offensive-security▌
113 indexed skills · max 10 per page
security-assessment
whyashthakker/beam-cli · security-assessment
### security-assessment - Coordinate a scoped security assessment across AI agents, applications, agent infrastructure, and supplied evidence. Route work to relevant - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
dependency-supply-chain
whyashthakker/beam-cli · dependency-supply-chain
### dependency-supply-chain - Review dependency changes and executable supply-chain inputs used by AI agents, skills, MCP servers, and applications. Inspect manifests, lo - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
mcp-scanner
whyashthakker/beam-cli · mcp-scanner
### mcp-scanner - Scan MCP configurations, server source, package references, and supplied tool manifests before connection or after updates. Review executabl - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
security-reporting
whyashthakker/beam-cli · security-reporting
### security-reporting - Review and consolidate security findings into a reproducible, redacted assessment report with calibrated severity, confidence, remediation, - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
data-retention-privacy-review
whyashthakker/beam-cli · data-retention-privacy-review
### data-retention-privacy-review - Review what agent transcripts, tool arguments, and outputs get retained, for how long, and who can access them — retention windows, deletion - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
rag-memory-security
whyashthakker/beam-cli · rag-memory-security
### rag-memory-security - Review retrieval-augmented generation and agent memory pipelines for cross-user disclosure, poisoned context, unsafe persistence, provenance - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
model-artifact-scanner
whyashthakker/beam-cli · model-artifact-scanner
### model-artifact-scanner - Statically review supplied model packages, checkpoints, adapters, tokenizer assets, and loader configuration for unsafe deserialization, exe - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
training-data-security
whyashthakker/beam-cli · training-data-security
### training-data-security - Review datasets and pipelines used for fine-tuning, embedding, or few-shot example curation for provenance, poisoning, label-flipping, embed - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
conducting-cloud-penetration-testing
mukul975/Anthropic-Cybersecurity-Skills · conducting-cloud-penetration-testing
This skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud-specific attack tools like Pacu and ScoutSuite, exploiting IAM misconfigurations, testing for SSRF to cloud metadata services, and reporting findings aligned to MITRE ATT&CK Cloud matrix.
performing-aws-privilege-escalation-assessment
mukul975/Anthropic-Cybersecurity-Skills · performing-aws-privilege-escalation-assessment
Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal Mapper, and manual IAM policy analysis techniques.