agent-launcher-orchest…
Use when a user wants to build, launch, grade, or schedule a Claude Managed Agent (CMA) in their own Anthropic account — "build me an agent", "launch this as a…
Use when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. Covers SEV1-SEV4 classification, false positive filtering, incident taxonomy, and NIST SP 800-61 lifecycle.
$ npx -y skills add alirezarezvani/claude-skills --skill incident-response --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/incident-responseContext preview
The summary Claude sees to decide when to auto-load this skill.
Use when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. Covers SEV1-SEV4 classification, false positive filtering, incident taxonomy, and NIST SP 800-61 lifecycle.
name: "incident-response" description: "Use when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. Covers SEV1-SEV4 classification, false positive filtering, incident taxonomy, and NIST SP 800-61 lifecycle."
Incident response skill for the full lifecycle from initial triage through forensic collection, severity declaration, and escalation routing. This is NOT threat hunting (see threat-detection) or post-incident compliance mapping (see governance/compliance-mapping) — this is about classifying, triaging, and managing declared security incidents.
---
---
This skill provides the methodology and tooling for **incident triage and response** — classifying security events into typed incidents, scoring severity, filtering false positives, determining escalation paths, and initiating forensic evidence collection under chain-of-custody controls.
| Skill | Focus | Approach | |-------|-------|----------| | **incident-response** (this) | Active incidents | Reactive — classify, escalate, collect evidence | | threat-detection | Pre-incident hunting | Proactive — find threats before alerts fire | | cloud-security | Cloud posture assessment | Preventive — IAM, S3, network misconfiguration | | red-team | Offensive simulation | Offensive — test detection and response capability |
A security event must be ingested before triage. Events can come from SIEM alerts, EDR detections, threat intel feeds, or user reports. The triage tool accepts JSON event payloads; see the input schema below.
---
The `incident_triage.py` tool classifies events, checks false positives, scores severity, determines escalation, and performs forensic pre-analysis.
# Classify an event from JSON file
python3 scripts/incident_triage.py --input event.json --classify --json
# Classify with false positive filtering enabled
python3 scripts/incident_triage.py --input event.json --classify --false-positive-check --json
# Force a severity level for tabletop exercises
python3 scripts/incident_triage.py --input event.json --severity sev1 --json
# Read event from stdin
echo '{"event_type": "ransomware", "host": "prod-db-01", "raw_payload": {}}' | \
python3 scripts/incident_triage.py --classify --false-positive-check --json{
"event_type": "ransomware",
"host": "prod-db-01",
"user": "svc_backup",
"source_ip": "10.1.2.3",
"timestamp": "2024-01-15T14:32:00Z",
"raw_payload": {}
}| Code | Meaning | Required Response | |------|---------|-------------------| | 0 | SEV3/SEV4 or clean | Standard ticket-based handling | | 1 | SEV2 — elevated | 1-hour bridge call, async coordination | | 2 | SEV1 — critical | Immediate 15-minute war room, all-hands |
---
Security events are classified into 14 incident types. Classification drives default severity, MITRE technique mapping, and response SLA.
| Incident Type | Default Severity | MITRE Technique | Response SLA | |--------------|-----------------|-----------------|--------------| | ransomware | SEV1 | T1486 | 15 minutes | | data_exfiltration | SEV1 | T1048 | 15 minutes | | apt_intrusion | SEV1 | T1566 | 15 minutes | | supply_chain_compromise | SEV1 | T1195 | 15 minutes | | domain_controller_breach | SEV1 | T1078.002 | 15 minutes | | credential_compromise | SEV2 | T1110 | 1 hour | | lateral_movement | SEV2 | T1021 | 1 hour | | malware_infection | SEV2 | T1204 | 1 hour | | insider_threat | SEV2 | T1078 | 1 hour | | cloud_account_compromise | SEV2 | T1078.004 | 1 hour | | unauthorized_access | SEV3 | T1190 | 4 hours | | policy_violation | SEV3 | N/A | 4 hours | | phishing_attempt | SEV4 | T1566.001 | 24 hours | | security_alert | SEV4 | N/A | 24 hours |
Any of the following automatically re-declare a higher severity:
| Trigger | New Severity | |---------|-------------| | Ransomware note found | SEV1 | | Active exfiltration confirmed | SEV1 | | CloudTrail or SIEM disabled | SEV1 | | Domain controller access confirmed | SEV1 | | Second system compromised | SEV1 | | Exfiltration volume exceeds 1 GB | SEV2 minimum | | C-suite account accessed | SEV2 minimum |
---
| Level | Name | Criteria | Skills Invoked | Escalation Path | |-------|------|----------|---------------|-----------------| | SEV1 | Critical | Confirmed ransomware; active PII/PHI exfiltration (>10K records); domain controller breach; defense evasion (CloudTrail disabled); supply chain compromise | All skills (parallel) | SOC Lead → CISO → CEO → Board Chair | | SEV2 | High | Confirmed unauthorized access to sensitive systems; credential compromise with elevated privileges; lateral movement confirmed; ransomware indicators without confirmed execution | triage + containment + forensics | SOC Lead → CISO | | SEV3 | Medium | Suspected unauthorized access (unconfirmed); malware detected and contained; single account compromise (no priv escalation) | triage + containment | SOC Lead → Security Manager | | SEV4 | Low | Security alert with no confirmed impact; informational indicator; policy violation with no data risk | triage only | L3 Analyst queue |
---
388 production-ready Claude Code skills, plugins, and agent skills for 13 AI coding tools. The most comprehensive open-source library of Claude Code skills and agent plugins — also works with OpenAI Codex, Gemini CLI, Cursor, and 9 more coding agents.
Repo: alirezarezvani/claude-skills
Use when a user wants to build, launch, grade, or schedule a Claude Managed Agent (CMA) in their own Anthropic account — "build me an agent", "launch this as a…
Phase 3 of building a Claude Managed Agent — the bounded grade→iterate loop. Define a CMA outcome (a required markdown rubric graded by an isolated grader),…
Phase 1 of building a Claude Managed Agent — interview the founder about the one job the agent should do, then produce a build sheet (CMA primitives table +…
Phase 4 of building a Claude Managed Agent — make it run without you. Turn a graded agent into a recurring scheduled deployment (POSIX-cron), an event-driven…
Phase 2 of building a Claude Managed Agent — turn a validated build sheet into exact API payloads and a resumable BYOK curl launch script, then launch…
Close out a launched Claude Managed Agent — recap every primitive the founder now owns, regenerate the single-file overview page, and suggest the next 1-2…