CtrlK
BlogDocsLog inGet started
Tessl Logo

building-soc-escalation-matrix

Build a structured SOC escalation matrix defining severity tiers, response SLAs, tiered escalation paths, and notification procedures for security incidents, using context-driven criteria that combine business risk, asset criticality, and data sensitivity. Use when designing or revising how a SOC triages and escalates incidents across analyst tiers.

61

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/building-soc-escalation-matrix/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

53%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The core matrix content (severity tables, decision matrix, escalation triggers, notification template) is concrete and useful, but the body explains SOC concepts Claude already knows, includes boilerplate sections, and completely fails to disclose its own bundle: the references/, scripts/, and assets/ files are never mentioned, so a reader cannot find the API details, workflow chart, standards, or builder scripts. Adding explicit pointers to the bundle files and trimming the generic tier-role and overview padding would lift the weakest dimensions.

Suggestions

Replace the generic 'When to Use'/'Prerequisites' boilerplate and the industry-statistic Overview with a short pointer-style overview, and move the detailed severity/SLA tables to references/api-reference.md to cut duplicated tokens.

Add a navigation section linking the existing bundle files, e.g. '**Escalation workflow diagram**: See [references/workflows.md](references/workflows.md); **Notification APIs (PagerDuty/Slack)**: See [references/api-reference.md](references/api-reference.md); **Fill-in-the-blank matrix**: See [assets/template.md](assets/template.md); **Matrix builder scripts**: See scripts/agent.py and scripts/process.py — currently none are discoverable from SKILL.md.

Add an explicit build sequence with checkpoints, e.g. 1) classify assets by criticality, 2) map severity x criticality via the decision matrix, 3) assign SLAs and notification channels per tier, 4) validate the resulting matrix against references/standards.md response-time benchmarks before delivery.

DimensionReasoningScore

Conciseness

The severity/SLA tables, decision matrix, and trigger tables are token-dense and earn their place, but the body pads with material Claude already knows — the SOC Tier Structure section restates standard Tier 1/2/3 analyst roles, the Overview includes a marketing statistic ('161 days, an 80-day improvement over the 241-day industry average') that adds no actionable value, and the 'When to Use'/'Prerequisites' sections are generic boilerplate ('Python 3.8+ with required dependencies installed' is never used by any body content). It is above a 2 because the core matrix content itself is efficient and tabular rather than prosaic.

3 / 5

Actionability

Concrete guidance dominates: specific SLA values per priority ('Initial Response 15 minutes', 'Resolution Target 4 hours'), a severity x asset-criticality decision matrix, explicit auto-escalation trigger rules, a copy-paste-ready P1 notification template, and a SOAR YAML example. It is not a 5 because the SOAR block is illustrative pseudocode with generic condition syntax rather than an executable playbook, and the body never tells Claude how to assemble these pieces into the finished matrix.

4 / 5

Workflow Clarity

The incident-handling flow is implicitly sequenced across sections (tier roles → severity classification → decision matrix → escalation triggers → time-based escalation → communication), but there is no explicit build procedure for the skill's stated task ('Build a SOC escalation matrix'): no ordered steps for gathering inputs, applying the matrix, or validating the result, and no checkpoints. It is above a 2 because the escalation lifecycle itself is well laid out via the decision matrix and time-based trigger tables.

3 / 5

Progressive Disclosure

The skill ships a substantial bundle — references/api-reference.md (PagerDuty/Slack APIs, notification channels), references/standards.md, references/workflows.md (an escalation flowchart), scripts/agent.py and scripts/process.py (matrix builders), and assets/template.md — yet the body references none of them; its 'References' section lists only external URLs. Detail that belongs in separate files is inlined instead (the body's severity/SLA tables duplicate content in references/api-reference.md and assets/template.md), leaving the bundle undiscoverable. It is not a 1 because the body itself is sectioned and navigable rather than a monolithic wall of text.

2 / 5

Total

12

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it names a concrete deliverable, enumerates its components and methodology in third person, and closes with an explicit, natural 'Use when...' trigger clause. The only improvement area is broader trigger-term synonym coverage.

DimensionReasoningScore

Specificity

The description lists multiple specific concrete components of the deliverable — 'defining severity tiers, response SLAs, tiered escalation paths, and notification procedures' — plus the methodology ('context-driven criteria that combine business risk, asset criticality, and data sensitivity'), giving comprehensive coverage. It is not a 4 because there are no meaningful coverage gaps; every major component of an escalation matrix is named.

5 / 5

Completeness

It explicitly answers both questions: what ('Build a structured SOC escalation matrix defining severity tiers, response SLAs, tiered escalation paths, and notification procedures... using context-driven criteria...') and when ('Use when designing or revising how a SOC triages and escalates incidents across analyst tiers'). Both are concrete with explicit trigger phrasing, matching the top anchor exactly.

5 / 5

Trigger Term Quality

Good natural keyword coverage: 'SOC', 'escalation matrix', 'severity tiers', 'SLAs', 'triages and escalates incidents', 'analyst tiers' — phrases a user would plausibly say. It falls short of 5 because common synonyms like 'incident response', 'on-call', 'SEV/P1 levels', or 'alert prioritization' are absent, leaving a few natural trigger terms uncovered.

4 / 5

Distinctiveness Conflict Risk

'SOC escalation matrix' is a clear niche with distinct triggers (severity tiers, SLAs, analyst-tier escalation); it is unlikely to fire for unrelated skills. It is not a 4 because overlap with adjacent skills (e.g., general incident-response playbooks) is minimal given the tightly scoped 'designing or revising how a SOC triages and escalates' framing.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.