Agent skill

Dt Sec Contextualization

by Dynatrace in Dynatrace/dynatrace-for-ai

Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity.

Apache-2.0Auto-check passedDevOps & Cloud

Install Dt Sec Contextualization

skills CLI
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-sec-contextualization -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Dynatrace/dynatrace-for-ai dt-sec-contextualization --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dt-sec-contextualization .claude/skills/dt-sec-contextualization && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dt-sec-contextualization
GitHub stars
162
Token cost
~2.1k tokens
SKILL.md length
821 words
Files
5 (incl. references)
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity.

  • Works in 2 steps: SKILL.md (this file) — entry point and… → references/
  • Broad security.events posture/overview (use dt-sec-insights)
  • SKILL.md covers What This Skill Covers, When to Use This Skill, How This Skill Is Organized and Universal Best Practices, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dt Sec Contextualization is an agent skill from Dynatrace/dynatrace-for-ai. Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity. Covers identity-to-Smartscape mapping (incl. container-image digest/ID to workload), cross-level topology (K8s pod detection vs. node CVE via pod-to-node), per-entity risk summarization, and coverage match recipes shared by dt-sec-insights. Trigger: "map these findings to workloads/hosts", "which workload does this container image run as", "do…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/correlation-and-coverage.md`, `references/entity-enrichment.md` and `references/identity-mapping.md`).

It sits in DevOps & Cloud, covering Container orchestration, Containers and Vulnerability scanning. It works with Kubernetes. The repository describes itself as: Skills, prompts, and instructions for building AI agents on top of Dynatrace production context. The licence is Apache-2.0.

When your agent uses it

  • Broad security.events posture/overview (use dt-sec-insights)
  • General DQL (use dt-dql-essentials)
  • IoC hunting in logs/spans (use dt-sec-ioc-hunting)
  • K8s observability outside the security cross-level context (use dt-obs-kubernetes)

Example prompts

  • “map these findings to workloads/hosts”
  • “which workload does this container image run as”
  • “do these findings relate through the same runtime entity”
  • “/dt-sec-contextualization”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. SKILL.md (this file) — entry point and routing.
  2. references/

What it can do on your machine

Read from SKILL.md and the folder at commit 4f9aa71. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dt Sec Contextualization loads about 2.1k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 259 tokens; SKILL.md has 821 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~259
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Dynatrace/dynatrace-for-ai at commit 4f9aa71, republished under its Apache-2.0 licence (© Dynatrace). 821 words, ~2,131 tokens.

Download SKILL.mdSave it as .claude/skills/dt-sec-contextualization/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
dt-sec-contextualization
description
Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity. Covers identity-to-Smartscape mapping (incl. container-image digest/ID to workload), cross-level topology (K8s pod detection vs. node CVE via pod-to-node), per-entity risk summarization, and coverage match recipes shared by dt-sec-insights. Trigger: "map these findings to workloads/hosts", "which workload does this container image run as", "do these findings relate through the same runtime entity", "enrich this IoC match with entity context", "which threat report mentions this IoC". Queries security.events ONLY for THREAT_REPORT IoC enrichment (matched IoC to attributing reports); Do NOT use for broad security.events posture/overview (use dt-sec-insights), general DQL (use dt-dql-essentials), IoC hunting in logs/spans (use dt-sec-ioc-hunting), or K8s observability outside the security cross-level context (use dt-obs-kubernetes).
license
Apache-2.0

Security Contextualization Skill

Resolve security signals and entity attribute sets to runtime Dynatrace Smartscape entities, summarize findings across entity levels, and connect signals that land on different levels (e.g. a detection on a K8S_POD vs. a CVE on a KUBERNETES_NODE) via a shared runtime entity.

What This Skill Covers

  • Identity → Smartscape mapping — given a row carrying any of dt.smartscape_source.id, container_image.digest, container_image.id, host.ip, dt.entity.*, or k8s.* fields, resolve it to a Smartscape entity at any requested level (CONTAINER / K8S_POD / workload / K8S_NODE / HOST / cloud / GENAI_SERVICE — AI/GenAI workloads).
  • Artifact → runtime bridge — container_image.digest → smartscapeNodes CONTAINER → is_part_of.* → parent workload or runs_on.host → HOST. Works without pre-enriched dt.smartscape_source.id.
  • Cross-level correlation — tiered entity matching to determine whether two findings (e.g. a detection and a CVE from different legs) relate through a shared runtime entity. Tier 1: exact entity id match; Tier 2: same workload/pod/host by name; Tier 3: same namespace/cluster (context-only — does not contribute to scoring).
  • Pod → node topology — resolve K8S_POD to its K8S_NODE via k8s.node.name (co-projected field) or Smartscape edge traversal. Enables "detection hit pod X — does that pod run on a vulnerable node?"
  • Coverage match recipes — 2-way and 3-way container→workload match patterns shared across dt-sec-insights coverage counting queries.
  • Entity enrichment — given findings, IoC matches, or raw Smartscape nodes, produce per-entity risk-level breakdowns and entity-key bundles for downstream scoring.
  • IoC enrichment — attribute an already-matched IoC (IP / domain / URL / email / CVE / hash / MITRE TTP) with adversary context (actor, malware family, MITRE technique, targeting, provider) by reverse-looking-up the ingested THREAT_REPORT events whose observable arrays contain that IoC.

When to Use This Skill

Intent / triggerReference
Map findings / IoC matches to workloads, hosts, or cloud entitiesidentity-mapping.md -> entity-enrichment.md
Which Smartscape entity does this container image / digest run as?identity-mapping.md § Mapping Primitive (Path 2 - container digest)
Do this detection and this CVE relate via a shared entity?correlation-and-coverage.md § Correlation
Pod X fired - does it run on a vulnerable node?correlation-and-coverage.md § Correlation (Pod->Node Topology)
Per-entity risk summary (Critical/High/Medium/Low)entity-enrichment.md
Coverage match recipe - which workloads are covered by product Y?correlation-and-coverage.md § Coverage
Which entity-identity fields are relevant to a finding type?identity-mapping.md § Data Model
Enrich a matched IoC (IP/domain/hash/CVE/...) with threat-report adversary contextioc-enrichment.md
Scope findings to AI/GenAI workloads; which processes belong to an AI service; resolve a process to its AI serviceidentity-mapping.md § Mapping Primitive (Path 4 - GENAI_SERVICE -> SERVICE -> PROCESS)

How This Skill Is Organized

  1. SKILL.md (this file) — entry point and routing.
  2. references/
    • identity-mapping.md — generalized identity->Smartscape resolver (mapping primitive Paths 1/2/3/4), pre-flight identifier checks, level selection, and entity-identity field guidance.
    • entity-enrichment.md — consumers of the mapping primitive: cloud (Path 1), K8s workload (3-way), host-by-IP, host-by-entity, natural-language fallback, problem->entities->findings chain. Per-entity risk-level breakdowns (Critical/High/Medium/Low).
    • correlation-and-coverage.md — cross-level entity convergence, pod->node topology resolution, scoring contract, and 2-way/3-way coverage match recipes shared with dt-sec-insights.
    • ioc-enrichment.md — reverse-lookup IoC enrichment: attribute a matched IoC to ingested THREAT_REPORT events and surface adversary context (actor / malware / MITRE / targeting). Single and batch (per-IoC) templates; supported-IoC taxonomy.
Show full SKILL.md (345 more words)Show less

Universal Best Practices

  1. Always load dt-dql-essentials first — DQL syntax and function names differ from SQL. Confirm all functions before generating queries.
  2. Ground every query in a named template — do not improvise Smartscape joins. The 3-way match, digest→CONTAINER→workload, and pod→node traversal patterns are precise; deviating produces silent zero-row results.
  3. Run the pre-flight check before the full 3-way enrichment — external providers vary widely. Confirm at least one identifier path is populated before running the expensive append chain.
  4. Check dt.smartscape_source.type before trusting Path 1 — a non-null dt.smartscape_source.id is not proof of workload-level resolution; the field may point to a namespace, cluster, or cloud resource. Only K8s workload types (K8S_DEPLOYMENT, K8S_DAEMONSET, K8S_STATEFULSET, K8S_CRONJOB, K8S_JOB, K8S_REPLICASET) are eligible for workload enrichment via Path 1.
  5. Dedup early and after append — dedup before joins to collapse re-ingested duplicates; dedup again after append because the same finding can match multiple paths.
  6. Tier 3 correlation is context only — same namespace/cluster shared by two findings does not raise the exposure score. Never treat a cluster-level shared attribute as proof of entity-level relatedness.
  7. Route topology queries to dt-obs-kubernetes — pod→node placement and Smartscape edge traversal patterns live in dt-obs-kubernetes/references/pod-node-placement.md. Do not re-author them here; reference them and apply the output in correlation-and-coverage.md.
  8. No dt.system.bucket filters — security event data may live in any bucket; filtering by bucket risks hiding findings.
  9. THREAT_REPORT is the one security.events query allowed here — reverse lookup only. ioc-enrichment.md attributes a matched IoC to reports (IoC → report). Broad THREAT_REPORT overviews, IOC rollups, and forward report → environment correlation stay in dt-sec-insights (threat-intelligence.md). Never author finding/posture queries here.
SkillRole
dt-dql-essentialsLoad first. Core DQL syntax, functions, Smartscape patterns.
dt-sec-insightsConsumer of mapping primitive; owns finding-schema queries and coverage counting logic. Owns forward threat-intel (report → environment correlation, overviews, IOC rollups) in threat-intelligence.md; this skill owns only the reverse IoC → report enrichment (ioc-enrichment.md).
dt-sec-ioc-huntingRoutes cross-evidence correlation and entity enrichment to this skill.
dt-obs-kubernetesPod→node topology; K8s entity placement patterns.
dt-obs-hostsHost inventory; process-level context for HOST/PROCESS_GROUP findings.
dt-obs-aws / dt-obs-azure / dt-obs-gcpCloud Smartscape topology for cloud-entity enrichment.

© Dynatrace, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/dt-sec-contextualization of Dynatrace/dynatrace-for-ai.

  • SKILL.md
  • references/correlation-and-coverage.md
  • references/entity-enrichment.md
  • references/identity-mapping.md
  • references/ioc-enrichment.md

Open the folder on GitHubat commit 4f9aa71

Compare with similar skills

Dt Sec Contextualization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dt Sec Contextualization compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dt Sec Contextualization this skillDynatrace/dynatrace-for-ai162—~2.1kAutomated safety check: PassApache-2.0
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.0
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Container Securityhardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNone
Scanning Kubernetes Manifests With Kubesecmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Container Security Hardeningsickn33/agentic-awesome-skills47k1 repos~1kAutomated safety check: NotesMIT

Similar skills

  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Scanning Kubernetes Manifests With Kubesec

    mukul975/Anthropic-Cybersecurity-Skills

    Scores Kubernetes resource manifests with Kubesec to flag misconfiguration and privilege-escalation risk before deployment, mapping each finding back to the securityContext change that fixes it.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check: notes

More from Dynatrace/dynatrace-for-ai

All 33 skills in this repo
  • Dt Obs Analytics

    Dynatrace/dynatrace-for-ai

    Analyze dashboards and notebooks using Davis analyzers — anomaly detection, novelty scoring, and correlation.

    162 GitHub stars~3.9k tokensUpdated 8 days ago
    Auto-check passed
  • Dt Setup iOS

    Dynatrace/dynatrace-for-ai

    Set up the Dynatrace iOS SDK (OneAgent) in an iOS project using Swift Package Manager.

    162 GitHub stars~3.3k tokensUpdated 8 days ago
    Auto-check passed
  • Dt Alerting

    Dynatrace/dynatrace-for-ai

    End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…

    162 GitHub stars~3.3k tokensUpdated 8 days ago
    Auto-check passed
  • Dt Obs AWS

    Dynatrace/dynatrace-for-ai

    AWS cloud resource monitoring including EC2, RDS, Lambda, ECS/EKS, VPC networking, load balancers, S3, DynamoDB, SQS/SNS, and cost optimization.

    162 GitHub stars~4.2k tokensUpdated 8 days ago
    Auto-check passed
  • Dt Obs Ext Monitors

    Dynatrace/dynatrace-for-ai

    3rd-party test and monitor result ingestion into Dynatrace Grail via the platform events ingest API (platform/ingest/custom/events/).

    162 GitHub stars~1.5k tokensUpdated 8 days ago
    Auto-check passed
  • Dt Obs Problems

    Dynatrace/dynatrace-for-ai

    DAVIS problem analysis including root cause identification, impact assessment, and correlation with other telemetry.

    162 GitHub stars~4.6k tokensUpdated 8 days ago
    Auto-check passed

Works with

Categories

Questions about Dt Sec Contextualization

What does Dt Sec Contextualization do?

Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity. Dt Sec Contextualization is an agent skill from Dynatrace/dynatrace-for-ai. Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity.

When should I use Dt Sec Contextualization?

Dt Sec Contextualization fits situations like: broad security.events posture/overview (use dt-sec-insights); general DQL (use dt-dql-essentials); ioC hunting in logs/spans (use dt-sec-ioc-hunting); K8s observability outside the security cross-level context (use dt-obs-kubernetes).

How do I install Dt Sec Contextualization in Claude Code?

Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-sec-contextualization -a claude-code`. Or copy the skill folder (skills/dt-sec-contextualization in Dynatrace/dynatrace-for-ai) into .claude/skills/dt-sec-contextualization in your project. Claude Code loads it when a task matches its description.

How do I install Dt Sec Contextualization in Codex?

Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-sec-contextualization -a codex`. Or copy the skill folder (skills/dt-sec-contextualization in Dynatrace/dynatrace-for-ai) into .agents/skills/dt-sec-contextualization in your project. Codex loads it when a task matches its description.

Can I use Dt Sec Contextualization in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-sec-contextualization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dt-sec-contextualization, .gemini/skills/dt-sec-contextualization, .github/skills/dt-sec-contextualization and .opencode/skills/dt-sec-contextualization in your project.

What does Dt Sec Contextualization need to run?

SKILL.md names no scripts, command-line tools or credentials: Dt Sec Contextualization is instructions for the agent only.

Does Dt Sec Contextualization access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dt Sec Contextualization safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dt Sec Contextualization use?

Dt Sec Contextualization is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dt Sec Contextualization use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 20k tokens, read only when the agent opens those files.

What are the alternatives to Dt Sec Contextualization?

Skills that share tags, products or a category with Dt Sec Contextualization: Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Container Security (hardw00t/ai-security-arsenal, 104 stars) and Scanning Kubernetes Manifests With Kubesec (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dt Sec Contextualization?

Dynatrace (a GitHub organization) maintains it in Dynatrace/dynatrace-for-ai, which has 162 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.

Source: Dynatrace/dynatrace-for-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.