Official agent skill

Security Alert Triage

by elastic in elastic/agent-skills

Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

OfficialApache-2.0Auto-check: notesSecurity

Install Security Alert Triage

skills CLI
$ npx skills add elastic/agent-skills --skill security-alert-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/agent-skills security-alert-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/alert-triage .claude/skills/security-alert-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-alert-triage
GitHub stars
592
Used in
1 other repo
Token cost
~3.5k tokens
SKILL.md length
1,009 words
Files
7 (incl. scripts, references)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

  • Works in 6 steps: Group alerts before triaging → Check existing cases → Gather context → …
  • Triaging alerts
  • SKILL.md covers Prerequisites, Quick start, Common multi-step workflows and Critical principles, plus 6 more sections
  • Runs JavaScript scripts from its folder; calls node and npm; needs ELASTICSEARCH_API_KEY and KIBANA_API_KEY

What it does

Security Alert Triage is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge. Use when triaging alerts, performing SOC analysis, or investigating detections.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/classification-guide.md`, `scripts/acknowledge-alert.js` and `scripts/es-client.js`). Compatibility notes: Requires Node.js 22+, network access to Elasticsearch. Environment variables: ELASTICSEARCHURL or ELASTICSEARCHCLOUDID, plus ELASTICSEARCHAPIKEY or…

It sits in Security, covering Security operations. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.

When your agent uses it

  • Triaging alerts
  • Performing SOC analysis
  • Investigating detections

Example prompts

  • “/security-alert-triage”

Requirements

  • Node.js
  • A credential in ELASTICSEARCH_API_KEY
  • A credential in KIBANA_API_KEY
  • Compatibility (from SKILL.md): Requires Node.js 22+, network access to Elasticsearch. Environment variables: ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID, plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Group alerts before triaging
  2. Check existing cases
  3. Gather context
  4. Create or update case
  5. Acknowledge alerts
  6. Repeat

What it can do on your machine

Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ELASTICSEARCH_API_KEY
    • KIBANA_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Node.js 22+, network access to Elasticsearch. Environment variables: ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID, plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.

    From compatibility in the SKILL.md frontmatter.

Context cost

Security Alert Triage loads about 3.5k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 50 tokens; SKILL.md has 1,009 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:28
    environment variables (or add them to a `.env` file in the workspace root):

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,009 words, ~3,499 tokens.

Download SKILL.mdSave it as .claude/skills/security-alert-triage/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
security-alert-triage
description
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge. Use when triaging alerts, performing SOC analysis, or investigating detections.
compatibility
Requires Node.js 22+, network access to Elasticsearch. Environment variables: ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID, plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.
metadata.author
elastic
metadata.version
0.1.0

Alert Triage

Analyze Elastic Security alerts one at a time: gather context, classify, create a case, and acknowledge. This skill depends on the case-management skill for case creation.

Prerequisites

Install dependencies before first use from the skills/security directory:

bash
cd skills/security && npm install

Set the required environment variables (or add them to a .env file in the workspace root):

bash
export ELASTICSEARCH_URL="https://your-cluster.es.cloud.example.com:443"
export ELASTICSEARCH_API_KEY="your-api-key"
export KIBANA_URL="https://your-cluster.kb.cloud.example.com:443"
export KIBANA_API_KEY="your-kibana-api-key"

Quick start

All commands from workspace root. Always fetch → investigate → document → acknowledge. Call the tools directly — do not read the skill file or explore the workspace first.

bash
node skills/security/alert-triage/scripts/fetch-next-alert.js
node skills/security/case-management/scripts/case-manager.js find --tags "agent_id:<id>"
node skills/security/alert-triage/scripts/run-query.js --query-file query.esql --type esql
node skills/security/case-management/scripts/case-manager.js create --title "..." --description "..." --tags "classification:..." "agent_id:<id>" --severity <level> --yes
node skills/security/case-management/scripts/case-manager.js attach-alert --case-id <id> --alert-id <id> --alert-index <index> --rule-id <uuid> --rule-name "<name>" --yes
node skills/security/alert-triage/scripts/acknowledge-alert.js --related --agent <id> --timestamp <ts> --window 60 --yes

Common multi-step workflows

TaskTools to call (in order)
End-to-end triagefetch_next_alert → run_query (context) → case_manager create (case) → acknowledge_alert
Gather contextrun_query (process tree, network, related alerts)
Create case after classificationcase_manager create → case_manager attach-alert
Acknowledge after triageacknowledge_alert (related mode for batch)

Always complete the full workflow: fetch → investigate → document → acknowledge. Do not stop after gathering context — create or update a case with findings before acknowledging.

Critical execution rules:

  • Start executing tools immediately — do not read SKILL.md, browse the workspace, or list files first.
  • For ES|QL queries, write the query to a temporary .esql file then pass it via --query-file. Do not use edit_file — use a single shell call with echo "..." > query.esql && node ... --query-file query.esql.
  • Keep context gathering focused: run 2-4 targeted queries (process tree, network, related alerts), not 10+.
  • Report only what tools return. Copy identifiers verbatim — do not paraphrase IDs, timestamps, or hostnames.

Critical principles

  • Do NOT classify prematurely. Gather ALL context before deciding benign/unknown/malicious.
  • Most alerts are false positives, even if they look alarming. Rule names like "Malicious Behavior" or severity "critical" are NOT evidence.
  • "Unknown" is acceptable and often correct when evidence is insufficient.
  • MALICIOUS requires strong corroborating evidence: persistence + C2, credential theft, lateral movement — not only suspicious API calls.
  • Report tool output verbatim. Copy IDs, hostnames, timestamps, and counts exactly as returned by tools. Do not round numbers, abbreviate IDs, or paraphrase error messages.

Workflow

When triaging multiple alerts, group first, then triage each group:

text
- [ ] Step 0: Group alerts by agent/host and time window
- [ ] Step 1: Check existing cases
- [ ] Step 2: Gather full context (DO NOT SKIP)
- [ ] Step 3: Create or update case (only AFTER context gathered)
- [ ] Step 4: Acknowledge alert and all related alerts
- [ ] Step 5: Fetch next alert group and repeat
Step 0: Group alerts before triaging

When the user asks about multiple open alerts, group them first to avoid redundant investigation: query open alerts, group by agent.id, sub-group by time window (~5 min = likely one incident), triage each group as a single unit.

Use ES|QL for an overview (write to file first for PowerShell):

esql
FROM .alerts-security.alerts-*
| WHERE kibana.alert.workflow_status == "open" AND @timestamp >= "<start>"
| STATS alert_count=COUNT(*), rules=VALUES(kibana.alert.rule.name) BY agent.id
| SORT alert_count DESC

For full query templates, see references/classification-guide.md.

Step 1: Check existing cases

Before creating a new case, check if this alert belongs to an existing one. Use the case-management skill:

bash
node skills/security/case-management/scripts/case-manager.js find --tags "agent_id:<agent_id>"
node skills/security/case-management/scripts/case-manager.js cases-for-alert --alert-id <alert_id>

Look for cases with the same agent ID, user, or related detection rule within a similar time window.

Note: find --search may return 500 errors on Serverless. Use find --tags or list instead.

Step 2: Gather context

This is the most important step. Do not skip or shortcut it. Complete ALL substeps before forming any classification opinion.

Time range warning: Alerts may be days or weeks old. NEVER use relative time like NOW() - 1 HOUR. Extract the alert's @timestamp and build queries around that time with +/- 1 hour window.

Substeps: (2a) Related alerts on same agent/user; (2b) Rule frequency across env (high = FP-prone); (2c) Entity context — process tree, network, registry, files; (2d) Behavior investigation — persistence, C2, lateral movement, credential access.

Example — process tree (use ES|QL with KEEP; avoid --full which produces 10K+ lines):

esql
FROM logs-endpoint.events.process-*
| WHERE agent.id == "<agent_id>" AND @timestamp >= "<alert_time - 5min>" AND @timestamp <= "<alert_time + 10min>"
  AND process.parent.name IS NOT NULL
  AND process.name NOT IN ("svchost.exe", "conhost.exe", "agentbeat.exe")
| KEEP @timestamp, process.name, process.command_line, process.pid, process.parent.name, process.parent.pid
| SORT @timestamp | LIMIT 80
Data typeIndex pattern
Alerts.alerts-security.alerts-*
Processeslogs-endpoint.events.process-*
Networklogs-endpoint.events.network-*
Logslogs-*

For full query templates and classification criteria, see references/classification-guide.md.

Step 3: Create or update case

After gathering context, create a case and attach alert(s). Use --rule-id and --rule-name (required; 400 error without them):

bash
node skills/security/case-management/scripts/case-manager.js create \
  --title "<concise summary>" \
  --description "<findings, IOCs, attack chain, MITRE techniques>" \
  --tags "classification:<benign|unknown|malicious>" "confidence:<0-100>" "mitre:<technique>" "agent_id:<id>" \
  --severity <low|medium|high|critical>

node skills/security/case-management/scripts/case-manager.js attach-alert \
  --case-id <case_id> --alert-id <alert_id> --alert-index <index> \
  --rule-id <rule_uuid> --rule-name "<rule name>"

# Multiple alerts: attach-alerts --alert-ids <id1> <id2>
# Add notes: add-comment --case-id <id> --comment "Findings..."

Case description: Summary (1-2 sentences); Attack chain; IOCs (hashes, IPs, paths); MITRE techniques; Behavioral findings; Response context (remediation, credentials at risk).

Show full SKILL.md (406 more words)Show less
Step 4: Acknowledge alerts

Acknowledge ALL related alerts together. Use --dry-run first to confirm scope, then run without it:

bash
# By host name — preferred when triaging a host
node skills/security/alert-triage/scripts/acknowledge-alert.js --query --host <hostname> --dry-run
node skills/security/alert-triage/scripts/acknowledge-alert.js --query --host <hostname> --yes

# By agent ID — preferred when agent.id is known
node skills/security/alert-triage/scripts/acknowledge-alert.js --related --agent <id> --timestamp <ts> --window 60 --dry-run
node skills/security/alert-triage/scripts/acknowledge-alert.js --related --agent <id> --timestamp <ts> --window 60 --yes

Increase --window for longer attack chains (e.g., 300 for 5 minutes). Report the exact count of acknowledged alerts from the tool output. Pass --yes to skip the confirmation prompt (required when called by an agent).

Step 5: Repeat
bash
node skills/security/alert-triage/scripts/fetch-next-alert.js

Tool reference

fetch-next-alert.js

Fetches the oldest unacknowledged Elastic Security alert.

bash
node skills/security/alert-triage/scripts/fetch-next-alert.js [--days <n>] [--json] [--full] [--verbose]
run-query.js

Runs KQL or ES|QL queries against Elasticsearch.

PowerShell warning: ES|QL queries contain pipe characters (|) which PowerShell interprets as shell pipes. ALWAYS use --query-file for ES|QL:

bash
# Write query to file, then run
node skills/security/alert-triage/scripts/run-query.js --query-file query.esql --type esql

KQL queries without pipes can be passed directly:

bash
node skills/security/alert-triage/scripts/run-query.js "agent.id:<id>" --index "logs-*" --days 7
ArgDescription
queryKQL query (positional)
--query-file, -qRead query from file (required for ES|QL on PowerShell)
--type, -tkql or esql (default: kql)
--index, -iIndex pattern (default: logs-*)
--size, -sMax results (default: 100)
--days, -dLimit to last N days
--jsonRaw JSON output
--fullFull document source
acknowledge-alert.js

Acknowledges alerts by updating workflow_status to acknowledged.

ModeCommand
Singlenode skills/security/alert-triage/scripts/acknowledge-alert.js <alert_id> --index <index> --yes
Relatednode skills/security/alert-triage/scripts/acknowledge-alert.js --related --agent <id> --timestamp <ts> [--window 60] --yes
By hostnode skills/security/alert-triage/scripts/acknowledge-alert.js --query --host <hostname> [--time-start <ts>] [--time-end <ts>] --yes
Querynode skills/security/alert-triage/scripts/acknowledge-alert.js --query --agent <id> [--time-start <ts>] [--time-end <ts>] --yes
Dry runAdd --dry-run to any mode (no confirmation needed)
ConfirmAll write modes prompt for confirmation; pass --yes to skip

Examples

  • "Fetch the next unacknowledged alert and triage it"
  • "Investigate alert ID abc-123 — gather context, classify, and create a case if malicious"
  • "Process the top 5 critical alerts from the last 24 hours"

Guidelines

  • Report only tool output — do not invent IDs, hostnames, IPs, or details not present in the tool response.
  • Preserve identifiers from the request — use exact values the user provides in tool calls and responses.
  • Confirm actions concisely using the tool's return data.
  • Distinguish facts from inference — label conclusions beyond tool output as your assessment.

Production use

  • All write operations (acknowledge-alert.js) prompt for confirmation. Pass --yes or -y to skip when called by an agent.
  • Use --dry-run before bulk acknowledgments to preview scope without modifying data.
  • The acknowledge script uses the Kibana Detection Engine API, which is compatible with both self-managed and Serverless deployments.
  • Verify environment variables point to the intended cluster before running any script — no undo for acknowledgments.

Environment variables

VariableRequiredDescription
ELASTICSEARCH_URLYesElasticsearch URL
ELASTICSEARCH_API_KEYYesElasticsearch API key
KIBANA_URLYesKibana URL (for case management)
KIBANA_API_KEYYesKibana API key (for case management)

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/security/alert-triage of elastic/agent-skills.

  • SKILL.md
  • references/classification-guide.md
  • scripts/acknowledge-alert.js
  • scripts/es-client.js
  • scripts/fetch-next-alert.js
  • scripts/kibana-client.js
  • scripts/run-query.js

Open the folder on GitHubat commit baa5111

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in elastic/agent-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Alert Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Alert Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Alert Triage this skillelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Chaitin CLIchaitin/chaitin-cli114—~15kAutomated safety check: NotesGPL-3.0
GatesNebulock-Inc/agentic-threat-hunting-framework388—~12kAutomated safety check: PassMIT
Elasticsearch Auditaspectrr/deer405—~1.7kAutomated safety check: PassMIT
Attack Flowwiz-sec-public/SITF182—~3.1kAutomated safety check: PassCustom licence

Similar skills

  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Chaitin CLI

    chaitin/chaitin-cli

    A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

    114 GitHub stars~15k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Gates

    Nebulock-Inc/agentic-threat-hunting-framework

    GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

    388 GitHub stars~12k tokensUpdated today
    SecurityAuto-check passed
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Attack Flow

    wiz-sec-public/SITF

    Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports.

    182 GitHub stars~3.1k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • DefectDojo Vulnerability Management

    AgentSecOps/SecOpsAgentKit

    Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

    220 GitHub stars~2.3k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from elastic/agent-skills

All 26 skills in this repo
  • Security Case Management

    elastic/agent-skills

    Official

    Create, search, update, and manage SOC cases via the Kibana Cases API.

    592 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Kibana Dashboards

    elastic/agent-skills

    Official

    Create and manage Kibana Dashboards and Lens visualizations.

    592 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Official

    Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

    592 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Official

    Create and manage Elastic ML anomaly detection jobs via the API.

    592 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Security Alert Triage

What does Security Alert Triage do?

Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge. Security Alert Triage is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

When should I use Security Alert Triage?

Security Alert Triage fits situations like: triaging alerts; performing SOC analysis; investigating detections.

How do I install Security Alert Triage in Claude Code?

Run `npx skills add elastic/agent-skills --skill security-alert-triage -a claude-code`. Or copy the skill folder (skills/security/alert-triage in elastic/agent-skills) into .claude/skills/security-alert-triage in your project. Claude Code loads it when a task matches its description.

How do I install Security Alert Triage in Codex?

Run `npx skills add elastic/agent-skills --skill security-alert-triage -a codex`. Or copy the skill folder (skills/security/alert-triage in elastic/agent-skills) into .agents/skills/security-alert-triage in your project. Codex loads it when a task matches its description.

Can I use Security Alert Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill security-alert-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-alert-triage, .gemini/skills/security-alert-triage, .github/skills/security-alert-triage and .opencode/skills/security-alert-triage in your project.

What does Security Alert Triage need to run?

Going by SKILL.md and its folder, Security Alert Triage needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and npm) and credentials named ELASTICSEARCH_API_KEY and KIBANA_API_KEY. Our summary lists: Node.js; A credential in ELASTICSEARCH_API_KEY; A credential in KIBANA_API_KEY. Compatibility (from SKILL.md): Requires Node.js 22+, network access to Elasticsearch. Environment variables: ELASTICSEARCH_URL or ELASTICSEARCH_CLOUD_ID, plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD. .

Does Security Alert Triage access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Alert Triage safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Alert Triage use?

Security Alert Triage is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Alert Triage use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Security Alert Triage?

Skills that share tags, products or a category with Security Alert Triage: Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Chaitin CLI (chaitin/chaitin-cli, 114 stars), Gates (Nebulock-Inc/agentic-threat-hunting-framework, 388 stars) and Elasticsearch Audit (aspectrr/deer, 405 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Alert Triage?

elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.