Directory Structure for Each Skill in the Anthropic Cybersecurity Skills Repository

Every skill in the repository follows a uniform, self-contained layout under skills/<skill-name>/, containing metadata files, executable scripts, and optional API references that make it discoverable and runnable by the marketplace.

The Anthropic Cybersecurity Skills repository organizes over 150 security capabilities as isolated packages within a top-level skills/ folder. This standardized directory structure for each skill ensures automated tooling can validate, invoke, and extend any capability without custom per-skill logic. Whether analyzing malicious PDFs or auditing AWS S3 buckets, every skill adheres to the same predictable hierarchy.

Standard Skill Directory Layout

Each skill directory follows a three-level nesting that separates documentation from executable code:


skills/
└─ <skill-name>/
   ├─ SKILL.md
   ├─ LICENSE
   ├─ references/
   │   └─ api-reference.md
   └─ scripts/
       ├─ agent.py
       └─ process.py

This layout guarantees that the marketplace can locate entry points and metadata consistently across all 150+ skills.

SKILL.md Metadata File

The SKILL.md file serves as the human-readable manifest for each skill. It contains the skill’s name, concise description, version, author, tags, and framework mappings such as NIST CSF (Cybersecurity Framework). This file enables the marketplace to index and display skills correctly. For example, the Analyzing Malicious PDF with peepdf skill includes detailed metadata at skills/analyzing-malicious-pdf-with-peepdf/SKILL.md.

LICENSE File

Every skill includes a LICENSE file at its root (e.g., skills/<skill-name>/LICENSE) specifying the SPDX-compatible open-source license. Most skills use Apache-2.0, ensuring clear permission for commercial and research use. This file is mandatory for validation.

References Directory

The optional references/ subdirectory contains supplementary documentation such as api-reference.md. When present, this file documents the JSON schema that the skill’s agent expects from the marketplace, allowing custom input parameters. Not all skills include this directory, but those with complex input requirements use it to define their contract.

Scripts Directory

The scripts/ folder houses the executable Python code:

  • agent.py – The primary entry point that the marketplace invokes. It parses input JSON, executes core logic, and returns structured results.
  • process.py – An optional secondary script containing helper functions or workflows that agent.py imports.

For instance, in the Analyzing Linux Kernel Rootkits skill, scripts/agent.py handles the detection logic while scripts/process.py (if present) manages system-level interactions.

Real-World Examples from the Repository

The following representative skills demonstrate the consistent directory structure across different security domains:

  • Analyzing Malicious PDF with peepdf – Static analysis of PDF-based malware using peepdf, pdfid, and pdf-parser. Key files include SKILL.md, LICENSE, references/api-reference.md, and scripts/agent.py.
  • Analyzing Linux Kernel Rootkits – Detects hidden kernel modules and suspicious syscalls. Contains SKILL.md, LICENSE, and scripts/agent.py.
  • Building Incident Timeline with Timesketch – Generates forensic timelines from collected artifacts. Follows the same pattern with metadata and executable scripts.
  • Auditing AWS S3 Bucket Permissions – Checks for overly permissive bucket policies and ACLs. Maintains SKILL.md and scripts/agent.py in the standard locations.
  • Analyzing Network Traffic with Wireshark – Parses PCAP files to identify suspicious traffic patterns. Uses the identical directory hierarchy.

Validating Skill Structure

Repository maintainers use the tools/validate-skill.py script to ensure every skill conforms to the required layout. This validator checks for the presence of SKILL.md, LICENSE, and scripts/agent.py, plus optional reference files.

Run the validator against any skill directory:

python tools/validate-skill.py \
  --skill-dir skills/<skill-name>

To execute a skill’s agent directly from the command line (requires Python 3.8+):

python -m skills.<skill-name>.scripts.agent \
  --input '{"file_path":"sample.pdf"}' \
  --output result.json

Both commands rely on the predictable location of agent.py and optional process.py helpers within each skill’s scripts/ folder.

Repository-Level Configuration Files

Beyond individual skill directories, the repository root contains supporting infrastructure:

  • tools/validate-skill.py – The validation script that enforces structural compliance across all skills.
  • README.md – Explains the marketplace concept and contribution guidelines for new skills.
  • index.json – An auto-generated catalogue recording each skill’s name, version, and GitHub path for programmatic discovery.
  • mappings/ – Cross-reference files (e.g., MITRE ATT&CK coverage) that skills can reference in their metadata to indicate technique mappings.

Summary

  • The Anthropic Cybersecurity Skills repository stores over 150 skills under skills/<skill-name>/ using a uniform directory structure.
  • Each skill requires SKILL.md for metadata, LICENSE for legal clarity, and scripts/agent.py as the executable entry point.
  • Optional components include references/api-reference.md for API contracts and scripts/process.py for helper functions.
  • The tools/validate-skill.py script automates compliance checking against this standard layout.
  • Repository-level files like index.json and mappings/ enable automated discovery and framework alignment.

Frequently Asked Questions

What files are mandatory in every skill directory?

Every skill must contain three core files: SKILL.md (metadata and description), LICENSE (SPDX-compatible license), and scripts/agent.py (the primary executable entry point). The tools/validate-skill.py script will fail validation if any of these are missing.

Where does the marketplace find the entry point to run a skill?

The marketplace invokes scripts/agent.py within each skill directory. This file acts as the universal interface that accepts JSON input, executes the security logic, and returns structured results. Skills may optionally include scripts/process.py to organize helper functions.

How does the repository handle different input requirements for various skills?

Skills with complex input parameters include a references/api-reference.md file that documents the expected JSON schema. This optional file lives in the references/ subdirectory and allows the marketplace to validate inputs before invoking agent.py.

Can I run a skill locally without the marketplace?

Yes. You can execute any skill directly using Python’s module syntax: python -m skills.<skill-name>.scripts.agent --input '{"key":"value"}' --output result.json. This command line interface relies on the standard directory structure to locate the agent script and any imported process modules.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →