Skillquality 0.53

find-cybersecurity-firm

Use whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed SOC, IAM, cloud security, and AppSec. Triggers on "find me a pen-testing firm for our SOC 2 audit", "s

Price
free
Protocol
skill
Verified
no

What it does

find-cybersecurity-firm

Drive the ServiceGraph API (https://api.servicegraph.co) to find, shortlist, and enrich US cybersecurity firms.

Always pin service_provided:cybersecurity — that's the only relevant structured tag in the live catalog. Older skill docs and the catalog source mention sub-tags like pen-testing and security-audit, but in the current release none of those exist as separate tagscybersecurity is the broad catch-all and every sub-type (pen-testing, red-team, vCISO, SOC 2 readiness, IR retainer, IAM, cloud security, AppSec) is a keyword substring search on firm text. Confirm via /v1/tags?include_values=1 once per session.

The industry tag also drifts between releases — newer catalogs use industry:cybersecurity, older ones used industry:security. Confirm the value via /v1/tags and pin both industry and service_provided:cybersecurity for safety.

Any HTTP client works (curl, fetch, requests). Examples below use curl.

When NOT to use this skill

  • Consumer/personal cybersecurity ("my Gmail got hacked", "how do I secure my home wifi") — the catalog is B2B procurement only.
  • In-house security hires (Security Engineer, CISO, SOC analyst).
  • DIY/configuration questions ("how do I patch CVE-X", "configure firewall rules", "review this nginx config").
  • Security-product comparisons (CrowdStrike vs SentinelOne, EDR vendors, SIEM vendors).
  • Generic security knowledge ("explain zero-trust", "what is OWASP Top 10").
  • Non-US firms.
  • Individual freelance pen-testers / bug-bounty hunters / contract CISOs.

If the user is a business procuring external cybersecurity services (pen test, audit, vCISO, IR retainer, SOC 2 prep), this skill applies — defaults to fire on B2B procurement intent.

MCP server (preferred for authed calls)

If your agent harness has the ServiceGraph MCP server loaded (https://mcp.servicegraph.co), prefer its tools for the authed tier (/search, /get, /stats). The MCP server uses OAuth 2.1 + PKCE — the host harness handles credentials in its own audited sandbox, so there's no .env.local, no shell dispatch, and no token value ever enters the LLM context.

For the anonymous tier (/tags, /check, /explore), MCP is not preferred — every MCP tool requires OAuth (the server has no anonymous tier), so plain curl against the REST URL is the simpler path for discovery calls. Use the REST patterns below for those.

The MCP tools 1:1-map to the public REST endpoints — same backend, same quota, same data:

MCP toolREST endpointAnon?Recommended path
list_tagsGET /v1/tagsyescurl
check_filterGET /v1/checkyescurl
explore_firmsGET /v1/exploreyescurl
search_firmsGET /v1/searchnoMCP if loaded, else curl + OTP
get_firmGET /v1/get/:idnoMCP if loaded, else curl + OTP
catalog_statsGET /v1/statsnoMCP if loaded, else curl + OTP

Detection: if you see any MCP tools with servicegraph in the name (the harness-specific prefix varies — agents pattern-match the substring), the ServiceGraph MCP server is loaded. Prefer those tools for the authed tier; complete any auth flow the harness initiates if needed. If no servicegraph MCP tools are present, fall through to the REST + OTP flow below for the authed tier.

The four-tier funnel

TierAuthCostUse it for
GET /v1/tagsnonefreeFirst call of every session. Discover legal field names, kinds, operators, values.
GET /v1/check?filter=...nonefreeValidate a filter before spending an explore/search call.
GET /v1/explore?filter=...nonefree, IP-throttledScope: count + breakdowns. Use to size the candidate pool before quota-spending.
GET /v1/search?filter=...bearer200 unique firms / month freeBrief firm cards. No url, no contact info. Use for ranking / shortlisting.
GET /v1/get/:idbearer50 unique firms / month freeFull bundle: url, phone, email, social, legal name, address. Only call for shortlisted firms.
POST /v1/researchpaidnot in MVPDeferred — skip.

Quota rule that matters: /search and /get charge per unique firm viewed per calendar month, not per call. Re-paging the same query is free. Two different filters that overlap charge once for the overlap. Re-fetching a firm you already pulled this month is free.

Session-start ritual

Before constructing any filter, call:

GET https://api.servicegraph.co/v1/tags?include_values=1

Cache the response for the conversation. Confirm the cybersecurity industry tag value name (cybersecurity or older security) and that cybersecurity is in the service_provided value list. The live catalog has only the broad service_provided:cybersecurity tag — there are no separate pen-testing / security-audit / appsec tags despite older docs sometimes mentioning them.

Field kinds you'll use most:

  • categorical: industry (cybersecurity), state, pricing_model, company_size_signal, geography_served — op :
  • tag_set_with_evidence: service_provided — Map<tag, evidence∈{low,medium,high}>. Op : with optional @evidence
  • numeric: rating, review_count_total, founded_year — ops = >= <= > <
  • presence: has:phone, has:clutch, has:rating, has:linkedin_company, …
  • keyword: free-text substring across firm name / brand / title / meta / legal_name. Many sub-types (vCISO, SOC 2, IR retainer, IAM, AppSec) are keyword-only.

Auth

/tags, /check, and /explore are anonymous. /search and /get require a bearer token.

Security model — keep the token out of the LLM context.

  • Never read .env, .env.local, or any other credential file into your context. The token's literal value should never appear in the conversation.
  • Use shell dispatch for every authed request so the token flows directly from the user's environment / dotenv file into the Authorization header without round-tripping through the LLM.
  • Always ask the user once per session before using a detected token, even if it's already in their shell or .env.local.

Resolution rule:

  1. Detect whether a token is available — without reading its value. Run a shell check that only inspects exit codes:

    ( [ -n "${SERVICEGRAPH_TOKEN:-}" ] \
      || grep -qs '^SERVICEGRAPH_TOKEN=' .env.local \
      || grep -qs '^SERVICEGRAPH_TOKEN=' .env )
    

    Exit code 0 = token is available somewhere; non-zero = no token.

  2. Confirm with the user before the first authed call this session:

    "I found a SERVICEGRAPH_TOKEN in your environment / .env.local. OK to use it for ServiceGraph API requests this session?"

    If the user says no, stay on the anonymous tiers (/tags, /check, /explore) and skip authed calls. Don't re-ask later unless the user asks for authed work.

  3. Dispatch via shell — every authed call goes through a shell wrapper so the literal token never enters the conversation:

    # If exported in the shell environment:
    curl -H "Authorization: Bearer $SERVICEGRAPH_TOKEN" \
         'https://api.servicegraph.co/v1/search?filter=...'
    
    # If in .env.local — source it inside a subshell so it doesn't
    # leak into the parent shell either:
    ( set -a; . ./.env.local; set +a;
      curl -H "Authorization: Bearer $SERVICEGRAPH_TOKEN" \
           'https://api.servicegraph.co/v1/search?filter=...' )
    

    Capture the response body to a tmp file or jq-process it, but do NOT echo the request command with the token expanded.

  4. OTP flow if no token is detected — capture the new token directly into .env.local without surfacing its value to the LLM:

    # 1. trigger the email — agent prompts the user for $EMAIL
    curl -fsS -X POST 'https://api.servicegraph.co/v1/auth/request-otp' \
      -H 'Content-Type: application/json' \
      -d "{\"email\":\"$EMAIL\"}"
    
    # 2. exchange the code — agent prompts the user for $CODE.
    #    The ?format=env query param returns SERVICEGRAPH_TOKEN=<token>
    #    as plain text appended to .env.local — no jq needed. The -f
    #    flag makes curl exit non-zero on 4xx so a wrong code doesn't
    #    pollute the file (the error mirror is also a `# comment` line,
    #    safe to ignore even if it lands).
    curl -fsS -X POST 'https://api.servicegraph.co/v1/auth/verify-otp?format=env' \
      -H 'Content-Type: application/json' \
      -d "{\"email\":\"$EMAIL\",\"code\":\"$CODE\",\"name\":\"claude-cli\"}" \
      >> .env.local
    
    # 3. confirm capture without revealing the value
    grep -q '^SERVICEGRAPH_TOKEN=' .env.local && echo "OTP token captured."
    

    After a successful capture, the user has implicitly consented (they just completed the flow), so proceed to dispatch (step 3). The token is now persistent in .env.local for future sessions.

  5. If a /search or /get returns 401 unauthorized mid-session, the token expired or was revoked — re-run the OTP flow.

Filter DSL

One query parameter, GitHub-search-style.

filter   := orExpr
orExpr   := andExpr ("OR" andExpr)*
andExpr  := notExpr (("AND")? notExpr)*    # whitespace = implicit AND
notExpr  := ("NOT" | "-") notExpr | atom
atom     := "(" filter ")" | predicate
predicate:= IDENT op valueOrList | bareword
op       := ":" | "=" | ">=" | "<=" | ">" | "<"
valueOrList := value ("," value)*
value    := IDENT | NUMBER | tagAtEvidence
tagAtEvidence := IDENT "@" ("low"|"medium"|"high")
bareword := IDENT | NUMBER          # → keyword:<bareword>

Four rules that bite:

  1. AND binds tighter than OR. a OR b c parses as a OR (b AND c). Use parens.
  2. Comma list = OR within one predicate. state:CA,NY,TX matches any of the three.
  3. Negation is -x or NOT x. Negative literals inside a comma list are not allowed: state:CA,-NY is rejected. Use state:CA -state:NY.
  4. Bareword = keyword search. Any IDENT or NUMBER not followed by an operator becomes a free-text substring across name / brand / title / meta / legal_name. Multiple barewords AND.

Cybersecurity examples (validate yours with /v1/check; replace cybersecurity with whatever /v1/tags returns as the industry value):

industry:cybersecurity service_provided:cybersecurity
service_provided:cybersecurity pen-testing
service_provided:cybersecurity security audit soc 2
service_provided:cybersecurity vciso
service_provided:cybersecurity incident response retainer
service_provided:cybersecurity cloud aws
service_provided:cybersecurity application security sast
service_provided:cybersecurity rating>=4 has:clutch
service_provided:cybersecurity hipaa

When in doubt, hit /v1/check?filter=... first. (Note: the live catalog has no separate pen-testing / security-audit / appsec tags. Pin service_provided:cybersecurity and treat all sub-types as keywords.)

Sub-type → keyword mapping (all sub-types are keyword-only — the live catalog has only the broad service_provided:cybersecurity tag):

User asks forUse
Pen test / red team / penetration testingkeywords pen-testing, red team
Security audit / assessmentkeywords audit, assessment
vCISO / fractional CISOvciso, fractional ciso
SOC 2 readiness / preparationsoc 2, readiness
Incident response / forensicsincident response, forensics, ir retainer
Cloud security (AWS/GCP/Azure)cloud security, aws, gcp, azure
Identity / IAMiam, identity
Application security / SAST/DASTapplication security, appsec, sast, dast
Compliance frameworkspci, hipaa, iso 27001, nist

firm_id contract

firm_id is a stable 12-hex-char handle:

firm_id = sha256(apex.lower().rstrip(".")).hexdigest()[:12]
import hashlib
def firm_id(apex):
    return hashlib.sha256(apex.lower().rstrip(".").encode()).hexdigest()[:12]
echo -n "mandiant.com" | tr 'A-Z' 'a-z' \
  | openssl dgst -sha256 -hex | awk '{print substr($2,1,12)}'

Recipes

A. Pen test for SOC 2

User: "Pen-testing firm for our SOC 2 audit."

GET /v1/explore?filter=industry:cybersecurity+service_provided:cybersecurity+pen-testing+soc 2
GET /v1/search?filter=industry:cybersecurity+service_provided:cybersecurity+pen-testing+soc 2&limit=10
GET /v1/get/<firm_id>     # ×3

B. vCISO for a healthcare-tech startup

User: "vCISO services for our healthcare-tech startup."

GET /v1/search?filter=industry:cybersecurity+vciso+(healthcare OR hipaa)

C. Incident response retainer

User: "Incident response retainer in case we get breached."

GET /v1/search?filter=industry:cybersecurity+incident response+retainer

If thin, drop retainer — most IR firms also offer retainer engagements.

D. Cloud security + AWS + HIPAA

User: "Cloud security consultancy familiar with AWS and HIPAA."

GET /v1/search?filter=industry:cybersecurity+cloud+aws+hipaa

E. Indirect intent — "we got breached"

User: "We got hit with a ransomware attack last week — we need help fast."

That's an emergency IR ask:

GET /v1/search?filter=industry:cybersecurity+incident response+ransomware&limit=10&order_by=relevance

Surface as urgent: skip /v1/explore, jump to /v1/search, present briefs immediately.

