Implementing Ransomware Kill Switch Detection
mukul975/Anthropic-Cybersecurity-Skills
Analyzes ransomware kill switch mechanisms, including mutex-based execution guards, domain-based kill switches (e.g.
Switch to Knowledge Work mode for research and writing — use when task is non-code focused
$ npx skills add nyldn/claude-octopus --skill skill-knowledge-work -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nyldn/claude-octopus skill-knowledge-work --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nyldn/claude-octopus.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skill-knowledge-work .claude/skills/skill-knowledge-work && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "skill-knowledge-work" agent skill from https://github.com/nyldn/claude-octopus/tree/main/skills/skill-knowledge-work into .claude/skills/skill-knowledge-work/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-knowledge-work", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nyldn/claude-octopus/tree/main/skills/skill-knowledge-workType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nyldn/claude-octopus --skill skill-knowledge-work -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nyldn/claude-octopus skill-knowledge-work --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nyldn/claude-octopus.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/skill-knowledge-work .agents/skills/skill-knowledge-work && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "skill-knowledge-work" agent skill from https://github.com/nyldn/claude-octopus/tree/main/skills/skill-knowledge-work into .agents/skills/skill-knowledge-work/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-knowledge-work", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nyldn/claude-octopus --skill skill-knowledge-work -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nyldn/claude-octopus skill-knowledge-work --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nyldn/claude-octopus.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/skill-knowledge-work .cursor/skills/skill-knowledge-work && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "skill-knowledge-work" agent skill from https://github.com/nyldn/claude-octopus/tree/main/skills/skill-knowledge-work into .cursor/skills/skill-knowledge-work/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-knowledge-work", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nyldn/claude-octopus.git --path skills/skill-knowledge-work--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nyldn/claude-octopus --skill skill-knowledge-work -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nyldn/claude-octopus skill-knowledge-work --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nyldn/claude-octopus.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/skill-knowledge-work .gemini/skills/skill-knowledge-work && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "skill-knowledge-work" agent skill from https://github.com/nyldn/claude-octopus/tree/main/skills/skill-knowledge-work into .gemini/skills/skill-knowledge-work/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-knowledge-work", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nyldn/claude-octopus skill-knowledge-workInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nyldn/claude-octopus --skill skill-knowledge-work -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nyldn/claude-octopus.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/skill-knowledge-work .github/skills/skill-knowledge-work && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "skill-knowledge-work" agent skill from https://github.com/nyldn/claude-octopus/tree/main/skills/skill-knowledge-work into .github/skills/skill-knowledge-work/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-knowledge-work", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nyldn/claude-octopus --skill skill-knowledge-work -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nyldn/claude-octopus skill-knowledge-work --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nyldn/claude-octopus.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/skill-knowledge-work .opencode/skills/skill-knowledge-work && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "skill-knowledge-work" agent skill from https://github.com/nyldn/claude-octopus/tree/main/skills/skill-knowledge-work into .opencode/skills/skill-knowledge-work/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "skill-knowledge-work", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skill-knowledge-workSwitch to Knowledge Work mode for research and writing — use when task is non-code focused
Skill Knowledge Work is an agent skill from nyldn/claude-octopus. Switch to Knowledge Work mode for research and writing — use when task is non-code focused
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
The repository describes itself as: Run multiple AI models against the same research, design, or coding task. Surface disagreements before you ship. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 18b66ca. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Skill Knowledge Work loads about 1.9k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 775 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nyldn/claude-octopus at commit 18b66ca, republished under its MIT licence (© nyldn). 775 words, ~1,940 tokens.
.claude/skills/skill-knowledge-work/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Host: Codex CLI — This skill was designed for Claude Code and adapted for Codex. Cross-reference commands use installed skill names in Codex rather than
/octo:*slash commands. Use the active Codex shell and subagent tools. Do not claim a provider, model, or host subagent is available until the current session exposes it. For host tool equivalents, seeskills/blocks/codex-host-adapter.md.
Claude Octopus now auto-detects work context! The system analyzes your prompt and project to determine whether you're in a Dev Context (code-focused) or Knowledge Context (research/strategy-focused).
You typically don't need this skill - context is detected automatically when you use:
octo research X - Auto-detects dev vs knowledge researchocto build X - Auto-detects code vs document buildingocto review X - Auto-detects code vs document reviewUse ONLY when auto-detection is wrong:
/octo:km onAll subsequent workflows will use Knowledge Context until reset.
/octo:km offAll subsequent workflows will use Dev Context until reset.
/octo:km autoContext detection returns to automatic mode.
/octo:kmShows current mode (auto, knowledge, or dev).
When you use any octo workflow, context is detected by analyzing:
Prompt Content (strongest signal):
Project Type (secondary signal):
package.json, Cargo.toml, go.mod → Dev Context.md, .docx, .pdf files → Knowledge ContextExplicit Override (if set via /octo:km):
When workflows run, you'll see the detected context in the banner:
Dev Context:
🐙 **CLAUDE OCTOPUS ACTIVATED** - Multi-provider research mode
🔍 [Dev] Discover Phase: Technical research on caching patternsKnowledge Context:
🐙 **CLAUDE OCTOPUS ACTIVATED** - Multi-provider research mode
🔍 [Knowledge] Discover Phase: Market analysis for APAC expansionUser: "octo research caching strategies for our Node.js API"
Claude: (auto-detects Dev Context from "Node.js API")
🐙 **CLAUDE OCTOPUS ACTIVATED** - Multi-provider research mode
🔍 [Dev] Discover Phase: Technical research on caching strategies
[Researches with technical/implementation focus]User: "octo research market opportunities in healthcare AI"
Claude: (auto-detects Knowledge Context from "market opportunities")
🐙 **CLAUDE OCTOPUS ACTIVATED** - Multi-provider research mode
🔍 [Knowledge] Discover Phase: Strategic research on healthcare AI market
[Researches with business/strategic focus]User: "octo research React patterns"
Claude: (auto-detects Dev) 🔍 [Dev] Discover Phase...
User: "Actually, this is for a presentation. Force knowledge mode."
Claude: "Setting context override to Knowledge Mode."
/octo:km onUser: "octo research React patterns"
Claude: (uses override) 🔍 [Knowledge] Discover Phase... (focuses on trends, adoption, strategic implications)
User: "What context mode am I in?"
Claude:
Current mode: Auto-detection (no override set)
Last detected context: Dev (based on project having package.json)
To override: /octo:km on (force Knowledge) or /octo:km off (force Dev)
To return to auto: /octo:km auto| Workflow | Focus |
|---|---|
octo research X | Technical implementation, libraries, code patterns |
octo build X | Code generation, architecture, tests |
octo review X | Code quality, security, performance |
| Agents | codex, backend-architect, code-reviewer, security-auditor |
| Workflow | Focus |
|---|---|
octo research X | Market analysis, competitive research, literature synthesis |
octo build X | PRDs, strategy docs, presentations, reports |
octo review X | Document quality, argument strength, completeness |
| Agents | strategy-analyst, ux-researcher, exec-communicator, product-writer |
After running knowledge workflows, export to professional formats:
Just say: "Export this to Word" or "Create a PowerPoint presentation"
| Command | Description |
|---|---|
/octo:km | Show current status (auto, on, or off) |
/octo:km on | Force Knowledge Context for all workflows |
/octo:km off | Force Dev Context for all workflows |
/octo:km auto | Return to auto-detection (default) |
Don't override if:
Override is for:
At the end of significant work sessions, extract learnings:
Store learnings in .claude-octopus/learnings/<date>-<summary>.json:
{
"date": "2026-03-21",
"task_type": "debugging",
"approach": "Traced the error from the test failure back to the API handler",
"outcome": "success",
"lesson": "Always check middleware ordering before investigating handler logic"
}Each learning file captures: task_type, approach, outcome, and lesson.
