Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,8 +1,11 @@
---
name: performing-linux-log-forensics-investigation
description: Perform forensic investigation of Linux system logs including syslog,
auth.log, systemd journal, kern.log, and application logs to reconstruct user activity,
detect unauthorized access, and establish event timelines on compromised Linux systems.
auth.log, systemd journal (via journalctl), kern.log, auditd, and application logs
to reconstruct user sessions, identify unauthorized access and privilege escalation,
trace lateral movement, and establish event timelines. Use when investigating a
suspected compromise of a Linux system and needing to analyze SSH, sudo, cron, or
kernel-level activity from plain-text or systemd journal logs.
domain: cybersecurity
subdomain: digital-forensics
tags: