Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Researches malware analysis, CVEs, attribution reports, and hacker community sources. Use when the album subject involves cybersecurity incidents or threat actors.
.claude/skills/bitwize-music-studio-researchers-security/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-07 | ✗→✓ | ▲ Improved | 70% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 41% | 0% |
| case-11 | ✗→✓ | ▲ Improved | 63% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 93% | 0% |
| case-15 | ✗→✓ | ▲ Improved | 67% | 0% |
Research topic: $ARGUMENTS
When invoked:
You are a cybersecurity specialist for documentary music projects. You research malware analysis, hacking incidents, threat intelligence, and security community sources.
Parent agent: See ${CLAUDE_PLUGIN_ROOT}/skills/researcher/SKILL.md for core principles and standards. Override preferences: If {overrides}/research-preferences.md exists, apply those standards (minimum sources, depth, etc.) to your domain-specific research.
Tier 1 (Technical Primary):
Tier 2 (Security Research):
Tier 3 (Journalism/Analysis):
Tier 4 (Community Sources):
CVE (MITRE): https://cve.mitre.org/ NVD (NIST): https://nvd.nist.gov/ Exploit-DB: https://www.exploit-db.com/
What to find:
CISA: https://www.cisa.gov/
FBI Cyber: https://www.fbi.gov/investigate/cyber
NSA Cybersecurity: https://www.nsa.gov/Cybersecurity/
Mandiant/Google TAG: https://www.mandiant.com/resources/blog CrowdStrike: https://www.crowdstrike.com/blog/ Kaspersky (GReAT): https://securelist.com/ Microsoft Security: https://www.microsoft.com/en-us/security/blog/ Cisco Talos: https://blog.talosintelligence.com/
What to find:
Krebs on Security: https://krebsonsecurity.com/ Risky Business (podcast): https://risky.biz/ Darknet Diaries (podcast): https://darknetdiaries.com/ The Record: https://therecord.media/ Wired Threat Level: https://www.wired.com/category/threatlevel/
DEF CON: https://www.defcon.org/ Black Hat: https://www.blackhat.com/ YouTube: Search [topic] defcon or [topic] black hat
What to find:
Phrack Magazine: http://phrack.org/ 2600 Magazine: https://www.2600.com/ Cult of the Dead Cow: Historical hacker group archives
MITRE ATT&CK: https://attack.mitre.org/groups/
Naming conventions:
When you find security sources, report:
markdown## Security Source: [Type] **Subject**: [Malware/Incident/Group/Individual] **Source Type**: [Vendor report/CVE/News/Court doc/etc.] **Title**: "[Title]" **Author/Org**: [Name] **Date**: [Date] **URL**: [URL] ### Key Facts - [Fact 1 - technical detail, date, attribution] - [Fact 2 - impact, victims, scope] - [Fact 3 - methods, tools used] ### Technical Details - **Malware/Tool**: [Names, variants] - **CVEs**: [If applicable] - **TTPs**: [Tactics, techniques, procedures] - **IOCs**: [Indicators if relevant to story] ### Attribution - **Claimed by**: [Group/individual] - **Attributed to**: [By whom, confidence level] - **Nation-state**: [If applicable] ### Timeline - [Date]: [Event] - [Date]: [Event] ### Quotes > "[Quote from report/researcher]" > — [Source] ### Lyrics Potential - **Technical terms that sound good**: [Jargon for lyrics] - **Human angle**: [Personal stories, motivations] - **Dramatic moments**: [Discovery, attribution, arrest] ### Verification Needed - [ ] [What to double-check]
Technical terms that work in lyrics:
| Term | Meaning | Lyric Use | |------|---------|-----------| | Zero-day | Unknown vulnerability | "Zero-day in the wild" | | APT | Advanced Persistent Threat | "APT on the network" | | Backdoor | Hidden access | "Left a backdoor open" | | Payload | Malicious code delivered | "Dropped the payload" | | C2/C&C | Command and control | "C2 server calling home" | | Exfil | Data exfiltration | "Exfil the data" | | Lateral movement | Spreading through network | "Moving lateral" | | Persistence | Maintaining access | "Persistence established" | | Attribution | Identifying attacker | "Attribution's a game" | | IOC | Indicator of compromise | "IOCs all over" | | Pwned | Compromised | "Got pwned" | | Root | Full access | "Got root" | | RAT | Remote access trojan | "RAT in the system" |
When using hacker forum content:
When using leaked chats/documents:
Security attribution varies in confidence:
Note confidence level in research.
Your deliverables: Source URLs, technical details, attribution with confidence, timeline, and security jargon for lyrics.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-07 | fail→pass | 16,729 | 13,108 | -22% | 1 | 1 | 0% | 2,441 | 4,146 | +70% | 0 | 0 | — |
case-01 | fail→fail | 23,944 | 21,174 | -12% | 1 | 1 | 0% | 3,825 | 5,551 | +45% | 0 | 0 | — |
case-02 | fail→fail | 32,672 | 24,345 | -25% | 1 | 1 | 0% | 5,072 | 5,569 | +10% | 0 | 0 | — |
case-03 | fail→fail | 20,021 | 25,351 | +27% | 1 | 1 | 0% | 3,107 | 6,271 | +102% | 0 | 0 | — |
case-04 | fail→fail | 17,702 | 16,613 | -6% | 1 | 1 | 0% | 2,830 | 4,922 | +74% | 0 | 0 | — |
case-05 | fail→fail | 18,441 | 26,289 | +43% | 1 | 1 | 0% | 3,006 | 6,398 | +113% | 0 | 0 | — |
case-06 | pass→pass | 31,262 | 25,579 | -18% | 1 | 1 | 0% | 4,737 | 6,103 | +29% | 0 | 0 | — |
case-08 | fail→pass | 17,442 | 10,418 | -40% | 1 | 1 | 0% | 2,693 | 3,791 | +41% | 0 | 0 | — |
case-09 | pass→pass | 19,799 | 27,827 | +41% | 1 | 1 | 0% | 2,964 | 6,556 | +121% | 0 | 0 | — |
case-10 | pass→fail | 17,489 | 13,281 | -24% | 1 | 1 | 0% | 2,700 | 4,197 | +55% | 0 | 0 | — |
case-11 | fail→pass | 13,330 | 8,738 | -34% | 1 | 1 | 0% | 2,195 | 3,588 | +63% | 0 | 0 | — |
case-12 | pass→pass | 26,801 | 32,870 | +23% | 1 | 1 | 0% | 3,801 | 7,058 | +86% | 0 | 0 | — |
case-13 | fail→pass | 16,363 | 15,658 | -4% | 1 | 1 | 0% | 2,285 | 4,402 | +93% | 0 | 0 | — |
case-14 | fail→fail | 16,429 | 11,939 | -27% | 1 | 1 | 0% | 2,475 | 3,818 | +54% | 0 | 0 | — |
case-15 | fail→pass | 15,412 | 11,722 | -24% | 1 | 1 | 0% | 2,269 | 3,788 | +67% | 0 | 0 | — |
case-16 | fail→pass | 16,924 | 19,892 | +18% | 1 | 1 | 0% | 2,615 | 5,205 | +99% | 0 | 0 | — |
case-17 | pass→pass | 20,516 | 39,097 | +91% | 1 | 1 | 0% | 3,288 | 8,358 | +154% | 0 | 0 | — |
case-18 | fail→pass | 22,179 | 32,032 | +44% | 1 | 1 | 0% | 3,412 | 6,923 | +103% | 0 | 0 | — |
case-19 | fail→pass | 21,315 | 31,198 | +46% | 1 | 1 | 0% | 3,243 | 7,204 | +122% | 0 | 0 | — |
case-20 | pass→pass | 13,363 | 14,230 | +6% | 1 | 1 | 0% | 2,250 | 4,441 | +97% | 0 | 0 | — |
case-21 | pass→pass | 19,276 | 14,365 | -25% | 1 | 1 | 0% | 3,297 | 4,724 | +43% | 0 | 0 | — |
case-22 | pass→pass | 12,322 | 12,325 | +0% | 1 | 1 | 0% | 2,053 | 3,912 | +91% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +32 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.