Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
+5 -8
View File
@@ -1,13 +1,10 @@
---
name: triaging-security-incident
description: 'Performs initial triage of security incidents to determine severity,
scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL
frameworks. Classifies incidents by type, assigns priority based on business impact,
and routes to appropriate response teams. Activates for requests involving incident
triage, security alert classification, severity assessment, incident prioritization,
or initial incident analysis.
'
description: 'Performs initial triage of security incidents using the NIST SP
800-61r3 and SANS PICERL frameworks, classifying incident type, assigning priority
by business impact, and routing to the appropriate response team. Use when a
SIEM/EDR alert needs human classification, concurrent alerts must be prioritized,
or a user report or threat-intel IOC match requires initial incident categorization.'
domain: cybersecurity
subdomain: incident-response
tags: