Anthropic Cybersecurity Skills

754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 26 security domains · Apache 2.0

Last verified:

Visit Anthropic Cybersecurity Skills

What is Anthropic Cybersecurity Skills?

Anthropic Cybersecurity Skills is the largest open-source cybersecurity skills library for AI agents, containing 754 production-grade structured cybersecurity skills across 26 security domains. Each skill follows the agentskills.io open standard with YAML frontmatter for fast discovery and structured Markdown for step-by-step execution. The library gives AI agents the security expertise of a senior analyst, enabling them to perform tasks like vulnerability analysis, threat detection, incident response, and security auditing with practitioner playbooks rather than generic LLM guesses.

The project's unique feature is mapping every skill to five industry frameworks simultaneously: MITRE ATT&CK (v18, 200+ techniques), NIST CSF 2.0 (6 functions, 22 categories), MITRE ATLAS (v5.4, 84 AI/ML adversarial techniques), MITRE D3FEND (v1.3, 267 defensive techniques), and NIST AI RMF (1.0, 72 subcategories). This unified cross-framework coverage makes it the only open-source skills library with such comprehensive compliance mapping. Skills cover domains including Cloud Security (60 skills), Threat Hunting (55), Threat Intelligence (50), Web Application Security (42), Malware Analysis (39), Digital Forensics (37), SOC Operations (33), and 19 other specialized areas.

This tool is for cybersecurity professionals, developers, AI platform providers, and enterprise teams looking to enhance AI capabilities in cybersecurity applications. It works with 26+ AI platforms including Claude Code, GitHub Copilot, Cursor, Windsurf, Gemini CLI, OpenAI Codex CLI, Devin, Replit Agent, LangChain, CrewAI, and any MCP-compatible agent. The library addresses the 4.8 million unfilled cybersecurity roles global workforce gap by equipping AI agents with structured domain knowledge for threat hunting, DFIR, penetration testing, and security analysis workflows.

Anthropic Cybersecurity Skills pricing

Pricing model: Freemium

Open source under Apache 2.0 license - completely free for personal and commercial use. No paid tiers or subscriptions. Available via GitHub repository and NPM. Optional: 50 Casky Tokens for early access to casky.ai playground when taking the GARS-2026 survey (10 min, 60 questions). Playground on Casky.ai lets you try skills hands-on with no setup required.

Anthropic Cybersecurity Skills pros

  • 754 production-grade structured cybersecurity skills
  • 26 security domains covering full cybersecurity spectrum
  • Unique 5-framework mapping (ATT&CK, NIST CSF, ATLAS, D3FEND, AI RMF)
  • Follows agentskills.io open standard for platform compatibility
  • Works with 26+ AI platforms including Claude Code and GitHub Copilot
  • YAML frontmatter enables ~30 token fast skill scanning
  • Progressive disclosure architecture preserves context windows
  • Real practitioner workflows, not generated summaries
  • MITRE ATT&CK covers all 14 tactics with 200+ techniques
  • Includes working helper scripts and report templates
  • Apache 2.0 license allows free commercial use
  • Active community with 10,475+ GitHub stars
  • Skill anatomy includes When/Prerequisites/Workflow/Verification sections
  • ATLAS mapping covers AI/ML adversarial threats including agent context poisoning
  • ATT&CK Navigator layer file included for visual coverage mapping

Anthropic Cybersecurity Skills cons

  • Community project not affiliated with Anthropic PBC
  • Requires AI agent platform supporting agentskills.io standard
  • Full skill load consumes 500-2,000 tokens per skill
  • Some domains have very few skills (Deception Technology only 2)
  • MITRE ATT&CK v19 mappings not yet updated (coming later 2026)
  • No official enterprise support or SLA
  • Setup required unless using Casky.ai playground
  • Technical knowledge needed to contribute new skills

Frequently asked questions about Anthropic Cybersecurity Skills

What is Anthropic Cybersecurity Skills?

It is the largest open-source cybersecurity skills library for AI agents, containing 754 structured cybersecurity skills across 26 security domains. Each skill follows the agentskills.io open standard with YAML frontmatter and Markdown body, giving AI agents senior analyst-level expertise for tasks like threat hunting, incident response, and vulnerability analysis.

Is this affiliated with Anthropic PBC?

No. This is an independent community-created project by Mahipal Jangra (mukul975). It is explicitly not affiliated with Anthropic PBC, though it works with Claude Code and other AI platforms.

Which AI platforms are compatible?

26+ platforms including Claude Code, GitHub Copilot, Cursor, Windsurf, Cline, Aider, Continue, Roo Code, Amazon Q Developer, Tabnine, Sourcegraph Cody, JetBrains AI, OpenAI Codex CLI, Gemini CLI, Devin, Replit Agent, SWE-agent, OpenHands, LangChain, CrewAI, AutoGen, Semantic Kernel, Haystack, Vercel AI SDK, and any MCP-compatible agent.

What are the 5 framework mappings?

Every skill maps to MITRE ATT&CK v18 (14 tactics, 200+ techniques), NIST CSF 2.0 (6 functions, 22 categories), MITRE ATLAS v5.4 (16 tactics, 84 AI/ML techniques), MITRE D3FEND v1.3 (7 categories, 267 defensive techniques), and NIST AI RMF 1.0 (4 functions, 72 subcategories). This is the only open-source library with unified cross-framework coverage.

How do agents use these skills?

Agents scan 754 skill frontmatters (~30 tokens each) to identify relevant skills by tags and description, then load top matches (500-2,000 tokens each) and execute the structured Workflow section step-by-step. They validate results using the Verification section and map findings to ATT&CK techniques.

What security domains are covered?

26 domains: Cloud Security (60), Threat Hunting (55), Threat Intelligence (50), Web App Security (42), Network Security (40), Malware Analysis (39), Digital Forensics (37), Security Operations (36), IAM (35), SOC Operations (33), Container Security (30), OT/ICS Security (28), API Security (28), Vulnerability Management (25), Incident Response (25), Red Teaming (24), Pen Testing (23), Endpoint Security (17), DevSecOps (17), Phishing Defense (16), Cryptography (14), Zero Trust (13), Mobile Security (12), Ransomware Defense (7), Compliance & Governance (5), Deception Technology (2).

How do I install it?

Option 1 (recommended): npx skills add mukul975/Anthropic-Cybersecurity-Skills. Option 2: git clone https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git and cd into the directory. Works immediately with compatible platforms with zero configuration.

What is the license?

Apache License 2.0. You are free to use, modify, and distribute these skills in both personal and commercial projects without restriction.

Can I contribute new skills?

Yes. The project grows through community contributions. Domains needing the most help include Deception Technology (only 2 skills) and Compliance & Governance (5 skills). Follow the template in CONTRIBUTING.md and submit a PR with title 'Add skill: your-skill-name'. Every PR is reviewed within 48 hours for technical accuracy and agentskills.io compliance.

Is there a playground to try it?

Yes. Casky.ai offers a free playground with no setup required. You can run live cybersecurity skill exercises against real targets, see AI agents execute structured skills in real time, explore MITRE ATT&CK mapped workflows interactively, and test threat hunting, DFIR, and penetration testing scenarios.

Categories

Use cases

Browse all AI tools on NeedAnAI