CtrlK
BlogDocsLog inGet started
Tessl Logo

building-ransomware-playbook-with-cisa-framework

Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework, covering preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Use when creating or updating a ransomware playbook, running a CISA-aligned readiness assessment, or validating response steps during a tabletop exercise.

67

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers concrete, well-sequenced incident-response guidance with specific commands and time-boxed priorities, and a genuine verification section. Its main weaknesses are undiscoverable bundle files (the reference guide and automation script are never mentioned), some explanatory padding of widely known security concepts, and missing feedback loops in verification.

Suggestions

Add a short "Resources" section pointing to references/api-reference.md (CISA URLs, NIST mapping, reporting channels) and scripts/agent.py (playbook generation and compliance checking), so the bundled materials are discoverable from SKILL.md.

Trim the Key Concepts and Tools & Systems tables to only non-obvious entries (e.g., RTO/RPO in this context) and drop definitions of widely known concepts like Double Extortion, MITRE ATT&CK, and NIST CSF.

Turn the Verification section into a feedback loop: after the tabletop exercise or checklist validation, explicitly instruct to record gaps, revise the playbook, and re-validate until no critical gaps remain.

DimensionReasoningScore

Conciseness

The core body is dense, high-value material — checklists, detection indicators, and a recovery priority matrix with time windows — with specific commands like "Reset ALL passwords including service accounts, krbtgt (twice, 12h apart)". However, the Key Concepts table defines terms Claude already knows ("Double Extortion", "Patient Zero", "Tabletop Exercise") and Tools & Systems re-describes NIST CSF and MITRE ATT&CK, so it is efficient with minor over-explanation rather than fully lean (5).

4 / 5

Actionability

Guidance is concrete and specific — "Disable or restrict RDP; require VPN for remote access", "Sysmon Event ID 11 (file creation) spikes", "Rebuild affected systems from known-clean images (do NOT decrypt in place)" — with a time-boxed containment and recovery matrix. It falls short of 5 because there is no example of the playbook deliverable itself and no invocation of the bundled automation despite the "Python 3.8+ for playbook generation and compliance checking automation" prerequisite.

4 / 5

Workflow Clarity

A clear five-step sequence (Preparation → Detection → Containment → Eradication/Recovery → Post-Incident) is followed by a Verification section ("Validate playbook completeness against CISA StopRansomware checklist items", "Conduct tabletop exercise"). Not 5 because verification steps are listed without explicit feedback loops (e.g., "if gaps are found, revise the playbook and re-run the tabletop"), keeping checkpoints implicit rather than error-recovering.

4 / 5

Progressive Disclosure

The body is well-sectioned with clear headers, but the bundle files references/api-reference.md and scripts/agent.py exist and are never referenced or signaled anywhere in SKILL.md, making them undiscoverable; the inlined CISA checklist detail also duplicates content that belongs in the reference file. This matches the 3 anchor ("references present but not clearly signaled; content that should be separate is inline") rather than 4, where references would be mostly clear.

3 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states concrete capabilities in third person, frames the scope with the CISA/NIST frameworks and all six IR phases, and provides an explicit "Use when" clause with three natural trigger scenarios. Trigger-term coverage is good but could add common synonyms such as "incident response plan" or "ransomware recovery".

DimensionReasoningScore

Specificity

Phrases like "Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework, covering preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists" list multiple concrete actions with comprehensive phase coverage in third person. It exceeds the 4 anchor because coverage is comprehensive rather than having minor gaps.

5 / 5

Completeness

It explicitly answers both what ("Builds a structured ransomware incident response playbook... covering... phases with actionable checklists") and when ("Use when creating or updating a ransomware playbook, running a CISA-aligned readiness assessment, or validating response steps during a tabletop exercise") with concrete trigger phrases. Not 4 because the when-clause is fully explicit and specific rather than improvable.

5 / 5

Trigger Term Quality

Natural triggers include "creating or updating a ransomware playbook", "CISA-aligned readiness assessment", and "validating response steps during a tabletop exercise" — phrases users would actually say. It falls short of 5 because common variations like "incident response plan", "IR plan", or "ransomware recovery" are missing.

4 / 5

Distinctiveness Conflict Risk

A clear niche (ransomware incident response playbooks per CISA/NIST frameworks) with distinct triggers like "ransomware playbook" and "tabletop exercise" creates minimal conflict risk with other skills. It is clearly more distinct than the 4 anchor's "minor overlap risk with closely related skills".

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.