Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,11 +1,11 @@
---
name: detecting-ransomware-encryption-behavior
description: 'Detects ransomware encryption activity in real time using entropy analysis,
file system I/O monitoring, and behavioral heuristics. Identifies mass file modification
patterns, abnormal entropy spikes in written data, and suspicious process behavior
characteristic of ransomware encryption routines. Activates for requests involving
ransomware behavioral detection, entropy-based file monitoring, I/O anomaly detection,
or real-time encryption activity alerting.
description: 'Detects ransomware encryption activity in real time using entropy
analysis, file system I/O monitoring (Sysmon, watchdog, psutil), and behavioral
scoring to identify mass file modification, abnormal entropy spikes in written
data, and suspicious process behavior characteristic of encryption routines.
Use when building real-time ransomware detection, tuning entropy thresholds,
or investigating suspected active encryption on an endpoint.
'
domain: cybersecurity