remediate-workspace-session-kill

Installation
SKILL.md

remediate-workspace-session-kill

What this closes

Pair skill for detect-google-workspace-suspicious-login — provider-marked suspicious Workspace login or repeated failures followed by success (MITRE ATT&CK T1110 Brute Force + T1078 Valid Accounts).

Closes #155 phase 4 (tracking issue: #312). After this lands, the closed-loop coverage matrix flips the Workspace row red→green. Ratio goes 7/11 → 8/11.

Why sign-out + force-password-change (not user.suspend)

Suspending the user breaks legitimate work for the legitimate owner. Sign-out + force-password-change is the standard Workspace account-takeover containment:

  • Kills the attacker's existing session tokens immediately (revokes web/mobile auth)
  • Requires the legitimate user to re-authenticate before regaining access
  • Recovery path is owned by the user (password reset via recovery phone/email or admin assist)

Same containment philosophy as remediate-okta-session-kill.

Inputs

Installs
2
GitHub Stars
3
First Seen
Jun 19, 2026
remediate-workspace-session-kill — msaad00/cloud-ai-security-skills