Do not delete the files based on alert severity alone. Severity indicates urgency and impact, not proof. Mark the incident `suspected` (or `blocked` if authorization/scope is missing), preserve originals in place, and record acquisition method, timestamps, hashes, custodian, and original references. Continue safe offline analysis. Any isolation or eradication requires a valid engagement/scope reference, approved operation, named owner, runtime-enforced controls, and independent approval for d...
Pro scans all 11 files and shows the line behind each finding
Scanned 9/24/2026
npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-incident-triage --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Cyber Incident Triage?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-incident-triage-6bc32821)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
Do not delete the files based on alert severity alone. Severity indicates urgency and impact, not proof.
Mark the incident `suspected` (or `blocked` if authorization/scope is missing), preserve originals in place, and record acquisition method, timestamps, hashes, custodian, and original references. Continue safe offline analysis.
Any isolation or eradication requires a valid engagement/scope reference, approved operation, named owner, runtime-enforced controls, and independent approval for disruptive containment. Separately authorize containment, eradication, and recovery; never perform production changes from prose alone.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!