All authors

Claude Skills by plurigrid
github.com/plurigrid2,535 skills6 installs3,507 views
- Analyzing Threat Actor Ttps With Mitre AttackMITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor behVotes: 0GitHub stars: 61
- Analyzing Threat Actor Ttps With Mitre NavigatorMap advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations, generates Navigator layer files for visualization, and compares defensive coverage against adversary profiles. Activates for requests involving APT TTP mapping, ATT&CK Navigator layers, threat actor profiling, or MITRE technique coverage analysis.Votes: 0GitHub stars: 61
- Analyzing Threat Intelligence FeedsAnalyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format, or enriching existing IOCs with campaign attribution. Activates for requests involving ThreatConnect, Recorded Future, Mandiant Advantage, MISP, AlienVault OTX, or automated feed aggregation pipelines.Votes: 0GitHub stars: 61
- Analyzing Threat Landscape With MispAnalyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time. Uses PyMISP to pull event data, compute IOC type breakdowns, identify top threat actors and malware families, and generate threat landscape reports with temporal trends.Votes: 0GitHub stars: 61
- Analyzing Tls Certificate Transparency LogsQueries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance. Use for proactive phishing domain detection and certificate monitoring.Votes: 0GitHub stars: 61
- Analyzing Typosquatting Domains With DnstwistDetect typosquatting, homograph phishing, and brand impersonation domains using dnstwist to generate domain permutations and identify registered lookalike domains targeting your organization.Votes: 0GitHub stars: 61
- Analyzing Uefi Bootkit PersistenceAnalyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families (BlackLotus, LoJax, MosaicRegressor, MoonBounce, CosmicStrand), ESP partition forensic inspection, chipsec-based firmware integrity verification, and Secure Boot configuration auditing. Activates for requests involving UEFI malware analysis, firmware persistence...Votes: 0GitHub stars: 61
- Analyzing Usb Device Connection HistoryInvestigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.Votes: 0GitHub stars: 61
- Analyzing Web Server Logs For IntrusionParse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source attribution, and statistical anomaly detection for request frequency and response size outliers.Votes: 0GitHub stars: 61
- Analyzing Windows Amcache ArtifactsParses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman's AmcacheParser and Timeline Explorer for artifact extraction, SHA-1 hash correlation with threat intel, and timeline reconstruction. Activates for requests involving Amcache forensics, program execution evidence, Windows artifact analysis, or application compatibility cache investigation.Votes: 0GitHub stars: 61
- Analyzing Windows Event Logs In SplunkAnalyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis of Windows endpoints and domain controllers.Votes: 0GitHub stars: 61
- Analyzing Windows Lnk Files For ArtifactsParse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.Votes: 0GitHub stars: 61
- Analyzing Windows Prefetch With PythonParse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.Votes: 0GitHub stars: 61
- Analyzing Windows Registry For ArtifactsExtract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.Votes: 0GitHub stars: 61
- Analyzing Windows Shellbag ArtifactsAnalyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.Votes: 0GitHub stars: 61
- Anoma IntentsAnoma intent-centric architecture for cross-chain obstruction passing with Geb semantics and Juvix compilationVotes: 0GitHub stars: 61
- Aptos AgentInteract with Aptos blockchain - check balances, transfer APT, swap tokens, stake, and execute Move view functions. Features game-theoretic decision analysis with Nash equilibrium detection. All transactions require explicit approval.Votes: 0GitHub stars: 61
- Aptos Gf3 SocietyAptos GF(3) Society SkillVotes: 0GitHub stars: 61
- Aptos SocietyAptos Society: World Extractable Value (WEV) implementation via GayMove contracts. Path A vault-only multiverse finance with worldnet ledger for 26 Agent-O-Rama worlds. Deployed 2024-12-29 on Aptos mainnet.Votes: 0GitHub stars: 61
- Aqua Voice MalleabilityAdversarial malleability analysis of Aqua Voice Electron app with IPC injection, WebSocket interception, and braided monoidal skill interleavingVotes: 0GitHub stars: 61
- Artifacts BuilderSuite of tools for creating elaborate, multi-component claude.ai HTMLVotes: 0GitHub stars: 61
- Asi Polynomial OperadsASI skill integrating polynomial functors, free monad/cofree comonadVotes: 0GitHub stars: 61
- Ask Questions If UnderspecifiedClarify requirements before implementing. Use when serious doubts araise.Votes: 0GitHub stars: 61
- Assembly IndexLee Cronin's Assembly Theory for molecular complexity measurement andVotes: 0GitHub stars: 61
- AtherisPython fuzzing with Atheris for discovering vulnerabilities in Python code.Votes: 0GitHub stars: 61
- Audit Context BuildingEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.Votes: 0GitHub stars: 61
- Audit Prep AssistantPrepare your codebase for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates comprehensive documentation (flowcharts, user stories, inline comments). (project, gitignored)Votes: 0GitHub stars: 61
- Auditing Aws S3 Bucket PermissionsSystematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls.Votes: 0GitHub stars: 61
- Auditing Azure Active Directory ConfigurationAuditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite.Votes: 0GitHub stars: 61
- Auditing Cloud With Cis BenchmarksThis skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite, remediating failed controls, and maintaining continuous compliance monitoring against CIS v5 for AWS, v4 for Azure, and v4 for GCP.Votes: 0GitHub stars: 61
- Auditing Gcp Iam PermissionsAuditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.Votes: 0GitHub stars: 61
- Auditing Kubernetes Cluster RbacAuditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.Votes: 0GitHub stars: 61
- Auditing Terraform Infrastructure For SecurityAuditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and OPA/Rego policies to detect overly permissive IAM policies, public resource exposure, missing encryption, and insecure defaults before cloud deployment.Votes: 0GitHub stars: 61
- Auditing Tls Certificate Transparency LogsMonitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build continuous monitoring pipelines that catch rogue certificates, track CA behavior, and map the external attack surface. Activates for requests involving certificate transparency monitoring, CT log auditing, subdomain discovery via certifi...Votes: 0GitHub stars: 61
- Automating Ioc EnrichmentAutomates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs. Use when building automated enrichment workflows integrated with SIEM alerts, email submission pipelines, or bulk IOC processing from threat feeds. Activates for requests involving SOAR enrichment, Cortex XSOAR, Splunk SOAR, TheHive, Python enrichment pipelines, or autom...Votes: 0GitHub stars: 61
- AutopoiesisSelf-producing skill system combining ruler enforcement with skill self-evolution. Implements trifurcation-first imperative via nbb sexp invocation for idempotent agent instruction.Votes: 0GitHub stars: 61
- BabashkaClojure scripting without JVM startup.Votes: 0GitHub stars: 61
- Backend DevelopmentBackend API design, database architecture, microservices patterns, andVotes: 0GitHub stars: 61
- Bdd Mathematical VerificationBDD-Driven Mathematical Content Verification SkillVotes: 0GitHub stars: 61
- BeeperUnified messaging via three access tiers — MCP (live API), beeper-cli (authenticated CLI), and direct SQLite→DuckDB (full archive). Search, analyze, and act across all networks. Subsumes beeper-mcp, messaging-world, and signal-messaging.Votes: 0GitHub stars: 61
- Behaviour Surprisal AnalysisBehaviour Surprisal AnalysisVotes: 0GitHub stars: 61
- Bidirectional Lens LogicHedges' 4-kind lattice for bidirectional programming - covariant/contravariant/invariant/bivariant types with GF(3) correspondenceVotes: 0GitHub stars: 61
- Bifurcation GeneratorGenerate bifurcation diagrams for dynamical systems. Use when visualizing parameter-dependent behavior transitions.Votes: 0GitHub stars: 61
- BigqueryBigQuery Expert Engineer Skill - Comprehensive guide for GoogleSQL queries, data management, performance optimization, and cost management Use when: - Running bq commands (query, load, extract) - Writing GoogleSQL queries (functions, JOINs, CTEs) - Designing partitioned/clustered tables - Using BigQuery ML or external data sourcesVotes: 0GitHub stars: 61
- Binary TriagePerforms initial binary triage by surveying memory layout, strings, imports/exports, and functions to quickly understand what a binary does and identify suspicious behavior. Use when first examining a binary, when user asks to triage/survey/analyze a program, or wants an overview before deeper reverse engineering.Votes: 0GitHub stars: 61
- Bisimulation GameBisimulation game for resilient skill dispersal across AI agents withVotes: 0GitHub stars: 61
- Blackhat GoGo-based security techniques from "Black Hat Go" extended with macOS, Cloud, Mobile, IoT, Supply Chain, API, Web3, AI/ML, Red Team, ATT&CK, and LLM chapters. 186 techniques, 36 tools, 33 defenses across 37 chapters. Includes adversarial bisimulation games with Ungar (order-dependent) and join-semilattice structures. AAIF-compatible multiplayer agent games for human-agent security exercises.Votes: 0GitHub stars: 61
- Bluesky JetstreamBluesky Jetstream Firehose SkillVotes: 0GitHub stars: 61
- Bmorphism Starsbmorphism's GitHub stars (2155 repos) and created repos - a curated indexVotes: 0GitHub stars: 61
- BorkdudeBabashka and ClojureScript runtime selection guidance by @borkdudeVotes: 0GitHub stars: 61