Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,6 +1,11 @@
---
name: post-exploiting-microsoft-graph-with-graphrunner
description: Perform recon, persistence, privilege escalation, and data search via the Microsoft Graph API using GraphRunner.
description: Runs GraphRunner, a PowerShell post-exploitation toolset built on
the Microsoft Graph API, to perform tenant recon, establish persistence (OAuth
app injection, inbox rules), escalate privilege via group manipulation, and pillage
mailboxes, SharePoint, and Teams data from a foothold Graph token. Use during
authorized red-team engagements against Microsoft 365/Entra ID tenants once you
hold a Graph token.
domain: cybersecurity
subdomain: identity-access-management
tags: