data-breach-response
Installation
SKILL.md
Data Breach Response Skill
The breach notification letter arrives months late, written by lawyers to minimize alarm and liability in the same paragraph — and the reader's real question is buried: what did they get, and what do I actually do? The answer depends entirely on the first part: a leaked password and a leaked government ID number are different emergencies with different ladders. This skill triages by what leaked, orders the response (some steps are today, most aren't), and decodes the letter itself — including the free-monitoring offer, which is worth taking and worth understanding.
What This Skill Produces
- The triage — what leaked, mapped to what it enables: account takeover, financial fraud, identity theft, targeted phishing
- The ladder — do-today / this-week / ongoing, ordered by damage-prevented-per-minute
- The monitoring plan — what to watch, where, at what cadence — calibrated, not paranoid
- The letter decode — what the notification actually admits, and what the monitoring offer covers
Required Inputs
Ask for these if not provided:
- What leaked — from the letter or breach-lookup: email? passwords (hashed or plain — the letter usually says)? card numbers? government ID / SSN? medical? The whole response keys off this list
- The account's blast radius — was that password reused? (The honest answer decides half the ladder) Is the breached account an identity anchor (primary email)?
- Jurisdiction, loosely — credit freezes, fraud alerts, and ID-theft reporting are country-specific; the ladder names the step types with verify-locally flags
- What's been noticed — any weird charges, logins, or mail already? That upgrades the response from preventive to active-incident