common-agent-guardrail…
Define deterministic guardrails for agent tool calls — protected paths, test-file locks during bug fixes, post-edit formatters, production approval gates,…
Conducts hypothesis-driven, evidence-preserving threat hunts with bounded negative conclusions and telemetry-gap handling. Use for hunt hypotheses, scoped offline analysis, or analytic follow-up; not unscoped scanning, malware execution, or generic intelligence summaries.
$ npx -y skills add hoangnguyen0403/agent-skills-standard --skill cyber-threat-hunting --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/cyber-threat-huntingContext preview
The summary Claude sees to decide when to auto-load this skill.
Conducts hypothesis-driven, evidence-preserving threat hunts with bounded negative conclusions and telemetry-gap handling. Use for hunt hypotheses, scoped offline analysis, or analytic follow-up; not unscoped scanning, malware execution, or generic intelligence summaries.
name: cyber-threat-hunting
guardrail: true
description: Conducts hypothesis-driven, evidence-preserving threat hunts with bounded negative conclusions and telemetry-gap handling. Use for hunt hypotheses, scoped offline analysis, or analytic follow-up; not unscoped scanning, malware execution, or generic intelligence summaries.
metadata:
triggers:
files: []
keywords:
- threat hunting
- hunt hypothesis
- hunting query
- negative conclusion
- suspicious activity hunt
- telemetry gapPreserve provenance and bound every conclusion to authorized evidence.
Input: falsifiable hypothesis, behavior, entities, scope, sources, window, expected signal, stop condition. Process: define positive/negative observations; normalize without overwriting originals; test narrowest evidence; correlate by entity/time; record gaps and alternatives. Output: status, cited evidence, bounded conclusion, limitations, owner.
The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.
Repo: hoangnguyen0403/agent-skills-standard
Define deterministic guardrails for agent tool calls — protected paths, test-file locks during bug fixes, post-edit formatters, production approval gates,…
Draws architecture diagrams as editable draw.io files with a fixed house style, C4 levels, evidence-tagged shapes, and optional multi-view identity checks. Use…
Enforce SOLID principles, guard-clause style, function size limits, and intention-revealing naming across all languages. Use when refactoring for readability,…
Standardize BRD and BRD-lite discovery for business goals, stakeholder impact, current-to-future state, and measurable value outcomes. Use when creating BRD,…
Conduct high-quality, persona-driven code reviews. Use when reviewing PRs, critiquing code quality, or analyzing changes for team feedback.
Maximize context window efficiency, reduce latency, and prevent lost-in-middle issues through strategic masking and compaction. Use when token budgets are…