Skills built for
defenders.
Write once in SKILL.md — Aegis compiles it to every platform format. System prompts, ChatGPT Actions, MCP endpoints. Deploy to Claude, Gemini, Cursor and any MCP-compatible tool without changing the source.
Aegis
Author defensive security skills in a portable SKILL.md format. One source compiles to system prompts, ChatGPT Actions, and MCP server manifests — deploy to any AI platform without rewriting.
Browse skills library→Themis
An AI-powered threat analysis engine. Decompose a security task, fan out to specialist skill agents in parallel, apply guardrails to every output, and synthesise a structured findings report.
Learn More→Universal Installation
Install once globally, use with Claude, ChatGPT, Cursor, Gemini, VS Code, or Antigravity CLI.
aegis init will:
- Detect your installed tools (Claude, ChatGPT, Cursor, Gemini, VS Code, Antigravity)
- Interactively select which tools to configure
- Inject skill manifests and system prompts to each tool
- Save configuration to
~/.aegisrc
Available Commands
Show installed skills and their status for each tool.
Reconfigure a specific tool (claude, chatgpt, cursor, gemini, vscode, antigravity-cli).
Rebuild artifacts from SKILL.md — system prompt, MCP manifest, and OpenAI action schema.
Ingest a threat-intel corpus, route findings into the skills they affect, and recompile.
Serve the skill library over MCP (stdio) to Claude, Cursor and other MCP clients.
Audit API
POST to /api/audit to run a standards-based security audit against CIS, NIST CSF, ISO 27001, SOC 2, PCI-DSS, HIPAA, IEC 62443, or NIST 800-53.
Exposure Validation API
POST to /api/exposure to assess a CVE against an asset: exposure, impact, control outcome and risk, each tracked as a separate state. Authorization gates and risk scores are deterministic. The workflow plans validation but never executes it, so exploitability stays unvalidated until you supply evidence.
Write SKILL.md
Author your skill in a single markdown bundle — metadata, phases, and guidance in one file.
Compile artifacts
Run aegis compile — generates a system prompt, OpenAI action schema, and MCP manifest.
Deploy anywhere
Push to Vercel. Paste the system prompt or wire the MCP endpoint — done in minutes.
Skills go stale as the threat landscape moves. aegis intel-sync ingests a threat-intelligence corpus — news feeds, knowledge graphs, and incident teardowns — extracts the reusable attack patterns, and routes each one into the skills whose attack surface it actually lands on.
Ingest
Pull the window's feeds, knowledge graph, and teardowns. Tier each source and deduplicate against prior runs.
Extract
Turn individual incidents into reusable attack patterns and map them across the full ATT&CK chain.
Route
Send each pattern to the skills whose attack surface it lands on — by technology and domain, not headline.
Map coverage
Derive coverage prompts: recurring CVEs, dominant techniques, and where telemetry may not even exist.
Generated intel is confined to its own reference file between explicit markers — hand-authored tradecraft is never modified, and every block is fully regenerable. Auto-generated phases are excluded from health scoring so a live feed can never inflate a skill's score.