Agent skill

Soc Alert Triage

by mrmps in mrmps/classifier-dev

Rank a SIEM or EDR alert queue before a human opens it. An agent skill from mrmps/classifier-dev.

MITAuto-check passedSecurity

Install Soc Alert Triage

skills CLI
$ npx skills add mrmps/classifier-dev --skill soc-alert-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mrmps/classifier-dev soc-alert-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mrmps/classifier-dev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/soc-alert-triage .claude/skills/soc-alert-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
soc-alert-triage
GitHub stars
424
Token cost
~1.5k tokens
SKILL.md length
515 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

Rank a SIEM or EDR alert queue before a human opens it. An agent skill from mrmps/classifier-dev.

  • Works in 5 steps: Flatten each alert → Two labels, not three → One call → …
  • Tasks that involve Security operations
  • SKILL.md covers When not to use it, 1. Flatten each alert, 2. Two labels, not three and 3. One call, plus 3 more sections
  • Calls curl and jq; reaches classifier.dev

What it does

Soc Alert Triage is an agent skill from mrmps/classifier-dev. Rank a SIEM or EDR alert queue before a human opens it. Scores each alert likely true positive or likely false positive from its own fields — rule, process, command line, parent, user — with a calibrated confidence, so the sure ones disposition themselves and an analyst starts at the top of the rest. Defensive triage only. Use on "which of these are worth opening", "tune out the noise", "rank the queue".

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations. The repository describes itself as: Zero-shot text classification over plain HTTP — no API key, no account. One Cloudflare Worker, a CLI, and an MCP server. https://classifier.dev. The licence is MIT.

When your agent uses it

  • Tasks that involve Security operations

Example prompts

  • “which of these are worth opening”
  • “tune out the noise”
  • “rank the queue”
  • “/soc-alert-triage”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Flatten each alert
  2. Two labels, not three
  3. One call
  4. The bands
  5. The weekly loop

What it can do on your machine

Read from SKILL.md and the folder at commit 629df75. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • classifier.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Soc Alert Triage loads about 1.5k tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 515 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mrmps/classifier-dev at commit 629df75, republished under its MIT licence (© mrmps). 515 words, ~1,499 tokens.

Download SKILL.mdSave it as .claude/skills/soc-alert-triage/SKILL.md (or your agent's skills folder).
name
soc-alert-triage
description
Rank a SIEM or EDR alert queue before a human opens it. Scores each alert likely true positive or likely false positive from its own fields — rule, process, command line, parent, user — with a calibrated confidence, so the sure ones disposition themselves and an analyst starts at the top of the rest. Defensive triage only. Use on "which of these are worth opening", "tune out the noise", "rank the queue".
license
MIT

Triage an alert queue before anyone opens it

Noise is usually obvious from the alert record alone: a service installed by msiexec.exe as SYSTEM is a package installer; the same rule on a service pointing into a public directory is not. classifier.dev scores that over a whole queue in one call, no key. It orders work for a defender; it closes nothing, touches no host.

When not to use it

  • As the detection itself. It reads the alert record, not telemetry.
  • When the answer needs context the record lacks — asset criticality, the change ticket, what the parent did an hour ago. Enrich first, classify after.
  • On fewer than about twenty alerts. Read them.

1. Flatten each alert

One line per alert, same fields in the same order every time. Stable order is what makes scores comparable across a queue.

rule=NAME | proc=IMAGE | cmd=COMMAND LINE | parent=PARENT IMAGE | user=ACCOUNT

Send no host names or addresses unless the rule needs one.

Smoke-test one line with the GET form, which answers the bare label (add --data-urlencode "verbose=1" for JSON with scores):

curl -s -G https://classifier.dev/ \
  --data-urlencode "labels=likely true positive,likely false positive" \
  --data-urlencode "text=rule=Encoded PowerShell | proc=powershell.exe | cmd=powershell -nop -w hidden -enc BASE64BLOB | parent=winword.exe | user=acct-temp3"
likely true positive

2. Two labels, not three

The obvious label set is true positive / false positive / needs analyst. Skip it: a third label takes probability from both sides, so sure answers stop being sure. On the six alerts below, adding needs analyst pulled every answer under 0.9 — the top fell from 0.95 to 0.86 — leaving nothing to act on. Needs analyst is a band, not a label.

3. One call

alerts.json, up to 1,000 alerts a call:

{
  "labels": ["likely true positive", "likely false positive"],
  "instructions": "Each input is one alert: rule, process, command line, parent process and user. Judge only those fields. A false positive is a pattern that is routine for that parent and that user on a managed corporate workstation.",
  "inputs": [
    "rule=Encoded PowerShell | proc=powershell.exe | cmd=powershell -nop -w hidden -enc BASE64BLOB | parent=winword.exe | user=acct-temp3",
    "rule=Encoded PowerShell | proc=powershell.exe | cmd=powershell -ExecutionPolicy Bypass -File C:/ProgramData/SCCM/inventory.ps1 | parent=ccmexec.exe | user=SYSTEM",
    "rule=Service installed from user path | proc=sc.exe | cmd=sc create Updater binPath= C:/Users/Public/u.exe start= auto | parent=cmd.exe | user=bkowalski",
    "rule=Service installed from user path | proc=sc.exe | cmd=sc create GoogleUpdaterService binPath= C:/Program Files/Google/GoogleUpdater.exe start= demand | parent=msiexec.exe | user=SYSTEM",
    "rule=LSASS handle access | proc=procdump64.exe | cmd=procdump -ma lsass.exe out.dmp | parent=cmd.exe | user=helpdesk-jm",
    "rule=Mass file copy | proc=rclone.exe | cmd=rclone copy C:/Finance remote:backup --transfers 32 | parent=powershell.exe | user=svc-backup"
  ]
}
curl -s https://classifier.dev/v1/classify -H 'content-type: application/json' --data @alerts.json \
  | jq -r '.results | to_entries | sort_by(-.value.confidence)[] | "\(.value.confidence)  \(.value.label)  alert \(.key)"'

Output:

0.95  likely false positive  alert 3
0.92  likely true positive  alert 0
0.92  likely false positive  alert 1
0.85  likely true positive  alert 2
0.55  likely false positive  alert 5
0.14  likely true positive  alert 4
Show full SKILL.md (263 more words)Show less

4. The bands

Confidence is calibrated: measured, answers at or above 0.9 were right 82 to 92% of the time; answers under 0.5, 29 to 64%.

  • 0.9 and up — act. False positives to a suppressed bucket, true positives promoted to a case. Read a 2% sample of the suppressed bucket weekly; that sample is how you learn the gate has drifted.
  • 0.5 to 0.9 — analyst queue, lowest confidence opened first. Alerts 2 and 5 sit here, and alert 5 — rclone copying a finance directory to a remote target — is the one to open first.
  • Below 0.5 — escalate. Alert 4 at 0.14: procdump against lsass.exe from a help desk account, and the model is guessing. Re-ask it with "tier": "smart" and put it at the top of the queue.

Confidence says whether the label is right, not whether the alert is serious; weight by asset criticality yourself.

5. The weekly loop

Each week, write the verdicts analysts closed into instructions as closed-case history. Nothing is retrained, no rule is edited; a sentence or two of ground truth is the update.

jq '.instructions += " Closed cases from the last four weeks: rclone or another cloud-sync tool reaching a remote target from a backup service account was a true positive twice; procdump run by a helpdesk account during a ticketed session was closed as a false positive four times."' alerts.json > alerts-week2.json

Alerts 4 and 5, re-run with that sentence appended:

0.99  likely false positive  alert 4
0.91  likely true positive  alert 5

Both left the analyst band, in opposite directions. Keep instructions under about six sentences — past that it reads as a policy document and the effect flattens — and keep last week's file to diff the bands against.

What done looks like

Every alert has a label, a confidence and a band: the 0.9 band dispositioned, the middle band a ranked queue with the below-0.5 alerts on top, and last week's instructions file next to this week's.

© mrmps, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/soc-alert-triage of mrmps/classifier-dev.

Open the folder on GitHubat commit 629df75

Compare with similar skills

Soc Alert Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Soc Alert Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Soc Alert Triage this skillmrmps/classifier-dev424—~1.5kAutomated safety check: PassMIT
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Security Detection Rule Managementelastic/agent-skills5921 repos~3.9kAutomated safety check: NotesApache-2.0
Chaitin CLIchaitin/chaitin-cli114—~15kAutomated safety check: NotesGPL-3.0
GatesNebulock-Inc/agentic-threat-hunting-framework388—~12kAutomated safety check: PassMIT

Similar skills

  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check: notes
  • Chaitin CLI

    chaitin/chaitin-cli

    A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

    114 GitHub stars~15k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Gates

    Nebulock-Inc/agentic-threat-hunting-framework

    GATES method validation for hunt-derived detections. An agent skill from Nebulock-Inc/agentic-threat-hunting-framework.

    388 GitHub stars~12k tokensUpdated yesterday
    SecurityAuto-check passed
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from mrmps/classifier-dev

All 21 skills in this repo
  • Bulk Classify

    mrmps/classifier-dev

    Sort many texts into your own categories without reading them, using a keyless HTTP API that returns a calibrated confidence per answer.

    424 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Computer Use Action Picker

    mrmps/classifier-dev

    Pick a browser or desktop agent's next action by choosing among the actions actually on screen instead of inventing one.

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Content Moderation Gate

    mrmps/classifier-dev

    Check user-generated text against a written policy before it is published.

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Label each context chunk keep, drop or replace-with-a-pointer and pass the survivors through byte for byte instead of summarising, with key-shaped chunks decided locally and never sent, and a…

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Document Intake Routing

    mrmps/classifier-dev

    Label each page of an intake packet with a document type and a page role before extraction runs, so only confident pages reach an extractor and the rest reach a person.

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Headline Filter Map Reduce

    mrmps/classifier-dev

    Filter hundreds or thousands of headlines, search results or feed items against a written brief before opening any of them, using a two-stage cascade that spends a fast model on everything and a…

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Soc Alert Triage

What does Soc Alert Triage do?

Rank a SIEM or EDR alert queue before a human opens it. An agent skill from mrmps/classifier-dev. Soc Alert Triage is an agent skill from mrmps/classifier-dev. Rank a SIEM or EDR alert queue before a human opens it.

When should I use Soc Alert Triage?

Soc Alert Triage fits situations like: tasks that involve Security operations.

How do I install Soc Alert Triage in Claude Code?

Run `npx skills add mrmps/classifier-dev --skill soc-alert-triage -a claude-code`. Or copy the skill folder (skills/soc-alert-triage in mrmps/classifier-dev) into .claude/skills/soc-alert-triage in your project. Claude Code loads it when a task matches its description.

How do I install Soc Alert Triage in Codex?

Run `npx skills add mrmps/classifier-dev --skill soc-alert-triage -a codex`. Or copy the skill folder (skills/soc-alert-triage in mrmps/classifier-dev) into .agents/skills/soc-alert-triage in your project. Codex loads it when a task matches its description.

Can I use Soc Alert Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mrmps/classifier-dev --skill soc-alert-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/soc-alert-triage, .gemini/skills/soc-alert-triage, .github/skills/soc-alert-triage and .opencode/skills/soc-alert-triage in your project.

What does Soc Alert Triage need to run?

Going by SKILL.md and its folder, Soc Alert Triage needs the command-line tools its instructions call (curl and jq).

Does Soc Alert Triage access the network?

SKILL.md names 1 domain. In commands or code: classifier.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Soc Alert Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Soc Alert Triage use?

Soc Alert Triage is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Soc Alert Triage use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Soc Alert Triage?

Skills that share tags, products or a category with Soc Alert Triage: Security Alert Triage (elastic/agent-skills, 592 stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Security Detection Rule Management (elastic/agent-skills, 592 stars) and Chaitin CLI (chaitin/chaitin-cli, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Soc Alert Triage?

mrmps (a GitHub user) maintains it in mrmps/classifier-dev, which has 424 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.

Source: mrmps/classifier-dev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.