Skip to content
Development
Skill

/assess-and-explain-threat

Assess whether suspicious evidence indicates a real threat and explain it plainly. Use for confidence, protective actions, uncertainty, impact, and advice after artifact, endpoint, identity, or incident evidence.

From plugin
socket
7200 skills5 MCP
Install
$ npx -y skills add gaelic-ghost/socket --skill assess-and-explain-threat --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/assess-and-explain-threat

Context preview

The summary Claude sees to decide when to auto-load this skill.

Assess whether suspicious evidence indicates a real threat and explain it plainly. Use for confidence, protective actions, uncertainty, impact, and advice after artifact, endpoint, identity, or incident evidence.

SKILL.md

assess-and-explain-threat.SKILL.md
name: assess-and-explain-threat
description: Assess whether suspicious evidence indicates a real threat and explain it plainly. Use for confidence, protective actions, uncertainty, impact, and advice after artifact, endpoint, identity, or incident evidence.

Assess And Explain Threat

Overview

Turn mixed evidence into a proportionate conclusion and advice the affected person can follow. Do not collapse signatures, reputation, scanner output, or unusual behavior into a binary safe/malicious verdict.

Read [references/confidence-and-advice.md](references/confidence-and-advice.md) for conclusion vocabulary and the explanation shape.

Workflow

1. Restate the decision.

  • Identify what the user must decide now and what can wait for more evidence.

2. Grade evidence by directness.

  • Separate direct observations, reproducible behaviors, vendor or threat-intelligence claims, weak indicators, absence of findings, and speculation.
  • Record contradicting evidence and coverage gaps.

3. Assess behavior and impact.

  • State what access, execution, persistence, collection, credential use, network behavior, or data exposure is observed or technically plausible.
  • Distinguish capability from intent and artifact presence from successful compromise.

4. Choose a calibrated classification.

  • Use one classification from the reference and state confidence separately.
  • Name the strongest supporting evidence and what would change the conclusion.

5. Give proportionate advice.

  • Put urgent harm-reduction actions first.
  • Separate containment, evidence preservation, recovery, credential actions, notification, and long-term hardening.
  • Avoid destructive cleanup when evidence is weak and reversible isolation is available.

6. Give a plain-language explanation.

  • Answer whether the concern is dangerous, what it appears to do, what is known versus inferred, what to do now, and when to escalate.
  • Define specialist terms at first use and avoid fear-amplifying language.

Output

Return the conclusion, confidence, decisive evidence, contradictions/gaps, immediate actions, follow-up analysis, and a short non-specialist explanation.

Read more
Ships withsocket

Stuff for Agents on macOS Promo audio: Socket Codex Marketplace Promo

Get the whole plugin

Other skills on socket.