Skill Catalog
Browse 5,478 curated AI agent skills. No account needed.
Agents Winui3 Expert
Agents Winui3 Expert linked from github/awesome-copilot, with the upstream skill instructions available on GitHub.
by github/awesome-copilot / agents/winui3-expert.agent.md
Agent Teams
Claude Code Agent Teams - default team-based development with strict TDD pipeline enforcement
by alinaqi/maggy / skills/agent-teams
Agile Product Owner
Agile product ownership for backlog management and sprint execution. Covers user story writing, acceptance criteria, sprint planning, and velocity tracking. Use when writing user stories, creating acceptance criteria, planning sprints, estimating story points, breaking down epics, or prioritizing the backlog.
by alirezarezvani/claude-skills / product-team/agile-product-owner/skills/agile-product-owner
Agp 9 Upgrade
Upgrades, or migrates, an Android project to use Android Gradle Plugin (AGP) version 9. Do not use this skill for migrating Kotlin Multiplatform (KMP) projects.
by android/skills / build/agp/agp-9-upgrade
AI Agent Builder
Build AI agents with tools, memory, and multi-step reasoning - ChatGPT, Claude, Gemini integration patterns
by claude-office-skills/skills / ai-agent-builder
AI Analyzer
AI驱动的综合健康分析系统,整合多维度健康数据、识别异常模式、预测健康风险、提供个性化建议。支持智能问答和AI健康报告生成。
by huifer/WellAlly-health / .claude/skills/ai-analyzer
🎬 AI Cinema Director Skill
Direct high-fidelity cinematic video with AI — translates creative intent into technical cinematographic directives for Veo3, Kling, and Luma video models via muapi.ai
by SamurAIGPT/Generative-Media-Skills / library/motion/cinema-director
AI Clipping
Turn a long video into N viral-ready short clips with a single managed API call. Wraps muapi.ai's `/ai-clipping` endpoint, which handles transcription, highlight ranking through a virality framework (hook / emotional peak / opinion bomb / revelation / conflict / quotable / story peak / practical value), overlap dedupe, and vertical face-tracking auto-crop server-side. No local Whisper, no local LLM, no GPU.
by SamurAIGPT/Generative-Media-Skills / library/edit/ai-clipping
AI Debate Hub Skill v4.8
Structured four-way AI debates between Claude, Sonnet, Gemini, and Codex — use for critical decisions
by nyldn/claude-octopus / skills/skill-debate
AI Model Recommendation for Copilot Chat Modes and Prompts
Analyze chatmode or prompt files and recommend optimal AI models based on task complexity, required capabilities, and cost-efficiency
by github/awesome-copilot / skills/model-recommendation
AI Models Reference Skill
Latest AI models reference - Claude, OpenAI, Gemini, Eleven Labs, Replicate
by alinaqi/maggy / skills/ai-models
AI Prompt Engineering & Safety Best Practices
Comprehensive best practices for AI prompt engineering, safety frameworks, bias mitigation, and responsible AI usage for Copilot and LLMs.
by github/awesome-copilot / instructions/ai-prompt-engineering-safety-best-practices.instructions.md
AI Prompt Engineering Safety Review
Comprehensive AI prompt engineering safety review and improvement prompt. Analyzes prompts for safety, bias, security vulnerabilities, and effectiveness while providing detailed improvement recommendations with extensive frameworks, testing methodologies, and educational content.
by github/awesome-copilot / skills/ai-prompt-engineering-safety-review
AI Readiness Reporter
Runs the AgentRC readiness assessment on the current repository and produces a self-contained, static HTML dashboard at reports/index.html. Explains every readiness pillar, the maturity level, and an actionable remediation plan, framed by AgentRC measure → generate → maintain loop. Use when asked to assess, audit, score, report on, or visualise the AI readiness of a repo.
by github/awesome-copilot / agents/ai-readiness-reporter.agent.md
AI Ready
Make any repo AI-ready — analyzes your codebase and generates AGENTS.md, copilot-instructions.md, CI workflows, issue templates, and more. Mines your PR review patterns and creates files customized to your stack. USE THIS SKILL when the user asks to "make this repo ai-ready", "set up AI config", or "prepare this repo for AI contributions".
by github/awesome-copilot / skills/ai-ready
Airflow Dag Patterns
Build production Apache Airflow DAGs with best practices for operators, sensors, testing, and deployment. Use when creating data pipelines, orchestrating workflows, or scheduling batch jobs.
by wshobson/agents / plugins/data-engineering/skills/airflow-dag-patterns
Airtable
Airtable REST API via curl. Records CRUD, filters, upserts.
by NousResearch/hermes-agent / skills/productivity/airtable
Airtable Automation
Airtable database automation - views, automations, integrations, and workflow triggers
by claude-office-skills/skills / airtable-automation
Airunway Aks Setup
Set up AI Runway on AKS — from bare cluster to running model. Covers cluster verification, controller install, GPU assessment, provider setup, and first deployment. WHEN: "setup AI Runway", "onboard AKS cluster", "install AI Runway", "airunway setup", "deploy model to AKS", "GPU inference on AKS", "KAITO setup on AKS", "run LLM on AKS", "vLLM on AKS", "set up model serving on AKS", "AI Runway controller".
by microsoft/skills / .github/plugins/azure-skills/skills/airunway-aks-setup
AI SDK 5
Vercel AI SDK 5 patterns. Trigger: When building AI chat features - breaking changes from v4.
by Gentleman-Programming/Gentleman-Skills / curated/ai-sdk-5
AI SEO
Optimize content to get cited by AI search engines — ChatGPT, Perplexity, Google AI Overviews, Claude, Gemini, Copilot. Use when you want your content to appear in AI-generated answers, not just ranked in blue links. Triggers: 'optimize for AI search', 'get cited by ChatGPT', 'AI Overviews', 'Perplexity citations', 'AI SEO', 'generative search', 'LLM visibility', 'GEO' (generative engine optimization). NOT for traditional SEO ranking (use seo-audit). NOT for content creation (use content-production).
by alirezarezvani/claude-skills / marketing-skill/skills/ai-seo
AI SEO
When the user wants to optimize content for AI search engines, get cited by LLMs, or appear in AI-generated answers. Also use when the user mentions 'AI SEO,' 'AEO,' 'GEO,' 'LLMO,' 'answer engine optimization,' 'generative engine optimization,' 'LLM optimization,' 'AI Overviews,' 'optimize for ChatGPT,' 'optimize for Perplexity,' 'AI citations,' 'AI visibility,' 'zero-click search,' 'how do I show up in AI answers,' 'LLM mentions,' 'optimize for Claude/Gemini,' 'llms.txt,' 'OKF,' 'Open Knowledge Format,' 'knowledge bundle,' or 'agent-readable site.' Use this whenever someone wants their content to be cited or surfaced by AI assistants and AI search engines. For traditional technical and on-page SEO audits, see seo-audit. For structured data implementation, see schema.
by coreyhaines31/marketingskills / skills/ai-seo
AI Slides
Generate complete presentations with AI - from outline to polished slides
by claude-office-skills/skills / ai-slides
AI Team Dev
AI development team agent (Nova, Sage, Milo). Use when: building features, writing application code, fixing bugs, implementing UI components, creating APIs, styling with CSS, writing database queries, or executing sprint plans. The team switches between frontend, backend, and design roles as needed.
by github/awesome-copilot / agents/ai-team-dev.agent.md
AI Team Orchestration
Bootstrap and run a multi-agent AI development team. Use when: starting a new software project with AI agents, setting up parallel dev/QA teams, creating sprint plans, writing brainstorm prompts with distinct agent voices, recovering a project workflow, or planning sprints.
by github/awesome-copilot / skills/ai-team-orchestration
AI Team Producer
AI team producer agent (Remy). Use when: planning sprints, creating PROJECT_BRIEF.md, triaging bugs, merging PRs, coordinating between dev and QA teams, filing GitHub Issues, writing sprint plans, running brainstorms, or recovering project context. NEVER writes application code.
by github/awesome-copilot / agents/ai-team-producer.agent.md
AI Team QA
AI QA engineer agent (Ivy). Use when: testing features, running E2E tests, playtesting, filing bug reports, writing test automation, creating QA sign-off documents, or verifying bug fixes. Reports bugs as GitHub Issues.
by github/awesome-copilot / agents/ai-team-qa.agent.md
AI Workflow Builder
Build, run, and visualize multi-step AI generation workflows. The AI architect translates natural language descriptions into connected node graphs — chain image generation, video creation, enhancement, and editing into automated pipelines.
by SamurAIGPT/Generative-Media-Skills / library/workflow
Album Art Director
Creates visual concepts for album artwork and generates AI art prompts. Use during planning for concept discussion, or after all tracks are Final for actual artwork generation.
by bitwize-music-studio/claude-ai-music-skills / skills/album-art-director
Album Conceptualizer
Designs album concepts, tracklist architecture, and thematic planning through 7 structured phases. Use when planning a new album or reworking an existing album concept.
by bitwize-music-studio/claude-ai-music-skills / skills/album-conceptualizer
Album Dashboard
Shows a structured progress dashboard for an album with percentage complete per phase, blocking items, and status breakdown. Use for a quick visual overview of album progress.
by bitwize-music-studio/claude-ai-music-skills / skills/album-dashboard
Album Ideas Management Agent
Tracks and manages album ideas including brainstorming, planning, and status updates. Use when the user wants to add, review, or organize their album idea backlog.
by bitwize-music-studio/claude-ai-music-skills / skills/album-ideas
Algodocs Automation via Rube MCP
Automate Algodocs tasks via Rube MCP (Composio). Always search tools first for current schemas.
by ComposioHQ/awesome-claude-skills / composio-skills/algodocs-automation
Algorithmic Art
Creating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems. Create original algorithmic art rather than copying existing artists' work to avoid copyright violations.
by foryourhealth111-pixel/Vibe-Skills / bundled/skills/algorithmic-art
Algorithmic Art
Creating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems. Create original algorithmic art rather than copying existing artists' work to avoid copyright violations.
by guanyang/antigravity-skills / skills/algorithmic-art
Algorithmic Art
Creating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems. Create original algorithmic art rather than copying existing artists' work to avoid copyright violations.
by snyk/agent-scan / tests/skills/algorithmic-art
Alliances
Airline alliance membership (Star Alliance, oneworld, SkyTeam) and cross-alliance booking relationships. Maps which loyalty programs book which airlines, including bilateral partnerships outside alliances.
by borski/travel-hacking-toolkit / plugins/travel-hacking-toolkit/skills/alliances
Alpha Vantage
Access real-time and historical stock market data, forex rates, cryptocurrency prices, commodities, economic indicators, and 50+ technical indicators via the Alpha Vantage API. Use when fetching stock prices (OHLCV), company fundamentals (income statement, balance sheet, cash flow), earnings, options data, market news/sentiment, insider transactions, GDP, CPI, treasury yields, gold/silver/oil prices, Bitcoin/crypto prices, forex exchange rates, or calculating technical indicators (SMA, EMA, MACD, RSI, Bollinger Bands). Requires a free API key from alphavantage.co.
by foryourhealth111-pixel/Vibe-Skills / bundled/skills/alpha-vantage
Alphaxiv
Quick single-paper lookup via AlphaXiv LLM-optimized summaries with tiered source fallback. Use when user says "explain this paper", "summarize paper", pastes an arXiv/AlphaXiv URL, or provides a bare arXiv ID for quick understanding - not for broad literature search.
by wanshuiyin/Auto-claude-code-research-in-sleep / skills/skills-codex/alphaxiv
Alphaxiv
Quick single-paper lookup via AlphaXiv LLM-optimized summaries with tiered source fallback. Use when user says "explain this paper", "summarize paper", pastes an arXiv/AlphaXiv URL, or provides a bare arXiv ID for quick understanding - not for broad literature search.
by wanshuiyin/Auto-claude-code-research-in-sleep / skills/alphaxiv
Alternatives
Analyze alternative investments including hedge funds, private equity, and venture capital. Use when the user asks about hedge fund strategies (long/short, macro, event-driven), PE or VC performance metrics (IRR, TVPI, DPI), fee structures ('2-and-20', carry, hurdle rates), the J-curve effect, illiquidity premiums, lock-up periods, or hedge fund replication. Also trigger when users mention 'managed futures', 'CTA', 'fund of funds', 'vintage year', 'capital calls', 'distributions', 'carried interest', or ask how to evaluate an alternative investment manager.
by JoelLewis/finance_skills / plugins/wealth-management/skills/alternatives
Alt Text Headings
Alternative text and heading structure specialist for web applications. Use when building or reviewing any page with images, icons, SVGs, videos, figures, charts, or heading hierarchies. Covers meaningful vs decorative images, complex image descriptions, heading levels, document outline, and landmark structure. Can analyze images visually, compare existing alt text against image content, and interactively suggest appropriate alternatives. Applies to any web framework or vanilla HTML/CSS/JS.
