Youngmaidainon/Agent-Level-Up

820+ production-grade skills and playbooks for AI coding agents (Antigravity, Claude Code, Cursor). Features DevSecOps, CTF & Security Ops, Full-Stack Architecture, and Caveman token optimizer.

3Stars on the repository
200Mods indexed here, across every type
17d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Design identity governance and lifecycle (IGA) programs on platforms like SailPoint, Saviynt, or Entra ID Governance, covering joiner-mover-leaver (JML) automation, role mining, access requests, periodic recertification, and orphaned-account remediation sourced from an HR feed. Use when automating cross-system JML…

not rated 3 17d ago A 103 tokens copy · 89% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident…

not rated 3 17d ago A 66 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Designs and documents structured incident response playbooks with step-by-step procedures per incident type, decision trees, escalation criteria, RACI matrices, and SOAR platform integration, aligned to NIST SP 800-61r3 and SANS PICERL. Use when creating or maturing an IR program, documenting response runbooks for a…

not rated 3 17d ago A 86 tokens copy · 89% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation documentation. Use when reconstructing the sequence of events during an incident investigation or when multiple analysts…

not rated 3 17d ago B 75 tokens copy · 94% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Build an automated pipeline that ingests raw IOCs (URLs, IPs, domains, emails), normalizes and deduplicates them, then produces defanged renderings for safe human reading alongside canonical STIX 2.1 bundles distributed via TAXII servers, MISP, or email reports. Use when preparing indicators of compromise for safe…

not rated 3 17d ago A 93 tokens original MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Build an automated IOC enrichment pipeline on OpenCTI (STIX 2.1 native threat intel platform) using its internal enrichment connectors to pull context from VirusTotal, Shodan, AbuseIPDB, and GreyNoise, correlate indicators with known actors/campaigns, and score them for analyst prioritization. Use when deploying…

not rated 3 17d ago A 93 tokens copy · 89% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Build structured communication templates for malware incidents (ransomware, wiper, trojan, worm), covering internal stakeholder notifications, executive briefings, technical advisories for IT teams, customer notifications, and regulatory disclosures, with severity-based escalation procedures. Use when drafting or…

not rated 3 17d ago A 74 tokens copy · 92% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Establish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within risk-based remediation SLAs, from advisory review through validation. Use when building or improving a monthly patch management…

not rated 3 17d ago A 80 tokens copy · 91% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Implement a phishing report button (Microsoft 365 built-in Report button or third-party like KnowBe4/Cofense) in email clients with a SOAR-driven automated triage workflow that classifies reported emails, extracts IOCs, takes remediation actions, and gives feedback to reporters. Use when deploying user-reported…

not rated 3 17d ago A 84 tokens copy · 92% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework, covering preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Use when creating or updating a ransomware playbook, running a…

not rated 3 17d ago A 87 tokens copy · 88% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex needs its repo

Deploy and configure the Havoc C2 framework (teamserver, HTTPS/HTTP/SMB listeners, Nginx redirectors, and Demon agents) with malleable traffic profiles and OPSEC-hardened infrastructure for authorized red team operations. Use when standing up or hardening Havoc C2 infrastructure for a written, authorized adversary…

not rated 3 17d ago A 85 tokens copy · 98% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Apply bottom-up and top-down role mining techniques, including clustering algorithms and formal concept analysis, to discover optimal RBAC roles from existing user-permission assignments, consolidating overlapping roles and enforcing least privilege. Use when an identity program needs to reduce role explosion or…

not rated 3 17d ago A 71 tokens copy · 94% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Build a structured SOC escalation matrix defining severity tiers, response SLAs, tiered escalation paths, and notification procedures for security incidents, using context-driven criteria that combine business risk, asset criticality, and data sensitivity. Use when designing or revising how a SOC triages and escalates…

not rated 3 17d ago A 71 tokens copy · 95% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when SOC leadership needs operational visibility, continuous improvement tracking, or executive-level…

not rated 3 17d ago A 73 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when SOC teams need formalized response procedures for ransomware incidents aligned to NIST SP 800-61 and…

not rated 3 17d ago A 76 tokens copy · 89% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py, psort.py, and psteal.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then triage and filter the results in Timesketch. Use when reconstructing the full sequence of events on a compromised or…

not rated 3 17d ago B 101 tokens copy · 92% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Build threat actor profiles by collecting OSINT from vendor reports, paste sites, dark web forums, social media, and code repos, correlating indicators, mapping adversary infrastructure with tools like Maltego and SpiderFoot, and producing structured dossiers of motivations, capabilities, infrastructure, and TTPs. Use…

not rated 3 17d ago A 84 tokens copy · 91% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization and STIX/TAXII-based integration with Splunk, Elasticsearch, and SOAR platforms. Use when standing up centralized IOC…

not rated 3 17d ago A 82 tokens copy · 86% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender, Splunk, Elastic, Sysmon, Velociraptor, Sigma) and documents findings in a standardized hunt report. Use when planning or…

not rated 3 17d ago A 96 tokens copy · 97% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework. Use when wiring threat intel into Splunk correlation searches to flag IOC…

not rated 3 17d ago A 71 tokens copy · 89% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion…

not rated 3 17d ago A 74 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Design and deploy a Threat Intelligence Platform (TIP) by integrating open-source CTI tools (MISP, OpenCTI, TheHive, Cortex) into a unified system with feed ingestion pipelines, enrichment workflows, STIX/TAXII interoperability, and analyst dashboards. Use when architecting or standing up a centralized CTI platform to…

not rated 3 17d ago A 86 tokens original MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Implement a vulnerability aging dashboard and SLA tracking system that measures time-to-remediation against severity-based deadlines (e.g. 14 days critical, 30 days high, 60 days medium, 90 days low), with automated escalations and compliance metrics reporting. Use when designing SLA policies, building…

not rated 3 17d ago A 81 tokens copy · 91% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Deploy DefectDojo as a centralized vulnerability management dashboard that ingests findings from 200+ security scanners, deduplicates results, tracks remediation metrics, and integrates with CI/CD, Jira ticketing, and Slack notifications via its REST API. Use when consolidating scanner output into one dashboard or…

not rated 3 17d ago A 77 tokens copy · 86% MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: