Agent skill

Tianmu Analyzer

by infometa in infometa/workbuddyskills

天幕 (安全治理) 阻断日志 L1 分析 skill 消费 L0 适配层 (soc-alert-pipeline) 输出的 parsed 字段, 基于天幕阻断日志的聚合统计, 产出: - 阻断概览 (总阻断次数 / 规则数 / 源IP数 / 目标IP数) - TOP 阻断规则排名 - 攻击者画像 (高频源IP / 多规则命中 / 多目标攻击) - 被攻击目标排名 - 误报识别 (黑名单 vs…

No licenceAuto-check passedDocuments & Office

Install Tianmu Analyzer

skills CLI
$ npx skills add infometa/workbuddyskills --skill tianmu-analyzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install infometa/workbuddyskills tianmu-analyzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/infometa/workbuddyskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/experts/soe/skills/soe/references/alert-analysis/tianmu-analyzer .claude/skills/tianmu-analyzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tianmu-analyzer
GitHub stars
348
Token cost
~670 tokens
SKILL.md length
102 words
Files
3 (incl. scripts, references)
Skills in repo
218
Repo updated
First seen
Licence
None found

At a glance

天幕 (安全治理) 阻断日志 L1 分析 skill 消费 L0 适配层 (soc-alert-pipeline) 输出的 parsed 字段, 基于天幕阻断日志的聚合统计, 产出: - 阻断概览 (总阻断次数 / 规则数 / 源IP数 / 目标IP数) - TOP 阻断规则排名 - 攻击者画像 (高频源IP / 多规则命中 / 多目标攻击) - 被攻击目标排名 - 误报识别 (黑名单 vs…

  • Tasks that involve Excel spreadsheets
  • SKILL.md covers 一、定位, 二、天幕数据特点, 三、分析维度 and 四、快速开始, plus 2 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Tianmu Analyzer is an agent skill from infometa/workbuddyskills. 天幕 (安全治理) 阻断日志 L1 分析 skill 消费 L0 适配层 (soc-alert-pipeline) 输出的 parsed 字段, 基于天幕阻断日志的聚合统计, 产出: - 阻断概览 (总阻断次数 / 规则数 / 源IP数 / 目标IP数) - TOP 阻断规则排名 - 攻击者画像 (高频源IP / 多规则命中 / 多目标攻击) - 被攻击目标排名 - 误报识别 (黑名单 vs 规则类) - 处置建议 (加黑 / 放行 / 调规则) - L2 关联建议 (天幕阻断 ↔ 御界检测 ↔ 主机安全) 适用场景: - 天幕安全治理阻断日志的批量分析 - 攻击者画像与高频阻断源识别 - 阻断规则效果评估与误报筛查 不适用: - 天幕 xlsx 解析 (用 soc-alert-pipeline L0) - 跨产品关联 (用 L2, 消费本 skill 的 correlation 输出)

Its SKILL.md is about 670 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/tianmu-rules.md` and `scripts/l1_tianmu_analyze.py`).

It sits in Documents & Office, covering Excel spreadsheets. It works with Microsoft Excel. The repository describes itself as: WorkBuddy skills / connectors / experts archive for offline study.

When your agent uses it

  • Tasks that involve Excel spreadsheets

Example prompts

  • “/tianmu-analyzer”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 91b77ea. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tianmu Analyzer loads about 670 tokens when it runs, and up to ~1.1k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 102 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~670
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 102 words (~670 tokens).

“这是 L1 产品分析 skill, 在 L0 适配层之上:”

— opening of SKILL.md by infometa
name
tianmu-analyzer
version
1.0.0
triggers
天幕, 安全治理, 阻断日志, NDR阻断

Read the full SKILL.md on GitHub

Files

SKILL.md and 2 other files (scripts, references) in experts/soe/skills/soe/references/alert-analysis/tianmu-analyzer of infometa/workbuddyskills.

  • SKILL.md
  • references/tianmu-rules.md
  • scripts/l1_tianmu_analyze.py

Open the folder on GitHubat commit 91b77ea

Compare with similar skills

Tianmu Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tianmu Analyzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tianmu Analyzer this skillinfometa/workbuddyskills348—~670Automated safety check: PassNone
MarkitdownImCa0/just-laws78114 repos~3.2kAutomated safety check: NotesMIT
Data Table Managern8n-io/n8n207k—~2.3kAutomated safety check: PassCustom licence
Docx4jplutext/docx4j2.4k—~2.5kAutomated safety check: PassNone
Instrument Data To Allotropeaws-samples/amazon-bedrock-agents-healthcare-lifesciences2742 repos~2.7kAutomated safety check: PassApache-2.0
Cyber Pptcrazyykhllc-bit/CyberPPT1.8k—~10kAutomated safety check: PassMIT

Similar skills

  • Markitdown

    ImCa0/just-laws

    Convert files and office documents to Markdown. An agent skill from ImCa0/just-laws.

    781 GitHub starsUsed in 14 repos~3.2k tokens
    Documents & OfficeAuto-check: notes
  • Official

    Load before calling data-tables or parse-file. An agent skill from n8n-io/n8n.

    207k GitHub stars~2.3k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Docx4j

    plutext/docx4j

    A skill your agent uses when writing Java code that creates, reads or edits Word (.docx), PowerPoint (.pptx) or Excel (.xlsx) files with docx4j — including generating documents, editing existing…

    2.4k GitHub stars~2.5k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Instrument Data To Allotrope

    aws-samples/amazon-bedrock-agents-healthcare-lifesciences

    Official

    Convert laboratory instrument output files (PDF, CSV, Excel, TXT) to Allotrope Simple Model (ASM) JSON format or flattened 2D CSV.

    274 GitHub starsUsed in 2 repos~2.7k tokens
    Documents & OfficeAuto-check passed
  • Cyber Ppt

    crazyykhllc-bit/CyberPPT

    当用户需要把 DOCX、PDF、TXT、XLSX、研究报告、业务材料或原始数据转成高密度、可编辑、咨询风格 PPTX 时使用;也适用于需要 SCR 论证、视觉风格探索、详细图表和渲染质检的 PPT。

    1.8k GitHub stars~10k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check passed
  • Jev SEO

    AgriciDaniel/jev-seo

    Full live SEO audit of any website from its homepage URL, powered by Jev (TypeSafe's System One model).

    543 GitHub stars~2.5k tokensUpdated 19 days ago
    Documents & OfficeAuto-check: notes

More from infometa/workbuddyskills

All 218 skills in this repo
  • Campus Event Playbook

    infometa/workbuddyskills

    This skill should be used when planning, coordinating, running, or reviewing student-led campus events, including club recruitment, freshman mixers, welcome activities, small talks, competitions…

    348 GitHub stars~861 tokensUpdated yesterday
    Auto-check passed
  • Teachany

    infometa/workbuddyskills

    K-12 interactive courseware creation. An agent skill from infometa/workbuddyskills.

    348 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check: notes
  • Weight Management HTML

    infometa/workbuddyskills

    A skill your agent uses when the adult weight-management MCP needs to be installed/set up in WorkBuddy (connector) or its result must be rendered as a standalone Chinese HTML plan.

    348 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Agent Browser

    infometa/workbuddyskills

    A skill your agent uses when the user needs browser automation, including opening web pages, taking screenshots, extracting page content, clicking elements, filling forms, or testing web flows.

    348 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • AI Research Radar

    infometa/workbuddyskills

    定时任务:每日研究简报。漏掉重要论文和行业报告?每天帮你盯着,关键信息一条不漏 This skill should be used when the user asks about 定时任务:每日研究简报.

    348 GitHub stars~438 tokensUpdated yesterday
    Auto-check passed
  • Check Deck

    infometa/workbuddyskills

    Investment banking presentation quality checker. An agent skill from infometa/workbuddyskills.

    348 GitHub stars~687 tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Tianmu Analyzer

What does Tianmu Analyzer do?

天幕 (安全治理) 阻断日志 L1 分析 skill 消费 L0 适配层 (soc-alert-pipeline) 输出的 parsed 字段, 基于天幕阻断日志的聚合统计, 产出: - 阻断概览 (总阻断次数 / 规则数 / 源IP数 / 目标IP数) - TOP 阻断规则排名 - 攻击者画像 (高频源IP / 多规则命中 / 多目标攻击) - 被攻击目标排名 - 误报识别 (黑名单 vs…. Tianmu Analyzer is an agent skill from infometa/workbuddyskills.

When should I use Tianmu Analyzer?

Tianmu Analyzer fits situations like: tasks that involve Excel spreadsheets.

How do I install Tianmu Analyzer in Claude Code?

Run `npx skills add infometa/workbuddyskills --skill tianmu-analyzer -a claude-code`. Or copy the skill folder (experts/soe/skills/soe/references/alert-analysis/tianmu-analyzer in infometa/workbuddyskills) into .claude/skills/tianmu-analyzer in your project. Claude Code loads it when a task matches its description.

How do I install Tianmu Analyzer in Codex?

Run `npx skills add infometa/workbuddyskills --skill tianmu-analyzer -a codex`. Or copy the skill folder (experts/soe/skills/soe/references/alert-analysis/tianmu-analyzer in infometa/workbuddyskills) into .agents/skills/tianmu-analyzer in your project. Codex loads it when a task matches its description.

Can I use Tianmu Analyzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add infometa/workbuddyskills --skill tianmu-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tianmu-analyzer, .gemini/skills/tianmu-analyzer, .github/skills/tianmu-analyzer and .opencode/skills/tianmu-analyzer in your project.

What does Tianmu Analyzer need to run?

Going by SKILL.md and its folder, Tianmu Analyzer needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Tianmu Analyzer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Tianmu Analyzer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Tianmu Analyzer use?

No licence was found for Tianmu Analyzer or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Tianmu Analyzer use?

About 670 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 461 tokens, read only when the agent opens those files.

What are the alternatives to Tianmu Analyzer?

Skills that share tags, products or a category with Tianmu Analyzer: Markitdown (ImCa0/just-laws, 781 stars), Data Table Manager (n8n-io/n8n, 207k stars), Docx4j (plutext/docx4j, 2.4k stars) and Instrument Data To Allotrope (aws-samples/amazon-bedrock-agents-healthcare-lifesciences, 274 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tianmu Analyzer?

infometa (a GitHub user) maintains it in infometa/workbuddyskills, which has 348 GitHub stars. The repository holds 218 skills in this directory. The repository was last updated on October 9, 2026.

Source: infometa/workbuddyskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.