Anthropic-Cybersecurity-Skills is an open-source library of 754 structured cybersecurity skills that give an AI agent the workflows of a senior security analyst. It hit GitHub trending with 930 stars in a day. Apache 2.0, spanning 26 security domains.
## The framework mapping
What sets it apart: every skill is mapped to five industry frameworks — MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, and NIST AI RMF. It’s billed as the only open-source skills library with unified cross-framework coverage. Built on the agentskills.io standard, it works immediately with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI, and 20+ platforms.
## The compliance angle
The NIST AI RMF mapping isn’t academic. Colorado’s AI Act (effective February 2026) gives a legal safe harbor to organizations complying with NIST AI RMF — so skills tagged to that framework translate directly into regulatory cover. As AI regulation arrives, framework-mapped agent skills become compliance infrastructure, not just productivity tools.
## Why it matters
Generic coding agents are weak at security — it’s specialized, framework-heavy, and high-stakes. A curated, framework-mapped skill library turns a general agent into a credible security analyst, and the compliance mapping makes it deployable in regulated environments. It’s the “skills specialize general agents” pattern applied to one of the highest-value verticals.

Leave a comment