coordinate-external-ag…
Coordinate independently operated external agents through durable handoffs. Use when work crosses hosts, sessions, accounts, services, queues, boards, pull…
Triage a suspected incident across endpoints, identities, applications, cloud resources, networks, or data. Use when an alert, compromise, disruption, unauthorized access, malware, credential concern, or exposure needs scope and ownership.
$ npx -y skills add gaelic-ghost/socket --skill triage-security-incident --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/triage-security-incidentContext preview
The summary Claude sees to decide when to auto-load this skill.
Triage a suspected incident across endpoints, identities, applications, cloud resources, networks, or data. Use when an alert, compromise, disruption, unauthorized access, malware, credential concern, or exposure needs scope and ownership.
name: triage-security-incident description: Triage a suspected incident across endpoints, identities, applications, cloud resources, networks, or data. Use when an alert, compromise, disruption, unauthorized access, malware, credential concern, or exposure needs scope and ownership.
Establish whether coordinated response is needed, what may be affected, and who owns decisions. Preserve uncertainty and avoid destructive cleanup while urgent harm reduction and evidence collection are balanced.
Read [references/incident-triage-record.md](references/incident-triage-record.md) for the initial record aligned with current NIST incident-response guidance.
1. Open the incident record.
2. Validate the signal.
3. Estimate scope and urgency.
4. Decide immediate harm reduction.
5. Preserve priority evidence.
6. Establish coordination.
7. Route the next phase.
Return incident identity/owner, signal confidence, affected/potential scope, urgency, immediate actions, evidence plan, contacts, open questions, and next phase.
Stuff for Agents on macOS Promo audio: Socket Codex Marketplace Promo
Coordinate independently operated external agents through durable handoffs. Use when work crosses hosts, sessions, accounts, services, queues, boards, pull…
Assign worktree, branch, write, validation, integration, and cleanup ownership before parallel repository work. Use when a worker will inspect or modify…
Design framework-neutral agent and automation workflows before implementation. Use when choosing between Codex app automations, codex exec, Codex subagents,…
Design evaluation workflows for agent, skill, prompt, and automation behavior before implementation. Use when choosing eval cases, graders, thresholds,…
Design safe n8n workflows with deterministic routing, credentials, idempotency, recovery, local-model checks, drafts, and exact approval gates.
Coordinate bounded worker tasks with a launch envelope, report-back, escalation, and synthesis contract. Use before spawning, resuming, steering, cancelling,…