Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,8 +1,11 @@
---
name: hunting-for-dns-based-persistence
description: Hunt for DNS-based persistence mechanisms including DNS hijacking, dangling
CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive
DNS databases, SecurityTrails API, and DNS audit log analysis.
description: Hunts for DNS-based persistence mechanisms such as DNS hijacking, dangling
CNAME records enabling subdomain takeover, wildcard DNS abuse, and unauthorized zone
or NS delegation changes, using passive DNS history (SecurityTrails API), Route53/Azure
DNS/Cloudflare audit logs, and zone transfer analysis. Use when investigating suspected
DNS hijacking or subdomain takeover, or when threat hunting for DNS record tampering
that persists across credential rotations and endpoint reimaging.
domain: cybersecurity
subdomain: threat-hunting
tags: