CtrlK
BlogDocsLog inGet started
Tessl Logo

building-cloud-siem-with-sentinel

Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps response playbooks. Use when establishing a centralized SOC for multi-cloud environments, migrating from a legacy SIEM, or performing petabyte-scale threat hunting; not for AWS-only setups where Security Hub/GuardDuty suffice or for endpoint EDR needs.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with executable Sentinel commands, KQL queries, and a Logic Apps playbook, and the workflow is well-sequenced. It loses points for verbosity, missing validation checkpoints on destructive operations, and failing to signal the existing bundle files.

Suggestions

Add explicit validation/verify checkpoints between workflow steps — e.g. confirm connector ingestion before writing rules, and verify a playbook in audit mode before auto-disabling users — to lift workflow_clarity above 2.

Reference the existing bundle files from the body (e.g. 'See references/api-reference.md for the Python KQL/Sentinel API clients' and 'Run scripts/agent.py to ...') so progressive_disclosure actually connects the SKILL.md overview to its materials.

Trim the Key Concepts glossary (remove definitions Claude already knows) and shorten or remove the fabricated Output Format block to improve token efficiency.

DimensionReasoningScore

Conciseness

Most of the body is concrete and earned, but the Key Concepts glossary explains terms Claude already knows (e.g. what KQL and SOAR playbooks are) and the Output Format block pads tokens with fabricated metrics and dates that add no instructional value.

2 / 3

Actionability

Provides copy-paste-ready executable artifacts — real 'az sentinel ... create' commands, complete KQL detection and hunting queries, and a full Logic Apps JSON playbook definition — rather than pseudocode.

3 / 3

Workflow Clarity

The five steps are clearly sequenced, but destructive/batch operations (auto-disabling Azure AD users, mass-deletion handling) lack any validation or verify checkpoints and there are no error-recovery feedback loops, which caps clarity at 2.

2 / 3

Progressive Disclosure

Bundle files references/api-reference.md and scripts/agent.py exist but are never referenced or linked from the body, and content that should be split out (the full playbook JSON, glossary) is inline, so references are present but not signaled.

2 / 3

Total

9

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, complete, and distinctive: it enumerates three concrete capabilities, provides explicit 'Use when' triggers with natural keywords, and adds negative scoping to avoid conflicts. It is a strong, copy-ready frontmatter description.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'configuring multi-cloud data connectors (AWS, Azure, GCP)', 'writing KQL detection and hunting queries', 'building automated Logic Apps response playbooks' — matching the multi-action anchor rather than just naming a domain.

3 / 3

Completeness

Explicitly answers what (deploy Sentinel via connectors, KQL, playbooks) and when, with a clear 'Use when establishing a centralized SOC..., migrating from a legacy SIEM, or performing petabyte-scale threat hunting' trigger clause.

3 / 3

Trigger Term Quality

Covers natural terms a user would say — 'Microsoft Sentinel', 'SIEM/SOAR', 'centralized SOC', 'threat hunting', 'KQL', 'Logic Apps' — across several relevant variations including named cloud platforms.

3 / 3

Distinctiveness Conflict Risk

The multi-cloud Sentinel SIEM niche plus negative scoping — 'not for AWS-only setups where Security Hub/GuardDuty suffice or for endpoint EDR needs' — sharply distinguishes it from adjacent skills.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.