cyberskills-hub: Instructions file for Claude Code

CLAUDE.md

cyberskills-hub CLAUDE.md is an instructions file for Claude Code from haporfirio/cyberskills-hub. It costs 1,452 tokens per session, scanned A, original, MIT.

A documentation and routing guide for a cybersecurity skills library containing hundreds of skills across eight areas. It tells the agent how to identify a cybersecurity term, role, and matching skill.

In plain words
What is it for?
Routing requests about penetration testing, defense, forensics, or security engineering to the relevant documented skill and resolving ambiguous keywords.
Why use it?
It reduces guesswork when several security skills could match the same request or when a term is not in the main index.

Instructions file for Claude Code

Written for Claude Code: the file is CLAUDE.md.

This is haporfirio/cyberskills-hub's own configuration. It tells Claude Code how to work on cyberskills-hub itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything cyberskills-hub configures →

Reuse

Borrowing it

Nothing to install: this file belongs to haporfirio/cyberskills-hub. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/haporfirio/cyberskills-hub/main/CLAUDE.md
Clone the repo
git clone --depth 1 https://github.com/haporfirio/cyberskills-hub

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for cyberskills-hub CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/haporfirio/cyberskills-hub/claude-md/github.svg)](https://agentmods.dev/instructions/haporfirio/cyberskills-hub/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/haporfirio/cyberskills-hub/claude-md"><img src="https://agentmods.dev/badge/instructions/haporfirio/cyberskills-hub/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for cyberskills-hub CLAUDE.md

Your own site · 80×15
<a href="https://agentmods.dev/instructions/haporfirio/cyberskills-hub/claude-md"><img src="https://agentmods.dev/badge/instructions/haporfirio/cyberskills-hub/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 1,452 This file is loaded in full into every session.
When invoked 1,452 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.01452 $0.01452
Opus 5 $0.00726 $0.00726
Sonnet 5 $0.00290 $0.00290
Haiku 4.5 $0.00145 $0.00145

Measured 12d ago against content hash d5fd759d1e5a, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

cyberskills-hub CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

CLAUDE.md · 97 lines

How it starts

The opening of the file, as written. The whole thing — 97 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CyberSkills Documentation Hub

Este projeto documenta 732 cybersecurity skills organizadas em 8 dominios com metadata estruturada, workflow guides e indices de referencia cruzada.

Instrucao de Routing

Quando o usuario mencionar um termo de cybersecurity, siga este fluxo:

  1. Detecte o role context (secao abaixo)
  2. Busque nos top-50 keywords (tabela abaixo)
  3. Se match direto -> navegue para a skill no catalogo correspondente
  4. Se [COLISAO] -> consulte _convencoes/colisoes.md para resolucao por role context
  5. Se nao encontrou -> busque no domain lookup file apropriado (grep no campo keywords)
  6. Se dominio incerto -> consulte referencias/semantic-hints.md para matching por padroes contextuais

Role Context

Role Sinais
offensive pentest, red team, exploit, attack, payload, bypass
defensive detect, monitor, SOC, blue team, alert, rule
forensic evidence, artifact, timeline, acquisition, chain of custody, memory dump
engineering configure, harden, deploy, architecture, pipeline, infrastructure

Default (sem contexto claro): defensive

Top-50 Keywords

Keyword Skill
credential dumping [COLISAO] ver _convencoes/colisoes.md
lateral movement [COLISAO] ver _convencoes/colisoes.md
privilege escalation [COLISAO] ver _convencoes/colisoes.md
phishing [COLISAO] ver _convencoes/colisoes.md
active directory [COLISAO] ver _convencoes/colisoes.md
command and control [COLISAO] ver _convencoes/colisoes.md
dns tunneling [COLISAO] ver _convencoes/colisoes.md
data exfiltration [COLISAO] ver _convencoes/colisoes.md
kerberoasting [COLISAO] ver _convencoes/colisoes.md
vulnerability scanning [COLISAO] ver _convencoes/colisoes.md
golden ticket [COLISAO] ver _convencoes/colisoes.md
process injection [COLISAO] ver _convencoes/colisoes.md
adversary emulation [COLISAO] ver _convencoes/colisoes.md
fileless malware [COLISAO] ver _convencoes/colisoes.md
memory analysis [COLISAO] ver _convencoes/colisoes.md
dependency confusion [COLISAO] ver _convencoes/colisoes.md
packet analysis [COLISAO] ver _convencoes/colisoes.md
ueba [COLISAO] ver _convencoes/colisoes.md
phishing investigation [COLISAO] ver _convencoes/colisoes.md
application security testing performing-web-application-penetration-test [offensive-security]
domain controller compromise exploiting-zerologon-vulnerability-cve-2020-1472 [offensive-security]
insecure direct object reference exploiting-idor-vulnerabilities [offensive-security]
social engineering pentest conducting-social-engineering-penetration-test [offensive-security]
internet-facing assessment performing-external-network-penetration-test [offensive-security]
internal service discovery exploiting-server-side-request-forgery [offensive-security]
c2 detection hunting-for-beaconing-with-frequency-analysis [defensive-security]
mimikatz detecting-mimikatz-execution-patterns [defensive-security]
pass the hash detecting-pass-the-hash-attacks [defensive-security]
hypothesis building-threat-hunt-hypothesis-framework [defensive-security]
c2 protocol reverse engineering analyzing-command-and-control-communication [dfir]
incident response procedures building-incident-response-playbook [dfir]
insider threat investigation performing-insider-threat-investigation [dfir]
lateral movement prevention containing-active-breach [dfir]
user activity reconstruction analyzing-windows-shellbag-artifacts [dfir]
infrastructure as code auditing-terraform-infrastructure-for-security [security-engineering]
container escape detection performing-container-escape-detection [security-engineering]
pod security admission implementing-pod-security-admission-controller [security-engineering]
bucket misconfiguration remediating-s3-bucket-misconfiguration [security-engineering]
automated phishing response implementing-soar-playbook-for-phishing [soc]
malware submission pipeline building-automated-malware-submission-pipeline [soc]
security chaos engineering implementing-security-chaos-engineering [soc]
privilege escalation detection detecting-golden-ticket-attacks [soc]
lateral movement correlation implementing-siem-correlation-rules-for-apt [soc]
authenticated vulnerability scan performing-authenticated-vulnerability-scan [vulnerability-management]
network vulnerability assessment scanning-infrastructure-with-nessus [vulnerability-management]
vulnerability scanner deployment implementing-rapid7-insightvm-for-scanning [vulnerability-management]
att&ck navigator mapping-mitre-attack-techniques [threat-intelligence]
threat emulation performing-threat-emulation-with-atomic-red-team [threat-intelligence]
threat landscape performing-threat-landscape-assessment-for-sector [threat-intelligence]
capability extension find-skills [simulation-training]

Read the full file on GitHub · 97 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 97 lines · 1,452 tokens per session scan A d5fd759d1e5a

Subscribe to this mod's changes

cyberskills-hub CLAUDE.md is an instructions file published in the GitHub repository haporfirio/cyberskills-hub (2 stars, last pushed 5mo ago), licensed MIT. It adds 1,452 tokens to every session, about $0.0073 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,126 tokens

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens