Ask the user to confirm before taking a significant action. Use before containment, remediation, or other impactful operations to ensure analyst approval. Presents options and waits for response.
50
54%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./skills/confirm-action/SKILL.mdAsk the user a confirmation question before proceeding with a significant action.
QUESTION_TEXT - The specific question to ask (e.g., "Isolate endpoint WORKSTATION-01?", "Proceed with account disable for jsmith?")RESPONSE_OPTIONS - Predefined options for the user:
["Yes", "No"]["Disable Account", "Reset Password", "Monitor Only"]Display the question to the user with available options.
Collect the user's selection or custom input.
Provide the response back to the calling workflow for decision branching.
| Output | Description |
|---|---|
USER_RESPONSE | The user's answer to the confirmation question |
Always confirm before:
May skip confirmation for:
Containment:
Question: "Isolate endpoint WORKSTATION-01 from the network?"
Options: ["Yes - Isolate", "No - Continue Monitoring", "Escalate First"]Account Action:
Question: "User jsmith shows signs of compromise. What action?"
Options: ["Disable Account", "Force Password Reset", "Monitor Only", "Escalate to IR"]Case Closure:
Question: "Close case 1234 as False Positive?"
Options: ["Yes - Close FP", "No - Keep Open", "Escalate to Tier 2"]086cbf6
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.