Expert guidance for security alert triage. Use this when the user asks to "triage" an alert or case.
72
Does it follow best practices?
If you maintain this skill, you can automatically optimize it using the tessl CLI to improve its score:
npx tessl skill review --optimize ./path/to/skillValidation for skill structure
Tool selection and triage workflow scripting
Remote/local branching
100%
100%
Remote context expand param
0%
100%
Remote list_case_alerts call
0%
100%
Local get_case_full_details
0%
100%
Duplicate check filter
0%
100%
Related cases status filter
0%
100%
Remote IOC summarize_entity
0%
100%
Remote IOC get_ioc_match
0%
100%
Local IOC enrichment tools
0%
100%
Login-specific SIEM search scope
50%
100%
Without context: $0.5790 · 2m 45s · 26 turns · 103 in / 10,882 out tokens
With context: $0.4614 · 2m 8s · 19 turns · 305 in / 8,410 out tokens
Alert classification and case closure actions
FP classification
100%
100%
BTP classification
0%
100%
TP classification
100%
100%
execute_bulk_close_case used
0%
100%
NOT_MALICIOUS reason
41%
100%
Correct RootCause value
0%
100%
Comment before close
30%
100%
TP escalation recommended
100%
100%
TP priority update mentioned
50%
100%
Assessment references evidence
100%
100%
Without context: $0.3893 · 2m · 16 turns · 21 in / 7,167 out tokens
With context: $0.4086 · 1m 51s · 17 turns · 270 in / 6,007 out tokens
NL search workflow and network alert SIEM strategy
Remote NL two-step
0%
100%
Remote no standalone udm_search
100%
100%
Local uses search_security_events
0%
86%
Local skips translate step
100%
100%
Network flows searched
100%
100%
DNS lookups searched
100%
100%
Source/dest IPs or domains as params
100%
100%
Separate Remote/Local strategies
100%
100%
Without context: $0.3012 · 1m 56s · 12 turns · 17 in / 6,293 out tokens
With context: $0.2758 · 1m 29s · 11 turns · 171 in / 5,092 out tokens
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.