# How AI Agents Can Search All 754 Skills Without Exceeding Context Windows

> Discover how AI agents can efficiently search 754 cybersecurity skills by leveraging progressive disclosure and compact metadata to overcome context window limitations.

- Repository: [Mahipal/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills)
- Tags: how-to-guide
- Published: 2026-05-24

---

**AI agents can search all 754 cybersecurity skills within standard context limits by using a progressive-disclosure architecture that scans compact YAML front-matter metadata (~30 tokens per skill) before selectively loading full workflow bodies only for top-matched candidates.**

The Anthropic Cybersecurity Skills repository presents a unique scale challenge for AI agents, packing 754 specialized security capabilities into a single library. To prevent token overflow, the repository implements a **progressive-disclosure architecture** that separates lightweight skill discovery from resource-intensive execution, allowing agents to search the entire catalog in approximately 22,000 tokens.

## Progressive-Disclosure Architecture

The architecture operates on a two-stage funnel: first, ingest metadata for every skill to identify candidates, then hydrate only the selected skills with their full procedural content. This approach keeps the initial search surface area small while preserving access to detailed workflows when needed.

### Stage 1: Front-Matter-Only Scanning

Each skill resides in its own directory under `skills/<skill-name>/` with a standardized [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file. These files lead with a YAML front-matter block containing fields like `name`, `description`, `domain`, `tags`, and framework mappings (`atlas_techniques`, `nist_csf`, etc.).

This front-matter averages only **~30 tokens per skill**. Multiplying across the full repository, all 754 front-matters consume roughly 22,000 tokens—well within the context window of modern models like Claude 3.5 Sonnet or GPT-4. The repository provides a pre-generated **[`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json)** file at the root that aggregates these front-matters into a single JSON array, eliminating filesystem traversal overhead. As documented in the [README.md (lines 42-45)](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/README.md#L42-L45), this index enables the cheap initial scan.

### Stage 2: Selective Loading of Full Bodies

Once the agent identifies the top-N most relevant skills (typically 3-5 matches), it loads the full markdown body containing the "Workflow" and "Verification" sections. These full skill bodies range from **500-2,000 tokens each**—an order of magnitude larger than their metadata. By loading these only after filtering, the agent preserves the majority of its context window for actual task execution.

If additional skills are needed, the agent loads them iteratively, replacing previous full bodies or appending only after completing earlier workflows. This sequential hydration prevents cumulative token bloat.

## Implementing the Search in Agent Code

The repository supports two implementation patterns for AI agent integration: using the pre-generated JSON index for metadata scanning, and directly parsing individual [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) files when full execution is required.

### Using the Pre-Generated Index

The recommended approach uses the **[`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json)** file created during installation (via `npx skills add mukul975/Anthropic-Cybersecurity-Skills`). This file contains the complete front-matter catalog, enabling token-efficient keyword matching.

```python
import json

# Load the compact index (all 754 skills' metadata)

with open('index.json') as f:
    index = json.load(f)

def find_relevant_skills(query, top_k=3):
    """Match query against front-matter fields"""
    matches = []
    query_tokens = query.lower().split()
    
    for skill in index['skills']:
        fm = skill['frontmatter']
        # Search description and tags

        desc = fm.get('description', '').lower()
        tags = ' '.join(fm.get('tags', [])).lower()
        
        if any(tok in desc or tok in tags for tok in query_tokens):
            matches.append((skill['name'], fm['description']))
    
    # Rank by relevance (length-based placeholder)

    matches.sort(key=lambda x: len(x[1]), reverse=True)
    return matches[:top_k]

# Example usage

results = find_relevant_skills('memory dump credential theft')
print(results)  # [('performing-memory-forensics-with-volatility3', ...), ...]

```

This method scans all 754 entries without filesystem I/O, keeping token usage minimal. The index structure mirrors the front-matter schema documented in [Skill anatomy (README.md lines 69-81)](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/README.md#L69-L81).

### Loading Full Skill Bodies on Demand

After identifying target skills, agents load the complete workflow by parsing individual [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) files directly:

```python
import yaml
import pathlib

def load_skill_body(skill_name):
    """
    Load full skill content including YAML front-matter
    and markdown workflow body.
    """
    skill_path = pathlib.Path('skills') / skill_name / 'SKILL.md'
    
    with open(skill_path) as f:
        content = f.read()
    
    # Split YAML front-matter from markdown body

    # File format: ---\nyaml\n---\nmarkdown

    parts = content.split('---', 2)
    frontmatter = yaml.safe_load(parts[1]) if len(parts) > 1 else {}
    md_body = parts[2] if len(parts) > 2 else content
    
    return frontmatter, md_body

# Load only after filtering to preserve context

fm, workflow = load_skill_body('performing-memory-forensics-with-volatility3')
print(f"Loaded skill: {fm['name']}")
print(f"Workflow preview: {workflow[:500]}...")

```

This targeted loading ensures that only the 500-2,000 token payload of selected skills enters the context window, rather than the full corpus.

## Key Files Supporting Efficient Search

The repository structure enables this scalable search pattern through several specialized files:

- **[`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json)** – A generated catalog containing the front-matter for all 754 skills without the full markdown bodies, enabling sub-25k token full-corpus scans.

- **`skills/<skill-name>/SKILL.md`** – The canonical skill definition file containing YAML front-matter (metadata) and the full workflow/verification sections. The `---` delimiter separates these sections.

- **`skills/<skill-name>/references/standards.md`** – Mapping files linking skills to external frameworks (ATT&CK, NIST CSF, ATLAS, D3FEND, AI RMF), used for compliance-based filtering without loading full skill bodies.

- **`skills/<skill-name>/scripts/process.py`** (or [`agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/agent.py)) – Executable scripts that agents invoke after selecting a skill, handling the actual security task execution.

- **[`tools/README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/tools/README.md)** – Documentation for the `npx skills add` installation workflow that generates the [`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json) file.

- **[`README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/README.md)** – Core documentation explaining the progressive-disclosure model and context window management strategies.

## Summary

- **Scan cheap, load expensive**: Agents query all 754 skills via the compact [`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json) (~22k tokens) before loading full workflows (~500-2k tokens each) for only the top matches.

- **YAML front-matter optimization**: Each [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file isolates metadata in a ~30 token YAML block, making bulk scanning feasible while preserving detailed workflows in the same file.

- **Iterative hydration**: Agents replace or sequence full skill loads to maintain context limits during multi-step security operations.

- **Framework tagging**: Front-matter includes standardized mappings (`atlas_techniques`, `nist_csf`) enabling policy-based skill discovery without parsing full content.

## Frequently Asked Questions

### How many tokens are required to search the entire skill library?

Scanning all 754 skills requires approximately **22,000 tokens** when using the [`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json) file or front-matter extraction, since each skill's metadata consumes only ~30 tokens. This fits comfortably within standard 100k-200k context windows, leaving ample room for loading 3-5 full skill bodies (500-2,000 tokens each) and maintaining conversation history.

### What metadata fields are available for filtering skills?

Each skill's front-matter includes **searchable fields** such as `name`, `description`, `domain`, `tags`, and framework mappings including `atlas_techniques`, `nist_csf`, `d3fend`, and `ai_rmf`. These fields allow agents to match user queries against security domains, compliance frameworks, or specific attack techniques without loading the full procedural content.

### Can an agent execute multiple skills simultaneously while staying within context limits?

Yes, through **iterative refinement**. Agents typically load the full body of one skill, execute its workflow, capture the results, then unload or replace that skill's context before loading the next. This sequential processing prevents the accumulation of 500-2,000 token payloads from multiple skills, keeping total context usage flat regardless of how many skills are executed in a session.

### How does the index.json file stay synchronized with the repository?

The [`index.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/index.json) file is **regenerated during installation** when running `npx skills add mukul975/Anthropic-Cybersecurity-Skills`. The installation script (documented in [`tools/README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/tools/README.md)) traverses the `skills/` directory structure, extracts front-matter from each [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file, and compiles the compact catalog. Agents should reinstall or refresh the index when pulling repository updates to ensure skill additions or metadata changes are reflected.