Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Cybersecurity

  • 32 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Guides enterprise cybersecurity: security architecture, control design, vulnerability and threat management, incident response, and GRC alignment.

About

An agent skill for enterprise cybersecurity spanning security architecture, control design, vulnerability and threat management, incident response, identity security, and GRC alignment (SOC 2, ISO 27001, NIST CSF). An operator uses it when defining security strategy, assessing risk, designing defense-in-depth, or scoping penetration tests.

  • Defense-in-depth architecture and security policy authoring
  • High-level GRC strategy across SOC 2, ISO 27001, and NIST CSF

Cybersecurity by the numbers

  • 32 all-time installs (skills.sh)
  • Ranked #1,475 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill cybersecurity

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs32
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Guides enterprise cybersecurity: security architecture, control design, vulnerability and threat management, incident response, and GRC alignment.

Files

SKILL.mdMarkdownGitHub ↗

Cybersecurity

When to Use

  • Define enterprise security strategy, policy, and control architecture
  • Assess risk across identity, infrastructure, applications, vendors, and incident readiness
  • Design defense-in-depth programs aligned to NIST CSF, ISO 27001, SOC 2, or similar frameworks
  • Scope penetration tests, vulnerability management programs, or security incident response
  • Prepare high-level GRC, board, or leadership security narratives

When NOT to Use

  • GRC program, framework scope, gap plans, audit prep → compliance-specialist
  • Implement audit evidence automation or control-by-control mapping → compliance-engineer
  • Add SAST, SBOM, OIDC, or pipeline security gates → devsecops
  • Triage SOC alerts, SIEM queues, or SOAR cases → soc-analyst
  • Proactive threat hunts and hunt program design → threat-hunter
  • Alert-driven investigation and detection tuning → defensive-security-analyst
  • Execute authorized penetration tests or PoCs → penetration-tester
  • Lead red team / adversary simulation campaigns → red-team-specialist
  • Execute web/API OWASP assessments → web-pentester
  • Hands-on binary, firmware, or protocol reverse engineering → reverse-engineer
  • Provision cloud networks, clusters, or infrastructure modules → infrastructure-engineer
  • Design application integration ADRs → senior-system-architecture

Related skills

NeedSkill
Pipeline scanning, SBOM, CI OIDCdevsecops
Cloud/K8s hardening implementationinfrastructure-engineer
AI model risk, policies, EU AI Actai-risk-governance
LLM jailbreaks and prompt injection testsai-redteam
SOC alert triage, playbooks, shift handoffssoc-analyst
Proactive threat hunts, ATT&CK campaigns, hunt metricsthreat-hunter
Alert investigation, detection tuning, DFIR depthdefensive-security-analyst
Authorized pentest, exploitation, retestpenetration-tester
CTI function, intel briefs, IOC/TTP production, ISAC sharingcti-analyst
Red team, purple team, adversary simulationred-team-specialist
Binary RE, patch diff, defensive malware analysisreverse-engineer
Network/AD/infra pentest methodologynetwork-pentester
Web/API pentest methodologyweb-pentester
Web/API OWASP and proxy-based pentestweb-pentester
Implement IAM, encryption, SIEM, guardrailsinformation-security-engineer
Product multi-tenancy, customer data plane securityproduct-infrastructure-security-engineer
GRC program, audit prep, vendor questionnairescompliance-specialist
Control implementation, audit evidence automationcompliance-engineer
On-call, SEV, postmortem, paging integrationsincident-management-engineer
Active security incident response (CSIRT)incident-responder
SOC alert triagesoc-analyst
Vendor/customer contract security exhibits and DPAscommercial-counsel
Solution architecture review (app layer)senior-system-architecture
Applied AI / LLM commercial & enterprise architectureapplied-ai-architect-commercial-enterprise
Crisis and security incident messagingcommunication-lead
Data center facility design and commissioningdata-center-design-execution-lead
CVD, bounty, disclosure calendartechnical-program-manager-security-cvd
Evidence acquisition, super-timelines, forensic reports for legal/IRdigital-forensics-analyst
Risk registers, residual scoring, committee/board risk narrativesecurity-risk-analyst
BCM/DRP, RTO/RPO, ransomware recovery, restore tests, tabletopsbcm-disaster-recovery-specialist

Core Workflows

1. Security architecture and control design

1. Identify assets, data classes, and trust boundaries 2. Apply defense-in-depth: prevent, detect, respond, recover 3. Map controls to framework (NIST CSF, ISO 27001 Annex A) 4. Document accepted risks with owner and review date 5. Validate with architecture review before major launches

See `references/security_architecture.md` for control catalogs and network zoning.

2. Vulnerability and exposure management

Program cadence:

ActivityFrequency
External attack surface reviewMonthly
Vuln scan aggregation + triageWeekly
Patch SLA trackingContinuous
Penetration testAnnual + major changes

Prioritize: exploitability × exposure × asset criticality.

See `references/vuln_threat_management.md` for SLAs, pentest scope, and threat intel use.

3. Identity and access security

  • Enforce MFA for all human access; phishing-resistant where possible
  • Least privilege; periodic access reviews (quarterly for prod)
  • Separate break-glass accounts; log and alert on use
  • Service accounts: scoped credentials, rotation, no shared passwords

See `references/identity_access.md` for IAM patterns and PAM considerations.

4. Security incident response

Phases: prepare → detect → analyze → contain → eradicate → recover → post-incident.

SeverityExamplesResponse target
SEV1Active breach, ransomwareImmediate, 24/7
SEV2Confirmed intrusion attempt< 1 hour
SEV3Policy violation, malware containedSame business day
SEV4Recon, blocked attackTrack and trend

See `references/incident_response.md` for playbooks and evidence preservation.

5. GRC and audit support

  • Maintain control matrix linked to evidence
  • Track exceptions/waivers with expiry
  • Coordinate with legal on breach notification thresholds
  • Align third-party risk with vendor reviews

See `references/grc_compliance.md` for SOC 2 / ISO mapping and audit artifacts.

When to load references

  • Architecture and controlsreferences/security_architecture.md
  • Vulns, pentest, threatsreferences/vuln_threat_management.md
  • IAM and accessreferences/identity_access.md
  • Incidentsreferences/incident_response.md
  • GRC and auditsreferences/grc_compliance.md

Related skills

Securityauditcompliance

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.