OT/ICS Security Skills in Anthropic's Cybersecurity Library: Complete Technical Reference
The repository contains 28 specialized OT/ICS security skills organized around the Purdue Reference Model and IEC 62443, covering asset discovery, network segmentation, remote access hardening, and incident response, with each skill mapped to MITRE ATT&CK and NIST CSF 2.0 frameworks.
The mukul975/Anthropic-Cybersecurity-Skills repository provides a dedicated collection of operational technology (OT) and industrial control system (ICS) security modules. These 28 self-contained skills enable AI agents and security practitioners to implement defense-in-depth strategies across the complete lifecycle of industrial control system protection, from Level 0 field devices to Level 5 enterprise networks.
Core OT/ICS Security Capabilities by Category
The skills are organized into functional domains aligned with the Purdue Reference Model and IEC 62443 concepts of zones, conduits, and defense-in-depth.
Remote Access and Conduit Security
securing-remote-access-to-ot-environment: Defined inskills/securing-remote-access-to-ot-environment/SKILL.md, this module designs jump-server architectures with DMZ segregation, MFA enforcement, and co-attendance controls for operators and vendors. Thereferences/api-reference.mdfile contains specific API endpoints for automation.implementing-conduit-security-for-ot-remote-access: Applies IEC 62443 zones-and-conduits modeling with strict access policies and data-flow documentation.
Network Segmentation and Architecture
implementing-purdue-model-network-segmentation: Located atskills/implementing-purdue-model-network-segmentation/SKILL.md, this skill builds Purdue-level zones (Level 0-5) and includes Terraform snippets for automated firewall and VLAN deployment.
Asset Discovery and Inventory
performing-ics-asset-discovery-with-claroty: Uses Claroty xDome passive sensors to enumerate OT devices and map protocol usage, creating comprehensive asset inventories without disrupting operations.
Vulnerability Assessment and Patch Management
performing-ot-vulnerability-assessment-with-claroty: Prioritizes findings against IEC 62443 and NIST CSF controls.performing-ot-vulnerability-scanning-safely: Implements passive banner grabbing and protocol-specific queries (e.g., Modbus Read Holding Registers) instead of intrusive port scans that could crash PLCs.implementing-patch-management-for-ot-systems: Defines safe patch cycles for devices that cannot tolerate reboots, leveraging out-of-band updates tracked against NIST CSF PR controls.
Network Monitoring and Protocol Analysis
monitoring-scada-modbus-traffic-anomalies: Captures Modbus-TCP traffic with function-code frequency baselining to detect rogue masters. The skill includesskills/monitoring-scada-modbus-traffic-anomalies/scripts/modbus_monitor.pyfor packet extraction.implementing-dragos-platform-for-ot-monitoring: Deploys Dragos sensors for real-time analytics and SIEM integration.performing-s7comm-protocol-security-analysis: Decodes S7 COTP and PDU structures to identify unsafe function codes in Siemens environments.
System Hardening and Data Protection
securing-historian-server-in-ot-environment: Hardens OSIsoft PI and Ignition historians by isolating them in Level 3.5, enforcing one-way data diodes, and applying role-based ACLs.implementing-ics-firewall-with-tofino: Deploys Tofino ASIC firewalls with whitelisting capabilities for Modbus and DNP3 function codes.performing-scada-hmi-security-assessment: Reviews HMI configurations, tests for insecure protocols, and validates patch levels.
Incident Response and Threat Intelligence
implementing-ot-incident-response-playbook: Tailors the SANS PICERL framework for PLC/SCADA outages with containment steps specific to safety systems.performing-threat-landscape-assessment-for-sector: Maps sector-specific threat actors to MITRE ATT&CK TTP libraries.
Additional skills cover DNP3 protocol hardening, PLC firmware integrity verification, OT-focused SOC metrics, and safety-aware scanning methodologies.
Framework Alignment and Skill Structure
Each OT/ICS skill follows a standardized anatomy defined in the repository README. The SKILL.md front-matter includes machine-readable metadata with domain: "ot-ics" and explicit mappings to five major frameworks:
- MITRE ATT&CK for adversarial technique coverage
- NIST CSF 2.0 for risk management alignment
- MITRE ATLAS for AI system threats
- MITRE D3FEND for defensive countermeasures
- NIST AI RMF for artificial intelligence risk
The metadata structure enables AI agents to automatically select appropriate skills by querying tags like remote-access or protocol-analysis. Each skill contains When-to-Use triggers, Prerequisites (e.g., nmap, Modbus-py, Dragos), step-by-step Workflow commands, and Verification criteria such as "no unauthorized Modbus writes observed for 24 hours."
Practical Implementation Examples
Installing and Executing OT/ICS Skills
Install the complete skill library using the Node.js package manager:
# Recommended one-liner – adds the whole Anthropic Skills collection
npx skills add mukul975/Anthropic-Cybersecurity-Skills
Execute a specific OT security skill with parameterized inputs:
# Search for OT/ICS skills by domain tag
skills search --domain ot-ics --tag remote-access
# Execute the remote access hardening skill
skills run securing-remote-access-to-ot-environment \
--param vpn_endpoint="vpn.corp.example.com" \
--param dmz_subnet="10.10.20.0/24"
The workflow automatically validates VPN connectivity, deploys a hardened jump-server VM using embedded Terraform scripts, configures firewall rules restricting OT device access to the jump-host, enables Duo MFA, and generates a Remote-Access Security Report in the assets/ directory.
Python Integration for Modbus Monitoring
Embed traffic monitoring capabilities into broader automation pipelines:
import subprocess
import json
# Launch the Modbus traffic monitor wrapper
result = subprocess.run(
["skills", "run", "monitoring-scada-modbus-traffic-anomalies",
"--param", "interface=eth0",
"--output", "json"],
capture_output=True, text=True)
alerts = json.loads(result.stdout)
for alert in alerts:
print(f"⚠️ {alert['timestamp']} – {alert['description']}")
This invokes modbus_monitor.py from the skill's scripts/ directory, which captures packets, extracts function-code statistics, and returns structured JSON alerts suitable for SIEM ingestion.
Summary
- 28 specialized skills cover the complete OT/ICS security lifecycle from discovery through remediation
- Purdue Model alignment ensures proper segmentation across Level 0-5 architectures
- Framework integration provides native mapping to MITRE ATT&CK, NIST CSF 2.0, and IEC 62443 standards
- Executable workflows include Terraform automation, Python monitoring scripts, and verification checklists
- AI-ready structure with machine-readable metadata enables autonomous skill selection based on domain tags and threat context
Frequently Asked Questions
How many OT/ICS security skills are available in the repository?
The repository contains 28 individual skills dedicated to OT/ICS security. Each skill functions as a self-contained module with front-matter metadata, reference documentation, and optional helper scripts located in respective skills/ subdirectories.
Which industrial cybersecurity frameworks do these skills support?
The skills map to five major frameworks: MITRE ATT&CK for threat intelligence, NIST CSF 2.0 for cybersecurity risk management, MITRE ATLAS for AI system security, MITRE D3FEND for defensive countermeasures, and IEC 62443 for zones and conduits architecture. Framework mappings are stored in each skill's references/standards.md file.
Can these skills be executed programmatically by AI agents?
Yes, each skill follows a standardized anatomy with machine-readable front-matter containing name, description, domain: "ot-ics", and framework tags. This structure allows AI agents to parse SKILL.md files and automatically trigger appropriate workflows using the skills run CLI interface or direct Python import of helper scripts.
What specific tools and platforms are referenced in the OT/ICS skills?
The skills reference industry-standard OT security platforms including Claroty xDome for passive asset discovery, Dragos for threat monitoring and analytics, Tofino ASIC firewalls for protocol enforcement, and OSIsoft PI/Ignition historians for data protection. Prerequisites for each tool are documented in the respective skill's SKILL.md under the Prerequisites section.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →