How AI Agents Can Search All 754 Skills Without Exceeding Context Windows

AI agents can search all 754 cybersecurity skills within standard context limits by using a progressive-disclosure architecture that scans compact YAML front-matter metadata (~30 tokens per skill) before selectively loading full workflow bodies only for top-matched candidates.

The Anthropic Cybersecurity Skills repository presents a unique scale challenge for AI agents, packing 754 specialized security capabilities into a single library. To prevent token overflow, the repository implements a progressive-disclosure architecture that separates lightweight skill discovery from resource-intensive execution, allowing agents to search the entire catalog in approximately 22,000 tokens.

Progressive-Disclosure Architecture

The architecture operates on a two-stage funnel: first, ingest metadata for every skill to identify candidates, then hydrate only the selected skills with their full procedural content. This approach keeps the initial search surface area small while preserving access to detailed workflows when needed.

Stage 1: Front-Matter-Only Scanning

Each skill resides in its own directory under skills/<skill-name>/ with a standardized SKILL.md file. These files lead with a YAML front-matter block containing fields like name, description, domain, tags, and framework mappings (atlas_techniques, nist_csf, etc.).

This front-matter averages only ~30 tokens per skill. Multiplying across the full repository, all 754 front-matters consume roughly 22,000 tokens—well within the context window of modern models like Claude 3.5 Sonnet or GPT-4. The repository provides a pre-generated index.json file at the root that aggregates these front-matters into a single JSON array, eliminating filesystem traversal overhead. As documented in the README.md (lines 42-45), this index enables the cheap initial scan.

Stage 2: Selective Loading of Full Bodies

Once the agent identifies the top-N most relevant skills (typically 3-5 matches), it loads the full markdown body containing the "Workflow" and "Verification" sections. These full skill bodies range from 500-2,000 tokens each—an order of magnitude larger than their metadata. By loading these only after filtering, the agent preserves the majority of its context window for actual task execution.

If additional skills are needed, the agent loads them iteratively, replacing previous full bodies or appending only after completing earlier workflows. This sequential hydration prevents cumulative token bloat.

Implementing the Search in Agent Code

The repository supports two implementation patterns for AI agent integration: using the pre-generated JSON index for metadata scanning, and directly parsing individual SKILL.md files when full execution is required.

Using the Pre-Generated Index

The recommended approach uses the index.json file created during installation (via npx skills add mukul975/Anthropic-Cybersecurity-Skills). This file contains the complete front-matter catalog, enabling token-efficient keyword matching.

import json

# Load the compact index (all 754 skills' metadata)

with open('index.json') as f:
    index = json.load(f)

def find_relevant_skills(query, top_k=3):
    """Match query against front-matter fields"""
    matches = []
    query_tokens = query.lower().split()
    
    for skill in index['skills']:
        fm = skill['frontmatter']
        # Search description and tags

        desc = fm.get('description', '').lower()
        tags = ' '.join(fm.get('tags', [])).lower()
        
        if any(tok in desc or tok in tags for tok in query_tokens):
            matches.append((skill['name'], fm['description']))
    
    # Rank by relevance (length-based placeholder)

    matches.sort(key=lambda x: len(x[1]), reverse=True)
    return matches[:top_k]

# Example usage

results = find_relevant_skills('memory dump credential theft')
print(results)  # [('performing-memory-forensics-with-volatility3', ...), ...]

This method scans all 754 entries without filesystem I/O, keeping token usage minimal. The index structure mirrors the front-matter schema documented in Skill anatomy (README.md lines 69-81).

Loading Full Skill Bodies on Demand

After identifying target skills, agents load the complete workflow by parsing individual SKILL.md files directly:

import yaml
import pathlib

def load_skill_body(skill_name):
    """
    Load full skill content including YAML front-matter
    and markdown workflow body.
    """
    skill_path = pathlib.Path('skills') / skill_name / 'SKILL.md'
    
    with open(skill_path) as f:
        content = f.read()
    
    # Split YAML front-matter from markdown body

    # File format: ---\nyaml\n---\nmarkdown

    parts = content.split('---', 2)
    frontmatter = yaml.safe_load(parts[1]) if len(parts) > 1 else {}
    md_body = parts[2] if len(parts) > 2 else content
    
    return frontmatter, md_body

# Load only after filtering to preserve context

fm, workflow = load_skill_body('performing-memory-forensics-with-volatility3')
print(f"Loaded skill: {fm['name']}")
print(f"Workflow preview: {workflow[:500]}...")

This targeted loading ensures that only the 500-2,000 token payload of selected skills enters the context window, rather than the full corpus.

The repository structure enables this scalable search pattern through several specialized files:

  • index.json – A generated catalog containing the front-matter for all 754 skills without the full markdown bodies, enabling sub-25k token full-corpus scans.

  • skills/<skill-name>/SKILL.md – The canonical skill definition file containing YAML front-matter (metadata) and the full workflow/verification sections. The --- delimiter separates these sections.

  • skills/<skill-name>/references/standards.md – Mapping files linking skills to external frameworks (ATT&CK, NIST CSF, ATLAS, D3FEND, AI RMF), used for compliance-based filtering without loading full skill bodies.

  • skills/<skill-name>/scripts/process.py (or agent.py) – Executable scripts that agents invoke after selecting a skill, handling the actual security task execution.

  • tools/README.md – Documentation for the npx skills add installation workflow that generates the index.json file.

  • README.md – Core documentation explaining the progressive-disclosure model and context window management strategies.

Summary

  • Scan cheap, load expensive: Agents query all 754 skills via the compact index.json (~22k tokens) before loading full workflows (~500-2k tokens each) for only the top matches.

  • YAML front-matter optimization: Each SKILL.md file isolates metadata in a ~30 token YAML block, making bulk scanning feasible while preserving detailed workflows in the same file.

  • Iterative hydration: Agents replace or sequence full skill loads to maintain context limits during multi-step security operations.

  • Framework tagging: Front-matter includes standardized mappings (atlas_techniques, nist_csf) enabling policy-based skill discovery without parsing full content.

Frequently Asked Questions

How many tokens are required to search the entire skill library?

Scanning all 754 skills requires approximately 22,000 tokens when using the index.json file or front-matter extraction, since each skill's metadata consumes only ~30 tokens. This fits comfortably within standard 100k-200k context windows, leaving ample room for loading 3-5 full skill bodies (500-2,000 tokens each) and maintaining conversation history.

What metadata fields are available for filtering skills?

Each skill's front-matter includes searchable fields such as name, description, domain, tags, and framework mappings including atlas_techniques, nist_csf, d3fend, and ai_rmf. These fields allow agents to match user queries against security domains, compliance frameworks, or specific attack techniques without loading the full procedural content.

Can an agent execute multiple skills simultaneously while staying within context limits?

Yes, through iterative refinement. Agents typically load the full body of one skill, execute its workflow, capture the results, then unload or replace that skill's context before loading the next. This sequential processing prevents the accumulation of 500-2,000 token payloads from multiple skills, keeping total context usage flat regardless of how many skills are executed in a session.

How does the index.json file stay synchronized with the repository?

The index.json file is regenerated during installation when running npx skills add mukul975/Anthropic-Cybersecurity-Skills. The installation script (documented in tools/README.md) traverses the skills/ directory structure, extracts front-matter from each SKILL.md file, and compiles the compact catalog. Agents should reinstall or refresh the index when pulling repository updates to ensure skill additions or metadata changes are reflected.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →