Agent skill

Ransomware First Response

by mohitagw15856 in mohitagw15856/pm-claude-skills

Handle the first hour of a suspected ransomware or malware infection calmly and correctly — contain it, preserve options, and avoid the moves that make it worse.

MITAuto-check passedDevOps & Cloud

Install Ransomware First Response

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill ransomware-first-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills ransomware-first-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ransomware-first-response .claude/skills/ransomware-first-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ransomware-first-response
GitHub stars
1.4k
Token cost
~1.3k tokens
SKILL.md length
600 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Handle the first hour of a suspected ransomware or malware infection calmly and correctly — contain it, preserve options, and avoid the moves that make it worse.

  • Works in 6 steps: Isolate now. Disconnect the device from… → Don't destroy your options. Don't wipe,… → Recover from clean backups. The best… → …
  • Asked what to do about ransomware
  • SKILL.md covers What This Skill Produces, Required Inputs, Framework: Isolate, Preserve,… and Output Format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ransomware First Response is an agent skill from mohitagw15856/pm-claude-skills. Handle the first hour of a suspected ransomware or malware infection calmly and correctly — contain it, preserve options, and avoid the moves that make it worse. Use when asked what to do about ransomware, my files are encrypted with a ransom note, I think I have malware, or my computer's been hacked. Produces an immediate containment checklist, a preserve-evidence-and-options step, a recovery path (backups, known decryptors, professional help), guidance on the ransom-payment decision, and reporting steps — for…

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Backup and disaster recovery and Incident response. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked what to do about ransomware
  • My files are encrypted with a ransom note
  • I think I have malware
  • My computers been hacked

Example prompts

  • “/ransomware-first-response”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Isolate now. Disconnect the device from Wi-Fi/network and unplug shared/external drives to stop encryption from spreading — but don't…
  2. Don't destroy your options. Don't wipe, don't reformat yet, and don't pay on impulse. Photograph the ransom note and record what/when you…
  3. Recover from clean backups. The best outcome is wiping and restoring from a known-good offline backup — verify it wasn't connected during…
  4. Check for legitimate decryptors. Some ransomware strains have free, reputable decryptors via official security projects — check before…
  5. Weigh payment honestly. Paying is risky: no guarantee of recovery, it funds criminals, and it flags you. Treat it as a last resort…
  6. Report and, if serious, get help. Notify the relevant authorities; for a business or sensitive-data incident, engage professional incident…

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ransomware First Response loads about 1.3k tokens when it runs. Until then it costs about 155 tokens; SKILL.md has 600 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~155
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 600 words, ~1,286 tokens.

Download SKILL.mdSave it as .claude/skills/ransomware-first-response/SKILL.md (or your agent's skills folder).
name
ransomware-first-response
description
Handle the first hour of a suspected ransomware or malware infection calmly and correctly — contain it, preserve options, and avoid the moves that make it worse. Use when asked what to do about ransomware, my files are encrypted with a ransom note, I think I have malware, or my computer's been hacked. Produces an immediate containment checklist, a preserve-evidence-and-options step, a recovery path (backups, known decryptors, professional help), guidance on the ransom-payment decision, and reporting steps — for personal/small-setup use, not a substitute for professional incident response.

Ransomware First Response

The first hour decides how bad a ransomware or malware incident gets. Panic leads to the wrong moves — paying immediately, wiping evidence, or reconnecting an infected machine and spreading it. This gives a calm, correct sequence: isolate, preserve your options, and recover from the safest source — while being honest that a serious business incident needs professional responders.

What This Skill Produces

  • Immediate containment — disconnect from networks and shared drives to stop spread, without destroying recovery options
  • Preserve evidence & options — don't wipe or pay reflexively; photograph the ransom note, note timing, keep the door open
  • The recovery path — restore from clean offline backups, check for a known/legitimate decryptor, or engage a professional
  • The payment decision — the honest tradeoffs and risks of paying (no guarantee, funds crime, marks you as payer)
  • Reporting — the authorities/agencies to notify, and (for orgs) any breach-notification duties
  • A scope flag — personal/small setup vs. a business incident that needs real incident-response help

Required Inputs

Ask for these if not provided:

  • What you're seeing — ransom note, encrypted/renamed files, pop-ups, or just suspicious behavior
  • The setup — personal device, home network, or a business/multi-device environment
  • Backups — do you have recent offline/cloud backups, and are they disconnected
  • Spread — is it one device or possibly shared drives/other machines
  • Sensitivity — is sensitive/regulated data involved

Framework: Isolate, Preserve, Recover — Don't Panic

  1. Isolate now. Disconnect the device from Wi-Fi/network and unplug shared/external drives to stop encryption from spreading — but don't start deleting.
  2. Don't destroy your options. Don't wipe, don't reformat yet, and don't pay on impulse. Photograph the ransom note and record what/when you noticed.
  3. Recover from clean backups. The best outcome is wiping and restoring from a known-good offline backup — verify it wasn't connected during infection.
  4. Check for legitimate decryptors. Some ransomware strains have free, reputable decryptors via official security projects — check before considering payment.
  5. Weigh payment honestly. Paying is risky: no guarantee of recovery, it funds criminals, and it flags you. Treat it as a last resort, ideally with professional advice.
  6. Report and, if serious, get help. Notify the relevant authorities; for a business or sensitive-data incident, engage professional incident response and check notification duties.
Show full SKILL.md (240 more words)Show less

Output Format

Suspected [ransomware/malware] · [personal/business] · backups: [yes/no]

Now (first minutes)

  1. Disconnect network + unplug external/shared drives.
  2. Don't wipe, don't pay yet. Photograph the ransom note; note time/first sign.
  3. Isolate any other devices that share the network/drives.

Recover: wipe + restore from a clean offline backup → or check for a legitimate free decryptor → or engage a professional. Payment: last resort, high risk — [tradeoffs]; get advice first. Report: [relevant authority/agency] · [breach-notification duties if applicable].

This is first-response guidance for a personal/small setup. A business incident, or anything with sensitive/regulated data, needs professional incident responders — engage them early.

Quality Checks

  • Containment (disconnect network/drives) is the first action
  • Warns against wiping or paying reflexively; preserve evidence
  • Prioritizes restoring from a verified offline backup
  • Mentions checking for legitimate free decryptors before payment
  • Presents the payment decision honestly as a risky last resort
  • Includes reporting and flags when to get professional IR help

Anti-Patterns

  • Paying immediately out of panic.
  • Reformatting/wiping before preserving evidence and confirming backups.
  • Reconnecting the infected device and spreading it.
  • Restoring from a backup that was connected during infection.
  • Treating a serious business breach as a DIY job.

Example Trigger Phrases

  • "My files are all encrypted and there's a ransom note — what do I do?"
  • "I think I've got ransomware, help me not make it worse."
  • "Suspicious pop-up locked my computer demanding payment."
  • "Should I pay the ransom to get my files back?"
  • "Malware on my work laptop — what's my first move?"

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ransomware-first-response of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Ransomware First Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ransomware First Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ransomware First Response this skillmohitagw15856/pm-claude-skills1.4k—~1.3kAutomated safety check: PassMIT
Msp MaintenanceRTFM-IT-Services-LLC/msp-claude-skills115—~2.6kAutomated safety check: PassCustom licence
Oraclecloud Incident Runbookjeremylongshore/tons-of-skills-marketplace2.8k—~2.7kAutomated safety check: PassMIT
Sentry Reliability Patternsjeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: PassMIT
Devops AgentLeoYeAI/openclaw-master-skills2.2k—~5.3kAutomated safety check: NotesMIT
Msp SecurityRTFM-IT-Services-LLC/msp-claude-skills115—~4.8kAutomated safety check: PassCustom licence

Similar skills

  • Msp Maintenance

    RTFM-IT-Services-LLC/msp-claude-skills

    A skill your agent uses for your MSP's proactive, recurring operations: patching and update cycles, maintenance windows, backup monitoring and test restores, monitoring and alert triage, the on-call…

    115 GitHub stars~2.6k tokensUpdated 8 days ago
    DevOps & CloudAuto-check passed
  • Oraclecloud Incident Runbook

    jeremylongshore/tons-of-skills-marketplace

    Self-service incident runbook for OCI outages — health probes, instance recovery, cross-AD/region failover.

    2.8k GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Sentry Reliability Patterns

    jeremylongshore/tons-of-skills-marketplace

    Build reliable Sentry integrations with graceful degradation, circuit breakers, and offline queuing.

    2.8k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Devops Agent

    LeoYeAI/openclaw-master-skills

    Your on-call DevOps assistant — one-click deploy, monitoring setup, scheduled backups, and fault diagnosis.

    2.2k GitHub stars~5.3k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Msp Security

    RTFM-IT-Services-LLC/msp-claude-skills

    A skill your agent uses for security standards at your managed IT services (MSP) business, in both directions: the baseline every managed client must meet (MFA, endpoint protection, email security…

    115 GitHub stars~4.8k tokensUpdated 8 days ago
    Sales & SupportAuto-check passed
  • Operational Risk

    JoelLewis/finance_skills

    Guide identification, measurement, and management of operational risk in trading and brokerage operations.

    206 GitHub stars~7.4k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Ransomware First Response

What does Ransomware First Response do?

Handle the first hour of a suspected ransomware or malware infection calmly and correctly — contain it, preserve options, and avoid the moves that make it worse. Ransomware First Response is an agent skill from mohitagw15856/pm-claude-skills. Handle the first hour of a suspected ransomware or malware infection calmly and correctly — contain it, preserve options, and avoid the moves that make it worse.

When should I use Ransomware First Response?

Ransomware First Response fits situations like: asked what to do about ransomware; my files are encrypted with a ransom note; I think I have malware; my computers been hacked.

How do I install Ransomware First Response in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill ransomware-first-response -a claude-code`. Or copy the skill folder (skills/ransomware-first-response in mohitagw15856/pm-claude-skills) into .claude/skills/ransomware-first-response in your project. Claude Code loads it when a task matches its description.

How do I install Ransomware First Response in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill ransomware-first-response -a codex`. Or copy the skill folder (skills/ransomware-first-response in mohitagw15856/pm-claude-skills) into .agents/skills/ransomware-first-response in your project. Codex loads it when a task matches its description.

Can I use Ransomware First Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill ransomware-first-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ransomware-first-response, .gemini/skills/ransomware-first-response, .github/skills/ransomware-first-response and .opencode/skills/ransomware-first-response in your project.

What does Ransomware First Response need to run?

SKILL.md names no scripts, command-line tools or credentials: Ransomware First Response is instructions for the agent only.

Does Ransomware First Response access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ransomware First Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ransomware First Response use?

Ransomware First Response is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ransomware First Response use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ransomware First Response?

Skills that share tags, products or a category with Ransomware First Response: Msp Maintenance (RTFM-IT-Services-LLC/msp-claude-skills, 115 stars), Oraclecloud Incident Runbook (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Sentry Reliability Patterns (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Devops Agent (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ransomware First Response?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.