Capture volatile and persistent Unix-like system artifacts quickly before evidence disappears or responders start changing the host.
Scanned 6/8/2026
Install via CLI
openskills install agentskillexchange/skills---
name: "Collect Unix-like incident-response artifacts into one portable evidence bundle with UAC"
slug: "collect-unix-like-incident-response-artifacts-into-one-portable-evidence-bundle-with-uac"
description: "Capture volatile and persistent Unix-like system artifacts quickly before evidence disappears or responders start changing the host."
github_stars: 1306
verification: "security_reviewed"
source: "https://github.com/tclahr/uac"
author: "tclahr"
publisher_type: "individual"
category: "Security & Verification"
framework: "Multi-Framework"
tool_ecosystem:
github_repo: "tclahr/uac"
github_stars: 1306
---
# Collect Unix-like incident-response artifacts into one portable evidence bundle with UAC
Capture volatile and persistent Unix-like system artifacts quickly before evidence disappears or responders start changing the host.
## Prerequisites
Shell access to the target Unix-like host, UAC runtime, sufficient privileges for artifact collection, storage location for the output bundle
## Installation
Requirements and caveats from upstream:
- ⚡ Lightweight, portable, and requires no installation or dependencies.
Basic usage or getting-started notes:
- <a href="#-usage">Usage</a>
- Run everywhere with no dependencies (no installation required).
- ## 🚀 Usage
- Source: https://github.com/tclahr/uac
- Extracted from upstream docs: https://raw.githubusercontent.com/tclahr/uac/HEAD/README.md
## Documentation
- https://github.com/tclahr/uac
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/collect-unix-like-incident-response-artifacts-into-one-portable-evidence-bundle-with-uac/)
No comments yet. Be the first to comment!
Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.