mcpbeat Sign in

Quickstart Skill for Claude

>- intro, then an offer to walk you through your first run on the canary cites where it looked, and hands you the next command. Use for "how do I…", "why does…", "where is…", "can this…", or just "/quickstart" to get oriented.

1k tokens
context cost
the whole folder, loaded on every use
1
files
instructions only
0
copies elsewhere
how many repositories repackaged it
6909
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/anthropics/defending-code-reference-harness --skill quickstart

What it tells the agent to use

found in the instruction text
Grep reads your files
Task spawns other agents

The instruction itself

7 sections, as written by the author

/quickstart

Two modes, picked by whether $ARGUMENTS is empty.

  • Empty → Intro mode. Short orientation, then offer the guided first run.
  • Non-empty → Help mode. Treat $ARGUMENTS as the operator's question.

Intro mode

Keep it short and a little warm; this is the first thing a new operator sees.

Say roughly:

> Welcome! This repo takes you from finding your first vulnerability to

> patching at scale, using a set of Claude Code skills and an autonomous

> pipeline. Two ways in: interactive skills (no setup, safe, start here)

> and the autonomous pipeline (Docker, scales to hundreds of parallel

> agents).

>

> The ramp-up:

>

> | Day 1 | Threat-model + first static scan + triage |

> | Day 2 | Run the reference pipeline (C/C++) |

> | Day 3-4 | Customize it for your stack |

> | Week 2 | Autonomous scanning, triage, and patching |

>

> Day-1 goal: threat-model, scan, and triage the bundled canary target.

> Most teams get there before lunch.

Remind them to export CLAUDE_CODE_SUBAGENT_MODEL=<model-id> so subagents

use the same model as the session.

Then AskUserQuestion with three options:

  • Walk me through Day 1 on the canary (~10 min) → run "Guided first

run" below.

  • I have a question → ask what it is, then switch to Help mode.
  • I'll read the README → point at README.md Step 1 and stop.

Guided first run

Runs the three Step-1 skills on targets/canary, pausing after each to show

what landed on disk. These only read/write files in the repo; no sandbox

needed.

  • /threat-model bootstrap targets/canary via Task. When done, open

THREAT_MODEL.md, show the focus areas, explain in 2-3 sentences how

this steers the scan.

  • /vuln-scan targets/canary via Task. When done, open

targets/canary/VULN-FINDINGS.md, summarize the count and top 2-3

findings, point at VULN-FINDINGS.json.

  • /triage targets/canary/VULN-FINDINGS.json via Task. When done, open

TRIAGE.md, explain what changed vs. raw findings (verified, deduped,

re-ranked).

Pause for the operator between each (AskUserQuestion); don't barrel through.

Close with a one-line recap of the three artifacts on disk, then point at

README Step 2 for the execution-verified pipeline. **Never run vuln-pipeline

or anything that executes target code here**; that's Step 2 and needs

Docker + a sandbox.


Help mode

Answer the operator's question using this repo as ground truth: README,

docs/*.md, harness/*.py, dnr_harness/*.py, targets/*/config.yaml,

.claude/skills/*.

Don't answer from general knowledge when the repo has a specific answer.

Routing map

| If the question is about… | Read first | Then offer |

|---------------------------------|-----------------------------------------|------------|

| running the pipeline | docs/pipeline.md, README Step 2 | the recon / run command |

| too many findings, triage | docs/triage.md | /triage <path> |

| porting, Java/Go/Rust/etc. | docs/customizing.md, README Step 3 | /customize |

| safety, sandbox, Docker | docs/security.md | cite; no action |

| rate limits, 429, token budget | docs/pipeline.md: Rate limits, docs/troubleshooting.md#rate-limits | cite the numbers |

| duplicates, dedup | docs/troubleshooting.md#duplicate-findings | known_bugs: hint |

| CLI flags, "what does --X do" | harness/cli.py (grep the argparse) | exact flag + example |

| which model, subagent pinning | docs/troubleshooting.md: Subagents | the export line |

| best practices, prompting | docs/best-practices.md, docs/prompting.md | cite the principle |

| threat model, attack surface, scope | docs/threat-model.md | /threat-model bootstrap <target-dir> |

| scan, audit, find vulns | .claude/skills/vuln-scan/SKILL.md | /vuln-scan <target-dir> |

| "how do I start" | README Step 1 | offer Guided first run |

| patching, fix, diff, re-attack | docs/patching.md, README Step 4 | /patch <input> |

| threat hunting, incident response, logs | docs/detection-response.md | /dnr-hunt or /dnr-respond |

| autonomous D&R, dnrcanary | docs/detection-response.md, targets/dnrcanary/README.md | the dnr-pipeline run command |

| binary, embedded, other domains | docs/other-use-cases.md | cite section |

| anything else | README Table of contents | best-match doc |

Answer format

  • Direct answer in 2-5 sentences.
  • > source: the file(s) and section you used.
  • Next action: one copy-pasteable command or skill invocation, if one

applies. If none does, say so.

  • If the question is ambiguous, ask one clarifying question; don't guess.

Constraints

  • Never fabricate CLI flags or file paths. If unsure, Grep for it in

harness/cli.py or the target configs and quote what you find.

  • If the repo doesn't answer the question, say so plainly and suggest the

operator open a GitHub issue on this repo.

  • Keep the Q&A dry and cited. Save the warmth for Intro mode.

Other skills for the same job

different authors, same section of the catalogue
Protocolsio Integration
by christophacham
×4

Integration with protocols.io API for managing scientific protocols. This skill should be used when working with protocols.io to search, create, update, or publish protocols; manage protocol steps and materials; handle discussions and comments; organize workspaces; upload and manage files; or integrate protocols.io functionality into workflows. Applicable for protocol discovery, collaborative protocol development, experiment tracking, lab protocol management, and scientific documentation.

16k tokens
Tailored Resume Generator
by frostant
×4

Analyzes job descriptions and generates tailored resumes that highlight relevant experience, skills, and achievements to maximize interview chances

3k tokens
Excalidraw Diagram Generator
by github
vendor ×3

Generate Excalidraw diagrams from natural language descriptions. Use when asked to "create a diagram", "make a flowchart", "visualize a process", "draw a system architecture", "create a mind map", or "generate an Excalidraw file". Supports flowcharts, relationship diagrams, mind maps, and system architecture diagrams. Outputs .excalidraw JSON files that can be opened directly in Excalidraw.

36k tokens scripts
Expo Dev Client
by openai
vendor ×3

Build and distribute Expo development clients locally or via TestFlight

961 tokens
Executing Plans
by ZhanlinCui
×3

Use when you have a written implementation plan to execute in a separate session with review checkpoints

542 tokens
Anndata
by christophacham
×3

Data structure for annotated matrices in single-cell analysis. Use when working with .h5ad files or integrating with the scverse ecosystem. This is the data format skill—for analysis workflows use scanpy; for probabilistic models use scvi-tools; for population-scale queries use cellxgene-census.

16k tokens
Benchling Integration
by christophacham
×3

Benchling R&D platform integration. Access registry (DNA, proteins), inventory, ELN entries, workflows via API, build Benchling Apps, query Data Warehouse, for lab data management automation.

14k tokens
Biopython
by christophacham
×3

Comprehensive molecular biology toolkit. Use for sequence manipulation, file parsing (FASTA/GenBank/PDB), phylogenetics, and programmatic NCBI/PubMed access (Bio.Entrez). Best for batch processing, custom bioinformatics pipelines, BLAST automation. For quick lookups use gget; for multi-service integration use bioservices.

24k tokens

How to use it

Copy the folder

Take anthropics/quickstart from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.