by Community-Access/accessibility-agents / codex-skills/alt-text-headings
Alz Accelerator
Deploy Azure Landing Zones using the ALZ Accelerator with AVM (Azure Verified Modules). Use this skill whenever the user mentions Azure Landing Zones, ALZ, Azure landing zone accelerator, AVM modules for landing zones, deploying management groups, hub-and-spoke networking, Virtual WAN, platform landing zones, or asks about Bicep vs Terraform for Azure infrastructure. Also trigger when the user wants to bootstrap CI/CD for Azure platform deployment, set up management groups hierarchy, or deploy connectivity/identity/management platform subscriptions.
by julianobarbosa/claude-code-skills / skills/alz-accelerator
Alz Accelerator Skill
Alz Accelerator Skill linked from Juliano Barbosa Claude Code Skills, with the upstream skill instructions available on GitHub.
by julianobarbosa/claude-code-skills / skills/alz-accelerator-skill
Amazon Seller
Automate Amazon seller operations including inventory, orders, pricing, and advertising management
by claude-office-skills/skills / amazon-seller
American Airlines
Check American Airlines AAdvantage balance, elite status, and loyalty points via Patchright. Handles email 2FA with 6-box code entry. Uses persistent browser profiles to skip 2FA on subsequent runs.
by borski/travel-hacking-toolkit / plugins/travel-hacking-toolkit/skills/american-airlines
Amex Travel
Search Amex travel portal for cash prices, MR points pricing, IAP discounts, and FHR/THC hotel benefits via Patchright. Use when comparing pay-with-points portal pricing to award alternatives.
by borski/travel-hacking-toolkit / plugins/travel-hacking-toolkit/skills/amex-travel
Amplitude Experiment Implementation
This custom agent uses Amplitude's MCP tools to deploy new experiments inside of Amplitude, enabling seamless variant testing capabilities and rollout of product features.
by github/awesome-copilot / agents/amplitude-experiment-implementation.agent.md
Analytics
Your GitHub analytics command center -- team velocity, review turnaround, issue resolution metrics, contribution activity, bottleneck detection, and code churn analysis with dual markdown + HTML reports.
by Community-Access/accessibility-agents / codex-skills/analytics
Analytics
When the user wants to set up, improve, or audit analytics tracking and measurement. Also use when the user mentions "set up tracking," "GA4," "Google Analytics," "conversion tracking," "event tracking," "UTM parameters," "tag manager," "GTM," "analytics implementation," "tracking plan," "how do I measure this," "track conversions," "attribution," "Mixpanel," "Segment," "are my events firing," or "analytics isn't working." Use this whenever someone asks how to know if something is working or wants to measure marketing results. For A/B test measurement, see ab-testing.
by coreyhaines31/marketingskills / skills/analytics
Analytics Tracking
Set up, audit, and debug analytics tracking implementation — GA4, Google Tag Manager, event taxonomy, conversion tracking, and data quality. Use when building a tracking plan from scratch, auditing existing analytics for gaps or errors, debugging missing events, or setting up GTM. Trigger keywords: GA4 setup, Google Tag Manager, GTM, event tracking, analytics implementation, conversion tracking, tracking plan, event taxonomy, custom dimensions, UTM tracking, analytics audit, missing events, tracking broken. NOT for analyzing marketing campaign data — use campaign-analytics for that. NOT for BI dashboards — use product-analytics for in-product event analysis.
by alirezarezvani/claude-skills / marketing-skill/skills/analytics-tracking
Analytics Tracking
Analytics Tracking linked from Corey Haines marketing skills, with the upstream skill instructions available on GitHub.
by coreyhaines31/marketingskills / skills/analytics-tracking
Analyze Copilot CLI history and generate personalized instructions
Use when the user asks to personalize the GitHub Copilot CLI assistant, adapt Copilot to their style, use vardoger, or analyze their Copilot CLI conversation history. Reads the local session directory at `~/.copilot/session-state/`, extracts recurring preferences and conventions, and writes a fenced personalization block into `~/.copilot/copilot-instructions.md`. Runs entirely on the user's machine via the local `vardoger` CLI (`pipx install vardoger`); no network calls and no uploads. Triggers: 'personalize my copilot', 'analyze my copilot history', 'tailor copilot to me', 'run vardoger', 'update my copilot instructions from history', 'make copilot learn my style'.
by github/awesome-copilot / skills/vardoger-analyze
Analyze Feature Requests
Analyze and prioritize a list of feature requests by theme, strategic alignment, impact, effort, and risk. Use when reviewing customer feature requests, triaging a backlog, or making prioritization decisions.
by phuryn/pm-skills / pm-product-discovery/skills/analyze-feature-requests
Analyze Results
Analyze ML experiment results, compute statistics, generate comparison tables and insights. Use when user says "analyze results", "compare", or needs to interpret experimental data.
by wanshuiyin/Auto-claude-code-research-in-sleep / skills/analyze-results
Analyzing Active Directory Acl Abuse
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-active-directory-acl-abuse
Analyzing Android Malware With Apktool
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-android-malware-with-apktool
Analyzing API Gateway Access Logs
'Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-api-gateway-access-logs
Analyzing Apt Group With Mitre Navigator
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-apt-group-with-mitre-navigator
Analyzing Azure Activity Logs For Threats
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-azure-activity-logs-for-threats
Analyzing Bootkit And Rootkit Samples
Analyzes bootkit and advanced rootkit malware that infects the Master Boot Record (MBR), Volume Boot Record (VBR), or UEFI firmware to gain persistence below the operating system. Covers boot sector analysis, UEFI module inspection, and anti-rootkit detection techniques. Activates for requests involving bootkit analysis, MBR malware investigation, UEFI persistence analysis, or pre-OS malware detection.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-bootkit-and-rootkit-samples
Analyzing Browser Forensics With Hindsight
Analyze Chromium-based browser artifacts using Hindsight to extract browsing history, downloads, cookies, cached content, autofill data, saved passwords, and browser extensions from Chrome, Edge, Brave, and Opera for forensic investigation.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-browser-forensics-with-hindsight
Analyzing Campaign Attribution Evidence
Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attr
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-campaign-attribution-evidence
Analyzing Certificate Transparency For Phishing
Monitor Certificate Transparency logs using crt.sh and Certstream to detect phishing domains, lookalike certificates, and unauthorized certificate issuance targeting your organization.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-certificate-transparency-for-phishing
Analyzing Cloud Storage Access Patterns
Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetObject spikes), and potential data exfiltration using statistical baselines and time-series anomaly detection.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-cloud-storage-access-patterns
Analyzing Cobalt Strike Beacon Configuration
Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure, malleable profiles, and operator tradecraft.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-cobalt-strike-beacon-configuration
Analyzing Cobaltstrike Malleable C2 Profiles
Parse and analyze Cobalt Strike Malleable C2 profiles using dissect.cobaltstrike and pyMalleableC2 to extract C2 indicators, detect evasion techniques, and generate network detection signatures.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-cobaltstrike-malleable-c2-profiles
Analyzing Command And Control Communication
Analyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence. Activates for requests involving C2 analysis, beacon detection, C2 protocol reverse engineering, or command-and-control infrastructure mapping.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-command-and-control-communication
Analyzing Cyber Kill Chain
Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have interrupted the attack at earlier phases. Use when conducting post-incident analysis, building prevention-focused security controls, or mapping detection gaps to kill chain phases. Activates for requests involving kill chain analysis, intrusion kill chain, attack phase mapping, or Lockheed Martin kill chain framework.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-cyber-kill-chain
Analyzing Disk Image With Autopsy
Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-disk-image-with-autopsy
Analyzing DNS Logs For Exfiltration
Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-dns-logs-for-exfiltration
Analyzing Docker Container Forensics
Investigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-docker-container-forensics
Analyzing Email Headers For Phishing Investigation
Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify spoofing through SPF, DKIM, and DMARC validation.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-email-headers-for-phishing-investigation
Analyzing Ethereum Smart Contract Vulnerabilities
Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy, integer overflow, access control, and other vulnerability classes before deployment to Ethereum mainnet.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-ethereum-smart-contract-vulnerabilities
Analyzing Golang Malware With Ghidra
Reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-golang-malware-with-ghidra
Analyzing Heap Spray Exploitation
Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-heap-spray-exploitation
Analyzing Indicators Of Compromise
Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign attribution, and blocking priority. Use when triaging IOCs from phishing emails, security alerts, or external threat feeds; enriching raw IOCs with multi-source intelligence; or making block/monitor/whitelist decisions. Activates for requests involving VirusTotal, AbuseIPDB, MalwareBazaar, MISP, or IOC enrichment pipelines.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-indicators-of-compromise
Analyzing iOS App Security With Objection
Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-ios-app-security-with-objection
Analyzing Kubernetes Audit Logs
Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns. Use when investigating Kubernetes cluster compromise or building k8s-specific SIEM detection rules.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-kubernetes-audit-logs
Analyzing Linux Audit Logs For Intrusion
Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log querying, timeline reconstruction, and integration with SIEM platforms. Activates for requests involving auditd analysis, Linux audit log investigation, ausearch queries, aureport summaries, or host-based intrusion detection on Linux.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-linux-audit-logs-for-intrusion
Analyzing Linux Elf Malware
Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x86_64 and ARM ELF samples. Activates for requests involving Linux malware analysis, ELF binary investigation, Linux server compromise assessment, or container malware analysis.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-linux-elf-malware
Analyzing Linux Kernel Rootkits
Detect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel modules, and tampered system structures.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-linux-kernel-rootkits
Analyzing Linux System Artifacts
Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-linux-system-artifacts
Analyzing Lnk File And Jump List Artifacts
Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing of the Shell Link Binary format.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-lnk-file-and-jump-list-artifacts
Analyzing Macro Malware In Office Documents
Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA deobfuscation to extract the attack chain. Activates for requests involving Office macro analysis, VBA malware investigation, maldoc analysis, or document-based threat examination.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-macro-malware-in-office-documents
Analyzing Malicious PDF With Peepdf
Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-malicious-pdf-with-peepdf
Analyzing Malicious URL With Urlscan
URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content, HTTP transactions, JavaScript behavior, and network connections of web pages in an isolat
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-malicious-url-with-urlscan
Analyzing Malware Behavior With Cuckoo Sandbox
Executes malware samples in Cuckoo Sandbox to observe runtime behavior including process creation, file system modifications, registry changes, network communications, and API calls. Generates comprehensive behavioral reports for malware classification and IOC extraction. Activates for requests involving dynamic malware analysis, sandbox detonation, behavioral analysis, or automated malware execution.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-malware-behavior-with-cuckoo-sandbox
Analyzing Malware Family Relationships With Malpedia
Use the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-malware-family-relationships-with-malpedia
Analyzing Malware Persistence With Autoruns
Use Sysinternals Autoruns to systematically identify and analyze malware persistence mechanisms across registry keys, scheduled tasks, services, drivers, and startup locations on Windows systems.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-malware-persistence-with-autoruns
Analyzing Malware Sandbox Evasion Techniques
Detect sandbox evasion techniques in malware samples by analyzing timing checks, VM artifact queries, user interaction detection, and sleep inflation patterns from Cuckoo/AnyRun behavioral reports
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-malware-sandbox-evasion-techniques
Analyzing Memory Dumps With Volatility
Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. Supports Windows, Linux, and macOS memory forensics. Activates for requests involving memory forensics, RAM analysis, volatile data examination, process injection detection, or memory-resident malware investigation.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-memory-dumps-with-volatility
Analyzing Memory Forensics With Lime And Volatility
Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-memory-forensics-with-lime-and-volatility
Analyzing Mft For Deleted File Recovery
Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space using MFTECmd, analyzeMFT, and X-Ways Forensics.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-mft-for-deleted-file-recovery
Analyzing Network Covert Channels In Malware
Detect and analyze covert communication channels used by malware including DNS tunneling, ICMP exfiltration, steganographic HTTP, and protocol abuse for C2 and data exfiltration.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-network-covert-channels-in-malware
Analyzing Network Flow Data With Netflow
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic baselines, and applies statistical analysis to identify flows with abnormal byte counts, connection durations, and periodic timing patterns.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-network-flow-data-with-netflow
Analyzing Network Packets With Scapy
Craft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and traffic anomaly detection in authorized security testing
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-network-packets-with-scapy
Analyzing Network Traffic For Incidents
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-network-traffic-for-incidents
Analyzing Network Traffic Of Malware
Analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement patterns using Wireshark, Zeek, and Suricata. Activates for requests involving malware network analysis, C2 traffic decoding, malware PCAP analysis, or network-based malware detection.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-network-traffic-of-malware
Analyzing Network Traffic With Wireshark
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
by mukul975/Anthropic-Cybersecurity-Skills / skills/analyzing-network-traffic-with-wireshark