Anthropic Cybersecurity Skills
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Analyzing Indicators Of Compromise
Analyzes indicators of compromise (IOCs) including IP addresses, domains,
Ai Vendor Privacy Due
>-
Abusing Dpapi For Credential Access
Extract DPAPI-protected secrets such as credentials and browser data offline and online.
Age Gating Services
>-
Postgres Mcp Server
🔄 PostgreSQL MCP Server – AI-Powered PostgreSQL Management & Monitoring. A powerful, AI-integrated PostgreSQL Model Context Protocol (MCP) server for automated database operations, monitoring, security, diagnostics, and optimization. Seamlessly manage PostgreSQL with 237+ tools designed for AI assistants like Claude and ChatGPT.
Cnil Cookie Banner
>-
Children Deletion Requests
>-
Ai Privacy Inference
>-
Ai Act High Risk Docs
>-
Ai Training Lawfulness
>-
Managing Mobile App Consent
>-
Coppa Compliance
>-
Consent For Transfers
>-
Llm Output Privacy Risk
>-
Cookie Lifetime Audit
>-
Eprivacy Essential Cookies
>-
Analyzing Kubernetes Audit Logs
Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod,
Analyzing Android Malware With Apktool
Perform static analysis of Android APK malware samples using apktool
Analyzing Network Flow Data With Netflow
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port
Analyzing Command And Control Communication
Analyzes malware command-and-control (C2) communication protocols to
Analyzing Cobalt Strike Beacon Configuration
Extract and analyze Cobalt Strike beacon configuration from PE files
Analyzing Browser Forensics With Hindsight
Analyze Chromium-based browser artifacts using Hindsight to extract browsing
Analyzing Docker Container Forensics
Investigate compromised Docker containers by analyzing images, layers,
Analyzing Office365 Audit Logs For Compromise
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect
Edtech Privacy Assessment
>-
Analyzing Linux Kernel Rootkits
Detect kernel-level rootkits in Linux memory dumps using Volatility3
Analytics Cookie Consent
>-
Report Templates
CVSS 3.1 vector examples, executive summary template, full technical finding template, and remediation language bank for pentest reports
Analyzing Network Traffic For Incidents
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
Cve Mcp Server
Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
Gdpr Parental Consent
>-
Analyzing Malware Family Relationships With Malpedia
Use the Malpedia platform and API to research malware family relationships,
Exploit Db
Exploit-DB and searchsploit reference — EDB→Metasploit module mappings, PoC reliability rubric, CVSS tier quick reference, and searchsploit usage patterns
Claude Team Dashboard
📊 Real-time monitoring dashboard for Claude Code agent teams
Ad Attacks
Active Directory attack reference — BloodHound Cypher queries, Kerberos attack decision tree, ACE/ACL abuse, ADCS ESC1-8, and AD misconfig checklist
Analyzing Malware Behavior With Cuckoo Sandbox
Executes malware samples in Cuckoo Sandbox to observe runtime behavior
Analyzing Network Packets With Scapy
Craft, send, sniff, and dissect network packets using Scapy for protocol
Mysql Mcp Server
A comprehensive Model Context Protocol (MCP) server for MySQL databases with 200+ tools for advanced database management, diagnostics, performance analysis, security auditing, and AI-powered database interactions.
Analyzing Malware Persistence With Autoruns
Use Sysinternals Autoruns to systematically identify and analyze malware
Children Privacy Notice
>-
Server Side Tracking
>-
Global Privacy Control
>-
Age Verification Methods
>-
Analyzing Heap Spray Exploitation
Detect and analyze heap spray attacks in memory dumps using Volatility3
Analyzing Bootkit And Rootkit Samples
Analyzes bootkit and advanced rootkit malware that infects the Master
Analyzing Mft For Deleted File Recovery
Analyze the NTFS Master File Table ($MFT) to recover metadata and content
Analyzing Disk Image With Autopsy
Perform comprehensive forensic analysis of disk images using Autopsy
Managing Consent For Children
>-
Ai Data Retention
>-
Analyzing Memory Dumps With Volatility
Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,
Cnil Compliant Cookies
>-
Analyzing Linux Audit Logs For Intrusion
Uses the Linux Audit framework (auditd) with ausearch and aureport utilities
Achieving Cmmc Level 2 Compliance
>-
Cookieless Alternatives
>-
Managing Consent For Research
>-
Gpc Cookie Integration
>-
Analyzing Campaign Attribution Evidence
Campaign attribution analysis involves systematically evaluating evidence
Children Data Minimization
>-
Cookie Consent Testing
>-
Analyzing Network Traffic Of Malware
Analyzes network traffic generated by malware during sandbox execution
Legit Interest Vs Consent
>-
Ai Deployment Checklist
>-
Google Consent Mode V2
>-
Consent Record Keeping
>-
Analyzing Ethereum Smart Contract Vulnerabilities
Perform static and symbolic analysis of Solidity smart contracts using
Mitre Attack
MITRE ATT&CK framework reference — tactics, techniques, and tool-to-TTP mappings for pentest documentation and detection rule writing
Double Opt In Email
>-
Ai Bias Special Category
>-
Ai Model Privacy Audit
>-
Ai Automated Decisions
>-
Ai Data Subject Rights
>-
Analyzing Network Covert Channels In Malware
Detect and analyze covert communication channels used by malware including
Analyzing Apt Group With Mitre Navigator
Analyze advanced persistent threat (APT) group techniques using MITRE
Analyzing Malware Sandbox Evasion Techniques
Detect sandbox evasion techniques in malware samples by analyzing timing
Abusing Shadow Credentials For Privesc
Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
Consent Withdrawal
>-
Consent Platform Eval
>-
Analyzing Active Directory Acl Abuse
Detect dangerous ACL misconfigurations in Active Directory using ldap3
Analyzing Email Headers For Phishing Investigation
Parse and analyze email headers to trace the origin of phishing emails,
Ai Dpia
>-
Cookie Consent Ab Audit
>-
Children Profiling Limits
>-
Analyzing Malicious Pdf With Peepdf
Perform static analysis of malicious PDF documents using peepdf, pdfid,
Ai Privacy Impact Template
>-
Consent Pref Center
>-
Analyzing Dns Logs For Exfiltration
Analyzes DNS query logs to detect data exfiltration via DNS tunneling,
Analyzing Golang Malware With Ghidra
Reverse engineer Go-compiled malware using Ghidra with specialized scripts
Analyzing Azure Activity Logs For Threats
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
Analyzing Macro Malware In Office Documents
Analyzes malicious VBA macros embedded in Microsoft Office documents
Analyzing Linux Elf Malware
Analyzes malicious Linux ELF (Executable and Linkable Format) binaries
Ai Transparency Reqs
>-
Mcp Web Scrape
🚀 mcp-web-scrape — Clean, cache-aware web content fetcher for AI agents. Fetch any URL → extract readable content → return Markdown/JSON with citations. ⚡ Fast caching, 🤝 robots.txt compliant, 📝 Markdown-ready output, �� works with ChatGPT/Claude Desktop.
Analyzing Lnk File And Jump List Artifacts
Analyze Windows LNK shortcut files and Jump List artifacts to establish
Analyzing Cyber Kill Chain
Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain
Analyzing Ios App Security With Objection
>-
Analyzing Linux System Artifacts
Examine Linux system artifacts including auth logs, cron jobs, shell
Mcp Windows Automation
🚀 AI-Powered Windows Automation Server using Model Context Protocol (MCP) | Control Windows apps, automate tasks, and manage systems through natural language commands with Claude, ChatGPT & other AI assistants | 80+ automation tools
Analyzing Api Gateway Access Logs
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
Analyzing Malicious Url With Urlscan
URLScan.io is a free service for scanning and analyzing suspicious URLs.
Gdpr Valid Consent
>-
Ai Federated Learning
>-
Cookie Audit
>-
Acquiring Disk Image With Dd And Dcfldd
Create forensically sound bit-for-bit disk images using dd and dcfldd
Analyzing Certificate Transparency For Phishing
Monitor Certificate Transparency logs using crt.sh and Certstream to
Analyzing Network Traffic With Wireshark
Captures and analyzes network packet data using Wireshark and tshark
Analyzing Memory Forensics With Lime And Volatility
Performs Linux memory acquisition using LiME (Linux Memory Extractor)
Malware Sandbox Mcp
Detonate files & URLs in cloud malware sandboxes (Hybrid Analysis, tria.ge, ANY.RUN) and enrich IOCs across MalwareBazaar, ThreatFox, URLhaus, Feodo, URLScan & VirusTotal — straight from Claude. BYOK, async, MITRE ATT&CK.
Analyzing Cobaltstrike Malleable C2 Profiles
Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike
Analyzing Cloud Storage Access Patterns
Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage
Wordlists
SecLists path map, hashcat rules, CeWL usage, and custom wordlist generation for all attack categories
Uk Aadc Implementation
>-
Cross Jurisdiction Cookies
>-