Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,11 +1,10 @@
---
name: performing-disk-forensics-investigation
description: 'Conducts disk forensics investigations using forensic imaging, file
system analysis, artifact recovery, and timeline reconstruction to support incident
response cases. Utilizes tools such as FTK Imager, Autopsy, and The Sleuth Kit for
evidence acquisition, deleted file recovery, and artifact examination. Activates
for requests involving disk forensics, hard drive analysis, forensic imaging, file
recovery, evidence acquisition, or digital forensic investigation.
description: 'Conduct disk forensics investigations using forensic imaging, file system
analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and
The Sleuth Kit, for evidence acquisition, deleted file recovery, and artifact examination.
Use when a security incident requires forensic analysis of persistent storage or
when evidence must be preserved for legal or HR proceedings.
'
domain: cybersecurity