Forensics Osquery
AgentSecOps/SecOpsAgentKit
SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.
A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.
$ npx skills add alirezarezvani/claude-skills --skill incident-response -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install alirezarezvani/claude-skills incident-response --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering-team/skills/incident-response .claude/skills/incident-response && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "incident-response" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/incident-response into .claude/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/incident-responseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add alirezarezvani/claude-skills --skill incident-response -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install alirezarezvani/claude-skills incident-response --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/engineering-team/skills/incident-response .agents/skills/incident-response && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "incident-response" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/incident-response into .agents/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alirezarezvani/claude-skills --skill incident-response -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install alirezarezvani/claude-skills incident-response --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/engineering-team/skills/incident-response .cursor/skills/incident-response && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "incident-response" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/incident-response into .cursor/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/alirezarezvani/claude-skills.git --path engineering-team/skills/incident-response--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add alirezarezvani/claude-skills --skill incident-response -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install alirezarezvani/claude-skills incident-response --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/engineering-team/skills/incident-response .gemini/skills/incident-response && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "incident-response" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/incident-response into .gemini/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install alirezarezvani/claude-skills incident-responseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add alirezarezvani/claude-skills --skill incident-response -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/engineering-team/skills/incident-response .github/skills/incident-response && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "incident-response" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/incident-response into .github/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alirezarezvani/claude-skills --skill incident-response -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install alirezarezvani/claude-skills incident-response --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/engineering-team/skills/incident-response .opencode/skills/incident-response && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "incident-response" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering-team/skills/incident-response into .opencode/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
incident-responseA skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.
Incident Response is an agent skill from alirezarezvani/claude-skills. Use when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. Covers SEV1-SEV4 classification, false positive filtering, incident taxonomy, and NIST SP 800-61 lifecycle.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/regulatory-deadlines.md` and `scripts/incident_triage.py`).
It sits in DevOps & Cloud, covering Incident response, Digital forensics and Security operations. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3jqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Incident Response loads about 3.8k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 1,363 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 1,363 words, ~3,836 tokens.
.claude/skills/incident-response/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Incident response skill for the full lifecycle from initial triage through forensic collection, severity declaration, and escalation routing. This is NOT threat hunting (see threat-detection) or post-incident compliance mapping (see governance/compliance-mapping) — this is about classifying, triaging, and managing declared security incidents.
This skill provides the methodology and tooling for incident triage and response — classifying security events into typed incidents, scoring severity, filtering false positives, determining escalation paths, and initiating forensic evidence collection under chain-of-custody controls.
| Skill | Focus | Approach |
|---|---|---|
| incident-response (this) | Active incidents | Reactive — classify, escalate, collect evidence |
| threat-detection | Pre-incident hunting | Proactive — find threats before alerts fire |
| cloud-security | Cloud posture assessment | Preventive — IAM, S3, network misconfiguration |
| red-team | Offensive simulation | Offensive — test detection and response capability |
A security event must be ingested before triage. Events can come from SIEM alerts, EDR detections, threat intel feeds, or user reports. The triage tool accepts JSON event payloads; see the input schema below.
The incident_triage.py tool classifies events, checks false positives, scores severity, determines escalation, and performs forensic pre-analysis.
# Classify an event from JSON file
python3 scripts/incident_triage.py --input event.json --classify --json
# Classify with false positive filtering enabled
python3 scripts/incident_triage.py --input event.json --classify --false-positive-check --json
# Force a severity level for tabletop exercises
python3 scripts/incident_triage.py --input event.json --severity sev1 --json
# Read event from stdin
echo '{"event_type": "ransomware", "host": "prod-db-01", "raw_payload": {}}' | \
python3 scripts/incident_triage.py --classify --false-positive-check --json{
"event_type": "ransomware",
"host": "prod-db-01",
"user": "svc_backup",
"source_ip": "10.1.2.3",
"timestamp": "2024-01-15T14:32:00Z",
"raw_payload": {}
}| Code | Meaning | Required Response |
|---|---|---|
| 0 | SEV3/SEV4 or clean | Standard ticket-based handling |
| 1 | SEV2 — elevated | 1-hour bridge call, async coordination |
| 2 | SEV1 — critical | Immediate 15-minute war room, all-hands |
Security events are classified into 14 incident types. Classification drives default severity, MITRE technique mapping, and response SLA.
