github.com/dandye/ai-runbooks
| Skill | Added | Review |
|---|---|---|
analyze-content-gaps skills/analyze-content-gaps/SKILL.md Identify content gaps and organizational opportunities. Analyzes missing content areas, redundancies, and consolidation opportunities. | 55 55 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
audit-content skills/audit-content/SKILL.md Comprehensive content quality and maintenance assessment. Evaluates documentation quality, relevance, maintenance needs, and provides actionable recommendations. | 49 49 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
check-duplicates skills/check-duplicates/SKILL.md Check for duplicate or similar cases. Use before deep analysis to avoid investigating the same incident twice. Takes a CASE_ID and returns list of similar cases. | 60 60 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
close-case-artifact skills/close-case-artifact/SKILL.md Close a case or alert with proper reason and documentation. Use when triage determines an alert is FP/BTP or investigation is complete. Requires artifact ID, type, closure reason, and root cause. | 71 71 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
cluster-documents skills/cluster-documents/SKILL.md Automated content similarity and grouping analysis. Groups related documents by topic, purpose, or content similarity. | 52 52 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
confirm-action skills/confirm-action/SKILL.md Ask the user to confirm before taking a significant action. Use before containment, remediation, or other impactful operations to ensure analyst approval. Presents options and waits for response. | 61 61 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: 72a6863 | |
correlate-ioc skills/correlate-ioc/SKILL.md Check for existing SIEM alerts and case management entries related to IOCs. Use to understand if an indicator has triggered previous alerts or is part of ongoing investigations. Takes IOC list and returns related alerts and cases. | 62 62 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 72a6863 | |
deep-dive-ioc skills/deep-dive-ioc/SKILL.md Perform exhaustive analysis of a critical IOC. Use when an IOC needs Tier 2+ investigation beyond basic enrichment - includes GTI pivoting, deep SIEM searches, correlation with related entities, and threat attribution. For escalated IOCs requiring comprehensive investigation. | 67 67 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 72a6863 | |
design-metadata-schema skills/design-metadata-schema/SKILL.md Design comprehensive metadata frameworks. Develops structured metadata templates and tagging systems. | 55 55 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
document-in-case skills/document-in-case/SKILL.md Add a comment to a case to document findings, actions, or recommendations. Use to maintain audit trail during investigations. Requires CASE_ID and comment text. | 60 60 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
enrich-ioc skills/enrich-ioc/SKILL.md Enrich an IOC (IP, domain, hash, URL) with threat intelligence. Use when you need to look up reputation and context for an indicator using GTI and SIEM. Returns threat intel findings, SIEM entity summary, and IOC match status. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
find-relevant-case skills/find-relevant-case/SKILL.md Search for existing cases related to specific indicators or entities. Use to find correlation with other investigations before starting new analysis. Takes search terms and returns matching case IDs. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
full-investigation skills/_workflows/full-investigation/SKILL.md Complete Tier 2 investigation workflow. Orchestrates deep investigation of escalated cases: deep-dive-ioc, correlate-ioc, specialized triage (malware/login), pivot-on-ioc, and generate comprehensive report. Use for escalated cases requiring thorough analysis. | 59 59 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 72a6863 | |
full-alert-triage skills/_workflows/full-alert-triage/SKILL.md Complete Tier 1 triage workflow. Orchestrates the full alert triage process: check-duplicates, triage-alert, enrich-ioc for each entity, and either close (FP/BTP) or escalate (TP/Suspicious). Use for end-to-end alert processing. | 55 55 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 72a6863 | |
generate-report skills/generate-report/SKILL.md Save investigation findings to a markdown report file. Use after completing triage, enrichment, or investigation to create a permanent record. Generates timestamped files in ./reports/ directory. | 64 64 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 72a6863 | |
generate-sitemap skills/generate-sitemap/SKILL.md Generate hierarchical site structure and navigation maps. Creates visual representations of information architecture and content relationships. | 52 52 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
generate-taxonomy skills/generate-taxonomy/SKILL.md Develop hierarchical classification systems. Creates parent-child categorical structures for content organization. | 45 45 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 72a6863 | |
generate-thesaurus skills/generate-thesaurus/SKILL.md Generate controlled vocabulary thesaurus for content domains. Creates comprehensive thesauri with preferred terms, broader/narrower/related terms. | 52 52 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 72a6863 | |
hunt-apt skills/hunt-apt/SKILL.md Hunt for a specific APT/threat actor in your environment. Use when you have a threat actor name or GTI collection ID and want to search for their TTPs and IOCs. Gathers intelligence from GTI, searches SIEM for IOCs and TTP-based indicators, and documents findings. | 62 62 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 72a6863 | |
hunt-credential-access skills/hunt-credential-access/SKILL.md Hunt for credential access techniques like LSASS dumping or browser credential theft. Use when searching for evidence of credential harvesting. Takes MITRE technique IDs and searches for behavioral indicators in SIEM. | 63 63 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
hunt-ioc skills/hunt-ioc/SKILL.md Hunt for specific IOCs across your environment. Use when you have a list of IPs, domains, hashes, or URLs from threat intel and want to check if they appear in your SIEM. Systematic searching with enrichment and documentation. | 64 64 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 72a6863 | |
hunt-lateral-movement skills/hunt-lateral-movement/SKILL.md Hunt for lateral movement using PsExec, WMI, or similar techniques. Use when proactively searching for attackers moving through your network using admin tools. Searches for service installations, remote process execution, and suspicious network correlations. | 69 69 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 72a6863 | |
hunt-threat skills/hunt-threat/SKILL.md Conduct proactive, hypothesis-driven threat hunting. Use when performing advanced hunting based on threat intelligence, TTPs, or anomalies. For Tier 3 analysts or dedicated threat hunters. Supports iterative search, pivoting, and comprehensive documentation. | 67 67 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 72a6863 | |
inventory-content skills/inventory-content/SKILL.md Systematic cataloging of information assets. Creates comprehensive inventories of all content with metadata and characteristics. | 52 52 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 | |
pivot-on-ioc skills/pivot-on-ioc/SKILL.md Explore GTI relationships for an IOC to discover related entities. Use to expand investigation by finding connected domains, IPs, files, or threat actors. Takes an IOC and relationship types to query. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 72a6863 |