# YAML Frontmatter Structure for Anthropic Cybersecurity Skills: Complete Schema Guide

> Learn the YAML frontmatter structure for Anthropic Cybersecurity Skills using the agentskills.io standard. Discover metadata essentials for AI agent discovery, filtering, and ranking.

- Repository: [Mahipal/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills)
- Tags: api-reference
- Published: 2026-05-24

---

**The Anthropic Cybersecurity Skills repository follows the agentskills.io standard, requiring every skill file to begin with a YAML frontmatter block that supplies metadata for AI agent discovery, filtering, and ranking before the full markdown body is loaded.**

The `mukul975/Anthropic-Cybersecurity-Skills` repository defines a strict YAML frontmatter schema that enables AI agents to index and retrieve cybersecurity workflows efficiently. This frontmatter appears at the top of every [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file within the `skills/<skill-name>/` directory, providing a lightweight metadata layer that agents scan before loading the full skill content.

## Required and Optional Frontmatter Fields

The frontmatter schema divides fields into four required core identifiers and optional framework mappings that enable cross-reference searching.

### Core Required Fields

Every skill must define these four fields at minimum:

- **name** – A kebab-case string (1–64 characters) serving as the unique identifier and primary key for catalog searches. This value typically matches the folder name containing the skill.
- **description** – A keyword-rich, multi-line summary that agents index for relevance matching against user queries.
- **domain** – High-level category string (e.g., `cybersecurity`).
- **subdomain** – Fine-grained functional area (e.g., `digital-forensics`, `threat-intelligence`).

Omitting any of these four fields prevents the skill from appearing in agent search results.

### Optional Framework Mappings

The schema supports alignment with major security frameworks for compliance and defensive recommendation generation:

- **atlas_techniques** – List of MITRE ATLAS IDs (e.g., `AML.T0047`) mapping AI-related threats.
- **d3fend_techniques** – List of MITRE D3FEND defensive technique IDs (e.g., `D3-MA`, `D3-PSMD`).
- **nist_ai_rmf** – List of NIST AI Risk Management Framework sub-categories (e.g., `MEASURE-2.6`).
- **nist_csf** – List of NIST Cybersecurity Framework 2.0 identifiers (e.g., `DE.CM-01`, `RS.AN-03`).

### Metadata and Tagging

Additional optional fields enhance discoverability and attribution:

- **tags** – Free-form keyword list for supplemental filtering (e.g., `forensics`, `volatility3`, `incident-response`).
- **version** – Semantic version string (e.g., `"1.2"`) indicating skill updates.
- **author** – Creator or maintainer identifier.
- **license** – SPDX-compatible license string (e.g., `Apache-2.0`).

## File Location and Schema Implementation

The frontmatter is implemented in every skill definition file. According to the repository source code, canonical examples appear in:

- [`README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/README.md) (lines 86–102) – Documents the schema architecture with a minimal example.
- `skills/<skill-name>/SKILL.md` – Contains the complete frontmatter plus executable workflow markdown.

For instance, the skill `analyzing-threat-actor-ttps-with-mitre-attack` defines its metadata in [`skills/analyzing-threat-actor-ttps-with-mitre-attack/SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/analyzing-threat-actor-ttps-with-mitre-attack/SKILL.md) at lines 2–18.

## Complete Frontmatter Examples

### Minimal Required Configuration

The following YAML block satisfies the minimum requirements for agent indexing:

```yaml
---
name: detecting-suspicious-dns-queries
description: Detect anomalous DNS lookups that may indicate data exfiltration or C2 activity.
domain: cybersecurity
subdomain: network-security
tags: [dns, detection, exfiltration, threat-hunting]
version: "0.1"
author: your-github-handle
license: Apache-2.0
---

```

### Full Production Example

This excerpt from [`skills/analyzing-threat-actor-ttps-with-mitre-attack/SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/analyzing-threat-actor-ttps-with-mitre-attack/SKILL.md) (lines 2–18) demonstrates comprehensive framework mapping:

```yaml
---
name: analyzing-threat-actor-ttps-with-mitre-attack
description: MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) …
domain: cybersecurity
subdomain: threat-intelligence
tags:
- threat-intelligence
- cti
- ioc
- mitre-attack
- stix
- ttp-analysis
- threat-actors
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Executable Denylisting
- Execution Isolation
- File Metadata Consistency Validation
- Content Format Conversion
- File Content Analysis
nist_csf:
- ID.RA-01
- ID.RA-05
- DE.CM-01
- DE.AE-02
---

```

## Progressive Disclosure Architecture

The YAML frontmatter structure enables a **progressive disclosure** pattern that optimizes token usage across agentskills-compatible runtimes like Claude Code, GitHub Copilot, and LangChain.

When a user submits a query, the runtime scans only the lightweight frontmatter (approximately 30 tokens per skill) to build an in-memory index. If the query matches fields like `tags`, `subdomain`, or `atlas_techniques`, the engine lazily fetches the full markdown body (500–2,000 tokens) for the most relevant matches. This architecture prevents loading unnecessary skill definitions into the context window.

Cross-framework mappings provide a single source of truth for compliance automation, allowing agents to generate defensive recommendations based on mapped offensive techniques.

## Summary

- The **YAML frontmatter structure for Anthropic Cybersecurity Skills** requires four mandatory fields: `name`, `description`, `domain`, and `subdomain`.
- Optional fields map skills to **MITRE ATLAS**, **D3FEND**, **NIST AI RMF**, and **NIST CSF** frameworks for compliance integration.
- Frontmatter resides at the top of every [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file under `skills/<skill-name>/`, as defined in the repository's [`README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/README.md) (lines 86–102).
- Agentskills-compatible runtimes use this metadata for **progressive disclosure**, scanning lightweight frontmatter before loading full skill workflows.
- The `name` field serves as the primary key and folder identifier, while `tags` enable extensible, niche categorization without schema changes.

## Frequently Asked Questions

### What fields are mandatory in the YAML frontmatter?

Only `name`, `description`, `domain`, and `subdomain` are required. All other fields—including framework mappings and metadata—are optional. If optional fields are omitted, the skill simply becomes unsearchable on those specific dimensions.

### How does the frontmatter enable AI agent discovery?

The frontmatter supplies structured metadata that agentskills-compatible runtimes parse into an in-memory index. When users query for specific capabilities (e.g., "memory forensics" or "MITRE ATT&CK analysis"), the runtime matches against `description`, `tags`, `subdomain`, and framework fields to retrieve the most relevant skills without loading the full markdown body.

### What MITRE frameworks are supported in the schema?

The schema supports **MITRE ATLAS** (via `atlas_techniques` for AI threats), **MITRE D3FEND** (via `d3fend_techniques` for defensive countermeasures), and references **MITRE ATT&CK** through the `subdomain` and `tags` fields. These mappings allow skills to link offensive techniques directly to defensive controls and risk management frameworks.

### Where is the frontmatter defined in the repository?

Each skill's frontmatter is defined in its respective [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file located at `skills/<skill-name>/SKILL.md`. The repository root [`README.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/README.md) (lines 86–102) documents the complete schema specification, while the concrete implementation example appears in [`skills/analyzing-threat-actor-ttps-with-mitre-attack/SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/analyzing-threat-actor-ttps-with-mitre-attack/SKILL.md) (lines 2–18).