Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,8 +1,10 @@
---
name: performing-cloud-incident-containment-procedures
description: Execute cloud-native incident containment across AWS, Azure, and GCP
by isolating compromised resources, revoking credentials, preserving forensic evidence,
and applying security group restrictions to prevent lateral movement.
description: Execute cloud-native incident containment across AWS, Azure, and GCP using platform
CLIs to revoke or disable compromised IAM credentials, isolate resources with security groups
and network ACLs, and preserve forensic evidence via snapshots. Use when responding to a cloud
security incident that requires stopping lateral movement while keeping evidence intact for
later investigation.
domain: cybersecurity
subdomain: incident-response
tags: