Emanuel-Walker

Cyber Portfolio — Security skill for Claude Code

Security community

My cyber + AI builder portfolio.

How to install Cyber Portfolio

This entry records only its repository, not the path inside it, so there is no exact command to give. Open Emanuel-Walker/cyber-portfolio and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Cyber Portfolio does

My cyber + AI builder portfolio. Six projects, six months. The thought partner side: Obsidian second brain + AI agent setups (Claude Code, Codex, Grok, Muse, Dot). The security side: detection-as-code, hardened LLM triage, crown jewel triage, AWS IR lab, agent skills. Plain-English walkthroughs.

Alternatives in Security

README


title: Cyber Portfolio owner: Emanuel Walker, SEC+, CySA+, SecurityX (CASP+), M.S. updated: 2026-10-03

Cyber Portfolio

**Emanuel Walker, SEC+, CySA+, SecurityX (CASP+), M.S.** Cyber + CloudSec + AI Builder

**Built by Emanuel Walker.** If this helps you, star the repo. If it changes your work, send a note.

Most people don't need another security tool. They need a thought partner they can workshop with, not a stranger that knows them.

Six projects. Two audiences. One repo.

I spent the last 6 months building both sides of that problem. The thought partner side (an Obsidian second brain plus AI agent setups you own on your own machine). And the security tooling side (detection content, triage frameworks, hardened LLM pipelines, cloud IR labs). Every project is runnable, honestly limited, and documented like a blog post I would want to read.

The six

1. Detection-as-Code with Discipline

`01-detection-as-code/`

Sigma rules shipped like software. Every rule gets a written spec, a positive test, a benign test, and a CI gate. The pipeline fails if the rule misses what it claims to catch or fires on things it should not.

**You read this if:** you want to see what detection engineering looks like when it's a program, not a hobby.

**Resume line:** Built a CI/CD pipeline for Sigma rules with Palantir ADS specs and dual-gated tests. Positive detection tests and benign non-fire tests both block merge. Converts to Elastic, Splunk, and Panther on green.

2. Prompt-Injection-Hardened LLM Triage

`02-llm-triage-hardened/`

A local Ollama triage agent for SOC alerts. Then an attack harness I built against my own agent. 12 out of 16 injections blocked. 4 still slip through. Named, explained, honest. Companion engineering to "The Agent on the Desk" (Gray Space, June 2026).

**You read this if:** you want to see what hardening an LLM for defensive work actually looks like, and what still breaks.

**Resume line:** Shipped a local LLM triage assistant with st