Agent skill

Security Incident Response

by mohitagw15856 in mohitagw15856/pm-claude-skills

Run or document a security incident response — contain, eradicate, recover, and learn.

MITAuto-check passedDevOps & Cloud

Install Security Incident Response

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill security-incident-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills security-incident-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-incident-response .claude/skills/security-incident-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-incident-response
GitHub stars
1.4k
Token cost
~1k tokens
SKILL.md length
457 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Run or document a security incident response — contain, eradicate, recover, and learn.

  • Works in 5 steps: Triage & declare — confirm it's a real… → Contain — stop the bleeding without… → Eradicate — remove the root cause: close… → …
  • Responding to a breach/compromise/security incident
  • SKILL.md covers Required Inputs, Output Format, Quality Checks and Anti-Patterns, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Incident Response is an agent skill from mohitagw15856/pm-claude-skills. Run or document a security incident response — contain, eradicate, recover, and learn. Use when responding to a breach/compromise/security incident, writing an IR plan or runbook, or producing a post-incident report. Produces a phase-by-phase response (triage, contain, eradicate, recover, post-incident) with the immediate actions, comms, evidence-handling, and a blameless review. For incidents on systems you own or defend.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Security operations and Runbooks and postmortems. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Responding to a breach/compromise/security incident
  • Writing an IR plan
  • Producing a post-incident report

Example prompts

  • “/security-incident-response”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Triage & declare — confirm it's a real incident, assign severity and an incident lead, start a timeline/log.
  2. Contain — stop the bleeding without destroying evidence: isolate hosts, revoke sessions/keys, block IOCs, disable compromised accounts…
  3. Eradicate — remove the root cause: close the entry point, remove malware/backdoors, patch the exploited flaw, rotate all potentially…
  4. Recover — restore from known-good, verify integrity, monitor closely for recurrence, return to normal service deliberately.
  5. Post-incident — a blameless review: timeline, root cause, what worked/didn't, and action items to prevent recurrence.

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Incident Response loads about 1k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 457 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 457 words, ~1,044 tokens.

Download SKILL.mdSave it as .claude/skills/security-incident-response/SKILL.md (or your agent's skills folder).
name
security-incident-response
description
Run or document a security incident response — contain, eradicate, recover, and learn. Use when responding to a breach/compromise/security incident, writing an IR plan or runbook, or producing a post-incident report. Produces a phase-by-phase response (triage, contain, eradicate, recover, post-incident) with the immediate actions, comms, evidence-handling, and a blameless review. For incidents on systems you own or defend.

Security Incident Response Skill

In a security incident, the order of operations matters: contain before you clean, preserve evidence before you wipe, and communicate deliberately. This skill drives a structured response through the standard phases, or documents one after the fact — with the immediate actions, decision points, comms, and a blameless post-incident review. For systems you own or are authorized to defend.

Required Inputs

Ask for these only if they aren't already provided:

  • What's happening — the observed incident (malware, unauthorized access, data exfiltration, ransomware, account compromise), and how it was detected.
  • Scope so far — affected systems/accounts/data, whether it's ongoing, entry point if known.
  • Environment & stakes — what's at risk (PII, funds, availability), regulatory/notification obligations.
  • Resources — who's responding, tooling/access available, and any IR plan already in place.

Output Format

Incident response: [incident]

Severity & summary — classify severity (e.g. SEV1–3) and state, in two lines, what's known and what's at stake.

Phase-by-phase actions:

  1. Triage & declare — confirm it's a real incident, assign severity and an incident lead, start a timeline/log.
  2. Contain — stop the bleeding without destroying evidence: isolate hosts, revoke sessions/keys, block IOCs, disable compromised accounts. Preserve forensic data (snapshots, logs, memory) before wiping.
  3. Eradicate — remove the root cause: close the entry point, remove malware/backdoors, patch the exploited flaw, rotate all potentially exposed credentials/secrets.
  4. Recover — restore from known-good, verify integrity, monitor closely for recurrence, return to normal service deliberately.
  5. Post-incident — a blameless review: timeline, root cause, what worked/didn't, and action items to prevent recurrence.

Communications — who to notify and when: internal (leadership, legal), customers, and any regulatory/breach-notification obligations (with the clock — many have strict deadlines). Draft the holding line.

Evidence & chain of custody — what to preserve and how, in case of legal/law-enforcement involvement.

IOCs & detection — indicators of compromise seen, and detections/monitoring to add.

Show full SKILL.md (164 more words)Show less

Quality Checks

  • Severity is classified and an incident lead + running timeline are established first
  • Containment preserves evidence (snapshots/logs) before eradication/wiping
  • Eradication addresses the root cause and rotates all potentially exposed credentials
  • Recovery restores from known-good with heightened monitoring
  • Communications cover internal, customer, and regulatory/breach-notification duties with timing
  • The post-incident review is blameless and produces concrete prevention action items

Anti-Patterns

  • Do not wipe/rebuild before preserving forensic evidence — you lose the ability to understand the breach
  • Do not skip credential rotation — attackers persist via stolen keys/tokens
  • Do not go quiet on comms — silence with customers/regulators creates legal and trust damage
  • Do not blame individuals in the review — blameless analysis surfaces the real systemic causes
  • Do not declare "recovered" without monitoring for re-compromise
  • Do not act on systems you don't own or aren't authorized to defend

Based On

Incident-response practice (NIST SP 800-61 / SANS PICERL: prepare, identify, contain, eradicate, recover, lessons-learned).

Example Trigger Phrases

  • "Respond to a breach/compromise/security incident."
  • "Write an IR plan."
  • "Produce a post-incident report."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-incident-response of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Security Incident Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Incident Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Incident Response this skillmohitagw15856/pm-claude-skills1.4k—~1kAutomated safety check: PassMIT
Soc Operationsbriiirussell/cybersecurity-skills413—~2.9kAutomated safety check: PassMIT
Breach Patternsbriiirussell/cybersecurity-skills413—~3.5kAutomated safety check: NotesMIT
Detecting Container Escape Attemptsmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Implementing Soar Playbook With Palo Alto Xsoarmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0
Canary Tripwire Responsedeonmenezes/mantishack503—~376Automated safety check: PassApache-2.0

Similar skills

  • Soc Operations

    briiirussell/cybersecurity-skills

    Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst…

    413 GitHub stars~2.9k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    DatabasesAuto-check: notes
  • Detecting Container Escape Attempts

    mukul975/Anthropic-Cybersecurity-Skills

    Detects container escape at runtime across tooling - namespace manipulation, capability abuse, kernel exploits, sensitive host mounts, and anomalous syscalls - and explains which signals matter…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Soar Playbook With Palo Alto Xsoar

    mukul975/Anthropic-Cybersecurity-Skills

    Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise…

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Canary Tripwire Response

    deonmenezes/mantishack

    What to do if a mantiscanary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result

    503 GitHub stars~376 tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Infra Triage

    papadopouloskyriakos/agentic-chatops

    Infrastructure alert triage — dedup via YT search, deep PVE/K8s investigation, auto-escalation for recurring/flapping alerts, control plane deep dive for K8s controller nodes.

    107 GitHub stars~714 tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about Security Incident Response

What does Security Incident Response do?

Run or document a security incident response — contain, eradicate, recover, and learn. Security Incident Response is an agent skill from mohitagw15856/pm-claude-skills. Run or document a security incident response — contain, eradicate, recover, and learn.

When should I use Security Incident Response?

Security Incident Response fits situations like: responding to a breach/compromise/security incident; writing an IR plan; producing a post-incident report.

How do I install Security Incident Response in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill security-incident-response -a claude-code`. Or copy the skill folder (skills/security-incident-response in mohitagw15856/pm-claude-skills) into .claude/skills/security-incident-response in your project. Claude Code loads it when a task matches its description.

How do I install Security Incident Response in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill security-incident-response -a codex`. Or copy the skill folder (skills/security-incident-response in mohitagw15856/pm-claude-skills) into .agents/skills/security-incident-response in your project. Codex loads it when a task matches its description.

Can I use Security Incident Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill security-incident-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-incident-response, .gemini/skills/security-incident-response, .github/skills/security-incident-response and .opencode/skills/security-incident-response in your project.

What does Security Incident Response need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Incident Response is instructions for the agent only.

Does Security Incident Response access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Incident Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Incident Response use?

Security Incident Response is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Incident Response use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Incident Response?

Skills that share tags, products or a category with Security Incident Response: Soc Operations (briiirussell/cybersecurity-skills, 413 stars), Breach Patterns (briiirussell/cybersecurity-skills, 413 stars), Detecting Container Escape Attempts (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Soar Playbook With Palo Alto Xsoar (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Incident Response?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.