YAML Frontmatter Structure for Anthropic Cybersecurity Skills: Complete Schema Guide
The Anthropic Cybersecurity Skills repository follows the agentskills.io standard, requiring every skill file to begin with a YAML frontmatter block that supplies metadata for AI agent discovery, filtering, and ranking before the full markdown body is loaded.
The mukul975/Anthropic-Cybersecurity-Skills repository defines a strict YAML frontmatter schema that enables AI agents to index and retrieve cybersecurity workflows efficiently. This frontmatter appears at the top of every SKILL.md file within the skills/<skill-name>/ directory, providing a lightweight metadata layer that agents scan before loading the full skill content.
Required and Optional Frontmatter Fields
The frontmatter schema divides fields into four required core identifiers and optional framework mappings that enable cross-reference searching.
Core Required Fields
Every skill must define these four fields at minimum:
- name – A kebab-case string (1–64 characters) serving as the unique identifier and primary key for catalog searches. This value typically matches the folder name containing the skill.
- description – A keyword-rich, multi-line summary that agents index for relevance matching against user queries.
- domain – High-level category string (e.g.,
cybersecurity). - subdomain – Fine-grained functional area (e.g.,
digital-forensics,threat-intelligence).
Omitting any of these four fields prevents the skill from appearing in agent search results.
Optional Framework Mappings
The schema supports alignment with major security frameworks for compliance and defensive recommendation generation:
- atlas_techniques – List of MITRE ATLAS IDs (e.g.,
AML.T0047) mapping AI-related threats. - d3fend_techniques – List of MITRE D3FEND defensive technique IDs (e.g.,
D3-MA,D3-PSMD). - nist_ai_rmf – List of NIST AI Risk Management Framework sub-categories (e.g.,
MEASURE-2.6). - nist_csf – List of NIST Cybersecurity Framework 2.0 identifiers (e.g.,
DE.CM-01,RS.AN-03).
Metadata and Tagging
Additional optional fields enhance discoverability and attribution:
- tags – Free-form keyword list for supplemental filtering (e.g.,
forensics,volatility3,incident-response). - version – Semantic version string (e.g.,
"1.2") indicating skill updates. - author – Creator or maintainer identifier.
- license – SPDX-compatible license string (e.g.,
Apache-2.0).
File Location and Schema Implementation
The frontmatter is implemented in every skill definition file. According to the repository source code, canonical examples appear in:
README.md(lines 86–102) – Documents the schema architecture with a minimal example.skills/<skill-name>/SKILL.md– Contains the complete frontmatter plus executable workflow markdown.
For instance, the skill analyzing-threat-actor-ttps-with-mitre-attack defines its metadata in skills/analyzing-threat-actor-ttps-with-mitre-attack/SKILL.md at lines 2–18.
Complete Frontmatter Examples
Minimal Required Configuration
The following YAML block satisfies the minimum requirements for agent indexing:
---
name: detecting-suspicious-dns-queries
description: Detect anomalous DNS lookups that may indicate data exfiltration or C2 activity.
domain: cybersecurity
subdomain: network-security
tags: [dns, detection, exfiltration, threat-hunting]
version: "0.1"
author: your-github-handle
license: Apache-2.0
---
Full Production Example
This excerpt from skills/analyzing-threat-actor-ttps-with-mitre-attack/SKILL.md (lines 2–18) demonstrates comprehensive framework mapping:
---
name: analyzing-threat-actor-ttps-with-mitre-attack
description: MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) …
domain: cybersecurity
subdomain: threat-intelligence
tags:
- threat-intelligence
- cti
- ioc
- mitre-attack
- stix
- ttp-analysis
- threat-actors
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Executable Denylisting
- Execution Isolation
- File Metadata Consistency Validation
- Content Format Conversion
- File Content Analysis
nist_csf:
- ID.RA-01
- ID.RA-05
- DE.CM-01
- DE.AE-02
---
Progressive Disclosure Architecture
The YAML frontmatter structure enables a progressive disclosure pattern that optimizes token usage across agentskills-compatible runtimes like Claude Code, GitHub Copilot, and LangChain.
When a user submits a query, the runtime scans only the lightweight frontmatter (approximately 30 tokens per skill) to build an in-memory index. If the query matches fields like tags, subdomain, or atlas_techniques, the engine lazily fetches the full markdown body (500–2,000 tokens) for the most relevant matches. This architecture prevents loading unnecessary skill definitions into the context window.
Cross-framework mappings provide a single source of truth for compliance automation, allowing agents to generate defensive recommendations based on mapped offensive techniques.
Summary
- The YAML frontmatter structure for Anthropic Cybersecurity Skills requires four mandatory fields:
name,description,domain, andsubdomain. - Optional fields map skills to MITRE ATLAS, D3FEND, NIST AI RMF, and NIST CSF frameworks for compliance integration.
- Frontmatter resides at the top of every
SKILL.mdfile underskills/<skill-name>/, as defined in the repository'sREADME.md(lines 86–102). - Agentskills-compatible runtimes use this metadata for progressive disclosure, scanning lightweight frontmatter before loading full skill workflows.
- The
namefield serves as the primary key and folder identifier, whiletagsenable extensible, niche categorization without schema changes.
Frequently Asked Questions
What fields are mandatory in the YAML frontmatter?
Only name, description, domain, and subdomain are required. All other fields—including framework mappings and metadata—are optional. If optional fields are omitted, the skill simply becomes unsearchable on those specific dimensions.
How does the frontmatter enable AI agent discovery?
The frontmatter supplies structured metadata that agentskills-compatible runtimes parse into an in-memory index. When users query for specific capabilities (e.g., "memory forensics" or "MITRE ATT&CK analysis"), the runtime matches against description, tags, subdomain, and framework fields to retrieve the most relevant skills without loading the full markdown body.
What MITRE frameworks are supported in the schema?
The schema supports MITRE ATLAS (via atlas_techniques for AI threats), MITRE D3FEND (via d3fend_techniques for defensive countermeasures), and references MITRE ATT&CK through the subdomain and tags fields. These mappings allow skills to link offensive techniques directly to defensive controls and risk management frameworks.
Where is the frontmatter defined in the repository?
Each skill's frontmatter is defined in its respective SKILL.md file located at skills/<skill-name>/SKILL.md. The repository root README.md (lines 86–102) documents the complete schema specification, while the concrete implementation example appears in skills/analyzing-threat-actor-ttps-with-mitre-attack/SKILL.md (lines 2–18).
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →