Agent skill

Rsigma

by timescale in timescale/rsigma

Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve.

MITAuto-check passedDevelopment

Install Rsigma

skills CLI
$ npx skills add timescale/rsigma --skill rsigma -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install timescale/rsigma rsigma --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/timescale/rsigma.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/rsigma .claude/skills/rsigma && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rsigma
GitHub stars
159
Token cost
~1.2k tokens
SKILL.md length
520 words
Files
2 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve.

  • The user mentions rsigma
  • SKILL.md covers Command names, Prefer MCP when it is connected, Which command and Convert
  • Calls npx
  • Linting Sigma rules

What it does

Rsigma is an agent skill from timescale/rsigma. Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve. Prefer MCP tools when rsigma mcp serve is connected. For authoring Sigma YAML (detection, correlation, filters, pipelines, modifiers), use the sigma-rules skill. Use this skill whenever the user mentions rsigma, evaluating or linting Sigma rules, converting rules to a SIEM query, running a detection daemon, drafting or tuning rules from events, or backtesting a ruleset, even…

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/workflows.md`).

It sits in Development, covering Linting and formatting, Trading and backtesting and MCP servers. It works with Model Context Protocol, PostgreSQL and Rust. The repository describes itself as: A complete Sigma detection engineering toolkit: parser, linter, evaluator, correlation engine, conversion framework, streaming daemon, MCP and LSP servers :crab:. The licence is MIT.

When your agent uses it

  • The user mentions rsigma
  • Linting Sigma rules
  • Converting rules to a SIEM query
  • Running a detection daemon

Example prompts

  • “/rsigma”

Requirements

  • Node.js
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 3acceb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • rsigma.io
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rsigma loads about 1.2k tokens when it runs, and up to ~2.2k if it reads all its reference files. Until then it costs about 139 tokens; SKILL.md has 520 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~139
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from timescale/rsigma at commit 3acceb3, republished under its MIT licence (© timescale). 520 words, ~1,184 tokens.

Download SKILL.mdSave it as .claude/skills/rsigma/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
rsigma
description
Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve. Prefer MCP tools when rsigma mcp serve is connected. For authoring Sigma YAML (detection, correlation, filters, pipelines, modifiers), use the sigma-rules skill. Use this skill whenever the user mentions rsigma, evaluating or linting Sigma rules, converting rules to a SIEM query, running a detection daemon, drafting or tuning rules from events, or backtesting a ruleset, even if they do not name the binary.

rsigma

Use rsigma to run Sigma rules. Author the YAML with the sigma-rules skill (npx skills add timescale/sigma-rules -g -y). This skill covers the toolchain: command names, when to call MCP versus the CLI, and which command fits the job.

Flag tables and option lists live at rsigma.io. Read them when you need a flag. Do not invent flags, and do not quote lint or auto-fix counts. The linting guide is the catalogue.

Command names

The CLI is noun-led. These old top-level forms do not exist:

Do not runRun instead
rsigma evalrsigma engine eval
rsigma lintrsigma rule lint
rsigma validatersigma rule validate
rsigma daemonrsigma engine daemon

Groups:

GroupUse it for
engineEvaluate events, explain a miss, classify schemas, and run or inspect the daemon (eval, explain, classify, discover-schemas, status, tap, tail, daemon)
ruleLint, validate, draft, tune, test exemplars, backtest, and reverse-convert
backendConvert rules to a query (convert, targets, formats)
pipelineSee how a pipeline rewrites a rule (diff) and dry-run dynamic sources (resolve)
mcpServe the toolchain to an agent (serve)
configScaffold and inspect rsigma.yaml

engine daemon and pipeline resolve need a build with the daemon feature. mcp serve needs the mcp feature. Release binaries and the Docker image include both. rsigma --features prints what this binary was built with.

Full tree: CLI reference.

Prefer MCP when it is connected

If rsigma mcp serve is already connected, call its tools. They return JSON (ok, findings, matches) and you do not scrape CLI text. If it is not connected, use the CLI commands in workflows.md.

Start a local server only when the user wants the agent wired up:

bash
rsigma mcp serve --rules-dir rules/

Point --daemon-url at a running daemon when the task is live triage (incidents, silences, dispositions). Those tools stay off until that URL is set. Writes stay behind --allow-operate-writes. Details: MCP server guide.

Show full SKILL.md (212 more words)Show less

Which command

  • One-shot check against a file or a few events: engine eval. A long-running process with reload, metrics, and sinks: engine daemon.
  • A rule from exemplar events (optional baseline, or --groups for a temporal correlation): rule draft. A rule the user already described in words: write the YAML with sigma-rules, then lint and evaluate it here.
  • A noisy rule with known false positives and true positives that must still fire: rule tune.
  • Embedded rsigma.exemplars: rule test. A separate corpus and expectations file: rule backtest.
  • Why a rule missed: engine explain. How a pipeline rewrote fields: pipeline diff.

