Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,8 +1,11 @@
---
name: detecting-rdp-brute-force-attacks
description: Detect RDP brute force attacks by analyzing Windows Security Event Logs
for failed authentication patterns (Event ID 4625), successful logons after failures
(Event ID 4624), NLA failures, and source IP frequency analysis.
description: Detect RDP brute force attacks by parsing Windows Security Event Logs
(EVTX files, via python-evtx) for failed logon patterns (Event ID 4625, Logon
Type 10/3), correlating with successful logons (Event ID 4624), and analyzing
NLA failures and source IP frequency. Use when investigating exposed RDP endpoints,
building SIEM detection rules for credential guessing, or confirming whether
a compromised account followed a brute-force pattern.
domain: cybersecurity
subdomain: threat-detection
tags: