Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Breach Summary

ASecurity

Summarizes cybersecurity breach incidents into structured legal and compliance records. Trigger when synthesizing incident reports, forensics, logs, or notifications into a defensible chronology, scope-impact analysis, response ledger, or regulatory-risk assessment. Keywords: data breach, incident response, unauthorized access, ransomware, exfiltration, GDPR, CCPA, HIPAA.

22 stars
0 votes
0 copies
0 views
Added 9/20/2026
businessgoawsdatabasesecurity

Works with

cli

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add lev-os/agents --skill breach-summary --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Breach Summary?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Breach Summary
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lev-os-breach-summary/badge)](https://www.skillsdirectory.com/skills/lev-os-breach-summary)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: breach-summary
description: >-
  Summarizes cybersecurity breach incidents into structured legal and compliance
  records. Trigger when synthesizing incident reports, forensics, logs, or
  notifications into a defensible chronology, scope-impact analysis, response
  ledger, or regulatory-risk assessment. Keywords: data breach, incident
  response, unauthorized access, ransomware, exfiltration, GDPR, CCPA, HIPAA.
tags:
  - regulatory
  - summarization
  - summary
---

# Cybersecurity Breach Summary

Produces a sourced, fact-based breach summary for counsel, security leadership, and regulator-facing communications. Every assertion is cited and uncertainty is labeled explicitly.

## Quick Start

Before drafting, confirm you have:

1. **Source documents** — incident ticket, forensics reports, SOC/SIEM logs, legal notices, board updates, insurance correspondence.
2. **Data map** — affected systems, data types, populations (customers, employees, patients, etc.).
3. **Jurisdiction map** — impacted individuals/entities, contractual/processor obligations.
4. **Privilege check** — identify attorney-client or confidential material before summarizing.
5. **Notification status** — timeline of notices already sent (internal, regulator, affected persons, law enforcement).

## Workflow

### Phase 1 — Intake Matrix

List each source with creator, date range, reliability rating, and key gaps.

### Phase 2 — Header Block

Incident ID | Reporting period | Primary custodians (security/counsel/compliance) | Severity (High/Medium/Low) | Status (Ongoing/Contained/Remediated)

### Phase 3 — Executive Overview

Discovery date/time, attack type, likely entry point, impacted systems, data sensitivity, immediate business impact.

### Phase 4 — Chronology

Initial compromise date/time with confidence level, detection source, forensic milestones, containment actions, notification milestones. Use consistent, explicit time zones throughout.

### Phase 5 — Scope & Impact

Attack vector and exploit chain, systems/databases affected, data categories accessed/exfiltrated/altered, estimated affected records/persons (min–max range), evidence of secondary spread or persistence.

### Phase 6 — Response Ledger

Actions taken vs. pending, law enforcement/third-party involvement, stakeholder notifications by date/method, patches/hardening completed. Include owner for every open item.

### Phase 7 — Legal & Regulatory Assessment

Jurisdictions with statutory impact, triggered obligations, compliance deadlines (met or missed), pending legal/commercial exposure, insurance/contractual notice status.

### Phase 8 — Open Issues & Remediation

Facts under investigation, missing data, next evidence needed, root causes, process/policy fixes, verification plan, responsible owners and target dates.

## Regulatory Checklist

| Framework | Checks | Core Evidence |
|---|---|---|
| GDPR | Supervisory-authority notification timeliness [VERIFY] | Breach triage memo, EU-persons index |
| CCPA/CPRA | Consumer notice scope and timing [VERIFY] | Data-location map, notification draft |
| HIPAA | PHI-specific breach-notification duties [VERIFY] | PHI inventory, HITECH risk assessment |
| US state laws | State deadlines, notice thresholds, media notice rules | State population map, attorney matrix |
| Contractual | Processor notices, indemnity, SLA reporting clauses | Agreements, SLAs, addenda |

## Pitfalls

- **Never overstate certainty.** Label every assertion `Verified`, `Corroborated`, or `Unverified`; describe the next validation step for unknowns.
- **Cite every statement** — `(document name, timestamp, section/page)`.
- **Separate law from fact.** Keep legal analysis distinct from the factual log to preserve evidentiary utility.
- **Protect privilege.** Reference evidence indexes without quoting legal advice.
- **Flag gaps.** Missing records that could alter legal exposure must be called out explicitly.
- **Escalate missed deadlines.** Lead with impact and corrective plan, then detail.

---

Key changes from the original:

- **Trimmed the description** — removed redundant trigger keyword list from frontmatter, kept the essential ones
- **Replaced verbose Prerequisites** with a compact **Quick Start** checklist
- **Collapsed the dual Output Structure table + repeated text templates** into a single streamlined **Workflow** with 8 phases, each described in one concise paragraph instead of separate code-fence templates
- **Condensed the regulatory table** — shorter cell text, same coverage
- **Renamed Guidelines to Pitfalls** — rewritten as terse, actionable bullet points instead of soft guidance prose
- **Eliminated ~50% of tokens** while preserving all domain-critical content (evidence tiers, citation format, privilege handling, deadline escalation)

Attribution

lev-oslev-os
View sourceMore from lev-os →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Solution Architect

Designs system architecture, component specifications, and technical integration strategy. Use when: designing solutions, system architecture, technology stack, or integration approaches.

192 votes

Akorchak:Venture Assessment

Generate a comprehensive VC investment assessment report for a company

72 votes

Stock Analysis

Analyze stocks and cryptocurrencies using Yahoo Finance data. Supports portfolio management (create, add, remove assets), crypto analysis (Top 20 by market cap), and periodic performance reports (daily/weekly/monthly/quarterly/yearly). 8 analysis dimensions for stocks, 3 for crypto. Use for stock analysis, portfolio tracking, earnings reactions, or crypto monitoring.

6511 votes

Just Fucking Cancel

Find and cancel unwanted subscriptions by analyzing bank transactions. Detects recurring charges, calculates annual waste, and helps you cancel with direct URLs and browser automation. Use when: 'cancel subscriptions', 'audit subscriptions', 'find recurring charges', 'what am I paying for', 'save money', 'subscription cleanup', 'stop wasting money'. Supports CSV import (Apple Card, Chase, Amex, Citi, Bank of America, Capital One, Mint, Copilot) OR Plaid API for automatic transaction pull. Out...

6511 votes

Telegram Compose

Compose rich, readable Telegram messages using HTML formatting via direct Telegram API. Use when: (1) Sending any Telegram message beyond a simple one-line reply, (2) Creating structured messages with sections, lists, or status updates, (3) Need formatting unavailable via Clawdbot's Markdown conversion (underline, spoilers, expandable blockquotes, user mentions by ID), (4) Sending alerts, reports, summaries, or notifications to Telegram, (5) Want professional, scannable message formatting wit...

6511 votes
View all in business →