Skip to content
Back to skills

Cyber Incident Triage

ASecurity

Do not delete the files based on alert severity. Treat the incident as `suspected` (or `blocked` if authorization/evidence is missing): severity indicates urgency and impact, not proof. Preserve the originals and record acquisition method, timestamps, hashes where available, custodian, and original references. Continue safe offline analysis, documenting the hypothesis and evidence gaps. Containment, eradication, or production changes require an engagement/scope reference, approved operation, ...

  • 571 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
development

Security analysis

A100/100

Pro scans all 15 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-incident-triage --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cyber Incident Triage?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cyber Incident Triage
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-cyber-incident-triage-agent-skills-standard/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-incident-triage-agent-skills-standard)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
Do not delete the files based on alert severity. Treat the incident as `suspected` (or `blocked` if authorization/evidence is missing): severity indicates urgency and impact, not proof.

Preserve the originals and record acquisition method, timestamps, hashes where available, custodian, and original references. Continue safe offline analysis, documenting the hypothesis and evidence gaps.

Containment, eradication, or production changes require an engagement/scope reference, approved operation, designated owner, and runtime-proven controls; disruptive containment also requires independent approval. Keep analysis separate from containment, eradication, and recovery. The next approved action should be evidence-preserving collection or authorized isolation—not deletion.

Files in this skill

  • eval-1.baseline.md1 KB
  • eval-1.with-skill.md1.3 KB
  • eval-2.baseline.md361 B
  • eval-2.with-skill.md779 B
  • eval-3.baseline.md385 B
  • eval-3.with-skill.md884 B
  • pressure-1.baseline.md542 B
  • pressure-1.with-skill.md1.1 KB
  • pressure-2.baseline.md403 B
  • pressure-2.with-skill.md820 B
  • trigger-1.md136 B
  • trigger-2.md156 B
  • trigger-3.md158 B
  • trigger-4.md176 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…