Performing False Positive Reduction In Siem
mukul975/Anthropic-Cybersecurity-Skills
Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.
Scan a release on VirusTotal. An agent skill from kdeldycke/dotfiles.
$ npx skills add kdeldycke/dotfiles --skill av-false-positive -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kdeldycke/dotfiles av-false-positive --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kdeldycke/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/dotfiles/.agents/skills/av-false-positive .claude/skills/av-false-positive && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "av-false-positive" agent skill from https://github.com/kdeldycke/dotfiles/tree/main/dotfiles/.agents/skills/av-false-positive into .claude/skills/av-false-positive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "av-false-positive", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kdeldycke/dotfiles/tree/main/dotfiles/.agents/skills/av-false-positiveType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kdeldycke/dotfiles --skill av-false-positive -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kdeldycke/dotfiles av-false-positive --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kdeldycke/dotfiles.git skills-src && mkdir -p .agents/skills && cp -r skills-src/dotfiles/.agents/skills/av-false-positive .agents/skills/av-false-positive && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "av-false-positive" agent skill from https://github.com/kdeldycke/dotfiles/tree/main/dotfiles/.agents/skills/av-false-positive into .agents/skills/av-false-positive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "av-false-positive", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kdeldycke/dotfiles --skill av-false-positive -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kdeldycke/dotfiles av-false-positive --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kdeldycke/dotfiles.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/dotfiles/.agents/skills/av-false-positive .cursor/skills/av-false-positive && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "av-false-positive" agent skill from https://github.com/kdeldycke/dotfiles/tree/main/dotfiles/.agents/skills/av-false-positive into .cursor/skills/av-false-positive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "av-false-positive", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kdeldycke/dotfiles.git --path dotfiles/.agents/skills/av-false-positive--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kdeldycke/dotfiles --skill av-false-positive -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kdeldycke/dotfiles av-false-positive --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kdeldycke/dotfiles.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/dotfiles/.agents/skills/av-false-positive .gemini/skills/av-false-positive && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "av-false-positive" agent skill from https://github.com/kdeldycke/dotfiles/tree/main/dotfiles/.agents/skills/av-false-positive into .gemini/skills/av-false-positive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "av-false-positive", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kdeldycke/dotfiles av-false-positiveInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kdeldycke/dotfiles --skill av-false-positive -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kdeldycke/dotfiles.git skills-src && mkdir -p .github/skills && cp -r skills-src/dotfiles/.agents/skills/av-false-positive .github/skills/av-false-positive && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "av-false-positive" agent skill from https://github.com/kdeldycke/dotfiles/tree/main/dotfiles/.agents/skills/av-false-positive into .github/skills/av-false-positive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "av-false-positive", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kdeldycke/dotfiles --skill av-false-positive -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kdeldycke/dotfiles av-false-positive --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kdeldycke/dotfiles.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/dotfiles/.agents/skills/av-false-positive .opencode/skills/av-false-positive && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "av-false-positive" agent skill from https://github.com/kdeldycke/dotfiles/tree/main/dotfiles/.agents/skills/av-false-positive into .opencode/skills/av-false-positive/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "av-false-positive", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
av-false-positiveScan a release on VirusTotal. An agent skill from kdeldycke/dotfiles.
Av False Positive is an agent skill from kdeldycke/dotfiles. Scan a release on VirusTotal. Write submission instructions for each AV vendor that flags a false positive.
Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code. Recommended model: Opus.
The repository describes itself as: 🍎 macOS dotfiles for Python developers. The licence is BSD-2-Clause.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 37173b9. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadWriteGrepGlobAgentFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
virustotal.comgithub.comAlso links to:
repomatic.netmicrosoft.combitdefender.comsupport.eset.comsymsubmit.symantec.comavast.comsupport.sophos.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
VIRUSTOTAL_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code. Recommended model: Opus.
From compatibility in the SKILL.md frontmatter.
Av False Positive loads about 4.7k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 2,018 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Write, Grep, Glob, AgentAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kdeldycke/dotfiles at commit 37173b9, republished under its BSD-2-Clause licence (© kdeldycke). 2,018 words, ~4,678 tokens.
.claude/skills/av-false-positive/SKILL.md (or your agent's skills folder).!gh repo view --json nameWithOwner --jq '.nameWithOwner' 2>/dev/null
!gh release view --json tagName --jq '.tagName' 2>/dev/null
!grep -m1 'license' pyproject.toml 2>/dev/null
!grep -m1 'name' pyproject.toml 2>/dev/null
!grep -A1 '\[project.urls\]' pyproject.toml 2>/dev/null | head -5
Scan release binaries on VirusTotal and generate per-vendor false-positive submission files for any flagged artifacts.
If $ARGUMENTS is empty, use the latest release tag from the context above. Otherwise treat $ARGUMENTS as the version (accept both 6.2.1 and v6.2.1; normalize to bare version for filenames, v-prefixed for tags).
Detect the repository from the context (nameWithOwner). Extract the project name, license, and homepage URL from pyproject.toml.
Start from the scan history when present: docs/assets/virustotal-scans.csv holds one at-release snapshot per binary (tag, filename, SHA-256, scan date, per-category verdict counts), written by the release pipeline's scan-virustotal job. It identifies the flagged binaries of the target release without any API call, and the catalog in docs/binaries.md shows the same data at a glance. That job publishes through one long-lived scan-virustotal pull request each release appends to, so the newest release's records reach the default branch only once someone merges it: read the branch copy (git show origin/scan-virustotal:docs/assets/virustotal-scans.csv) before concluding the history carries nothing for the version. Fall back to listing release assets when neither copy has records for it:
$ gh release view v{VERSION} --json assets --jq '.assets[].name'The release pipeline already uploaded every release binary at publication time, so a fresh upload is rarely needed. Per-engine detection details (which neither the CLI nor the scan history expose) always require querying the VT API directly via Python with the vt library. For a re-upload, use the scan-virustotal CLI command: it requires --tag and --binaries-dir, and --poll --records docs/assets/virustotal-scans.csv appends the fresh snapshot to the scan history (same-day re-scans replace their record; later dates accumulate, and the catalog keeps showing the earliest, at-release snapshot). Add --carry-from scan-virustotal, which restores the records still pending in that pull request before appending: without it the run writes a history missing every snapshot nobody has merged yet.
The VT API key comes from: $VIRUSTOTAL_API_KEY env var, or ask the user.
For each binary artifact (.bin, .exe):
gh release download.GET /api/v3/files/{sha256} to see if VT already has results.POST /api/v3/files.GET /api/v3/analyses/{id} until status == "completed".For each artifact, record:
https://www.virustotal.com/gui/file/{sha256}Also record the VT report URLs for the clean .whl and .tar.gz source distributions (used as evidence in every submission).
Print a markdown table:
| Artifact | Detections | VT report | Verdict |
|---|---|---|---|
filename | N/M | [link] | Clean / FP (engines) |
For each vendor in § Vendor definitions, check if any artifacts were flagged by that vendor's engine(s). If so, generate fp-submission-{vendor}.md at the project root.
Only generate a file for a vendor if at least one artifact was flagged by that vendor.
Each submission file must be optimized for copy-paste. The maintainer should be able to work through each submission without scrolling back or cross-referencing. Concretely:
## Submission N section with --- separators.All submission text blocks must derive project details from pyproject.toml and git metadata:
[project] name.[project] license.[project.urls].git config user.name or [project] authors.User-facing documentation of vendor portals, submission priority, and common issues is in docs/security.md § AV false-positive submissions.
