Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,13 +1,11 @@
---
name: extracting-iocs-from-malware-samples
description: 'Extracts indicators of compromise (IOCs) from malware samples including
file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths,
registry keys, mutexes), and behavioral patterns for threat intelligence sharing
and detection rule creation. Activates for requests involving IOC extraction, threat
indicator harvesting, malware indicator collection, or building detection content
from samples.
'
description: Extracts indicators of compromise (IOCs) from malware samples, including
file hashes, network indicators (IPs, domains, URLs, PCAP indicators), host artifacts
(file paths, registry keys, mutexes), and behavioral patterns, using tools like
CyberChef, then defangs and exports them in standard threat-intel formats. Use
for IOC extraction, threat indicator harvesting, or building detection content
from a sample.
domain: cybersecurity
subdomain: malware-analysis
tags: