{
  "markdown": "# SecSkills\n\n**Security skills for [Claude Code](https://claude.com/claude-code) that encode\nthe *judgment* professionals bring, not another wrapper around a scanner.**\nOffense, defense, and the reverse-engineering and code-audit core both sides\nshare. Every skill is fact-checked against primary sources.\n\nClaude already knows what `nmap -sV` does. What it does not reliably hold is the\ndiscipline: trace a finding to demonstrated impact before you report it,\ncapture memory before someone reimages the box, refuse to ship a detection that\nwas never tested against production noise, notice the honeypot before you touch\nit. SecSkills is that discipline, written down and routed to the moment it\napplies.\n\nThree plugins in one marketplace. Install only the side you work:\n\n| Plugin | For |\n| --- | --- |\n| **`secskills-offense`** | Red team, pentest, offensive AppSec |\n| **`secskills-defense`** | DFIR, SOC, detection engineering, threat intel |\n| **`secskills-core`** | Reverse engineering, code/crypto audit, AI/MCP security, reporting; shared by both |\n\n```bash\n/plugin marketplace add trilwu/secskills\n\n# Offensive — red team / pentest / offensive AppSec\n/plugin install secskills-offense@secskills-marketplace\n/plugin install secskills-core@secskills-marketplace\n\n# Defensive — DFIR / SOC / detection\n/plugin install secskills-defense@secskills-marketplace\n/plugin install secskills-core@secskills-marketplace\n\n/reload-plugins\n```\n\nSkills reference their siblings by name across plugins. A hand-off to a skill\nyou did not install is an inert mention, so nothing breaks. You get the skills\nyou have.\n\n---\n\n## Who it's for\n\nSecSkills is built for four working roles. Each gets a coherent toolkit, not a\ngrab-bag.\n\n### 🔴 Red team / pentest → `offense` + `core`\n\nFull attack-chain methodology with the tradecraft judgment that separates a\nfinding from a footgun: recon and enumeration, Active Directory and Entra ID\n(Kerberos delegation, AD CS ESC1-16, DCSync), cloud and managed Kubernetes,\ncontainer escapes, mobile, wireless, and web/API/auth exploitation. Plus the\nengagement discipline most collections skip: **`recognizing-deception`**\n(spot the honeypot/canary before you trip it), **`maintaining-engagement-state`**\n(credential provenance and the cleanup register that survives a context\nwindow), and **`reporting-security-findings`**.\n\n### 🛡️ AppSec / code review → `core` (+ `offense` to prove impact)\n\nSource-audit methodology with a four-question verification gate, PR review that\nreads the lines a change *removed*, cryptography-misuse review, supply-chain and\nCI/CD auditing, and AI/LLM + MCP security. Language-agnostic by default, with\n**`auditing-php-applications`** for PHP's specific footguns (unserialize/`phar://`\nPOP chains, type-juggling auth bypass, `php://` wrappers) and\n**`hunting-web-backdoors`** for planted webshells. Reach into `offense` when you\nneed to demonstrate the bug, not just describe it. And when the target is big\nenough to warrant a campaign, **`orchestrating-vulnerability-research`** runs the\nhunt as an adversarial loop: builders hunt each slice, an independent critic\ntries to *refute* every candidate against the running target, and nothing counts\nuntil it is proven, not plausible.\n\n### 🔵 DFIR / incident response → `defense` + `core`\n\nPreserve-first response: memory/disk/network forensics, malware and shellcode\nanalysis, Windows endpoint DFIR, Linux persistence hunting, and cross-cloud\nincident investigation for **AWS, Azure, GCP, and M365/Entra**. Each is built\naround the audit-log defaults that decide whether a question is even\nanswerable. Backed by the RE core (native, Go/Rust/.NET, iOS, firmware,\npackers).\n\n### 🟣 SOC / detection engineering → `defense` + `core`\n\nThe high-volume work, done with base-rate discipline:\n**`triaging-security-alerts`** (the true / benign-true / false-positive\ndistinction that keeps a detection program alive), detection-as-code across\nSigma/YARA/Suricata with *real* false-positive analysis, hypothesis-driven\nthreat hunting, risk-based vulnerability management (KEV + EPSS, not raw CVSS),\nand finished threat intelligence with attribution discipline.\n\nCloud and Kubernetes are covered from **both** sides: `exploiting-cloud-platforms`\n/ `attacking-eks-gke-aks` for red, `hardening-cloud-posture` / `defending-kubernetes`\n/ `investigating-*-incidents` for blue, so purple-team work stays in one\nvocabulary.\n\n## What makes a skill\n\nEach skill is a methodology, not a command dump, with three things a cheat\nsheet does not give you:\n\n- **An explicit scope and hand-off.** Every skill says when to use a *different*\n  one, named in backticks. That is how the skills compose instead of colliding.\n- **A `Rationalizations to Reject` section:** the plausible-sounding shortcuts\n  that cause missed findings and bad calls, each with why it is wrong. This is\n  the highest-value part of most skills; it is the judgment a command list\n  cannot carry.\n- **Two tiers that stay out of your way.** *Domain* skills carry methodology for\n  a whole area and trigger on plain-language requests. *Procedure* skills cover\n  one exact target-and-toolchain that is rare and unrecoverable from general\n  knowledge (reversing a Flutter app with blutter, say), and load only when\n  their identifying evidence is present. Neither costs context until it applies.\n\n## Every skill is fact-checked, and dated\n\n**Every skill has been verified line-by-line against primary sources** (vendor\ndocs, RFCs, tool source) and carries a `verified:` date in frontmatter. That is\nthe whole point: the opposite of confidently-wrong AI output.\n\n```bash\npython3 scripts/validate.py --strict                 # \"Fact-checked ...: 92/92\"\ngrep -L \"^verified:\" secskills-*/skills/*/SKILL.md   # unverified skills (none)\n```\n\nWhat that pass caught is why it exists. The first sampled dozen skills held\n**31 factual errors, about 2.6 per skill**, so the whole collection was driven\nthrough the same pass. Cross-cutting sweeps then found the high-impact ones:\nCrackMapExec archived since 2023 (14 dead invocations → NetExec/`nxc`), the\nretired AzureAD PowerShell module (→ Microsoft Graph), Volatility's entry point\nwrong in ~40 commands (`vol`, not `volatility3`), a fabricated Sigma `utf8`\nmodifier, and stale M365 audit-log retention that would read an empty 90-day\nwindow as \"no activity\" when six months of history existed.\n\nTwo honest caveats:\n\n- **`verified:` is dated, not eternal.** Tool flags, CVE version bounds,\n  retention windows, and API paths drift. Trust the methodology (the\n  sequencing, the scope, the *Rationalizations to Reject*) and re-confirm any\n  specific before it lands in a deliverable. The re-verification method is\n  itself a skill: `.claude/skills/verifying-skill-accuracy`.\n- **CI checks form, not truth.** `validate.py`, `sync_attack.py`, and\n  `run_evals.py` verify structure, the ATT&CK index, and routing against\n  self-authored cases. A green run means well-formed; the `verified:` dates are\n  the accuracy signal.\n\n## Skills\n\n### Code and application security\n\n| Skill | Use it for |\n| --- | --- |\n| `auditing-code-for-vulnerabilities` | Full source audit: context → attack surface → bug-class hunt → variant analysis, with a four-question verification gate |\n| `orchestrating-vulnerability-research` | Run a discovery campaign across a codebase, binary, or live target: split the surface into slices, hunt each with a builder agent, and have a separate critic refute every candidate against the running artifact before it counts |\n| `auditing-php-applications` | PHP-specific bugs: unserialize/`phar://` POP chains, type juggling, `php://` wrappers, superglobal trust, WordPress/Magento/Laravel |\n| `hunting-web-backdoors` | Sweep a web tree for planted webshells: static deobfuscation, append-infections, known shell families as leads |\n| `reviewing-code-changes` | Security review of a diff, branch, or PR, including the lines the change *removed* |\n| `testing-web-applications` | Black-box web testing: injection, auth, JWT, SSRF, uploads |\n| `testing-apis` | REST and GraphQL: BOLA, mass assignment, rate limits |\n| `reviewing-cryptography` | Crypto misuse: AEAD, nonces, key management, timing, TLS, JWT |\n| `auditing-supply-chain` | Dependencies, malicious packages, GitHub Actions, SBOM, provenance |\n| `auditing-mcp-servers` | Reviewing an MCP server: tool-definition injection, token passthrough, per-tool authorization |\n| `vetting-agent-extensions` | Deciding whether a third-party skill, plugin, or MCP server is safe to install: context-loaded content as injection surface, config that runs on startup, trust verdict |\n| `securing-ai-systems` | LLM and agentic security: prompt injection, tool authority, RAG isolation, the lethal trifecta |\n| `exploiting-web3-smart-contracts` | Solidity and smart contract auditing |\n\n### Defense, detection, and response\n\n| Skill | Use it for |\n| --- | --- |\n| `triaging-security-alerts` | Work an alert queue to a defensible disposition: true / benign-true / false-positive, base rates, time-boxing |\n| `responding-to-incidents` | DFIR: evidence preservation, artifact analysis, timelining, scoping, containment |\n| `analyzing-malware` | Containment-first sample analysis, config and C2 extraction, IOC and YARA output |\n| `engineering-detections` | Sigma/YARA/Suricata authoring with real false-positive analysis |\n| `hunting-threats` | Hypothesis-driven hunting with stack counting and outlier analysis |\n| `managing-vulnerabilities` | Risk-based remediation order: KEV + EPSS + reachability + asset value, SSVC, not raw CVSS |\n| `producing-threat-intelligence` | Indicator pivoting, actor/campaign tracking, attribution discipline, finished intel products |\n| `reporting-security-findings` | Severity, proof of concept, report structure, disclosure |\n\n### Offensive operations\n\n| Skill | Use it for |\n| --- | --- |\n| `recognizing-deception` | Spot honeypots, canary tokens, and decoy accounts before you trip them |\n| `maintaining-engagement-state` | Credential provenance, access inventory, and the cleanup register across a multi-day engagement |\n| `performing-reconnaissance` | OSINT, subdomain enumeration, attack surface mapping |\n| `enumerating-network-services` | Service enumeration and exploitation |\n| `attacking-active-directory` | Kerberoasting, BloodHound, DCSync, lateral movement |\n| `escalating-linux-privileges` | SUID, capabilities, sudo, cron, kernel |\n| `escalating-windows-privileges` | Services, DLL hijacking, tokens, potato attacks |\n| `exploiting-containers` | Docker and Kubernetes escapes and misconfiguration |\n| `exploiting-cloud-platforms` | AWS, Azure, GCP enumeration and abuse |\n| `testing-mobile-applications` | Android and iOS assessment |\n| `attacking-wireless-networks` | Wi-Fi attacks and capture |\n| `cracking-passwords` | Hash identification and offline cracking |\n| `establishing-persistence` | Post-exploitation persistence |\n| `transferring-files` | File transfer and exfiltration channels |\n| `performing-social-engineering` | Authorized phishing and pretexting |\n| `exploiting-memory-corruption` | Turn a crash into a working exploit: ROP, heap grooming, defeating ASLR/NX/canary/RELRO |\n| `testing-thick-clients` | Desktop fat-client testing: non-HTTP proxying, config/memory secrets, client-side trust bypass, two-tier DB access |\n| `attacking-hardware-interfaces` | Physical device surface: UART/JTAG, SPI flash-off, secure-boot triage, sub-GHz SDR replay feasibility |\n\n### Web and API procedure skills\n\n| Skill | Triggers on |\n| --- | --- |\n| `exploiting-ssrf` | Any feature that fetches a user-supplied URL; webhooks, importers, renderers |\n| `exploiting-deserialization` | `rO0AB`, `AAEAAAD`, `O:`, `gAJ` in a cookie or parameter |\n| `attacking-graphql` | `/graphql`, a `query`/`mutation` body, `{data, errors}` envelope |\n| `attacking-grpc-protobuf` | HTTP/2 with `application/grpc`, opaque binary bodies |\n| `attacking-jwt` | A token starting `eyJ` in a header, cookie, or body |\n| `attacking-oauth-oidc` | `/authorize`, `redirect_uri`, `state=`, \"Sign in with X\", OIDC discovery |\n| `attacking-saml` | `SAMLResponse`, `<saml:Assertion>`, `/saml/acs`, IdP federation |\n| `exploiting-xxe` | An endpoint parsing XML, SOAP, SVG, or Office (OOXML) files |\n\n### Binary and runtime procedure skills\n\n`analyzing-binaries` is the native reverse-engineering domain skill (triage,\ndisassembly with Ghidra/radare2/IDA, and instrumentation) that the language-\nand framework-specific procedures below hand back to.\n\n| Skill | Triggers on |\n| --- | --- |\n| `analyzing-binaries` | An unknown native executable: format triage, disassembly, dynamic instrumentation |\n| `analyzing-go-binaries` | `runtime.main`, `go:buildid`, a huge \"stripped\" binary |\n| `analyzing-rust-binaries` | `rustc version`, `core::panicking`, `_R`/`_ZN` symbols |\n| `analyzing-dotnet-assemblies` | Managed PE, mangled names, `Assembly.Load` loaders |\n| `analyzing-macos-binaries` | A `.app`/Mach-O on macOS: entitlements, XPC auth, dylib hijack, TCC |\n| `unpacking-protected-binaries` | High entropy, three imports, `UPX0`/`.vmp0` sections |\n| `devirtualizing-vm-protected-code` | A giant fetch-decode-dispatch loop: VMProtect/Themida/custom VM lifting |\n| `reversing-obfuscated-javascript` | A minified/obfuscated web bundle, `_0x` names, a reachable `.js.map` |\n| `reversing-browser-extensions` | A CRX/XPI: manifest permissions and the page↔content↔background trust boundary |\n| `reversing-network-protocols` | A proprietary binary protocol Wireshark shows as raw bytes |\n| `diffing-binary-patches` | Two versions of a DLL/ELF: find the fixed bug for 1-day analysis |\n\n### Mobile procedure skills\n\nNarrow by design: each triggers on the artifacts or the symptom that\nidentifies the situation, and hands back to the domain skill when done.\n\n| Skill | Triggers on |\n| --- | --- |\n| `bypassing-mobile-pinning` | TLS handshake alert, empty proxy, \"network error\" with the proxy on |\n| `bypassing-root-jailbreak-detection` | App exits on a rooted device, or dies when Frida attaches |\n| `analyzing-ios-binaries` | IPA with `cryptid 1`, Mach-O, `class-dump` returning nothing |\n| `testing-mobile-ipc` | Exported components, deep links, URL schemes, content providers |\n| `reversing-flutter-apps` | `libapp.so`, `libflutter.so`, `flutter_assets/` |\n| `reversing-react-native-apps` | `index.android.bundle`, `libhermes.so`, `main.jsbundle` |\n| `reversing-unity-il2cpp` | `global-metadata.dat`, `libil2cpp.so`, `Assembly-CSharp.dll` |\n| `reversing-xamarin-maui` | `libmonodroid.so`, `assemblies.blob`, `libxamarin-app.so` |\n\n### Active Directory and identity procedure skills\n\n| Skill | Triggers on |\n| --- | --- |\n| `abusing-adcs` | A CA in the domain, `certipy find` flagging a template, ESC1-ESC16 |\n| `attacking-kerberos-delegation` | Unconstrained/constrained/RBCD delegation, `GenericWrite` over a computer |\n| `attacking-entra-id` | Entra ID / Azure AD as the target: tokens, PRTs, consent grants, hybrid sync |\n\n### Cloud, container, and Kubernetes skills\n\n| Skill | Triggers on |\n| --- | --- |\n| `attacking-eks-gke-aks` | A managed Kubernetes cluster: pod-to-cloud IMDS, IRSA/Workload Identity, k8s RBAC |\n| `defending-kubernetes` | Hardening/monitoring a cluster: RBAC by capability, Pod Security Admission, audit logging |\n| `hardening-cloud-posture` | Proactive AWS/Azure/GCP posture: attack-path ranking, CSPM triage, org guardrails |\n| `attacking-serverless` | Lambda / Azure Functions / Cloud Functions / Workers; event injection, execution-role abuse |\n| `abusing-ci-cd-oidc` | GitHub Actions / GitLab CI / Jenkins, OIDC federation with broad trust policies |\n| `escaping-hardened-containers` | Seccomp on, capabilities dropped, `--privileged` absent, obvious escapes blocked |\n\n### DFIR and detection procedure skills\n\n| Skill | Triggers on |\n| --- | --- |\n| `analyzing-memory-images` | A RAM capture to work with Volatility: injected code, in-memory creds |\n| `analyzing-disk-images` | An `.E01`/`.dd`/`.vmdk`: deleted-file recovery, carving, super-timeline |\n| `investigating-windows-endpoints` | A Windows host: EVTX/Sysmon, prefetch, amcache, `$MFT`/USN, persistence |\n| `investigating-m365-entra` | A cloud-only compromise: UAL, sign-in logs, OAuth consent grants, mailbox rules |\n| `investigating-aws-incidents` | Exposed AWS keys, anomalous CloudTrail, a GuardDuty finding, IAM persistence |\n| `investigating-azure-incidents` | Anomalous Azure Activity Log, a Defender for Cloud alert, service-principal abuse |\n| `investigating-gcp-incidents` | A leaked service-account key, GCP audit-log gaps, a Security Command Center finding |\n| `analyzing-network-traffic` | A `.pcap`/`.pcapng`: C2 beacons, DNS tunneling, JA3/TLS, exfil, file carving |\n| `analyzing-phishing-emails` | A reported `.eml`/`.msg`: headers, SPF/DKIM/DMARC, links, attachments |\n| `analyzing-shellcode` | A raw position-independent blob: decoder stubs, PEB-walk/API-hash, stagers |\n| `analyzing-linux-persistence` | Finding how an attacker persisted on a Linux host across every init path |\n| `writing-sigma-rules` | Authoring a portable Sigma rule: field taxonomy, modifiers, backend conversion |\n| `writing-yara-rules` | Authoring a durable YARA rule for a file/memory artifact or malware family |\n\n### Specialist procedure skills\n\n| Skill | Triggers on |\n| --- | --- |\n| `testing-ics-ot-protocols` | Modbus/502, DNP3, S7comm/102, OPC UA, BACnet on a SCADA/OT network |\n| `analyzing-firmware-images` | A firmware update file or dump: `binwalk`, filesystem carving, cross-arch emulation |\n| `attacking-bluetooth-nfc` | BLE GATT enumeration, NFC/MIFARE card cloning, RF sniffing |\n\n### Navigation\n\n| Skill | Use it for |\n| --- | --- |\n| `mapping-attack-techniques` | Resolving an ATT&CK ID, tactic, or intel report to the skill that holds the procedure; purple-team loop and coverage reporting |\n\nTechniques are indexed in [`secskills-core/ttp-index.json`](secskills-core/ttp-index.json)\n(143 mapped, spanning all three plugins), which generates the `## ATT&CK\nCoverage` section in each skill. CI fails if a section drifts from the index,\nand skills that use a different framework (ATLAS for AI, the Mobile matrix,\nCWE for code-level work) are declared as such rather than counted as coverage.\n\n## In practice\n\n**Hunt a hacked site (DFIR / AppSec)**\n\n```\n\"This WordPress site is redirecting to spam and grep for eval comes back empty.\"\n```\n\nExplains that an empty grep is not a clean tree (concatenation and callback\nsinks evade it), then diffs against a pristine copy, checks `functions.php` for\nappend-infection, and decodes any obfuscation *statically*, never by running it.\n\n**Work an alert (SOC)**\n\n```\n\"EDR critical: a signed vendor binary opened an LSASS handle at 03:00, 47th time.\"\n```\n\nReads it as a likely *benign* true positive, warns against filing it as a false\npositive (which weakens a working rule), and sends an authorized-context filter\nto detection engineering instead.\n\n**Drive a domain (Red team)**\n\n```\n\"BloodHound flags svc_backup_admin: DA, SPN set, but no logon history. Roast it?\"\n```\n\nFlags the profile as a probable honeyuser whose Kerberoast raises a\nhigh-fidelity alert, and routes around it, recording provenance as it goes.\n\n**Investigate GCP (DFIR)**\n\n```\n\"A leaked service-account key was used. Did they read our storage buckets?\"\n```\n\nAnswers with the audit-log defaults: GCP Data Access logging is off unless\nenabled in advance, so it reports a *visibility gap*, not \"no exfiltration.\"\n\n**Assess an AI feature (AppSec)**\n\n```\n\"Review this RAG agent for prompt injection.\"\n```\n\nChecks whether the lethal trifecta closes (private data, untrusted content, and\negress in one agent) before any payload, and refuses prompt-level defenses as a\ncontrol.\n\n**Run a discovery campaign (AppSec / Red team)**\n\n```\n\"Find previously-unknown bugs in this service. Fan out agents, and don't count anything you can't prove.\"\n```\n\nSplits the attack surface into independent slices and hunts each with its own\nbuilder agent, then hands every candidate to a *separate* critic that tries to\nrefute it against the running target: a reproduced trigger or a live response,\nnever the hunter's own writeup. It kills the plausible-but-safe candidate (the\n`subprocess` call that looks injectable but passes an argv list, so nothing\nexecutes) and confirms the real ones, then reconciles across slices to surface\nthe chain no single hunter could see.\n\n## Where this fits\n\nSecSkills is domain expertise, not a scanner. It complements first-party tooling\nrather than replacing it:\n\n| Layer | Tool |\n| --- | --- |\n| While Claude writes code | [`security-guidance`](https://code.claude.com/docs/en/security-guidance) plugin |\n| One-pass branch review | Built-in `/security-review` |\n| Deep multi-agent scan | [`claude-security`](https://code.claude.com/docs/en/claude-security) plugin |\n| **Domain methodology and judgment** | **SecSkills** |\n| In CI | Your existing SAST and dependency scanners |\n\nThe scanners find what they have rules for; the skills supply the reasoning\naround them.\n\n## Requirements\n\nClaude Code, and the tools a given technique calls for (`nmap`, `semgrep`,\n`vol` (Volatility 3), `capa`, `ghidra`, …) installed separately. The plugin\nsupplies knowledge and method, not binaries.\n\n## Antivirus false positives\n\nSome skills document attacker artefacts verbatim: webshell one-liners,\ndownload cradles, persistence snippets. Antivirus engines match on file\n*content*, not extension, so a Markdown file quoting China Chopper looks the\nsame to a signature scanner as a live `.php` webshell. Microsoft Defender has\nquarantined skill files under names like `Backdoor:PHP/Chopper.B!dha` and\n`Backdoor:PHP/Perhetshell.B!dha`.