Configuring Windows Event Logging For Detection
mukul975/Anthropic-Cybersecurity-Skills
Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation.
Generate time-windowed product pulse reports from configured signals.
$ npx skills add EveryInc/compound-engineering-plugin --skill ce-product-pulse -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install EveryInc/compound-engineering-plugin ce-product-pulse --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/EveryInc/compound-engineering-plugin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ce-product-pulse .claude/skills/ce-product-pulse && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ce-product-pulse" agent skill from https://github.com/EveryInc/compound-engineering-plugin/tree/main/skills/ce-product-pulse into .claude/skills/ce-product-pulse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ce-product-pulse", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/EveryInc/compound-engineering-plugin/tree/main/skills/ce-product-pulseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add EveryInc/compound-engineering-plugin --skill ce-product-pulse -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install EveryInc/compound-engineering-plugin ce-product-pulse --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EveryInc/compound-engineering-plugin.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/ce-product-pulse .agents/skills/ce-product-pulse && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ce-product-pulse" agent skill from https://github.com/EveryInc/compound-engineering-plugin/tree/main/skills/ce-product-pulse into .agents/skills/ce-product-pulse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ce-product-pulse", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add EveryInc/compound-engineering-plugin --skill ce-product-pulse -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install EveryInc/compound-engineering-plugin ce-product-pulse --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EveryInc/compound-engineering-plugin.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/ce-product-pulse .cursor/skills/ce-product-pulse && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ce-product-pulse" agent skill from https://github.com/EveryInc/compound-engineering-plugin/tree/main/skills/ce-product-pulse into .cursor/skills/ce-product-pulse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ce-product-pulse", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/EveryInc/compound-engineering-plugin.git --path skills/ce-product-pulse--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add EveryInc/compound-engineering-plugin --skill ce-product-pulse -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install EveryInc/compound-engineering-plugin ce-product-pulse --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EveryInc/compound-engineering-plugin.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/ce-product-pulse .gemini/skills/ce-product-pulse && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ce-product-pulse" agent skill from https://github.com/EveryInc/compound-engineering-plugin/tree/main/skills/ce-product-pulse into .gemini/skills/ce-product-pulse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ce-product-pulse", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install EveryInc/compound-engineering-plugin ce-product-pulseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add EveryInc/compound-engineering-plugin --skill ce-product-pulse -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/EveryInc/compound-engineering-plugin.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/ce-product-pulse .github/skills/ce-product-pulse && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ce-product-pulse" agent skill from https://github.com/EveryInc/compound-engineering-plugin/tree/main/skills/ce-product-pulse into .github/skills/ce-product-pulse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ce-product-pulse", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add EveryInc/compound-engineering-plugin --skill ce-product-pulse -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install EveryInc/compound-engineering-plugin ce-product-pulse --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EveryInc/compound-engineering-plugin.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/ce-product-pulse .opencode/skills/ce-product-pulse && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ce-product-pulse" agent skill from https://github.com/EveryInc/compound-engineering-plugin/tree/main/skills/ce-product-pulse into .opencode/skills/ce-product-pulse/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ce-product-pulse", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ce-product-pulseGenerate time-windowed product pulse reports from configured signals.
Ce Product Pulse is an agent skill from EveryInc/compound-engineering-plugin. Generate time-windowed product pulse reports from configured signals.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `agents/openai.yaml`, `references/config.md` and `references/interview.md`).
The repository describes itself as: Official Compound Engineering plugin for Claude Code, Codex, Cursor, and more. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 67035e9. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteGlobGrepBashAskUserQuestionFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ce Product Pulse loads about 1.9k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 22 tokens; SKILL.md has 1,104 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Write, Glob, Grep, Bash, AskUserQuestionAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from EveryInc/compound-engineering-plugin at commit 67035e9, republished under its MIT licence (© EveryInc). 1,104 words, ~1,942 tokens.
.claude/skills/ce-product-pulse/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.ce-product-pulse queries the product's data sources for a given time window and produces a compact, single-page report covering usage, performance, errors, and followups. The report is saved to <root>/pulse-reports/ and the key points are shown in chat.
Done: a report of 30-40 lines exists at <root>/pulse-reports/YYYY-MM-DD_HH-MM.md, its headlines and top followup are in chat, and Phase 3 (Scheduling) has been reached.
.compound-engineering/config.local.yaml (interview and opt-out writes stay on the local override) and the report file. MCP and other data-source tools are invoked read-only; if a tool offers write modes, do not use them. A database source must be a read-only connection — the interview refuses read-write credentials, and DB access is optional, since many products complete the pulse with analytics and tracing alone.Default to the host's blocking question tool already in the current tool list (match by capability, not by a host-specific name). Presence in the current tool list is proof the tool exists; never call a user-facing question tool to discover whether it exists. If a matching tool is listed but unloaded, use the host's tool-discovery primitive to load that capability — do not search for another host's tool name. Fall back to numbered options on the host's user-visible chat surface only when no such tool is in the list or a real question call errors. Never silently skip the question.
Ask one question at a time. Reserve multi-select for first-run configuration only.
The lookback window is the time range this skill was invoked with (e.g. 24h, 7d) — present in the current prompt or conversation, whether the user gave it directly or a calling skill passed it. Common forms are trailing hours (24h, 48h, 72h), trailing days (7d, 30d), and 1h for launches.
If the argument is empty, default to pulse_lookback_default from config (resolved in Phase 0, Route by config state); if that is also unset, fall through to the hard default of 24h. If the argument is unparseable, ask the user to clarify.
Apply a 15-minute trailing buffer to the window's upper bound. Many analytics and tracing tools have ingestion lag; querying right up to now under-reports the most recent events. For a 24h window, query [now - 24h - 15m, now - 15m].
This skill writes pulse reports under <root>/pulse-reports/. Resolve <root> when you first compose a <root>/ path (per the block below), never before you need it. A write to <root>/... and a read of <root>/solutions/ both count as composing a <root>/ path, so either one triggers resolution; only a run that touches no <root>/ path at all -- a scratch-only or no-repo flow -- skips it.
<!-- ce-docs-root:start -->
Resolve the CE artifact root <root> before composing any artifact path.
docs_root from <repo-root>/.compound-engineering/config.yaml only (<repo-root> = git rev-parse --show-toplevel). Do not read it from config.local.yaml. Unset -> <root> is docs, exactly as before..git/. Otherwise stop with an error naming docs_root and the value -- never fall back to docs.<root> as the sole artifact location: create it if absent, compose each path as <root>/<subdir> with this skill's own subdirectory, and never also read docs.<!-- ce-docs-root:end -->
<!-- ce-config-layers:start -->
Resolve ordinary CE yaml keys from the two repo files.
<repo-root>/.compound-engineering/config.local.yaml, then config.yaml (<repo-root> = git rev-parse --show-toplevel). Missing files are skipped. Gitignore does not change resolution.docs_root — that key is config.yaml only.<!-- ce-config-layers:end -->
Resolve <repo-root> with git rev-parse --show-toplevel, then apply the ordinary-key rule above to the pulse_* keys. Read references/config.md whenever a pulse_* value has to be interpreted — it is the key schema and nothing else: each key, its allowed values, and its default, with an unset or invalid value taking the documented default rather than being guessed.
Routing: every run passes through Phase 2 (Run the pulse) and then Phase 3 (Scheduling). Run Phase 1 (First-run interview) first when pulse_product_name is unset after cascade (the ordinary-key rule above), when the repo root cannot be resolved, or when the argument was setup, reconfigure, or edit config. Otherwise start at Phase 2 (Run the pulse).
Read references/setup.md first; this read is required. It defines the strategy-doc seeding, the interview order and its pushback bar, the read-write database refusal, how the config is written to config.local.yaml without disturbing other keys, and the one-time scheduling offer. The questions themselves come from references/interview.md, which that file names as its own required read.
If Phase 1 (First-run interview) ran, re-apply the ordinary-key rule (local then tracked) from the repo root using the native file-read tool before any query, to pick up edits accepted during the Phase 1 review step. Otherwise use the pulse_* values already extracted in Phase 0 (Route by config state), applying the defaults in references/config.md for anything unset.
Then read references/run.md before dispatching any query; this read is required. It defines which queries run in parallel and which run serially, the pulse_db_enabled check that decides whether database work runs, the optional quality sampling and its scoring discipline, the four report sections, and where the report is written.
Setup offers a recurring run once (references/setup.md). On later runs, mention it again lightly: if the argument was a schedule keyword (daily, hourly, weekly), say this run is ad-hoc and point at the harness's scheduling primitive; if no schedule is on file and this is the third or later run, mention once that scheduling is available. Do not nag on every run, and never schedule automatically — any handoff to a scheduling primitive requires explicit confirmation.
