Do not delete the files based on alert severity. Treat the incident as `suspected` (or `blocked` if authorization/evidence is missing): severity indicates urgency and impact, not proof. Preserve the originals and record acquisition method, timestamps, hashes where available, custodian, and original references. Continue safe offline analysis, documenting the hypothesis and evidence gaps. Containment, eradication, or production changes require an engagement/scope reference, approved operation, ...
Pro scans all 15 files and shows the line behind each finding
Scanned 9/24/2026
npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-incident-triage --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Cyber Incident Triage?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-incident-triage-agent-skills-standard)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
Do not delete the files based on alert severity. Treat the incident as `suspected` (or `blocked` if authorization/evidence is missing): severity indicates urgency and impact, not proof.
Preserve the originals and record acquisition method, timestamps, hashes where available, custodian, and original references. Continue safe offline analysis, documenting the hypothesis and evidence gaps.
Containment, eradication, or production changes require an engagement/scope reference, approved operation, designated owner, and runtime-proven controls; disruptive containment also requires independent approval. Keep analysis separate from containment, eradication, and recovery. The next approved action should be evidence-preserving collection or authorized isolation—not deletion.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!