cybersecurity-skills: Instructions file for Claude Code

CLAUDE.md

cybersecurity-skills CLAUDE.md is an instructions file for Claude Code from briiirussell/cybersecurity-skills. It costs 699 tokens per session, scanned A, original, MIT.

Project instructions for a collection of cybersecurity skills used by AI coding agents, including their file formats, folders, and build process.

In plain words
What is it for?
It helps maintain skill files, agent-specific instruction files, templates, directory layouts, and the script that builds the adaptations.
Why use it?
It gives contributors a shared structure for writing skills and adapting them for Claude Code, Cursor, and Codex.

Instructions file for Claude Code

Written for Claude Code: the file is CLAUDE.md. Also seen: reads .claude/ paths; mentions CLAUDE.md; mentions Claude Code.

This is briiirussell/cybersecurity-skills's own configuration. It tells Claude Code how to work on cybersecurity-skills itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything cybersecurity-skills configures →

Reuse

Borrowing it

Nothing to install: this file belongs to briiirussell/cybersecurity-skills. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/briiirussell/cybersecurity-skills/main/CLAUDE.md
Clone the repo
git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for cybersecurity-skills CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/briiirussell/cybersecurity-skills/claude-md/github.svg)](https://agentmods.dev/instructions/briiirussell/cybersecurity-skills/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/briiirussell/cybersecurity-skills/claude-md"><img src="https://agentmods.dev/badge/instructions/briiirussell/cybersecurity-skills/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for cybersecurity-skills CLAUDE.md

Your own site · 80×15
<a href="https://agentmods.dev/instructions/briiirussell/cybersecurity-skills/claude-md"><img src="https://agentmods.dev/badge/instructions/briiirussell/cybersecurity-skills/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 699 This file is loaded in full into every session.
When invoked 699 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00699 $0.00699
Opus 5 $0.00349 $0.00349
Sonnet 5 $0.00140 $0.00140
Haiku 4.5 $0.00070 $0.00070

Measured 11d ago against content hash c1ffbb2c6848, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

cybersecurity-skills CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 79 lines

How it starts

The opening of the file, as written. The whole thing — 79 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md

Project Overview

Cybersecurity Skills is a collection of cybersecurity skill prompts for AI coding agents. Skills are authored as Claude Code SKILL.md files (the canonical format) and adapted for Cursor and Codex via a build script.

Supported Agents

Agent Format Location
Claude Code SKILL.md (canonical) skills/<skill-name>/SKILL.md — copy to .claude/skills/
Cursor .mdc rule files adapters/cursor/
Codex Instruction .md adapters/codex/

Directory Structure

skills/
├── recon/SKILL.md
├── owasp-audit/SKILL.md
├── disk-forensics/SKILL.md
├── osint-recon/SKILL.md
├── incident-triage/SKILL.md
└── cloud-audit/SKILL.md
adapters/
├── cursor/          # Generated .mdc files
└── codex/           # Generated .md files
templates/
└── skill-template.md
scripts/
└── build-adapters.mjs

Skill Format (Claude Code SKILL.md)

Every skill follows the Anthropic skill creator guidelines:

---
name: skill-name                    # Lowercase, hyphens, max 64 chars
description: "What it does and when to use it. 200-1024 chars. Include trigger phrases."
allowed-tools: Bash, Read, Write    # Tools the skill can use
---

Frontmatter fields:

  • name — Slug used for /skill-name invocation. Lowercase + hyphens only.
  • description — Explains WHAT the skill does and WHEN to use it. Claude uses this to decide automatic invocation. Be "pushy" to combat undertriggering.
  • allowed-tools — Comma-separated list of tools the skill can access.
  • disable-model-invocation — Set true for manual-only skills (e.g., deploy).
  • user-invocable — Set false for background knowledge only.

Content guidelines:

  • Use imperative form ("Run this command", "Check for X")
  • Keep SKILL.md under 500 lines
  • Move reference material to separate files if needed
  • Define output formats explicitly

Build Commands

node scripts/build-adapters.mjs    # Generate Cursor + Codex adapters from SKILL.md files

Read the full file on GitHub · 79 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 79 lines · 699 tokens per session scan A c1ffbb2c6848

Subscribe to this mod's changes

cybersecurity-skills CLAUDE.md is an instructions file published in the GitHub repository briiirussell/cybersecurity-skills (387 stars, last pushed 3mo ago), licensed MIT. It adds 699 tokens to every session, about $0.0035 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens