Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add Masriyan/Claude-Code-CyberSecurity-Skillnpx agentmods add plugins/masriyan/claude-code-cybersecurity-skill/cybersecuritygit clone --depth 1 https://github.com/Masriyan/Claude-Code-CyberSecurity-SkillWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/masriyan/claude-code-cybersecurity-skill/cybersecurity)<a href="https://agentmods.dev/plugins/masriyan/claude-code-cybersecurity-skill/cybersecurity"><img src="https://agentmods.dev/badge/plugins/masriyan/claude-code-cybersecurity-skill/cybersecurity.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
cybersecurity scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "cybersecurity",
"source": "./",
"description": "A complete cybersecurity toolkit: 19 skills spanning reconnaissance, vulnerability assessment, exploit development, reverse engineering, malware analysis, threat hunting, incident response, network/web/cloud security, SOC automation, log analysis, cryptography, red and blue team operations, and AI/LLM, mobile, OT/ICS, and GRC security.",
"version": "3.0.0",
"author": {
"name": "Masriyan (sudo3rs)"
},
"license": "MIT",
"keywords": [
"cybersecurity",
"pentest",
"blue-team",
"red-team",
"soc",
"dfir",
"threat-hunting"
],
"skills": [
"./skills/01-recon-osint",
"./skills/02-vulnerability-scanner",
"./skills/03-exploit-development",
"./skills/04-reverse-engineering",
"./skills/05-malware-analysis",
"./skills/06-threat-hunting",
"./skills/07-incident-response",
"./skills/08-network-security",
"./skills/09-web-security",
"./skills/10-cloud-security",
"./skills/11-csoc-automation",
"./skills/12-log-analysis",
"./skills/13-crypto-analysis",
"./skills/14-red-team-ops",
"./skills/15-blue-team-defense",
"./skills/16-ai-llm-security",
"./skills/17-mobile-security",
"./skills/18-ot-ics-security",
"./skills/19-grc-compliance"
]
}What it installs
The manifest is a name and a version. 19 skills travel with it, and installing the plugin installs all of them — 676 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill CSOC Operations & Playbook Automation A 28 tokens
- Skill Cryptographic Analysis & Assessment A 30 tokens
- Skill Log Analysis & SIEM Integration A 39 tokens
- Skill Malware Analysis & Sandboxing A 28 tokens
- Skill Red Team Operations & Engagement Planning A 31 tokens
- Skill Reverse Engineering & Binary Analysis A 26 tokens
- Skill Threat Hunting & IOC Analysis A 28 tokens
- Skill Exploit Development & Payload Engineering A 28 tokens
- Skill Network Security & Traffic Analysis A 28 tokens
- Skill Reconnaissance & OSINT Automation A 33 tokens
- Skill Vulnerability Scanning & Assessment A 26 tokens
- Skill GRC & Compliance A 58 tokens
- Skill Mobile Application Security A 46 tokens
- Skill OT / ICS / SCADA Security A 64 tokens
- Skill Blue Team Defense & Hardening B 30 tokens
- Skill Cloud Security & Container Hardening B 30 tokens
- Skill Incident Response & Digital Forensics B 43 tokens
- Skill Web Application Security Testing B 30 tokens
- Skill AI & LLM Security B 50 tokens
What ships with it
1 file beside marketplace.json#cybersecurity in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 40 lines scan A f0c7e729033a
cybersecurity is a plugin published in the GitHub repository Masriyan/Claude-Code-CyberSecurity-Skill (389 stars, last pushed 26d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other plugins, from other repositories
insurgent-campaign
Produces grassroots-first campaign plans for startups, NGOs, movements, and solo brands being outspent by incumbents. Ideates campaigns of any kind (awareness, launch, fundraising, mobilization, counter-narrative), audits spend asymmetry, assembles an insurgent channel stack with 70/30 boost rules, and outputs a…
relationship-design
Design AI-first interfaces that build ongoing relationships through memory, trust evolution, and collaborative planning.
typography
Professional typography rules for UI design enforcing correct quote marks, dashes, spacing, hierarchy, and layout. Auto-applies to generated HTML/CSS/React code.
bencium-aeo
Answer Engine Optimization for AI search visibility. Optimize content for ChatGPT, Claude, Gemini, AI Overviews citations.
a11y-audit
Full accessibility audit with WCAG compliance checking.
backend-architect
Backend service architecture design with endpoint scaffolding.