Securitymarketdata skill
Query curated cybersecurity market and company intelligence.
by danielmiessler·MIT license·★ 19,269 Stars on the repo·GitHub ↗
npx degit danielmiessler/LifeOS/LifeOS/install/skills/SecurityMarketData#main ~/.claude/skills/securitymarketdataChecked ·commit main
Files of Securitymarketdata
Show the full text76 lines
SecurityMarketData
Query Return on Security's Signal data through its live MCP interface, with evidence, freshness, and analytical boundaries intact.
Customization
Before executing, check ~/.claude/LIFEOS/USER/CUSTOMIZATIONS/SKILLS/SecurityMarketData/. If present, load enabled preferences and configuration; otherwise use these defaults.
Voice Notification
When executing QueryMarket, run:
curl -s -X POST http://localhost:31337/notify -H 'Content-Type: application/json' -d '{"message":"Running the QueryMarket workflow in the SecurityMarketData skill to query cybersecurity market data"}' > /dev/null 2>&1 &
Output: Running the QueryMarket workflow in the SecurityMarketData skill to query cybersecurity market data...
Workflow Routing
| Workflow | Trigger | File |
|---|---|---|
| QueryMarket | Any supported market, company, investor, funding, M&A, or lifecycle query | Workflows/QueryMarket.md |
Load References/ToolCatalog.md only when selecting tools, confirming tiers, or using the REST fallback. Do not preload it for routing.
Setup and Diagnostics
Prefer Streamable HTTP MCP. For Hermes:
hermes mcp add signal-mcp --url https://mcp.returnonsecurity.com/mcp
hermes mcp list
OAuth 2.1 authorization is interactive. It cannot be bypassed, automated away, or claimed complete before the user finishes it.
Optional vendor examples:
claude mcp add signal-mcp https://mcp.returnonsecurity.com/mcp
claude mcp list
codex mcp add signal-mcp https://mcp.returnonsecurity.com/mcp
codex mcp login signal-mcp
Examples
Funding trend: “Show quarterly funding trends for cloud security and distinguish observed rounds from forecasts.”
Company enrichment: “Enrich this security company and report its category, funding, investors, lifecycle, and data freshness.”
Category M&A: “Map identity-security M&A activity, acquirers, and observed consolidation signals for the last three years.”
Gotchas
Prefer Streamable HTTP MCP with OAuth 2.1. Tokens last 24 hours; never report authentication as complete until the interactive OAuth flow succeeds.
Free access provides 180 calls/day and 12 tools; Pro adds 21 tools; Enterprise adds one. Preserve and report returned quota information.
Discover live schemas and never guess arguments. For unfamiliar filters, begin with
list_categoriesand/orlist_countries; checkget_data_statusbefore substantive queries.Preserve and report freshness. Never imply values the data does not disclose.
The proprietary taxonomy has two layers: category domains and product categories, with metadata tags. Do not flatten them into an invented taxonomy.
Separate observed records from heuristics and forecasts. Explicitly label
suggest_acquirers,forecast_funding,exit_score, and consolidation or growth scores as analytical outputs rather than observed facts.Do not scrape when MCP or REST is available. Use REST only when
ROS_API_KEYexists; never request or expose its value.
| 1 | |
| 2 | name SecurityMarketData |
| 3 | version 1.0.0 |
| 4 | description Query curated cybersecurity market and company intelligence. USE WHEN security market data OR cybersecurity funding OR cyber M&A OR security-company/investor research OR market maps OR deal activity OR Return on Security OR The Signal. NOT FOR vulnerability research, security news, or investment advice. |
| 5 | |
| 6 | |
| 7 | # SecurityMarketData |
| 8 | |
| 9 | Query Return on Security's Signal data through its live MCP interface, with evidence, freshness, and analytical boundaries intact. |
| 10 | |
| 11 | ## Customization |
| 12 | |
| 13 | Before executing, check `~/.claude/LIFEOS/USER/CUSTOMIZATIONS/SKILLS/SecurityMarketData/`. If present, load enabled preferences and configuration; otherwise use these defaults. |
| 14 | |
| 15 | ## Voice Notification |
| 16 | |
| 17 | When executing **QueryMarket**, run: |
| 18 | |
| 19 | |
| 20 | curl -s -X POST http://localhost:31337/notify -H 'Content-Type: application/json' -d '{"message":"Running the QueryMarket workflow in the SecurityMarketData skill to query cybersecurity market data"}' > /dev/null 2>&1 & |
| 21 | |
| 22 | |
| 23 | Output: Running the **QueryMarket** workflow in the **SecurityMarketData** skill to query cybersecurity market data... |
| 24 | |
| 25 | ## Workflow Routing |
| 26 | |
| 27 | | Workflow | Trigger | File | |
| 28 | |---|---|---| |
| 29 | | **QueryMarket** | Any supported market, company, investor, funding, M&A, or lifecycle query | `Workflows/QueryMarket.md` | |
| 30 | |
| 31 | Load `References/ToolCatalog.md` only when selecting tools, confirming tiers, or using the REST fallback. Do not preload it for routing. |
| 32 | |
| 33 | ## Setup and Diagnostics |
| 34 | |
| 35 | Prefer Streamable HTTP MCP. For Hermes: |
| 36 | |
| 37 | |
| 38 | hermes mcp add signal-mcp --url https://mcp.returnonsecurity.com/mcp |
| 39 | hermes mcp list |
| 40 | |
| 41 | |
| 42 | OAuth 2.1 authorization is interactive. It cannot be bypassed, automated away, or claimed complete before the user finishes it. |
| 43 | |
| 44 | Optional vendor examples: |
| 45 | |
| 46 | |
| 47 | claude mcp add signal-mcp https://mcp.returnonsecurity.com/mcp |
| 48 | claude mcp list |
| 49 | codex mcp add signal-mcp https://mcp.returnonsecurity.com/mcp |
| 50 | codex mcp login signal-mcp |
| 51 | |
| 52 | |
| 53 | ## Examples |
| 54 | |
| 55 | **Funding trend:** “Show quarterly funding trends for cloud security and distinguish observed rounds from forecasts.” |
| 56 | |
| 57 | **Company enrichment:** “Enrich this security company and report its category, funding, investors, lifecycle, and data freshness.” |
| 58 | |
| 59 | **Category M&A:** “Map identity-security M&A activity, acquirers, and observed consolidation signals for the last three years.” |
| 60 | |
| 61 | ## Gotchas |
| 62 | |
| 63 | Prefer Streamable HTTP MCP with OAuth 2.1. Tokens last 24 hours; never report authentication as complete until the interactive OAuth flow succeeds. |
| 64 | |
| 65 | Free access provides 180 calls/day and 12 tools; Pro adds 21 tools; Enterprise adds one. Preserve and report returned quota information. |
| 66 | |
| 67 | Discover live schemas and never guess arguments. For unfamiliar filters, begin with `list_categories` and/or `list_countries`; check `get_data_status` before substantive queries. |
| 68 | |
| 69 | Preserve and report freshness. Never imply values the data does not disclose. |
| 70 | |
| 71 | The proprietary taxonomy has two layers: category domains and product categories, with metadata tags. Do not flatten them into an invented taxonomy. |
| 72 | |
| 73 | Separate observed records from heuristics and forecasts. Explicitly label `suggest_acquirers`, `forecast_funding`, `exit_score`, and consolidation or growth scores as analytical outputs rather than observed facts. |
| 74 | |
| 75 | Do not scrape when MCP or REST is available. Use REST only when `ROS_API_KEY` exists; never request or expose its value. |
| 76 |
Discussion
Alternatives
Browse more free Claude skills or everything in Development.