Analyzes security risks, threats, and vulnerabilities using industry frameworks like STRIDE, MITRE ATT&CK, and CIA triad.
Works with
Applies threat modeling, attack surface analysis, and defense-in-depth principles to identify security weaknesses across systems, applications, and architectures
Evaluates confidentiality, integrity, and availability risks; assesses threat actors, attack vectors, and defensive control effectiveness
Provides incident analysis, vulnerability assessment, securit
AI-first code editor with Composer
Before installing skills in Cursor, ensure your development environment meets these requirements:
node --versioncybersecurity-analystExecute the skills CLI command in your project's root directory to begin installation:
Fetches cybersecurity-analyst from rysweet/amplihack and configures it for Cursor.
The CLI shows a list of agents. Use arrow keys and space to select Cursor:
Confirm successful installation by checking the skill directory location:
Restart Cursor to activate cybersecurity-analyst. Access via /cybersecurity-analyst in your agent's command palette.
We perform automated surface-level scans (Gen AI Scanner, Socket, Snyk) during installation. These checks detect common vulnerabilities but do not guarantee complete security. Always review skill source code and verify the publisher's reputation before production use.
Skills execute code in your environment. Always review source, verify the publisher, and test in isolation before production.
Submit your Claude Code skill and start earning
Create detailed user stories, acceptance criteria, and feature specs
Example
Generate user stories for 'password reset feature' with acceptance criteria, edge cases, and test scenarios
Reduce spec writing time by 50%, ensure comprehensive coverage
Research competitors, compare features, identify gaps
Example
Analyze 5 competitor products, create feature comparison matrix, suggest differentiation opportunities
Complete competitive research in 2 hours instead of 2 days
Evaluate features using frameworks (RICE, ICE, Kano) and create prioritized backlogs
Example
Score 20 feature ideas using RICE framework, generate prioritized roadmap with rationale
0
total installs
0
this week
44
GitHub stars
0
upvotes
Run in your terminal
0
installs
0
this week
44
stars
Analyze events through the disciplinary lens of cybersecurity, applying rigorous security frameworks (CIA triad, defense-in-depth, zero-trust), threat modeling methodologies (STRIDE, PASTA, VAST), attack surface analysis, and industry standards (NIST, ISO 27001, MITRE ATT&CK) to understand security risks, identify vulnerabilities, assess threat actors and attack vectors, evaluate defensive controls, and recommend risk mitigation strategies.
Cybersecurity analysis rests on fundamental principles:
Defense in Depth: No single security control is perfect. Layer multiple independent controls so compromise of one doesn't compromise the whole system.
Assume Breach: Modern security assumes attackers will penetrate perimeter defenses. Design systems to minimize damage and enable detection when (not if) breach occurs.
Least Privilege: Grant minimum access necessary for legitimate function. Every excess permission is an opportunity for exploitation.
Zero Trust: Never trust, always verify. Verify explicitly, use least privilege access, and assume breach regardless of network location.
Security by Design: Security cannot be bolted on afterward. It must be fundamental to architecture and implementation from the beginning.
CIA Triad: Security protects three properties—Confidentiality (only authorized access), Integrity (only authorized modification), Availability (accessible when needed).
Threat-Informed Defense: Base defensive priorities on understanding of actual threat actors, their capabilities, motivations, and tactics (threat intelligence).
Risk-Based Approach: Perfect security is impossible. Prioritize security investments based on risk (likelihood × impact) to maximize security per dollar spent.
Components:
Confidentiality: Information accessible only to authorized entities
Integrity: Information modifiable only by authorized entities in authorized ways
Availability: Information and systems accessible when needed by authorized entities
Extensions:
Application: Every security analysis should identify which aspects of CIA triad are at risk and how controls protect each.
Sources:
Principle: Deploy multiple layers of security controls so compromise of one layer doesn't compromise entire system.
Historical Origin: Military defensive strategy—multiple concentric perimeter defenses
Security Layers:
Key Insight: Redundancy is not waste—it's resilience. Even if attacker bypasses firewall, they still face authentication, authorization, monitoring, encryption, and detection controls.
Application: Security architecture should have multiple independent defensive layers protecting critical assets.
Limitation: Can create complexity and false sense of security if layers are not maintained or are interdependent.
Sources:
Core Principle: "Never trust, always verify" regardless of network location
Contrast with Perimeter Model: Traditional security assumed internal network is trusted ("castle and moat"). Zero trust assumes no network location is trusted.
Key Tenets (NIST SP 800-207):
Components:
Drivers:
Application: Modern security architectures should be designed with zero trust principles, especially for cloud and hybrid environments.
