CtrlK
BlogDocsLog inGet started
Tessl Logo

building-incident-response-playbook

Designs and documents structured incident response playbooks with step-by-step procedures per incident type, decision trees, escalation criteria, RACI matrices, and SOAR platform integration, aligned to NIST SP 800-61r3 and SANS PICERL. Use when creating or maturing an IR program, documenting response runbooks for a new incident type, or designing SOAR playbooks.

64

Quality

78%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./skills/building-incident-response-playbook/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

60%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is well-structured and mostly actionable with concrete containment commands, but it over-explains known concepts and, critically, never references the provided bundle files. Linking the api-reference.md and agent.py from SKILL.md and trimming the Key Concepts table would materially improve it.

Suggestions

Add explicit one-level-deep links to the bundle files (e.g., 'API examples: See references/api-reference.md' and 'Playbook scaffolding: See scripts/agent.py') so the provided references are discoverable from SKILL.md.

Remove or drastically shorten the 'Key Concepts' table — RACI, decision tree, and escalation criteria are concepts Claude already knows — to recover token budget.

Replace the placeholder lines in the Output Format and playbook template ('[Detailed steps...]', '[Flowchart logic]') with one fully worked example so the common case is copy-paste ready.

DimensionReasoningScore

Conciseness

Mostly efficient, but the 'Key Concepts' table defines RACI Matrix, Decision Tree, and Escalation Criteria (concepts Claude already knows) and the 'Tools & Systems' blurbs pad the token budget with unnecessary explanation.

3 / 5

Actionability

Step 4 provides concrete copy-paste commands (ssh to DNS server, echo zone block into named.conf.local, rndc reload, dig verification) and specific CrowdStrike console steps, but the playbook template and Output Format rely on placeholders like '[Detailed steps with tool-specific instructions]'.

4 / 5

Workflow Clarity

A clear 6-step sequence with verification checkpoints in the technical procedures ('Verify containment: Host should show Contained status badge') and a testing step (tabletop, live-fire), though the build workflow lacks an explicit validate-fix-retry feedback loop.

4 / 5

Progressive Disclosure

Bundle files references/api-reference.md and scripts/agent.py exist but are never linked from the body, and content that belongs in separate files (API reference, tools list, full playbook template) is inlined, leaving the bundle orphaned.

2 / 5

Total

13

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states what the skill does and gives three concrete 'Use when' triggers, with good natural-term coverage and synonyms. The only soft spot is minor overlap risk with general incident-response or security-automation skills.

DimensionReasoningScore

Specificity

Enumerates multiple concrete actions — 'step-by-step procedures per incident type, decision trees, escalation criteria, RACI matrices, and SOAR platform integration' — giving comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

Explicitly answers both 'what' (designs/documents playbooks with named components) and 'when' ('Use when creating or maturing an IR program, documenting response runbooks... or designing SOAR playbooks') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural terms a user would say are well covered with synonyms — 'incident response playbooks', 'IR program', 'response runbooks', 'SOAR playbooks', 'incident type' — matching the comprehensive-coverage anchor.

5 / 5

Distinctiveness Conflict Risk

The IR-playbook/RACI/SOAR/NIST combination is a clear niche, but the broad 'incident response' framing carries minor overlap risk with adjacent security skills, fitting the mostly-distinct anchor.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.