Casky.AI
ApproachPathsBlogAboutCommunity
Sign inGet Access
🚦 NEW WORKSHOP SERIES

You're doing 100 mph in the vibe-coding fast lane,
with no security checks.

The Vibe Coding Security Top 10 Gotchas investigates a real, sourced breach pattern: Supabase RLS left open, secrets shipped in the JS bundle, slopsquatted packages, the way it actually happened in 2025–26. Free to run yourself. Live 2-session workshop on Maven.

✓Free to run yourself
✓Lightning Lesson — announcing soon
✓Two 90-min live sessions
✓Real, sourced 2025–26 incidents
Reserve your seat on Maven →Run it yourself, free →
Speeding cars on a neon night track, each branded with an AI coding tool decal — the vibe-coding fast lane
↗Based on the popular Anthropic Cybersecurity Skills & Agents open-source repo
31.9k stars·3.8k forksfeatured in★
mapped to
MITRE ATT&CK14 tactics · 291 techniques
NIST CSF 2.06 functions · full lifecycle
OWASP Top 102025 edition
Claude Sonnet 4.6Multi-Agent Investigation Pipeline

The approach

The investigation platform built for
how security actually works

Real evidence in. Structured, CVSS-scored, MITRE-mapped findings out.

01

Ingest your evidence

Paste logs, upload files, or drop a CloudTrail export. Any source, any format.

02

Context assembles automatically

CVE exposure, matched investigation playbooks, your team's rated past cases, and organizational memory from past outcomes — assembled in parallel before any AI touches your evidence.

03

Review and approve the plan

Four specialist agents generate a MITRE-mapped plan, each step with a rationale and expected finding. You edit and approve before anything runs.

The platform

See it in action

A real look at the Casky Playground.

Your mission control — runs, findings, and activity at a glance
Dashboard
Your mission control — runs, findings, and activity at a glance
Real-time overview of your security work
Dashboard
Real-time overview of your security work
Pick a skill, set your target, run a Claude agent
Skills Lab
Pick a skill, set your target, run a Claude agent
Navigate the curriculum by MITRE, NIST, or OWASP
Learning Path
Navigate the curriculum by MITRE, NIST, or OWASP
Track every agent run directly from your dashboard
Dashboard — Runs
Track every agent run directly from your dashboard
All your CVSS-scored findings in one view
Dashboard — Findings
All your CVSS-scored findings in one view
From agent run to structured security finding
Runs & Findings
From agent run to structured security finding
Detailed run output with linked findings
Runs & Findings
Detailed run output with linked findings
Claude reasoning live through a security problem
Skills Run
Claude reasoning live through a security problem
Full run history with status, target, and timing
Runs
Full run history with status, target, and timing
Stream Claude's agent reasoning in real time
Run Detail
Stream Claude's agent reasoning in real time
From findings to a professional assessment report
Reports & Findings
From findings to a professional assessment report
Export full reports — executive summary, findings, remediation
Reports
Export full reports — executive summary, findings, remediation
818 skills mapped to MITRE ATT&CK, NIST CSF, and OWASP
Skills Registry
818 skills mapped to MITRE ATT&CK, NIST CSF, and OWASP
CVSS-scored findings tagged to MITRE techniques
Findings
CVSS-scored findings tagged to MITRE techniques

818 skills · 12 domains

Every security domain, covered.

Not just cloud. Not just web. From OSINT to container security, Casky covers the full attack surface. The investigation pipeline adapts to whatever evidence you bring.

OSINT & Recon
0 skills
TA0043NIST ID
Web App & API Security
70 skills
OWASP A01–A10

Built for every practitioner

Democratizing cybersecurity for everyone.

From network security to cloud security to penetration testing — Casky is for every practitioner. The investigation plan adapts to your role. Same evidence in. Role-aware plan out.

Cloud Security Engineer

IAM escalation · S3 exposure · cross-account access · GuardDuty findings

TA0004NIST PR

Network Security Engineer

Traffic anomalies · lateral movement · C2 detection · DNS tunneling

Built forSOC AnalystsSecurity Leads & CISOsJunior PractitionersSecurity ConsultantsSMB Security Teams
Early access — Playground waitlist now open

Run your first real
investigation — free.

Paste your evidence. Get CVSS-scored, MITRE-mapped findings. No simulation. No CTF flags. Your actual security work — with 818 AI-powered skills behind it. Free for early members.

We'll email you when the Playground opens. No spam. Unsubscribe anytime.

818
Skills in Playground
Free
For early members
Async
Learn at your pace
Casky.AI, Inc.· AI-Powered Cyber Skills
AboutEnterpriseCommunityContributeSign inContact
XInstagramLinkedIn
awesome-agent-skills
·
SkillsLLM
·
Openflows
Apache 2.0·Open source

AI Security Investigation

Run real investigations.
Ship professional findings.

A CVE drops. Your multi-agent pipeline has an investigation plan in under 5 minutes. Ingest real logs, configs, or incident data and Casky's agents generate a structured plan your team approves, then execute in parallel to produce CVSS-scored, MITRE-mapped findings.

Find Your First Real Vulnerability — FreeSee how it works
818
AI-powered skills
5
Investigation paths
< 5 min
Evidence → findings
RJ
MJ

Built by practitioners.
15+ years of real engagements →

claude-agent · OWASP A03: Injection
running
01▶ target: demo.testfire.net
02 loading: SQL Injection Detection
03 mapping: MITRE T1190 · OWASP A03
04 probing /login — testing 8 vectors
05⚠ anomalous response on: username
06 testing boolean-based blind inject...
07✗ CONFIRMED: Blind SQLi at /login
08 estimating blast radius...
09✓ report_finding("SQL Injection", "critical")
10 CVSS: 9.8 · CWE-89 · T1190
11 generating remediation guidance ▌
04

Agents run in parallel

Each approved step executes as a skill run. CVSS-scored, technique-tagged findings land as they complete.

05

Generate the CISO report

One click. Executive summary, confirmed MITRE techniques, findings table, prioritised remediation. The format used in real engagements.

Makes SOC analysts better, faster,
and smarter as a team.

Makes good analysts better.

A structured, MITRE-mapped plan from raw evidence — anchored to specific log artifacts, reviewable in 60 seconds.

No one analyst knows everything.

Pool any evidence into one investigation. The AI planner sees everything; your team's rated cases calibrate every future plan.

Your best work trains your next analyst.

Every rated investigation becomes a step-by-step training artifact — evidence, rationale, findings, and report — from your own environment.

Run a free investigation →Building a security team? →
Malware Analysis
39 skills
TA0002NIST DE
Cloud & Infrastructure
66 skills
TA0004NIST PR
Digital Forensics & IR
67 skills
TA0040NIST RS
Network Security
43 skills
TA0011NIST DE
Identity & Access
54 skills
TA0006NIST PR
Red Teaming
54 skills
AllNIST ID
DevSecOps
18 skills
NIST PROWASP A03,A08
Threat Intelligence
110 skills
TA0043NIST ID
SOC Operations
35 skills
NIST DE/RS
Container Security
33 skills
NIST PROWASP A05,A06
TA0011NIST DE

Web & App Security Engineer

OWASP Top 10 · API abuse · auth bypass · injection chains

OWASP A01–A10

SOC Analyst

Alert triage · threat detection · incident timeline · CISO escalation

TA0040NIST DE/RS

Penetration Tester

Recon · exploitation · privilege escalation · engagement report

AllNIST ID
TikTok
TermsPrivacyLegal Disclaimer

© 2026 Casky.AI, Inc. · AI Security Investigation