Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,8 +1,10 @@
---
name: performing-cloud-forensics-with-aws-cloudtrail
description: Perform forensic investigation of AWS environments using CloudTrail logs
to reconstruct attacker activity, identify compromised credentials, and analyze
API call patterns.
description: Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents
or AWS Athena SQL over S3-delivered logs, filtering on suspicious user agents, source IPs, and
event names to reconstruct an attacker timeline. Use when tracing unauthorized API calls, S3
data exfiltration, IAM privilege escalation, or credential exposure, and building a forensic
report of findings and remediation steps.
domain: cybersecurity
subdomain: cloud-security
tags: