Security And Hardening
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written.
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-research-system-and-tradecraft --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/hunt-research-system-and-tradecraft .claude/skills/hunt-research-system-and-tradecraft && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hunt-research-system-and-tradecraft" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-research-system-and-tradecraft into .claude/skills/hunt-research-system-and-tradecraft/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-research-system-and-tradecraft", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-research-system-and-tradecraftType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-research-system-and-tradecraft --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/hunt-research-system-and-tradecraft .agents/skills/hunt-research-system-and-tradecraft && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hunt-research-system-and-tradecraft" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-research-system-and-tradecraft into .agents/skills/hunt-research-system-and-tradecraft/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-research-system-and-tradecraft", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-research-system-and-tradecraft --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/hunt-research-system-and-tradecraft .cursor/skills/hunt-research-system-and-tradecraft && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hunt-research-system-and-tradecraft" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-research-system-and-tradecraft into .cursor/skills/hunt-research-system-and-tradecraft/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-research-system-and-tradecraft", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OTRF/ThreatHunter-Playbook.git --path .github/skills/hunt-research-system-and-tradecraft--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-research-system-and-tradecraft --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/hunt-research-system-and-tradecraft .gemini/skills/hunt-research-system-and-tradecraft && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hunt-research-system-and-tradecraft" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-research-system-and-tradecraft into .gemini/skills/hunt-research-system-and-tradecraft/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-research-system-and-tradecraft", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-research-system-and-tradecraftInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/hunt-research-system-and-tradecraft .github/skills/hunt-research-system-and-tradecraft && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hunt-research-system-and-tradecraft" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-research-system-and-tradecraft into .github/skills/hunt-research-system-and-tradecraft/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-research-system-and-tradecraft", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OTRF/ThreatHunter-Playbook hunt-research-system-and-tradecraft --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OTRF/ThreatHunter-Playbook.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/hunt-research-system-and-tradecraft .opencode/skills/hunt-research-system-and-tradecraft && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hunt-research-system-and-tradecraft" agent skill from https://github.com/OTRF/ThreatHunter-Playbook/tree/main/.github/skills/hunt-research-system-and-tradecraft into .opencode/skills/hunt-research-system-and-tradecraft/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-research-system-and-tradecraft", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hunt-research-system-and-tradecraftBuilds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written.
This skill works through a fixed step order and refuses to read reference documents or run web searches outside the step that calls for them. It first normalizes a vague topic like WMI abuse into an explicit scope, naming the concrete platform or feature in scope and stating any assumption needed to remove ambiguity, asking the user only when critical details are genuinely missing.
It then researches system internals with a capped number of web searches per step, stopping once core capabilities and observability are understood, and separately researches adversary tradecraft the same way, producing citable sources, candidate abuse patterns, and key assumptions rather than raw notes or a finished hunt hypothesis. This output is meant to inform the hunt-hypothesis and data-source steps that follow it, not replace them.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d310f38. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Threat Hunt Research Grounding loads about 1.3k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 142 tokens; SKILL.md has 584 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from OTRF/ThreatHunter-Playbook at commit d310f38, republished under its MIT licence (© OTRF). 584 words, ~1,253 tokens.
.claude/skills/hunt-research-system-and-tradecraft/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Provide structured research context at the start of a threat hunt by incrementally applying only the references explicitly called for in each workflow step. This skill establishes a grounded understanding of system capabilities and adversary behaviors so downstream hunt planning reflects how the environment actually works and how it is realistically abused.
Translate the user's high-level topic into a precise research scope before any investigation begins. This step exists to remove ambiguity and establish a shared frame for system and adversary analysis.
This step is complete only when the scope is explicit and unambiguous.
Do NOT perform web searches or read reference documents during this step.
Build a grounded understanding of how the system functions under normal conditions.
Tavily:tavily-search, and do not exceed 5 total web search queries in this step.references/tavily-search-guide.md.During this step only:
references/system-internals-research-guide.md within this step ONLY.Do NOT read adversary tradecraft reference documents in this step. Do not synthesize or summarize findings.
Analyze how adversaries leverage or manipulate the system capabilities identified above.
Tavily:tavily-search, and do not exceed 5 total web search queries in this step.references/tavily-search-guide.md.During this step only:
references/adversary-tradecraft-research-guide.md within this step ONLY.Do Not read system internals reference documents in this step. Do Not synthesize or summarize findings.
Using the completed adversary tradecraft research, extract concrete abuse patterns that will guide hypothesis-driven hunting.
Porivide the list of patterns if they exist. They must be tool-agnostic and suitable for use in the next hunt-planning step.
Produce the final structured research artifact using the following documents within this step ONLY.
references/research-summary-template.md.references/research-citations-guide.md.This step is synthesis only. Do not introduce new research, assumptions, or evidence at this stage.
© OTRF, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (references) in .github/skills/hunt-research-system-and-tradecraft of OTRF/ThreatHunter-Playbook.
Open the folder on GitHubat commit d310f38
Threat Hunt Research Grounding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Threat Hunt Research Grounding this skillOTRF/ThreatHunter-Playbook | 4.7k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Security And Hardeningpenpot/penpot | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | |
| X Raypashov/skills | 1.2k | 1 repos | ~10k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 190 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Security Audit Scannerruvnet/ruflo | 74k | 1 repos | ~823 | Automated safety check: Pass | MIT | |
| Osintsmixs/osint-skill | 141 | — | ~5.5k | Automated safety check: Pass | MIT |
penpot/penpot
Hardens code against vulnerabilities. An agent skill from penpot/penpot.
pashov/skills
Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
smixs/osint-skill
Conduct deep OSINT research on individuals. An agent skill from smixs/osint-skill.
responsibleai/ASSERT
Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.
OTRF/ThreatHunter-Playbook
Assembles a single execution-ready hunt blueprint from the outputs of earlier hunt planning steps, without adding new research, evidence or analytics.
OTRF/ThreatHunter-Playbook
Maps a structured threat hunt hypothesis to candidate telemetry sources by semantic search over a Sentinel table catalog, before any queries are written.
OTRF/ThreatHunter-Playbook
Turns completed system-internals and adversary-tradecraft research into one focused, testable threat hunt hypothesis about a single attack pattern.
OTRF/ThreatHunter-Playbook
Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.
Works with
Categories
Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written. This skill works through a fixed step order and refuses to read reference documents or run web searches outside the step that calls for them. It first normalizes a vague topic like WMI abuse into an explicit scope, naming the concrete platform or feature in scope and stating any assumption needed to remove ambiguity, asking the user only when critical details are genuinely missing.
Threat Hunt Research Grounding fits situations like: starting a threat hunt on a topic you don't yet understand deeply; grounding a hunt hypothesis in real system behavior before writing it; researching how a specific Windows feature is realistically abused.
Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a claude-code`. Or copy the skill folder (.github/skills/hunt-research-system-and-tradecraft in OTRF/ThreatHunter-Playbook) into .claude/skills/hunt-research-system-and-tradecraft in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a codex`. Or copy the skill folder (.github/skills/hunt-research-system-and-tradecraft in OTRF/ThreatHunter-Playbook) into .agents/skills/hunt-research-system-and-tradecraft in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OTRF/ThreatHunter-Playbook --skill hunt-research-system-and-tradecraft -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-research-system-and-tradecraft, .gemini/skills/hunt-research-system-and-tradecraft, .github/skills/hunt-research-system-and-tradecraft and .opencode/skills/hunt-research-system-and-tradecraft in your project.
SKILL.md names no scripts, command-line tools or credentials: Threat Hunt Research Grounding is instructions for the agent only. Our summary lists: Tavily search access.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Threat Hunt Research Grounding is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Threat Hunt Research Grounding: Security And Hardening (penpot/penpot, 61k stars), X Ray (pashov/skills, 1.2k stars), Forensify (alexgreensh/repo-forensics, 190 stars) and Security Audit Scanner (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OTRF (a GitHub organization) maintains it in OTRF/ThreatHunter-Playbook, which has 4,683 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on January 12, 2026.
Source: OTRF/ThreatHunter-Playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.