Skip to content
Development
Skill

/contain-security-incident

Contain an active or credible incident across hosts, identities, applications, cloud resources, networks, or data. Use when access, execution, exfiltration, fraud, destruction, or repeated compromise needs authorized interruption.

From plugin
socket
7200 skills5 MCP
Install
$ npx -y skills add gaelic-ghost/socket --skill contain-security-incident --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/contain-security-incident

Context preview

The summary Claude sees to decide when to auto-load this skill.

Contain an active or credible incident across hosts, identities, applications, cloud resources, networks, or data. Use when access, execution, exfiltration, fraud, destruction, or repeated compromise needs authorized interruption.

SKILL.md

contain-security-incident.SKILL.md
name: contain-security-incident
description: Contain an active or credible incident across hosts, identities, applications, cloud resources, networks, or data. Use when access, execution, exfiltration, fraud, destruction, or repeated compromise needs authorized interruption.

Contain Security Incident

Overview

Interrupt the validated path of harm with the smallest effective action, then verify the containment. Do not confuse a blocked symptom with eradication or recovery.

Read [references/containment-plan.md](references/containment-plan.md) before making disruptive changes.

Workflow

1. Confirm incident lead, authority, current scope, harm path, critical services, evidence priorities, and emergency contacts. 2. Model containment choices.

  • Consider host/network isolation, process/service suspension, account disablement, session/token/key revocation, access-policy change, application feature disablement, route/rule changes, or provider controls.
  • Record expected harm reduction, operational impact, volatile evidence loss, dependencies, rollback, and attacker visibility.

3. Sequence actions.

  • Address active exfiltration/destruction/safety first, then privileged access, propagation, persistence, and re-entry paths.
  • Coordinate simultaneous identity, host, application, and network actions when staggered changes would alert or strand access.

4. Apply approved changes.

  • Record exact target, operator, time, command/control surface, result, failures, and unexpected effects.

5. Verify containment.

  • Check that the harmful path stopped, access/session state changed, affected services remain understood, and monitoring still functions.

6. Expand scope carefully.

  • Hunt for related indicators and access paths; update the incident record before new targets or actions.

7. Define exit criteria.

  • State what evidence permits eradication/recovery and what temporary controls must remain.

Output

Return containment objective, options/tradeoffs, actions/results, verification, residual access, business impact, temporary controls, rollback, and next-phase criteria.

Read more
Ships withsocket

Stuff for Agents on macOS Promo audio: Socket Codex Marketplace Promo

Get the whole plugin

Other skills on socket.