tabletop-exercise

tabletop-exercise is a skill for Claude Code, Codex from cjcsecurity/claude-tabletop. It costs 147 tokens per session (4,109 once invoked), scanned A, original, Apache-2.0.

A tabletop exercise runbook generator for practicing responses to technical incidents. A tabletop exercise is a structured discussion where a team walks through a realistic scenario without making changes to a live system.

In plain words
What is it for?
Use it to prepare cybersecurity, product security, DevOps, reliability, privacy, compliance, data, or machine-learning response exercises for a project team.
Why use it?
It turns the project's actual technology and risks into a prepared exercise, so teams do not have to invent scenarios and facilitation materials from scratch. It also supports different durations, audiences, difficulty levels, and group sizes.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/cjcsecurity/claude-tabletop/tabletop-exercise
Any agent
npx skills add cjcsecurity/claude-tabletop --skill tabletop-exercise
Clone the repo
git clone --depth 1 https://github.com/cjcsecurity/claude-tabletop

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for tabletop-exercise

README.md
[![agentmods](https://agentmods.dev/badge/skills/cjcsecurity/claude-tabletop/tabletop-exercise.svg)](https://agentmods.dev/skills/cjcsecurity/claude-tabletop/tabletop-exercise)
Your own site
<a href="https://agentmods.dev/skills/cjcsecurity/claude-tabletop/tabletop-exercise"><img src="https://agentmods.dev/badge/skills/cjcsecurity/claude-tabletop/tabletop-exercise.svg" alt="Measured on agentmods" height="20"></a>
Per session 147 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,109 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00147 $0.04109
Opus 5 $0.00073 $0.02055
Sonnet 5 $0.00029 $0.00822
Haiku 4.5 $0.00015 $0.00411

Measured 3d ago against content hash ca887d8ba013, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

tabletop-exercise scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/tabletop-exercise/SKILL.md · 209 lines

How it starts

The opening of the file, as written. The whole thing — 209 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/tabletop — generate a tabletop exercise runbook

You produce a complete tabletop exercise (TTX) package tailored to the project in the current working directory. Output is a folder of artifacts the user can run a real exercise from, plus an interactive HTML version for live facilitation.

Inputs

The skill is interactive: after a fast project recon (Step 1) it asks one round of setup questions (Step 1.5), then runs scenario triage (Step 2). Every input also accepts a flag, and passing a flag skips the matching prompt — so the same skill works flagless for first-timers and fully-flagged for scripted / repeat use. If all interactive inputs are supplied as flags, Step 1.5 is skipped entirely.

Asked interactively (with flag fast-paths)

Input Flag Values Default
Duration --duration <len> 30m, 60m, 90m, half-day, full-day 90m
Audience / departments --audience <who> eng, eng+leadership, cross-functional, board eng+leadership
Difficulty --difficulty <lvl> basic, intermediate, advanced intermediate
Headcount --headcount <range> 2-4, 5-8, 9-15, 16+ 5-8
Scenario (Step 2 triage) --scenario <slug> any slug from references/scenario-library.md (triage picks from 3)

Flag-only (not surfaced interactively)

Flag Values Default Why flag-only
--domain <name> cybersec, prodsec, devops, privacy, data-ml, platform, mobile, ai-safety (inferred from recon) Recon usually picks the right domain; manual override is rare.
--frameworks <list> comma-sep: NIST-CSF, SOC2, PCI, ISO27001, HIPAA, GDPR, MITRE-ATTACK (off) Most exercises don't tag controls; opt-in keeps the prompt round focused.
--no-html (presence) (HTML on) Default-on; opting out is rare. Useful for smoke tests.
--campaign <name> string none Multi-session linked exercises — advanced / niche.

Read the full file on GitHub · 209 lines

Files

What ships with it

6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 209 lines · 147 tokens per session scan A ca887d8ba013

Subscribe to this mod's changes

tabletop-exercise is a skill published in the GitHub repository cjcsecurity/claude-tabletop (0 stars, last pushed 3mo ago), licensed Apache-2.0. It adds 147 tokens to every session and 4,109 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

hue

Meta-skill that generates new design language skills. Works on Claude Code and Codex. Use when the user says 'create a design skill', 'generate design language', 'new design system skill', 'design skill inspired by X', 'design skill from this screenshot', '/hue', or 'use hue'. Also triggers for 'remix my design skill'…

dominikmartn/hue · 84 tokens

thesis-figure-skill

生成学术论文配图:LaTeX/TikZ 代码(结构化图表,直接嵌入论文)或 draw.io XML (技术路线图、汇报配图)。自动按论文领域风格设计,编译验证后交付。 Use when the user asks for: 论文配图、画架构图、画流程图、TikZ 图、draw.io 学术图、复刻论文图、tikz/latex diagram。.

0xE1337/thesis-figure-skill · 107 tokens

tikz-figure-code

写出高质量、一次过编译、编辑安全的 TikZ/LaTeX 配图代码的工程基础技能。 教 agent 用「按构造布局」(positioning/fit/chains/anchor) 而非「手填绝对坐标」, 附 8 条硬约束、canonical 箭头、before/after 范例、一个静态检查入口 (lint.sh)。 Use when: 写/审 TikZ 或 LaTeX 图代码、修图的排版/对齐/溢出/箭头问题、 tikz layout、latex figure code、tikz 编译报错、CJK 中文图渲染成色块。.

0xE1337/thesis-figure-skill · 152 tokens

kling-ai

Write and improve prompts for Kling AI video generation, and pick the right Kling model for the job. Covers image-to-video, text-to-video, multi-shot storyboards, talking avatars from one photo plus audio, motion transfer, video editing of an existing clip, Element Reference for character consistency, Voice Control…

maciejdzierzek/kling-ai-prompt-generator · 89 tokens

FlowForge

TRIGGER when: user asks to draw, illustrate, or visualize any process, structure, or concept — "画个流程图", "draw an architecture diagram", "帮我画个对比图", "visualize this process", "make a diagram for this doc", or mentions 流程图/架构图/示意图/对比图/时序图/泳道图/时间线. Also trigger when user provides a document/article and asks for…

wentong2022-arch/flowforge-skill · 153 tokens

kimchi

Turn a raw product idea into build-ready docs — one doc per EPIC with locked decisions, exact API contracts, a story-by-story priority plan, and an execute.md handoff Claude can build from across sessions. Gets the clarity by interrogating the user through a roster of expert personas that grill, counter, and refuse to…

chitransh-cj/kimchi · 122 tokens