F. AppSec / SAST

User: "Application security firms experienced with code review and SAST."

GET /v1/search?filter=industry:cybersecurity+application security+(sast OR code review)

G. SOC 2 readiness ahead of enterprise sales

User: "SOC 2 readiness partner ahead of our enterprise sales push."

GET /v1/search?filter=industry:cybersecurity+soc 2+(readiness OR preparation)

H. BYO apex list — enrich domains

User pastes 8–20 cybersecurity firm domains. For each:

  1. Compute firm_id locally.
  2. GET /v1/get/<firm_id> — full bundle if in catalog, 404 if not.
  3. Aggregate, present, flag the not-found ones.

Gotchas

  • Always pin the cybersecurity industry tag. Without it, pen-testing / vciso / appsec keywords leak into IT-services or other industries that mention security.
  • Confirm the industry value name via /v1/tags — older catalog releases used industry:security, newer ones may use industry:cybersecurity. Don't hardcode; check once per session.
  • Refuse consumer-personal asks. "My Gmail got hacked", "how do I secure my home wifi", "should I use a VPN" — none of these are B2B procurement. The catalog is for businesses procuring security services.
  • DIY/configuration questions ("patch CVE-X", "configure firewall rules", "review this Terraform") are NOT procurement.
  • Security-product comparisons (EDR, SIEM, identity providers) are NOT procurement either.
  • "Hire a security engineer / CISO" is recruiting, not procurement of a firm. Refuse.
  • Bug-bounty / freelance pen-testers are out of scope (catalog is firm-level only).
  • Many sub-types are keyword-only. Multi-word sub-types split into ANDed barewords (incident responseincident AND response).
  • looks_not_pro_services 404 is not a bug. A firm_id may exist in /search but 404 on /get if it's been flagged. Skip and continue; not charged.
  • /v1/explore k=20 suppression. When fewer than 20 firms match, the response is {"count": "<20", "suppressed": true, "breakdowns": {}}. Drilling further makes the count smaller. Broaden or escalate to /v1/search.
  • Briefs from /search do NOT include apex, url, phone_primary, email_primary, legal_name, or address. If the user asks for contact info, you must /get/:id.
  • Quota is per-user-per-month, deduped on first view. Re-views are free; re-pagination is free.

Errors

All errors return JSON: {"error": {"code": "...", "message": "..."}}.

StatusCodeWhat to do
400filter_parse_errorPayload includes position. Fix the filter, re-validate with /v1/check.
400filter_requiredEmpty filter where one is required.
400invalid_firm_idfirm_id must be 12 lowercase hex chars. Re-derive.
401unauthorizedToken missing/expired. Re-run OTP.
404not_foundFirm not in catalog or flagged. Not charged. Skip and continue.
429rate_limitedHonor Retry-After header / retry_after field.
429monthly_quota_exhaustedSwitch to /v1/explore-only mode for the rest of the month. Tell the user.

End-to-end example

User: "Three pen-testing firms for our SOC 2 audit, 4-star ratings, ideally with HIPAA experience for a healthcare-tech context."

GET /v1/tags?include_values=1
GET /v1/check?filter=industry:cybersecurity+service_provided:cybersecurity+pen-testing+soc 2+hipaa+rating>=4
GET /v1/explore?filter=industry:cybersecurity+service_provided:cybersecurity+pen-testing+soc 2+hipaa+rating>=4
GET /v1/search?filter=...&limit=10
GET /v1/get/<firm_id>     # ×3

End of session: report X-Quota-Remaining-Month.

Capabilities

skillsource-nostrbandskill-find-cybersecurity-firmtopic-agent-skillstopic-ai-agentstopic-b2b-datatopic-claude-code-marketplacetopic-claude-code-pluginstopic-claude-code-skillstopic-claude-pluginstopic-claude-skillstopic-mcp-servertopic-openapitopic-professional-servicestopic-vendor-discovery

Install

Quality

0.53/ 1.00

deterministic score 0.53 from registry signals: · indexed on github topic:agent-skills · 160 github stars · SKILL.md body (17,188 chars)

Provenance

Indexed fromgithub
Enriched2026-05-18 18:56:02Z · deterministic:skill-github:v1 · v1
First seen2026-05-06
Last seen2026-05-18

Agent access