Cybersecurity skills for AI agents
11 practitioner-grade cybersecurity skills, each a focused Markdown document your agent loads into context on demand. Search them from Claude Desktop, Cursor or any MCP client, or pull one with the CLI.
All 11 skills
- Appsec
Use this skill when building or improving application security programs. Activate when users mention AppSec, SAST, DAST, IAST, secure SDLC, security champions, dependency scanning, secrets management, security testing in CI/CD, or when they need to integrate security into the software development lifecycle.
388 lines - Cloud Security
Use this skill when securing cloud infrastructure across AWS, Azure, or GCP. Activate when users mention cloud security, IAM policies, security groups, encryption at rest or in transit, cloud misconfigurations, CIS benchmarks, shared responsibility model, or hardening cloud environments.
296 lines - Compliance Security
Use this skill when navigating security compliance frameworks, preparing for audits, or building compliance programs. Activate when users mention SOC 2, ISO 27001, HIPAA, PCI DSS, compliance automation, audit preparation, evidence collection, continuous compliance, or when they need to map security controls to regulatory requirements.
349 lines - Identity Access
Use this skill when designing or evaluating identity and access management strategies. Activate when users mention IAM, SSO, MFA, RBAC, ABAC, privileged access management, identity governance, OAuth, SAML, OIDC, authentication protocols, or when they need to control who can access what across their organization.
338 lines - Incident Response
Use this skill when preparing for, detecting, responding to, or recovering from security incidents. Activate when users mention incident response, IR playbooks, breach handling, containment, eradication, NIST IR framework, severity classification, post-incident reviews, or communication during security events.
331 lines - Privacy Engineering
Design and implement privacy-preserving systems and practices that protect user data while enabling legitimate business functions. Use this skill when the user asks about data privacy, implementing privacy by design, data minimization, consent management, anonymization techniques, or wants guidance on building systems that respect user privacy.
135 lines - Security Awareness
Use this skill when building, improving, or evaluating security awareness programs. Activate when users mention security training, phishing simulations, security culture, social engineering awareness, security policies, measuring security awareness, or building a human-centric security program.
354 lines - Security Operations
Use this skill when building, managing, or improving security operations capabilities. Activate when users mention SOC operations, SIEM configuration, log management, alert triage, detection engineering, security monitoring, threat hunting, or building a security operations center from scratch.
261 lines - Threat Modeling
Use this skill when identifying, analyzing, and prioritizing threats to systems, applications, or infrastructure. Activate when users mention threat modeling, STRIDE, DREAD, attack trees, trust boundaries, asset classification, or when they need to systematically evaluate what can go wrong with their architecture.
236 lines - Vulnerability Management
Use this skill when establishing or improving vulnerability management programs. Activate when users mention vulnerability scanning, CVE tracking, patch management, risk-based prioritization, CVSS scoring, vulnerability disclosure, remediation SLAs, or when they need to systematically reduce their attack surface.
313 lines - Zero Trust
Use this skill when designing or evaluating zero trust architectures, implementing identity-centric security, or moving away from perimeter-based models. Activate when users mention zero trust, never trust always verify, micro-segmentation, BeyondCorp, least privilege access, identity-aware proxies, or implementation roadmaps for zero trust.
273 lines