Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,10 +1,10 @@
---
name: implementing-network-traffic-analysis-with-arkime
description: Deploy and query Arkime (formerly Moloch) for full packet capture network
traffic analysis. Uses the Arkime API v3 to search sessions, download PCAPs, analyze
connection patterns, detect beaconing behavior, and identify suspicious network
flows. Monitors DNS queries, HTTP traffic, and TLS certificate anomalies across
captured traffic.
description: Queries Arkime (formerly Moloch) full packet capture via its API to search sessions,
download PCAPs, detect C2 beaconing through connection interval/jitter stats,
spot DNS tunneling via query-length analysis, and flag known-bad TLS certificate
issuers, using the bundled scripts/agent.py. Use when investigating suspicious
network flows or doing full-packet-capture forensics against an Arkime deployment.
domain: cybersecurity
subdomain: network-security
tags: