Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,12 +1,10 @@
---
name: performing-ransomware-tabletop-exercise
description: 'Plans and facilitates tabletop exercises simulating ransomware incidents
to test organizational readiness, decision-making, and communication procedures.
Designs realistic scenarios based on current ransomware threat actors (LockBit,
ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and
regulatory notification requirements. Evaluates participant responses against NIST
CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident
response exercise, or ransomware readiness drill.
description: 'Plans and facilitates tabletop exercises simulating ransomware incidents,
using realistic scenarios based on threat actors like LockBit and ALPHV/BlackCat
with injects covering double extortion and backup destruction, then evaluates responses
against NIST CSF and CISA guidelines. Use when planning or running a ransomware
tabletop exercise or incident response readiness drill.
'
domain: cybersecurity