| Incident Type | Default Severity | MITRE Technique | Response SLA |
|---|---|---|---|
| ransomware | SEV1 | T1486 | 15 minutes |
| data_exfiltration | SEV1 | T1048 | 15 minutes |
| apt_intrusion | SEV1 | T1566 | 15 minutes |
| supply_chain_compromise | SEV1 | T1195 | 15 minutes |
| domain_controller_breach | SEV1 | T1078.002 | 15 minutes |
| credential_compromise | SEV2 | T1110 | 1 hour |
| lateral_movement | SEV2 | T1021 | 1 hour |
| malware_infection | SEV2 | T1204 | 1 hour |
| insider_threat | SEV2 | T1078 | 1 hour |
| cloud_account_compromise | SEV2 | T1078.004 | 1 hour |
| unauthorized_access | SEV3 | T1190 | 4 hours |
| policy_violation | SEV3 | N/A | 4 hours |
| phishing_attempt | SEV4 | T1566.001 | 24 hours |
| security_alert | SEV4 | N/A | 24 hours |
Any of the following automatically re-declare a higher severity:
| Trigger | New Severity |
|---|---|
| Ransomware note found | SEV1 |
| Active exfiltration confirmed | SEV1 |
| CloudTrail or SIEM disabled | SEV1 |
| Domain controller access confirmed | SEV1 |
| Second system compromised | SEV1 |
| Exfiltration volume exceeds 1 GB | SEV2 minimum |
| C-suite account accessed | SEV2 minimum |
| Level | Name | Criteria | Skills Invoked | Escalation Path |
|---|---|---|---|---|
| SEV1 | Critical | Confirmed ransomware; active PII/PHI exfiltration (>10K records); domain controller breach; defense evasion (CloudTrail disabled); supply chain compromise | All skills (parallel) | SOC Lead → CISO → CEO → Board Chair |
| SEV2 | High | Confirmed unauthorized access to sensitive systems; credential compromise with elevated privileges; lateral movement confirmed; ransomware indicators without confirmed execution | triage + containment + forensics | SOC Lead → CISO |
| SEV3 | Medium | Suspected unauthorized access (unconfirmed); malware detected and contained; single account compromise (no priv escalation) | triage + containment | SOC Lead → Security Manager |
| SEV4 | Low | Security alert with no confirmed impact; informational indicator; policy violation with no data risk | triage only | L3 Analyst queue |
The triage tool applies five filters before escalating to prevent false positive inflation.
| Filter | Description | Example Pattern |
|---|---|---|
| CI/CD agent activity | Known build/deploy agents flagged as anomalies | jenkins, github-actions, circleci, gitlab-runner |
| Test environment tagging | Assets tagged as non-production | test-, staging-, dev-, sandbox- |
| Scheduled job patterns | Expected batch processes triggering alerts | cron, scheduled_task, batch_job, backup_ |
| Whitelisted identities | Explicitly approved service accounts | svc_monitoring, svc_backup, datadog-agent |
| Scanner activity | Known security scanners and vulnerability tools | nessus, qualys, rapid7, aws_inspector |
A confirmed false positive suppresses escalation and logs the suppression reason for audit purposes. Recurring false positives from the same source should be tuned out at the detection layer, not filtered repeatedly at triage.
Evidence collection follows the DFRWS six-phase framework and the principle of volatile-first acquisition.
| Phase | Activity | Priority |
|---|---|---|
| Identification | Identify what evidence exists and where | Immediate |
| Preservation | Prevent modification — write-block, snapshot, legal hold | Immediate |
| Collection | Acquire evidence in order of volatility | Immediate |
| Examination | Technical analysis of collected evidence | Within 2 hours |
| Analysis | Interpret findings in investigative context | Within 4 hours |
| Presentation | Produce findings report with chain of custody | Before incident closure |
netstat, ps)Every evidence item must be recorded with:
| Severity | Immediate Contact | Bridge Call | External Notification |
|---|---|---|---|
| SEV1 | SOC Lead + CISO (15 min) | Immediate war room | Legal + PR standby; regulatory notification per deadline table |
| SEV2 | SOC Lead (30 min async) | 1-hour bridge | Legal notification if PII involved |
| SEV3 | Security Manager (4 hours) | Async only | None unless scope expands |
| SEV4 | L3 Analyst queue (24 hours) | None | None |
| Incident Type | Primary Escalation | Secondary |
|---|---|---|
| Ransomware / APT | CISO + CEO | Board if data at risk |
| PII/PHI breach | Legal + CISO | Regulatory body (per deadline table) |
| Cloud account compromise | Cloud security team | CISO |
| Insider threat | HR + Legal + CISO | Law enforcement if criminal |
| Supply chain | CISO + Vendor management | Board |
The notification clock starts at incident declaration, not at investigation completion.
| Framework | Incident Type | Deadline | Penalty |
|---|---|---|---|
| GDPR (EU 2016/679) | Personal data breach | 72 hours after discovery | Up to 4% global revenue |
| PCI-DSS v4.0 | Cardholder data breach | 24 hours to acquirer | Card brand fines |
| HIPAA (45 CFR 164) | PHI breach (>500 individuals) | 60 days after discovery | Up to $1.9M per violation category |
| NY DFS 23 NYCRR 500 | Cybersecurity event | 72 hours to DFS | Regulatory sanctions |
| SEC Rule (17 CFR 229.106) | Material cybersecurity incident | 4 business days after materiality determination | SEC enforcement |
| CCPA / CPRA | Breach of sensitive PI | Without unreasonable delay | AG enforcement; private right of action |
| NIS2 (EU 2022/2555) | Significant incident (essential services) | 24-hour early warning; 72-hour notification | National authority sanctions |
Operational rule: If scope is unclear at declaration, assume the most restrictive applicable deadline and confirm scope within the first response window.
Full deadline reference: references/regulatory-deadlines.md
For single alert requiring classification before escalation decision:
# 1. Classify the event with false positive filtering
python3 scripts/incident_triage.py --input alert.json \
--classify --false-positive-check --json
# 2. Review severity, escalation_path, and false_positive_flag in output
# 3. If severity = sev1 or sev2, page SOC Lead immediately
# 4. If false_positive_flag = true, document and closeDecision: Exit code 2 = SEV1 war room now. Exit code 1 = SEV2 bridge call within 30 minutes.
T+0 Detection arrives (SIEM alert, EDR, user report)
T+5 Classify with incident_triage.py --classify --false-positive-check
T+10 If SEV1: page CISO, open war room, start regulatory clock
T+15 Initiate forensic collection (volatile evidence first)
T+15 Containment assessment (parallel with forensics)
T+30 Human approval gate for any containment action
T+45 Execute approved containment
T+60 Assess containment effectiveness, brief Legal if PII/PHI scope
T+4h Final forensic evidence package, dwell time estimate
T+8h Eradication and recovery plan
T+72h Regulatory notification submission (if GDPR/NIS2 triggered)# Full classification with forensic context
python3 scripts/incident_triage.py --input incident.json \
--classify --false-positive-check --severity sev1 --json > incident_triage_output.json
# Forensic pre-analysis
python3 scripts/incident_triage.py --input incident.json --json | \
jq '.forensic_findings, .chain_of_custody_steps'Simulate incidents at specific severity levels without real events:
# Simulate SEV1 ransomware incident
echo '{"event_type": "ransomware", "host": "prod-db-01", "user": "svc_backup"}' | \
python3 scripts/incident_triage.py --classify --severity sev1 --json
# Simulate SEV2 credential compromise
echo '{"event_type": "credential_compromise", "user": "admin_user", "source_ip": "203.0.113.5"}' | \
python3 scripts/incident_triage.py --classify --false-positive-check --json
# Verify escalation paths for all 14 incident types
for type in ransomware data_exfiltration credential_compromise lateral_movement; do
echo "{\"event_type\": \"$type\"}" | python3 scripts/incident_triage.py --classify --json
done| Skill | Relationship |
|---|---|
| threat-detection | Confirmed hunting findings escalate to incident-response for triage and classification |
| cloud-security | Cloud posture findings (IAM compromise, S3 exposure) may trigger incident classification |
| red-team | Red team findings validate detection coverage; confirmed gaps become hunting hypotheses |
| security-pen-testing | Pen test vulnerabilities exploited in the wild escalate to incident-response for active incident handling |
© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts, references) in engineering-team/skills/incident-response of alirezarezvani/claude-skills.
Open the folder on GitHubat commit 19392f7
Incident Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Incident Response this skillalirezarezvani/claude-skills | 28k | — | ~3.8k | Automated safety check: Pass | MIT | |
| Forensics OsqueryAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~4.9k | Automated safety check: Notes | Custom licence | |
| Ir VelociraptorAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3.1k | Automated safety check: Pass | Custom licence | |
| Incident Response NetworkLeoYeAI/openclaw-master-skills | 2.2k | — | ~5k | Automated safety check: Pass | Apache-2.0 | |
| Malware Persistence Analysis with Autorunsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Soar Playbook With Palo Alto Xsoarmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 |
AgentSecOps/SecOpsAgentKit
SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.
AgentSecOps/SecOpsAgentKit
Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.
LeoYeAI/openclaw-master-skills
Network forensics evidence collection and analysis during security incidents.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise…
mukul975/Anthropic-Cybersecurity-Skills
Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic…
alirezarezvani/claude-skills
Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.
alirezarezvani/claude-skills
OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.
alirezarezvani/claude-skills
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.
alirezarezvani/claude-skills
Design AWS architectures for startups using serverless patterns and IaC templates.
alirezarezvani/claude-skills
Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.
alirezarezvani/claude-skills
Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.
Categories
A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. Incident Response is an agent skill from alirezarezvani/claude-skills. Use when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.
Incident Response fits situations like: A security incident has been detected; declared and needs classification; escalation path determination; forensic evidence collection.
Run `npx skills add alirezarezvani/claude-skills --skill incident-response -a claude-code`. Or copy the skill folder (engineering-team/skills/incident-response in alirezarezvani/claude-skills) into .claude/skills/incident-response in your project. Claude Code loads it when a task matches its description.
Run `npx skills add alirezarezvani/claude-skills --skill incident-response -a codex`. Or copy the skill folder (engineering-team/skills/incident-response in alirezarezvani/claude-skills) into .agents/skills/incident-response in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill incident-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/incident-response, .gemini/skills/incident-response, .github/skills/incident-response and .opencode/skills/incident-response in your project.
Going by SKILL.md and its folder, Incident Response needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and jq). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Incident Response is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Incident Response: Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars), Ir Velociraptor (AgentSecOps/SecOpsAgentKit, 220 stars), Incident Response Network (LeoYeAI/openclaw-master-skills, 2.2k stars) and Malware Persistence Analysis with Autoruns (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,891 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.
Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.