AEGISDefensive AI Skills

Skills built for
defenders.

Write once in SKILL.md — Aegis compiles it to every platform format. System prompts, ChatGPT Actions, MCP endpoints. Deploy to Claude, Gemini, Cursor and any MCP-compatible tool without changing the source.

ChatGPTClaudeCursorGemini
01The Platform
AEGIS

Aegis

Skill compiler · Marketplace · API

Author defensive security skills in a portable SKILL.md format. One source compiles to system prompts, ChatGPT Actions, and MCP server manifests — deploy to any AI platform without rewriting.

Browse skills library→
THEMIS

Themis

LangGraph orchestrator · Multi-agent analysis

An AI-powered threat analysis engine. Decompose a security task, fan out to specialist skill agents in parallel, apply guardrails to every output, and synthesise a structured findings report.

Learn More→
02Getting Started

Universal Installation

Install once globally, use with Claude, ChatGPT, Cursor, Gemini, VS Code, or Antigravity CLI.

npm install -g @aegis-skills/core
aegis init

aegis init will:

  • Detect your installed tools (Claude, ChatGPT, Cursor, Gemini, VS Code, Antigravity)
  • Interactively select which tools to configure
  • Inject skill manifests and system prompts to each tool
  • Save configuration to ~/.aegisrc

Available Commands

aegis list

Show installed skills and their status for each tool.

aegis configure --for <tool>

Reconfigure a specific tool (claude, chatgpt, cursor, gemini, vscode, antigravity-cli).

aegis compile [skill]

Rebuild artifacts from SKILL.md — system prompt, MCP manifest, and OpenAI action schema.

aegis intel-sync

Ingest a threat-intel corpus, route findings into the skills they affect, and recompile.

aegis mcp

Serve the skill library over MCP (stdio) to Claude, Cursor and other MCP clients.

Audit API

POST to /api/audit to run a standards-based security audit against CIS, NIST CSF, ISO 27001, SOC 2, PCI-DSS, HIPAA, IEC 62443, or NIST 800-53.

POST /api/audit
{ "input": "<config or policy text>",
"inputType": "config",
"standards": ["cis-l1", "nist-csf"] }

Exposure Validation API

POST to /api/exposure to assess a CVE against an asset: exposure, impact, control outcome and risk, each tracked as a separate state. Authorization gates and risk scores are deterministic. The workflow plans validation but never executes it, so exploitability stays unvalidated until you supply evidence.

POST /api/exposure
{ "input": "<advisory or asset description>",
"cve": "CVE-2026-12345", "kevListed": true,
"authorization": { "authorized": true, "scopeConfirmed": true,
"targetIdentityVerified": true },
"context": { "businessCriticality": "high", "environments": ["cloud"] } }
03How it works
01

Write SKILL.md

Author your skill in a single markdown bundle — metadata, phases, and guidance in one file.

02

Compile artifacts

Run aegis compile — generates a system prompt, OpenAI action schema, and MCP manifest.

03

Deploy anywhere

Push to Vercel. Paste the system prompt or wire the MCP endpoint — done in minutes.

04Skills Library

Find skills for your environment

Select environments and attack surface focus areas to get ranked recommendations.

Environments
Attack surface
24 skills · 22 live
application-securityLIVEApplication security assessment workflow covering threat modelling, static analysis, dependency auditing, API security, and security…Domain Defence5 phases94attack-surface-mappingLIVEAttack surface mapping and exposure analysis workflowThreat Intel5 phases92complianceLIVEEnd-to-end security compliance workflow covering scope definition, regulatory mapping, control assessment, evidence collection, and…Governance & Risk5 phases100data-loss-preventionLIVECross-layer data loss prevention (DLP) programme covering data classification and discovery, network egress and DNS exfiltration con…Domain Defence6 phases97deception-engineeringLIVEEnd-to-end deception engineering workflow for defensive security programsDomain Defence6 phases99digital-forensicsLIVEEnd-to-end digital forensics and incident response (DFIR) workflowResponse & Analysis6 phases100endpoint-securityLIVEEndpoint security workflow covering EDR deployment, baseline hardening, malware analysis, and endpoint incident responseDomain Defence5 phases96exposure-validationContinuous exposure validation (CTEM) — prove which vulnerabilities are actually exposed, exploitable and impactful in an authorized…Threat Intel6 phases94governanceLIVESecurity governance programme design and managementGovernance & Risk4 phases95identity-access-managementLIVEComprehensive IAM programme covering identity governance (Joiners/Movers/Leavers), human authentication (FIDO2, SSO, passwordless),…Domain Defence6 phases100infrastructure-securityLIVEInfrastructure security assessment workflow covering asset discovery, configuration baseline, patch management, hardening controls,…Domain Defence5 phases95malware-analysisLIVEComprehensive malware analysis workflow from sample triage through intelligence reportingResponse & Analysis6 phases100mitre-atlasLIVEMITRE ATLAS adversarial ML/AI attack surface assessment and countermeasure planning workflowFrameworks5 phases100mitre-attackLIVEMITRE ATT&CK threat modelling workflowFrameworks3 phases94mitre-engageLIVEMITRE Engage adversary engagement and deception planning workflowFrameworks2 phases91network-securityLIVENetwork security assessment and hardening workflowDomain Defence5 phases98operational-technologyLIVEOT/ICS security programme covering asset discovery, risk assessment, network security (ISA/IEC 62443 zone and conduit model), incide…Domain Defence7 phases99reverse-engineeringLIVEEnd-to-end binary reverse engineering workflow for security analystsResponse & Analysis5 phases99risk-managementLIVEEnd-to-end information security risk management programme covering risk identification, qualitative and quantitative assessment (FAI…Governance & Risk6 phases100security-documentationLIVESecurity documentation authoring workflow for policies, runbooks, and incident response templatesGovernance & Risk3 phases93security-operationsLIVEFull security operations workflow covering the complete SOC operating model — from alert triage through threat intelligence, vulnera…Response & Analysis9 phases98threat-huntingLIVEProactive threat hunting workflowThreat Intel5 phases93threat-intel-synthesisLIVETurn raw threat intelligence — news feeds, knowledge graphs, vendor advisories, and incident teardowns — into structured attack patt…Threat Intel6 phases94threat-modelingStructured threat modelling workflow using STRIDE and PASTA methodologiesThreat Intel4 phases95
05Self-Updating Intel

Skills go stale as the threat landscape moves. aegis intel-sync ingests a threat-intelligence corpus — news feeds, knowledge graphs, and incident teardowns — extracts the reusable attack patterns, and routes each one into the skills whose attack surface it actually lands on.

01

Ingest

Pull the window's feeds, knowledge graph, and teardowns. Tier each source and deduplicate against prior runs.

02

Extract

Turn individual incidents into reusable attack patterns and map them across the full ATT&CK chain.

03

Route

Send each pattern to the skills whose attack surface it lands on — by technology and domain, not headline.

04

Map coverage

Derive coverage prompts: recurring CVEs, dominant techniques, and where telemetry may not even exist.

$ aegis intel-sync --days 7
corpus: 199 article(s) · 2 teardown(s) · graph 323 nodes
routed to 19 skill(s) · coverage prompts written
✓ intel blocks written · artifacts recompiled

Generated intel is confined to its own reference file between explicit markers — hand-authored tradecraft is never modified, and every block is fully regenerable. Auto-generated phases are excluded from health scoring so a live feed can never inflate a skill's score.