Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,14 +1,6 @@
---
name: deploying-ransomware-canary-files
description: 'Deploys and monitors ransomware canary files across critical directories
using Python''s watchdog library for real-time filesystem event detection. Places
strategically named decoy files that mimic high-value targets (financial records,
credentials, database exports) in locations ransomware typically enumerates first.
Monitors for any read, modify, rename, or delete operations on canary files and
triggers immediate alerts via email, Slack webhook, or syslog when interaction is
detected, providing early warning before full encryption begins.
'
description: Deploys and monitors ransomware canary files using Python's watchdog library, placing decoy files mimicking high-value targets (financial records, credentials, database exports) where ransomware enumerates first, and alerting via email, Slack, or syslog on any read/modify/rename/delete. Use for early-warning ransomware detection on file servers, NAS, or endpoints, or to supplement EDR where agents can't be deployed.
domain: cybersecurity
subdomain: ransomware-defense
tags: