Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,9 +1,10 @@
---
name: detecting-compromised-cloud-credentials
description: 'Detecting compromised cloud credentials across AWS, Azure, and GCP by
analyzing anomalous API activity, impossible travel patterns, unauthorized resource
provisioning, and credential abuse indicators using GuardDuty, Defender for Identity,
and SCC Event Threat Detection.
description: 'Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing
anomalous API activity, impossible-travel patterns, and credential-stuffing indicators
using GuardDuty, Microsoft Defender for Identity, and Google SCC Event Threat Detection.
Use when investigating alerts about cloud API activity from unfamiliar locations,
responding to an exposed-credential notification, or scoping a credential compromise.
'
domain: cybersecurity