security-incident-response
Installation
SKILL.md
Security Incident Response Skill
In a security incident, the order of operations matters: contain before you clean, preserve evidence before you wipe, and communicate deliberately. This skill drives a structured response through the standard phases, or documents one after the fact — with the immediate actions, decision points, comms, and a blameless post-incident review. For systems you own or are authorized to defend.
Required Inputs
Ask for these only if they aren't already provided:
- What's happening — the observed incident (malware, unauthorized access, data exfiltration, ransomware, account compromise), and how it was detected.
- Scope so far — affected systems/accounts/data, whether it's ongoing, entry point if known.
- Environment & stakes — what's at risk (PII, funds, availability), regulatory/notification obligations.
- Resources — who's responding, tooling/access available, and any IR plan already in place.