Sources:
Definition: Structured approach to identify and prioritize potential threats to a system
Purpose: Proactively identify security issues during design phase when fixes are cheapest
Benefits:
Common Methodologies:
STRIDE (Microsoft):
PASTA (Process for Attack Simulation and Threat Analysis):
VAST (Visual, Agile, and Simple Threat modeling):
Application: Use threat modeling for new features, architecture changes, or security reviews.
Sources:
Description: Knowledge base of adversary tactics and techniques based on real-world observations
Purpose: Understand how attackers operate to inform defense, detection, and threat hunting
Structure:
14 Tactics (Enterprise Matrix):
Application:
Value: Common language for describing attacker behavior; basis for threat-informed defense
Sources:
Definition: Identification and assessment of all points where unauthorized user could enter or extract data from system
Components:
Attack Surface Elements:
Attack Vectors: Methods attackers use to exploit attack surface
Analysis Process:
Metrics:
Application: Reducing attack surface is fundamental defensive strategy. Eliminate unnecessary exposure.
Sources:
Purpose: Quantify and prioritize security risks to guide resource allocation
Common Frameworks:
CVSS (Common Vulnerability Scoring System):
FAIR (Factor Analysis of Information Risk):
NIST Risk Management Framework (RMF):
Qualitative vs. Quantitative:
Application: Risk assessment informs prioritization. Not all vulnerabilities are equally important—focus on highest risks.
Sources:
Purpose: Structured set of security controls to achieve security objectives
Major Frameworks:
NIST Cybersecurity Framework:
NIST SP 800-53 (Security and Privacy Controls):
CIS Controls (Center for Internet Security):
ISO/IEC 27001:
Application: Use frameworks to:
Sources:
Definition: Structured approach to handling security incidents
Standard Model (NIST SP 800-61):
Phase 1: Preparation
Phase 2: Detection and Analysis
Phase 3: Containment, Eradication, and Recovery
Phase 4: Post-Incident Activity
Key Concepts:
Metrics:
Application: Effective incident response minimizes damage, reduces recovery time, and captures learning.
Sources:
Purpose: Integrate security into software development process
Microsoft SDL Phases:
Key Practices:
OWASP SAMM (Software Assurance Maturity Model):
Application: Security must be integrated throughout development lifecycle, not just at the end.
Sources:
Purpose: Understand adversaries, their capabilities, tactics, and targets to inform defense
Types of Threat Intelligence:
Strategic: High-level trends for executives
Operational: Campaign-level information for security operations
Tactical: Technical indicators for immediate defense
Analytical Process:
Frameworks:
Application: Threat intelligence enables proactive, threat-informed
Make data-driven prioritization decisions faster
Draft PRDs, status updates, and stakeholder presentations
Example
Create executive summary of Q3 roadmap, monthly progress report, feature launch announcement
Save 3-5 hours/week on communication overhead
Prerequisites
Time Estimate
30-60 minutes to see productivity improvements
Steps
Common Pitfalls
✓ Do
✗ Don't
💡 Pro Tips
✓ Use when
Use for user story writing, competitive research, roadmap prioritization, stakeholder communication, and PRD drafting. Best for reducing repetitive documentation and research work.
✗ Avoid when
Avoid for strategic product vision (requires deep customer empathy), pricing decisions (needs market and financial expertise), or when face-to-face customer discovery is more valuable than speed.
mattpocock/skills
parcadei/continuous-claude-v3
cursor/plugins
ailabs-393/ai-labs-claude-skills
ailabs-393/ai-labs-claude-skills
pproenca/dot-skills
Solid pick for teams standardizing on skills: cybersecurity-analyst is focused, and the summary matches what you get after install.
Useful defaults in cybersecurity-analyst — fewer surprises than typical one-off scripts, and it plays nicely with `npx skills` flows.
We added cybersecurity-analyst from the explainx registry; install was straightforward and the SKILL.md answered most questions upfront.
Registry listing for cybersecurity-analyst matched our evaluation — installs cleanly and behaves as described in the markdown.
cybersecurity-analyst reduced setup friction for our internal harness; good balance of opinion and flexibility.
cybersecurity-analyst reduced setup friction for our internal harness; good balance of opinion and flexibility.
Registry listing for cybersecurity-analyst matched our evaluation — installs cleanly and behaves as described in the markdown.
I recommend cybersecurity-analyst for anyone iterating fast on agent tooling; clear intent and a small, reviewable surface area.
cybersecurity-analyst fits our agent workflows well — practical, well scoped, and easy to wire into existing repos.
cybersecurity-analyst is among the better-maintained entries we tried; worth keeping pinned for repeat workflows.
showing 1-10 of 75