At session start, check for relevant learnings:
.claude-octopus/learnings/ directory/octo:discover - Research workflow (auto-detects context)/octo:develop - Build workflow (auto-detects context)/octo:deliver - Review workflow (auto-detects context)/octo:docs - Document export (works in both contexts)© nyldn, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/skill-knowledge-work of nyldn/claude-octopus.
Open the folder on GitHubat commit 18b66ca
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in nyldn/claude-octopus, which our catalogue first saw on October 7, 2026.
Skill Knowledge Work next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Skill Knowledge Work this skillnyldn/claude-octopus | 4.2k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Implementing Ransomware Kill Switch Detectionmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Wiki SwitchAr9av/obsidian-wiki | 3.5k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Switch Personaopenakita/openakita | 2k | — | ~286 | Automated safety check: Pass | AGPL-3.0 | |
| Bio Isoform SwitchingFreedomIntelligence/OpenClaw-Medical-Skills | 3.1k | — | ~1.5k | Automated safety check: Pass | None | |
| Switch Brandindranilbanerjee/digital-marketing-pro | 854 | 1 repos | ~473 | Automated safety check: Pass | MIT |
mukul975/Anthropic-Cybersecurity-Skills
Analyzes ransomware kill switch mechanisms, including mutex-based execution guards, domain-based kill switches (e.g.
Ar9av/obsidian-wiki
List, create, or switch named Obsidian wiki vault profiles under the global config directory.
openakita/openakita
Switch Agent persona preset. An agent skill from openakita/openakita.
FreedomIntelligence/OpenClaw-Medical-Skills
Analyzes isoform switching events and functional consequences using IsoformSwitchAnalyzeR.
indranilbanerjee/digital-marketing-pro
Switch the active brand profile for multi-client and agency work by running setup.py --switch-brand, after listing configured brands with the active one starred; confirms the new brand's industry…
aws/agent-toolkit-for-aws
Answers questions about Amazon Application Recovery Controller (ARC) Region switch including architecture, plans, execution blocks, workflows, triggers, active/active vs active/passive…
nyldn/claude-octopus
Quick execution for ad-hoc tasks without full workflow overhead — use for small, self-contained requests
nyldn/claude-octopus
Thorough research across multiple sources — use for complex topics needing broad synthesis
nyldn/claude-octopus
OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews
nyldn/claude-octopus
Audit codebases for quality, consistency, and broken patterns — use for pre-release or tech debt review
nyldn/claude-octopus
Extract patterns and anatomy from URLs — use to reverse-engineer content strategies from live pages
nyldn/claude-octopus
Auto-detect work context (Dev vs Knowledge) — use to tailor workflows based on current task type
Switch to Knowledge Work mode for research and writing — use when task is non-code focused. Skill Knowledge Work is an agent skill from nyldn/claude-octopus.
Skill Knowledge Work fits situations like: task is non-code focused.
Run `npx skills add nyldn/claude-octopus --skill skill-knowledge-work -a claude-code`. Or copy the skill folder (skills/skill-knowledge-work in nyldn/claude-octopus) into .claude/skills/skill-knowledge-work in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nyldn/claude-octopus --skill skill-knowledge-work -a codex`. Or copy the skill folder (skills/skill-knowledge-work in nyldn/claude-octopus) into .agents/skills/skill-knowledge-work in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nyldn/claude-octopus --skill skill-knowledge-work -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-knowledge-work, .gemini/skills/skill-knowledge-work, .github/skills/skill-knowledge-work and .opencode/skills/skill-knowledge-work in your project.
SKILL.md names no scripts, command-line tools or credentials: Skill Knowledge Work is instructions for the agent only. Our summary lists: Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Skill Knowledge Work is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Skill Knowledge Work: Implementing Ransomware Kill Switch Detection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Wiki Switch (Ar9av/obsidian-wiki, 3.5k stars), Switch Persona (openakita/openakita, 2k stars) and Bio Isoform Switching (FreedomIntelligence/OpenClaw-Medical-Skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nyldn (a GitHub user) maintains it in nyldn/claude-octopus, which has 4,173 GitHub stars. The repository holds 62 skills in this directory. The repository was last updated on October 7, 2026.
Source: nyldn/claude-octopus on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.