Claude knows the commands. What these encode is the discipline — trace impact before you report it, preserve before you remediate, spot the honeypot before you touch it. Every skill fact-checked against primary sources.
No commands to memorize, no manual invocation. This is what a skill changes versus asking Claude cold.
Say audit this repo for auth bugs or a host is beaconing — where do I start?. Claude Code matches the right skill from its description; you never type a skill name.
Only each skill's one-line description sits in context. The full methodology loads when your task triggers it — 82 skills cost nothing until one is relevant. Procedure skills wait for their evidence (a libflutter.so, a SAMLResponse, an .E01 image).
The skill enforces a methodology — sequence, scope, the verification gate — and names the sibling skill to switch to as the task moves. That is how the collection composes instead of dumping commands.
Each skill's Rationalizations to Reject blocks the plausible-but-wrong call — grep was clean, so the tree is clean
, the tool rated it critical, so escalate
.
You don't need the jargon. Describe the situation — here are good starting prompts, and where each lands.
Cloud and Kubernetes are covered from both sides, so purple-team work stays in one vocabulary.
AD & Entra, AD CS ESC1–16, cloud, managed k8s, mobile, wireless, web/auth — plus recognizing-deception and maintaining-engagement-state.
Source audit with a verification gate, PR review that reads deleted lines, crypto & supply-chain, AI/MCP, PHP depth, backdoor hunting.
Preserve-first forensics and cross-cloud IR for AWS, Azure, GCP, M365/Entra, built on the audit-log defaults that decide what's answerable.
Base-rate alert triage, detection-as-code with real FP analysis, threat hunting, KEV+EPSS vuln management, finished intel.
Search by name or technique; filter by plugin. Click any skill for the full methodology.
The differentiator, and the honest version of it — not confidently-wrong output.
verified: is dated, not eternal — trust the methodology and re-confirm any specific before it lands in a deliverable. CI checks form, not truth; the dates are the accuracy signal.