Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
+4 -4
View File
@@ -1,10 +1,10 @@
---
name: detecting-rootkit-activity
description: 'Detects rootkit presence on compromised systems by identifying hidden
processes, hooked system calls, modified kernel structures, hidden files, and covert
network connections using memory forensics, cross-view detection, and integrity
checking techniques. Activates for requests involving rootkit detection, hidden
process discovery, kernel integrity checking, or system call hook analysis.
processes, hooked system calls, modified kernel structures, and covert network
connections using Volatility memory forensics, cross-view detection, and tools
like GMER, rkhunter, chkrootkit, and RootkitRevealer. Use when standard tools
(Task Manager, netstat, AV/EDR) show nothing abnormal but compromise is suspected.
'
domain: cybersecurity