Design or change a Cerebro finding rule. Use for new durable rules, rule lifecycle fixes, fingerprint changes, or promoting source evidence into findings.
70
86%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
The full design rationale lives in the "Finding Rule Design Notes" section of AGENTS.md. This skill is the working checklist.
Lifecycle semantics and stable FingerprintFields.OpenAnchor and CloseOnEvent that meet in the middle: the close event must
produce the same anchor stored on the open finding, or the rule must not
claim closeout support.make finding-dsl-check policy-rule-check policy-mapping-check detection-catalog-check.make changed-check for the diff-selected remainder; make contracts-check
if contract-governed docs moved.ce4230a
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.