Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,11 +1,6 @@
---
name: conducting-malware-incident-response
description: 'Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection
vectors, assessing spread, and executing eradication procedures. Covers the full lifecycle from detection through containment,
analysis, removal, and recovery. Activates for requests involving malware response, malware eradication, trojan removal,
worm containment, malware triage, or infected endpoint remediation.
'
description: Respond to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing containment, analysis, eradication, and recovery procedures aligned to MITRE ATT&CK. Use when responding to a confirmed or suspected malware infection, including trojan/worm/ransomware outbreaks, malware triage, or infected endpoint remediation.
domain: cybersecurity
subdomain: incident-response
tags: