CtrlK
BlogDocsLog inGet started
Tessl Logo

building-cloud-siem-with-sentinel

Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps response playbooks. Use when establishing a centralized SOC for multi-cloud environments, migrating from a legacy SIEM, or performing petabyte-scale threat hunting; not for AWS-only setups where Security Hub/GuardDuty suffice or for endpoint EDR needs.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with executable code and a clear workflow, but destructive/batch operations lack validation checkpoints and the existing reference bundle is never linked from the body.

Suggestions

Add explicit validation/verification checkpoints to the SOAR playbook and connector-provisioning steps (e.g., verify a connector is enabled before running detection queries, confirm a user was disabled after the playbook runs).

Link references/api-reference.md and scripts/agent.py from the relevant sections in SKILL.md so the bundle is clearly signaled and one level deep.

Trim or compress the illustrative Output Format block to reduce token cost without losing the example.

DimensionReasoningScore

Conciseness

Mostly efficient, leaning on code blocks and a definitions table rather than prose, with no over-explanation of basic concepts; the large decorative Output Format block is the main instance that could be trimmed.

4 / 5

Actionability

Provides copy-paste ready executable az CLI commands, KQL detection/hunting queries, and a Logic Apps playbook JSON covering the common cases.

5 / 5

Workflow Clarity

A clear 5-step sequence is present, but the destructive SOAR playbook (auto-disabling Azure AD users) and batch detection steps lack explicit validation/verification checkpoints, capping this dimension at 3 per the rubric guideline.

3 / 5

Progressive Disclosure

The body is well-organized into sections, but a real references/api-reference.md (and scripts/agent.py) bundle exists yet is never linked or signaled from SKILL.md, leaving references present but not clearly navigated.

3 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, complete, and distinctive, clearly stating concrete actions, natural use-when triggers, and explicit out-of-scope boundaries. Minor keyword synonym coverage keeps trigger term quality just short of full marks.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'configuring multi-cloud data connectors (AWS, Azure, GCP)', 'writing KQL detection and hunting queries', 'building automated Logic Apps response playbooks' — giving comprehensive coverage of capabilities.

5 / 5

Completeness

Explicitly answers both what ('Deploy Microsoft Sentinel... by configuring connectors, writing KQL queries, building playbooks') and when ('Use when establishing a centralized SOC... migrating... threat hunting'), with concrete trigger phrases and explicit exclusions.

5 / 5

Trigger Term Quality

Includes natural triggers users would say ('establishing a centralized SOC', 'migrating from a legacy SIEM', 'petabyte-scale threat hunting'), but misses some natural synonyms such as 'Azure Sentinel' or 'incident response automation'.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear Sentinel SIEM/SOAR multi-cloud niche with explicit negation ('not for AWS-only setups where Security Hub/GuardDuty suffice or for endpoint EDR needs'), minimizing conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.