CtrlK
BlogDocsLog inGet started
Tessl Logo

triage-malware

Triage a suspected malicious file hash. Use when investigating malware alerts or suspicious files. Analyzes GTI file report, behavioral indicators, identifies affected hosts, enriches network IOCs, and recommends containment actions.

68

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable triage workflow with strong conciseness. The main gap is the absence of an explicit verification checkpoint before recommending destructive containment actions.

Suggestions

Add an explicit validation step between evidence gathering and containment (e.g., 'Verify TRIAGE_VERDICT is malicious/suspicious before isolating hosts or blocking IOCs') to satisfy the destructive-operation feedback-loop requirement.

Flesh out the referenced sub-skills (/enrich-ioc, /find-relevant-case, /document-in-case) with the specific inputs/outputs expected at each handoff so the workflow is fully self-contained.

Include a brief error-handling note for failed tool calls (e.g., GTI report unavailable, empty SIEM results) to make the sequence more robust.

DimensionReasoningScore

Conciseness

Lean and efficient throughout; assumes Claude's competence with no basic concept explanations, and every section (workflow, outputs, severity matrix, actions) earns its tokens.

5 / 5

Actionability

Provides concrete MCP tool calls with specific parameters and search queries, but uses placeholders and references other skills (/enrich-ioc, /find-relevant-case) without full invocation detail.

4 / 5

Workflow Clarity

Eight steps are clearly sequenced, but the workflow recommends destructive/batch actions (isolate hosts, block IOCs) without an explicit validation checkpoint before acting, capping the score at 3 per the rubric.

3 / 5

Progressive Disclosure

Well-organized into clear sections (Inputs, Workflow, Required Outputs, Severity Matrix, Actions) in a self-contained file with no nested references; the longer reference-style tables could arguably split out but are appropriately inline.

4 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states both capability and trigger conditions in third-person voice. Minor room for broader trigger-term synonyms, but otherwise excellent.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('Analyzes GTI file report, behavioral indicators, identifies affected hosts, enriches network IOCs, and recommends containment actions') with comprehensive coverage of the triage task.

5 / 5

Completeness

Explicitly answers both what ('Triage a suspected malicious file hash...') and when ('Use when investigating malware alerts or suspicious files') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Includes natural trigger terms ('investigating malware alerts or suspicious files', 'malicious file hash') but lacks synonyms and common variations a user might say.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (malware hash triage via GTI/SIEM) with distinct triggers and specific tooling, minimizing overlap with other skills.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
dandye/ai-runbooks
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.