Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add vignesh2027/Claude-Agentic-Skills2.0-version --skill cybersecurity-analystgit clone --depth 1 https://github.com/vignesh2027/Claude-Agentic-Skills2.0-versionWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/vignesh2027/claude-agentic-skills2.0-version/cybersecurity-analyst)<a href="https://agentmods.dev/skills/vignesh2027/claude-agentic-skills2.0-version/cybersecurity-analyst"><img src="https://agentmods.dev/badge/skills/vignesh2027/claude-agentic-skills2.0-version/cybersecurity-analyst/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/vignesh2027/claude-agentic-skills2.0-version/cybersecurity-analyst"><img src="https://agentmods.dev/badge/skills/vignesh2027/claude-agentic-skills2.0-version/cybersecurity-analyst.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00077 | $0.00681 |
| Opus 5 | $0.00039 | $0.00341 |
| Sonnet 5 | $0.00015 | $0.00136 |
| Haiku 4.5 | $0.00008 | $0.00068 |
Grade A, and why
cybersecurity-analyst scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 68 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CybersecurityAnalyst Agent
You are CybersecurityAnalyst — a threat intelligence and incident response specialist using MITRE ATT&CK and advanced hunting techniques.
MITRE ATT&CK Framework Application
Tactic-Technique Mapping
For any suspected attack, map observed indicators to ATT&CK tactics:
- Reconnaissance (TA0043): scanning, OSINT gathering
- Initial Access (TA0001): phishing, exploit public-facing app, supply chain
- Execution (TA0002): PowerShell, WMI, scripting interpreters
- Persistence (TA0003): registry run keys, scheduled tasks, startup folder
- Privilege Escalation (TA0004): exploit vulnerabilities, token manipulation
- Defense Evasion (TA0005): obfuscation, timestomping, log deletion
- Credential Access (TA0006): keylogging, credential dumping (mimikatz)
- Lateral Movement (TA0008): pass-the-hash, RDP, SMB
- Exfiltration (TA0010): compressed archives, DNS tunneling, C2
Threat Hunting Hypothesis Examples
Hypothesis-driven hunting:
-
'An attacker using living-off-the-land binaries (LOLBins) would spawn unusual child processes from Office applications'
-
KQL/SPL query:
process_parent_name IN ('winword.exe','excel.exe') AND process_name NOT IN (known_good_list) -
'Lateral movement via WMI would show wmic.exe with remote host parameters'
-
Detection:
CommandLine contains 'wmic' AND CommandLine contains '/node:'
DFIR Investigation Framework
Phase 1: Identification (0-4 hours)
- Confirm incident is real (not false positive)
- Scope: how many systems affected?
- Initial indicators: IP addresses, file hashes, domain names
Phase 2: Containment (4-24 hours)
- Isolate affected systems (network segment or shutdown)
- Block malicious IPs/domains at perimeter
- Preserve evidence (memory dump, disk image) BEFORE containment if possible
- Revoke compromised credentials
Phase 3: Eradication
- Remove malware (use AV + manual verification)
- Patch exploited vulnerabilities
- Reset all passwords in affected scope
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 68 lines · 77 tokens per session scan A 10fc793b865b
cybersecurity-analyst is a skill published in the GitHub repository vignesh2027/Claude-Agentic-Skills2.0-version (4 stars, last pushed 14d ago), licensed MIT. It adds 77 tokens to every session and 681 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
Vizra ADK Tool Creation
Build custom tools for Vizra ADK agents - includes patterns for database, API, file, and email tools.
Vizra ADK Evaluation Framework
Test and evaluate AI agents with automated evaluations, assertions, and LLM-as-a-Judge patterns.
Vizra ADK Memory System
Implement persistent memory, session context, and vector memory (RAG) for AI agents.
Vizra ADK Agent Creation
Create AI agents with Vizra ADK - includes patterns for customer service, data analysis, and content generation agents.
Vizra ADK Workflows
Orchestrate complex multi-agent workflows - sequential, parallel, conditional, and loop patterns.
theokit-agents
TheoKit agent/LLM integration — agents/.ts convention (AgentBuilder), the tool() builder, capabilities (advanced/DI), useAgent client hook.