Microsoft)## Submission N section per flagged binary.category == "malicious". Windows ARM64 binaries are typically not flagged by Microsoft (only by MaxSecure), so check before including.Wacatac variants): include them if detected.| Field | Value |
|---|---|
| Microsoft security product used to scan the file | Microsoft Defender Antivirus (Windows 10) or (Windows 11) |
| Company Name | Maintainer name from project metadata |
| Do you have a Microsoft support case number? | No |
| Select the file | Upload the exact filename |
| Should this file be removed from our database at a certain date? | No |
| What do you believe this file is? | Incorrectly detected as malware/malicious |
| Detection name | Exact detection name for this binary |
| Definition version | (leave blank) |
| Additional information | Paste the text below |
.whl and .tar.gz VT links, GitHub release link, project URL, PyPI URL, license, previous FP reference if found.microsoft.com and wdsiprod.westus.cloudapp.azure.com, sign back in, submit immediately. Also check the URL doesn't have a duplicated ?persona=SoftwareDeveloper&persona=SoftwareDeveloper parameter.BitDefender, ALYac, Arcabit, Emsisoft, GData, MicroWorld-eScan, VIPRE)BitDefender engine itself (not downstream).| Field | Value |
|---|---|
| Select the category | False Positive |
| Full Name | Maintainer name from project metadata |
| (user's email) | |
| Sample type | File |
| Attach a file | Upload the exact filename |
| Detection name | Exact detection name |
| Description | Paste the pre-written text |
| Sensitive files / Screenshot | Screenshot of the VT report page showing the BitDefender detection |
## Submission N section per binary.ESET-NOD32)samples@eset.cominfected).False positive: {detection_name} in {Project Name} {VERSION}Symantec).exe or .bin file uploads. The file upload field only accepts images, logs, and text files (for supporting evidence). Use hash submission instead.Binary 1:, Binary 2:) so the text remains readable even when flattened.Product Details:
| Field | Value |
|---|---|
| Which product were you using? | Symantec Endpoint Protection 16.x (avoid "Don't know": it maps to UNKNOWN in their tracking system) |
| When did the detection occur? | When downloading or uploading a file |
| Which type of detection? | Download/File Insight (Reputation Based Detection) (best match for ML.Attribute.* detections; avoid "Don't know") |
| Detection Name | Exact detection name |
Submission Details:
| Field | Value |
|---|---|
| Submission Type | Provide an MD5 or SHA-256 hash of a file |
| File Hash | SHA256 of first binary |
Additional Information (expand the collapsed section):
| Field | Value |
|---|---|
| Recurring False Positive? | Yes |
| Business Impact? | Medium |
| Application Type? | Third Party Application |
Then paste the description text listing all binaries with SHA256, VT links, clean source VT links, and GitHub release link.
Your Details:
| Field | Value |
|---|---|
| Contact Name | Maintainer name from project metadata |
| Email Address | (user's email) |
| Site ID Number | (leave blank) |
Avast, AVG)## Submission N section per binary with all details inline.Sophos)| Field | Value |
|---|---|
| First Name | Maintainer first name |
| Last Name | Maintainer last name |
| Country | (user's country) |
| Email Address | (user's email) |
| About You | Using a free product |
| Operating System | Windows |
| Why do you want to send this sample? | Paste the pre-written text |
| File | Upload the exact filename |
## Submission N section per binary.Every binary entry in every submission file must include:
https://www.virustotal.com/gui/file/{sha256}).whl and .tar.gz (as comparison evidence)https://github.com/{owner/repo}/releases/tag/v{VERSION})https://github.com/{owner/repo}/releases/download/v{VERSION}/{filename})Pre-written text blocks must mention: Nuitka --onefile compilation, open-source project, GitHub and PyPI URLs, license from pyproject.toml, and the previous FP issue reference if one was found in the repo's GitHub issues.
Sabsik, Wacatac) are the most impactful to fix.Download all artifacts that appear in any submission file to $TMPDIR using gh release download with --pattern flags. These are needed for manual upload to vendor portals.
Print a summary of what was generated:
fp-submission-*.md files were created (and which vendors were skipped because they had no detections)Suggest a follow-up for after the vendors process the reports: re-running scan-virustotal --tag v{VERSION} --binaries-dir {dir} --poll --records docs/assets/virustotal-scans.csv --carry-from scan-virustotal appends the post-submission snapshot to the scan history, keeping the delisting trajectory on record without altering the at-release numbers shown in docs/binaries.md.
© kdeldycke, BSD-2-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in dotfiles/.agents/skills/av-false-positive of kdeldycke/dotfiles.
Open the folder on GitHubat commit 37173b9
Av False Positive next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Av False Positive this skillkdeldycke/dotfiles | 173 | — | ~4.7k | Automated safety check: Notes | BSD-2-Clause | |
| Performing False Positive Reduction In Siemmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| False Positive Reviewerconorbronsdon/avoid-ai-writing | 4.9k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Scanwshobson/agents | 40k | — | ~2.2k | Automated safety check: Pass | MIT | |
| Repo Scanaffaan-m/ECC | 276k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Repo Scanaffaan-m/ECC | 276k | — | ~1.3k | Automated safety check: Pass | MIT |
mukul975/Anthropic-Cybersecurity-Skills
Reduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment.
conorbronsdon/avoid-ai-writing
A skill your agent uses when a user asks what AI-writing flags mean, whether detector output proves AI authorship, or wants a careful interpretation of possible false positives, especially for…
wshobson/agents
Scans the codebase to generate project-doc.md and AGENTS.md.
affaan-m/ECC
固定されレビュー可能なコミットから外部の repo-scan スキルをインストールするブートストラップ用ポインター。クロススタックのソースコード資産監査を実行する前に repo-scan のインストールが必要な場合に使用する。この ECC ポインター自体は監査を実行しない。
affaan-m/ECC
用于从固定且可审查的提交安装外部 repo-scan 技能的引导指针。在运行跨栈源代码资产审计前需要安装 repo-scan 时使用;此 ECC 指针本身不执行审计。
sickn33/agentic-awesome-skills
Scan systems and dependencies for CVEs and security vulnerabilities.
kdeldycke/dotfiles
Audit and tune the configuration of coding agents across Claude Code and pi - settings files (settings.json, settings.local.json), permission rules, instruction files (CLAUDE.md, AGENTS.md), skill…
kdeldycke/dotfiles
Analyze a GitHub repository's issues and PRs to find unaddressed feature requests, dismissed ideas, maintenance signals, and opportunities relevant to the current project.
kdeldycke/dotfiles
Create project logo and banner SVGs, then export them to light and dark PNG variants.
kdeldycke/dotfiles
Fill a web form using data extracted from local documents (PDFs, images, spreadsheets).
kdeldycke/dotfiles
Rename documents and files (PDFs, images, screenshots, etc.) by reading their content to extract the effective/publication date, then renaming them with a "YYYY-MM-DD - Clear descriptive title.ext"…
kdeldycke/dotfiles
Choose what a repository's CI test matrix covers. An agent skill from kdeldycke/dotfiles.
Scan a release on VirusTotal. An agent skill from kdeldycke/dotfiles. Av False Positive is an agent skill from kdeldycke/dotfiles. Scan a release on VirusTotal.
Run `npx skills add kdeldycke/dotfiles --skill av-false-positive -a claude-code`. Or copy the skill folder (dotfiles/.agents/skills/av-false-positive in kdeldycke/dotfiles) into .claude/skills/av-false-positive in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kdeldycke/dotfiles --skill av-false-positive -a codex`. Or copy the skill folder (dotfiles/.agents/skills/av-false-positive in kdeldycke/dotfiles) into .agents/skills/av-false-positive in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kdeldycke/dotfiles --skill av-false-positive -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/av-false-positive, .gemini/skills/av-false-positive, .github/skills/av-false-positive and .opencode/skills/av-false-positive in your project.
Going by SKILL.md and its folder, Av False Positive needs the command-line tools its instructions call (gh and git) and credentials named VIRUSTOTAL_API_KEY. Our summary lists: Python 3; A credential in VIRUSTOTAL_API_KEY. Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, Agent. Compatibility (from SKILL.md): Designed for Claude Code. Recommended model: Opus..
SKILL.md names 9 domains. In commands or code: virustotal.com and github.com; the agent is likely to contact these when it follows the instructions. As links in the text: repomatic.net, microsoft.com, bitdefender.com, support.eset.com, symsubmit.symantec.com, avast.com and support.sophos.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Av False Positive is published under the BSD-2-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Av False Positive: Performing False Positive Reduction In Siem (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), False Positive Reviewer (conorbronsdon/avoid-ai-writing, 4.9k stars), Scan (wshobson/agents, 40k stars) and Repo Scan (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kdeldycke (a GitHub user) maintains it in kdeldycke/dotfiles, which has 173 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on October 9, 2026.
Source: kdeldycke/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.