© EveryInc, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in skills/ce-product-pulse of EveryInc/compound-engineering-plugin.
Open the folder on GitHubat commit 67035e9
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in EveryInc/compound-engineering-plugin, which our catalogue first saw on October 7, 2026.
Ce Product Pulse next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ce Product Pulse this skillEveryInc/compound-engineering-plugin | 25k | 1 repos | ~1.9k | Automated safety check: Notes | MIT | |
| Configuring Windows Event Logging For Detectionmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| Pulsealirezarezvani/claude-skills | 28k | — | ~3.8k | Automated safety check: Pass | MIT | |
| Configuring Windows Defender Advanced Settingsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Configure Channelopenclaw/openclaw | 392k | — | ~946 | Automated safety check: Pass | MIT | |
| Windows Desktop E2Eaffaan-m/ECC | 276k | 1 repos | ~7.6k | Automated safety check: Pass | MIT |
mukul975/Anthropic-Cybersecurity-Skills
Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for threat detection and forensic investigation.
alirezarezvani/claude-skills
Multi-source recency research skill that takes the pulse of any topic across Reddit, Hacker News, the open web, and optionally X/Twitter within a configurable recent window (default 30 days).
mukul975/Anthropic-Cybersecurity-Skills
Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection.
openclaw/openclaw
Configure and prove a chat channel with non-interactive one-liners; secrets only as SecretRefs.
affaan-m/ECC
E2E testing for Windows native desktop apps (WPF, WinForms, Win32/MFC, Qt) using pywinauto and Windows UI Automation.
affaan-m/ECC
E2E testing for Windows native desktop apps (WPF, WinForms, Win32/MFC, Qt) using pywinauto and Windows UI Automation.
EveryInc/compound-engineering-plugin
Records one solved and verified problem as a durable learning in the repository, but only when the reasoning is not already clear from the final code, tests or docs.
EveryInc/compound-engineering-plugin
Audits a repo's stored learnings against the current codebase, fixes stale, overlapping or superseded docs and reports on every document.
EveryInc/compound-engineering-plugin
Builds a throwaway prototype at just the fidelity needed to settle a specific how-it-should-work-or-feel question, before committing to an approach other work will treat as fixed.
EveryInc/compound-engineering-plugin
Checks Compound Engineering plugin health and repo-local config, or scaffolds a Compound Pack when you ask for one by id.
EveryInc/compound-engineering-plugin
Watches an open GitHub pull request over time, routing review comments and CI failures to other skills until the PR is ready to merge.
EveryInc/compound-engineering-plugin
Turns a vague or ambitious feature idea into a requirements-only plan through dialogue with you, sized to the work, before any code is written.
Generate time-windowed product pulse reports from configured signals. Ce Product Pulse is an agent skill from EveryInc/compound-engineering-plugin. Generate time-windowed product pulse reports from configured signals.
Run `npx skills add EveryInc/compound-engineering-plugin --skill ce-product-pulse -a claude-code`. Or copy the skill folder (skills/ce-product-pulse in EveryInc/compound-engineering-plugin) into .claude/skills/ce-product-pulse in your project. Claude Code loads it when a task matches its description.
Run `npx skills add EveryInc/compound-engineering-plugin --skill ce-product-pulse -a codex`. Or copy the skill folder (skills/ce-product-pulse in EveryInc/compound-engineering-plugin) into .agents/skills/ce-product-pulse in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EveryInc/compound-engineering-plugin --skill ce-product-pulse -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ce-product-pulse, .gemini/skills/ce-product-pulse, .github/skills/ce-product-pulse and .opencode/skills/ce-product-pulse in your project.
Going by SKILL.md and its folder, Ce Product Pulse needs the command-line tools its instructions call (git). Its frontmatter pre-approves these tools: Read, Write, Glob, Grep, Bash, AskUserQuestion.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Ce Product Pulse is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Ce Product Pulse: Configuring Windows Event Logging For Detection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Pulse (alirezarezvani/claude-skills, 28k stars), Configuring Windows Defender Advanced Settings (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Configure Channel (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
EveryInc (a GitHub organization) maintains it in EveryInc/compound-engineering-plugin, which has 25,447 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on October 8, 2026.
Source: EveryInc/compound-engineering-plugin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.