\n\nThese are false positives. Nothing in this repo executes: the files are\nMarkdown, there are no binaries, no packed or encoded payloads, and no\ninstaller. The detections were signature hits on documented indicators,\nincluding, at one point, on `hunting-web-backdoors`, a *defensive* skill\nflagged for containing the IOC it teaches you to hunt.\n\nWhere a payload string was getting whole skills quarantined, the identifiers\nare now bracket-broken (`syst[e]m`, `ev[a]l`, `$_G[E]T`) with a note at each\nsite. Detection regexes and hunting patterns are left intact, since breaking\nthose would make the defensive skills wrong.\n\nIf your scanner still quarantines a file, exclude the plugin path rather than\ndisabling protection:\n\n```powershell\nAdd-MpPreference -ExclusionPath \"$env:USERPROFILE\\.claude\\plugins\"\n```\n\nPlease open an issue with the detection name and file path if you hit a new\none. That's what pins down which string is responsible.\n\n## Contributing\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md) for the authoring standard. Before\nopening a PR:\n\n```bash\npython3 scripts/validate.py --strict     # frontmatter, sections, manifests, verified count\npython3 scripts/sync_attack.py --check   # ATT&CK sections match the index\npython3 scripts/run_evals.py --check     # every skill has a trigger eval\npython3 scripts/build_site.py --check    # the docs/ site is in sync\n```\n\nCI runs the same checks. Every new skill ships with at least one\ntrigger-accuracy case in [`evals/cases.jsonl`](evals/README.md): a realistic\nrequest labelled with the skill that should activate, plus a `trap_for` case\nwhere it sits near an existing skill, so routing stays correct as the collection\ngrows. Two repo-local skills, `authoring-security-skills` and\n`verifying-skill-accuracy`, encode the standard and the fact-checking method.\nContributions must serve authorized security work; no working malware, implants,\nor evasion tooling.\n\n## Legal\n\n**For authorized use only.** Penetration testing with written permission,\nin-scope bug bounty work, research on systems you control, education and CTFs,\nand defensive operations.\n\nNot for unauthorized access, illegal activity, or violating terms of service.\nYou are responsible for obtaining authorization and complying with applicable\nlaw. Provided as-is, without warranty; the authors accept no liability for\nmisuse.\n\n## Website\n\nA browsable site (role-based prompts, a searchable catalog, and a page per\nskill with its full methodology) is generated from this repo into\n[`docs/`](docs/) by `scripts/build_site.py` (stdlib only, no drift: CI fails if\nit is stale). Serve it with GitHub Pages → Settings → Pages → Source: `main`\n/ `docs`.\n\n## License\n\nMIT. See [LICENSE](LICENSE).\n\n## Related work\n\nWorth knowing about, and in several cases worth installing alongside this:\n\n- [trailofbits/skills](https://github.com/trailofbits/skills): deep code-audit\n  workflows, Semgrep/CodeQL rule authoring, verification, and secure contracts\n- [anthropics/claude-plugins-official](https://github.com/anthropics/claude-plugins-official):\n  the `security-guidance` and `claude-security` plugins\n- [OWASP ASVS](https://owasp.org/www-project-application-security-verification-standard/),\n  [MITRE ATT&CK](https://attack.mitre.org/),\n  [Sigma](https://github.com/SigmaHQ/sigma),\n  [Atomic Red Team](https://github.com/redcanaryco/atomic-red-team)\n",
  "bytes": 25036,
  "sha": "a69f3b1d73e085c26a0b7a3457e341474811191da83342f81d7c4538af33f28a",
  "repo_slug": "trilwu/secskills",
  "fonte": "repo",
  "truncated": false,
  "api": "https://api.agentalog.com/api/listings/skl_trilwu_secskills_transferring_files_4328f5c3/readme"
}