.last_analysis_stats'

# Check IP reputation with AbuseIPDB
curl -s "https://api.abuseipdb.com/api/v2/check?ipAddress=$SRC_IP&maxAgeInDays=90" \
  -H "Key: $ABUSEIPDB_KEY" -H "Accept: application/json" | jq '.data'

# Enrich file hash with threat intelligence
curl -s "https://www.virustotal.com/api/v3/files/$FILE_HASH" \
  -H "x-apikey: $VT_API_KEY" | jq '.data.attributes.last_analysis_stats'

# Query internal asset database for affected systems
curl -s "https://cmdb.local/api/assets?ip=$DEST_IP" \
  -H "Authorization: Bearer $CMDB_TOKEN" | jq '.asset_criticality, .owner, .environment'
Step 3: Classify Incident Type
bash
# Map alert to incident category using playbook lookup
# Categories: Malware, Phishing, Unauthorized Access, Data Exfiltration,
# DoS/DDoS, Insider Threat, Ransomware, Account Compromise, Web Attack

# Check if alert matches known playbook trigger conditions
grep -i "$ALERT_SIGNATURE" /opt/ir/playbooks/trigger_conditions.yaml

# Determine incident type from MITRE ATT&CK technique
curl -s "https://attack.mitre.org/api/techniques/$TECHNIQUE_ID" | jq '.name, .tactic'
Step 4: Assign Severity Level
bash
# Severity matrix factors:
# 1. Asset criticality (Critical/High/Medium/Low)
# 2. Data sensitivity (PII/PHI/PCI/Confidential/Public)
# 3. Number of affected systems
# 4. Active vs historical threat
# 5. Confirmed vs suspected compromise

# Automated severity calculation
python3 -c "
severity_score = 0
# Asset criticality: Critical=4, High=3, Medium=2, Low=1
severity_score += 4  # Critical server
# Data sensitivity: PII/PHI=4, PCI=3, Confidential=2, Public=1
severity_score += 3  # PCI data
# Scope: Enterprise=4, Department=3, Single system=2, Single user=1
severity_score += 2  # Single system
# Threat status: Active=4, Recent=3, Historical=2, Potential=1
severity_score += 4  # Active threat

if severity_score >= 12: print('CRITICAL - P1')
elif severity_score >= 9: print('HIGH - P2')
elif severity_score >= 6: print('MEDIUM - P3')
else: print('LOW - P4')
print(f'Score: {severity_score}/16')
"
Step 5: Select and Initiate Playbook
bash
# Load appropriate playbook based on incident type
cat /opt/ir/playbooks/ransomware_playbook.yaml
cat /opt/ir/playbooks/phishing_playbook.yaml
cat /opt/ir/playbooks/unauthorized_access_playbook.yaml

# Create incident ticket in TheHive
curl -X POST "https://thehive.local/api/v1/case" \
  -H "Authorization: Bearer $THEHIVE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "title": "IR-2024-XXX: [Incident Type] - [Brief Description]",
    "description": "Triage summary and initial findings",
    "severity": 3,
    "tlp": 2,
    "pap": 2,
    "tags": ["ransomware", "triage-complete"],
    "customFields": {
      "playbook": {"string": "ransomware_v2"},
      "affected_systems": {"integer": 5}
    }
  }'
Step 6: Assign Response Team
bash
# Check on-call schedule
curl -s "https://pagerduty.com/api/v2/oncalls?schedule_ids[]=$SCHEDULE_ID" \
  -H "Authorization: Token token=$PD_TOKEN" | jq '.oncalls[].user.summary'

# Page incident responders based on severity
# P1/Critical: Page IR lead + senior analysts + CISO
# P2/High: Page IR lead + available analysts
# P3/Medium: Assign to next available analyst
# P4/Low: Queue for business hours processing

curl -X POST "https://events.pagerduty.com/v2/enqueue" \
  -H "Content-Type: application/json" \
  -d '{
    "routing_key": "'$PD_ROUTING_KEY'",
    "event_action": "trigger",
    "payload": {
      "summary": "P1 Security Incident: Ransomware detected on PROD-DB-01",
      "severity": "critical",
      "source": "SIEM-Splunk",
      "custom_details": {"incident_id": "IR-2024-042", "playbook": "ransomware_v2"}
    }
  }'
Step 7: Document Triage Decision and Hand Off
bash
# Update incident ticket with triage summary
curl -X PATCH "https://thehive.local/api/v1/case/$CASE_ID" \
  -H "Authorization: Bearer $THEHIVE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "status": "InProgress",
    "customFields": {
      "triage_analyst": {"string": "analyst_name"},
      "triage_time": {"date": '$(date +%s000)'},
      "severity_justification": {"string": "Critical asset + active threat + PCI data"}
    }
  }'

Key Concepts

ConceptDescription
True PositiveAlert correctly identifying a real security incident
False PositiveAlert incorrectly flagging benign activity as malicious
Severity ClassificationRanking incident priority based on impact and urgency
Playbook SelectionChoosing the appropriate response procedure based on incident type
IOC EnrichmentAdding context to indicators from threat intelligence sources
Escalation ThresholdCriteria triggering escalation to higher severity or management
Triage SLATime target for initial assessment (typically 15-30 min for critical)

Tools & Systems

ToolPurpose
Splunk/Elastic/QRadarSIEM alert correlation and querying
TheHive/SIRPIncident case management and playbook tracking
VirusTotal/AbuseIPDBIOC reputation and enrichment
PagerDuty/OpsGenieOn-call management and alerting
MITRE ATT&CKTechnique classification and mapping
Cortex XSOARSOAR platform for automated triage workflows
Show full SKILL.md (143 more words)Show less

Common Scenarios

  1. Brute Force Alert: Multiple failed logins from single IP. Enrich IP reputation, check geo-location, verify if account was compromised, assign P3 if unsuccessful.
  2. Malware Detection on Endpoint: AV/EDR quarantined malware. Verify quarantine success, check for lateral movement, assign P2 if persistence detected.
  3. Suspicious Outbound Traffic: Large data transfer to unknown external IP. Check if known cloud service, verify data classification, assign P1 if exfiltration confirmed.
  4. Phishing Email Reported: User reports suspicious email. Extract IOCs, check if others received it, assign P2 if credentials were entered.
  5. Privilege Escalation: User gained admin rights unexpectedly. Verify if authorized change, check for exploitation, assign P1 if unauthorized.

Output Format

  • Triage decision document with severity justification
  • Incident ticket with assigned playbook and team
  • IOC enrichment summary attached to case
  • Escalation notification to appropriate stakeholders
  • Initial timeline of events from alert data

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/triaging-security-incident-with-ir-playbook of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Triaging Security Incident With Ir Playbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Triaging Security Incident With Ir Playbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Triaging Security Incident With Ir Playbook this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Detection SigmaAgentSecOps/SecOpsAgentKit2201 repos~4kAutomated safety check: PassCustom licence
Siem Detectionbriiirussell/cybersecurity-skills413—~2.6kAutomated safety check: NotesMIT
Doca ArgusNVIDIA/skills3.6k—~4.8kAutomated safety check: PassApache-2.0
Hunting Threatstrilwu/secskills157—~3.5kAutomated safety check: PassMIT
Siem Loggingancoleman/ai-design-components525—~3.4kAutomated safety check: PassMIT

Similar skills

  • Detection Sigma

    AgentSecOps/SecOpsAgentKit

    Generic detection rule creation and management using Sigma, the universal SIEM rule format.

    220 GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Siem Detection

    briiirussell/cybersecurity-skills

    Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows.

    413 GitHub stars~2.6k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Doca Argus

    NVIDIA/skills

    Official

    A skill your agent uses when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for…

    3.6k GitHub stars~4.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Hunting Threats

    trilwu/secskills

    Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…

    157 GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Siem Logging

    ancoleman/ai-design-components

    Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance.

    525 GitHub stars~3.4k tokensUpdated 10 mo ago
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Triaging Security Incident With Ir Playbook

What does Triaging Security Incident With Ir Playbook do?

Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the…. Triaging Security Incident With Ir Playbook is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the appropriate response procedures.

When should I use Triaging Security Incident With Ir Playbook?

Triaging Security Incident With Ir Playbook fits situations like: A new SOC alert needs triage; multiple concurrent incidents require prioritization; automated triage rules need validation.

How do I install Triaging Security Incident With Ir Playbook in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill triaging-security-incident-with-ir-playbook -a claude-code`. Or copy the skill folder (skills/triaging-security-incident-with-ir-playbook in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/triaging-security-incident-with-ir-playbook in your project. Claude Code loads it when a task matches its description.

How do I install Triaging Security Incident With Ir Playbook in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill triaging-security-incident-with-ir-playbook -a codex`. Or copy the skill folder (skills/triaging-security-incident-with-ir-playbook in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/triaging-security-incident-with-ir-playbook in your project. Codex loads it when a task matches its description.

Can I use Triaging Security Incident With Ir Playbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill triaging-security-incident-with-ir-playbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triaging-security-incident-with-ir-playbook, .gemini/skills/triaging-security-incident-with-ir-playbook, .github/skills/triaging-security-incident-with-ir-playbook and .opencode/skills/triaging-security-incident-with-ir-playbook in your project.

What does Triaging Security Incident With Ir Playbook need to run?

Going by SKILL.md and its folder, Triaging Security Incident With Ir Playbook needs Python for the scripts in its folder, the command-line tools its instructions call (curl, jq and python3) and credentials named THEHIVE_API_KEY, VT_API_KEY, SPLUNK_TOKEN and ABUSEIPDB_KEY. Our summary lists: Python 3; A credential in THEHIVE_API_KEY; A credential in SPLUNK_TOKEN.

Does Triaging Security Incident With Ir Playbook access the network?

SKILL.md names 5 domains. In commands or code: virustotal.com, api.abuseipdb.com, attack.mitre.org, pagerduty.com and events.pagerduty.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Triaging Security Incident With Ir Playbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Triaging Security Incident With Ir Playbook use?

Triaging Security Incident With Ir Playbook is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Triaging Security Incident With Ir Playbook use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Triaging Security Incident With Ir Playbook?

Skills that share tags, products or a category with Triaging Security Incident With Ir Playbook: Detection Sigma (AgentSecOps/SecOpsAgentKit, 220 stars), Siem Detection (briiirussell/cybersecurity-skills, 413 stars), Doca Argus (NVIDIA/skills, 3.6k stars) and Hunting Threats (trilwu/secskills, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Triaging Security Incident With Ir Playbook?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.