Skip to content
Development
Skill

/recover-security-incident

Recover from an incident by eradicating compromise and restoring service. Use when hosts, identities, applications, cloud resources, network controls, or data need rebuild, patching, rotation, repair, validation, and return to service.

From plugin
socket
7200 skills5 MCP
Install
$ npx -y skills add gaelic-ghost/socket --skill recover-security-incident --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/recover-security-incident

Context preview

The summary Claude sees to decide when to auto-load this skill.

Recover from an incident by eradicating compromise and restoring service. Use when hosts, identities, applications, cloud resources, network controls, or data need rebuild, patching, rotation, repair, validation, and return to service.

SKILL.md

recover-security-incident.SKILL.md
name: recover-security-incident
description: Recover from an incident by eradicating compromise and restoring service. Use when hosts, identities, applications, cloud resources, network controls, or data need rebuild, patching, rotation, repair, validation, and return to service.

Recover Security Incident

Overview

Return systems and people to a trusted operating state using explicit eradication and validation criteria. Recovery is complete only when restored behavior, security controls, access, monitoring, and residual risk are verified.

Read [references/recovery-gates.md](references/recovery-gates.md) for staged return-to-service gates.

Workflow

1. Establish eradication criteria.

  • Identify root/access path, persistence, affected identities/secrets, vulnerable configuration/code, related artifacts, and known scope.

2. Choose restore basis.

  • Decide clean rebuild, known-good backup, patched image, repaired configuration, provider recovery, or controlled cleanup from evidence and integrity confidence.

3. Eradicate.

  • Remove verified mechanisms, patch or mitigate the entry path, rotate/revoke secrets and sessions from trusted systems, repair policies/configuration, and preserve evidence of changes.

4. Restore in stages.

  • Validate offline or isolated, restore dependencies/data, enable limited traffic/users, monitor, then broaden service.

5. Verify security and function.

  • Reproduce the original detection/path as a negative test, confirm expected functionality, review access/persistence/network/logging, and check backups and monitoring.

6. Remove temporary controls deliberately.

  • Inventory emergency rules, disabled services, isolation, temporary accounts, logging, tokens, and exceptions; retain only approved controls with owners/expiry.

7. Close and improve.

  • Record timeline, root cause, affected scope, actions, notifications, evidence retention, lessons, structural hardening, and residual risk owner.

Output

Return eradication evidence, restore basis, staged recovery results, negative retest, temporary-control disposition, monitoring window, lessons/actions, and residual-risk decision.

Read more
Ships withsocket

Stuff for Agents on macOS Promo audio: Socket Codex Marketplace Promo

Get the whole plugin

Other skills on socket.