Skip to content
Back to skills

Cyber Incident Triage

ASecurity

Do not delete the files based on alert severity alone. Severity indicates urgency and impact, not proof. Mark the incident `suspected` (or `blocked` if authorization/scope is missing), preserve originals in place, and record acquisition method, timestamps, hashes, custodian, and original references. Continue safe offline analysis. Any isolation or eradication requires a valid engagement/scope reference, approved operation, named owner, runtime-enforced controls, and independent approval for d...

  • 571 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
development

Security analysis

A100/100

Pro scans all 11 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-incident-triage --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cyber Incident Triage?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cyber Incident Triage
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-cyber-incident-triage-6bc32821/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-incident-triage-6bc32821)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
Do not delete the files based on alert severity alone. Severity indicates urgency and impact, not proof.

Mark the incident `suspected` (or `blocked` if authorization/scope is missing), preserve originals in place, and record acquisition method, timestamps, hashes, custodian, and original references. Continue safe offline analysis.

Any isolation or eradication requires a valid engagement/scope reference, approved operation, named owner, runtime-enforced controls, and independent approval for disruptive containment. Separately authorize containment, eradication, and recovery; never perform production changes from prose alone.

Files in this skill

  • eval-1.baseline.md1 KB
  • eval-1.with-skill.md1.4 KB
  • eval-2.baseline.md361 B
  • eval-2.with-skill.md634 B
  • eval-3.baseline.md385 B
  • eval-3.with-skill.md802 B
  • trigger-1.md136 B
  • trigger-2.md156 B
  • trigger-3.md158 B
  • trigger-4.md176 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…