The write-lint-evaluate-convert loop, with the MCP tool beside each CLI command, is in workflows.md.

Convert

Native targets run inside rsigma. Anything else is delegated to an installed sigma-cli.

bash
rsigma backend targets
rsigma backend convert -t postgres rules/
rsigma backend convert -t splunk rules/

Native targets are postgres (postgresql, pg), lynxdb, and fibratus, plus a backend-neutral test target that is not a deployment backend. backend targets is the live list. Delegated conversion needs sigma on PATH (override with RSIGMA_SIGMA_CLI). The Docker image has no Python, so delegation is a local-binary feature. On MCP, convert_rules delegates only when the server was started with --allow-sigma-cli. Builtin pipeline names (ecs_windows, fibratus_windows, sysmon) are not translated for delegated targets. Pass a sigma-cli pipeline name or a YAML path.

See backend convert and sigma-cli delegation.

© timescale, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/rsigma of timescale/rsigma.

  • SKILL.md
  • references/workflows.md

Open the folder on GitHubat commit 3acceb3

Compare with similar skills

Rsigma next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rsigma compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rsigma this skilltimescale/rsigma159—~1.2kAutomated safety check: PassMIT
Agnixagent-sh/agnix445—~874Automated safety check: PassApache-2.0
Agnixagent-sh/agnix445—~563Automated safety check: PassApache-2.0
Ue Code AuthoringJasonMa0012/MooaToon749—~1.9kAutomated safety check: NotesCustom licence
Building Glamorous TuisDicklesworthstone/meta_skill205—~3.4kAutomated safety check: PassCustom licence
Projectatlasstyler-ai/ProjectAtlas440—~9.2kAutomated safety check: PassMIT

Similar skills

  • Agnix

    agent-sh/agnix

    A skill your agent uses when user asks to 'lint agent configs', 'validate skills', 'check CLAUDE.md', 'validate hooks', 'lint MCP'.

    445 GitHub stars~874 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Agnix

    agent-sh/agnix

    A skill your agent uses when user asks to 'lint agent configs', 'validate skills', 'check CLAUDE.md', 'validate hooks', 'lint MCP'.

    445 GitHub stars~563 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Ue Code Authoring

    JasonMa0012/MooaToon

    A skill your agent uses when writing or modifying UE C++ (classes, actors, components, subsystems, interfaces, function libraries) with Rider MCP available.

    749 GitHub stars~1.9k tokensUpdated 20 days ago
    DevelopmentAuto-check: notes
  • Building Glamorous Tuis

    Dicklesworthstone/meta_skill

    Build terminal UIs with Charmbracelet (Bubble Tea, Lip Gloss, Gum).

    205 GitHub stars~3.4k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Projectatlas

    styler-ai/ProjectAtlas

    Use ProjectAtlas before broad source reads, preferring the installed short atlas CLI for an exact checkout and MCP for registered worktree routing, compact session briefs, or federated graph evidence.

    440 GitHub stars~9.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Typescript Style

    tjx666/vscode-mcp

    TypeScript code style and repo conventions for VSCode MCP — inference vs explicit types, ESM import suffixes, zod schema contracts, async VSCode/Node APIs, JSON-safe IPC results, JSDoc for public…

    106 GitHub stars~961 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

Questions about Rsigma

What does Rsigma do?

Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve. Rsigma is an agent skill from timescale/rsigma. Use the rsigma CLI and MCP server: engine eval, engine daemon, rule lint, rule draft, rule tune, rule backtest, backend convert, mcp serve.

When should I use Rsigma?

Rsigma fits situations like: the user mentions rsigma; linting Sigma rules; converting rules to a SIEM query; running a detection daemon.

How do I install Rsigma in Claude Code?

Run `npx skills add timescale/rsigma --skill rsigma -a claude-code`. Or copy the skill folder (skills/rsigma in timescale/rsigma) into .claude/skills/rsigma in your project. Claude Code loads it when a task matches its description.

How do I install Rsigma in Codex?

Run `npx skills add timescale/rsigma --skill rsigma -a codex`. Or copy the skill folder (skills/rsigma in timescale/rsigma) into .agents/skills/rsigma in your project. Codex loads it when a task matches its description.

Can I use Rsigma in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add timescale/rsigma --skill rsigma -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rsigma, .gemini/skills/rsigma, .github/skills/rsigma and .opencode/skills/rsigma in your project.

What does Rsigma need to run?

Going by SKILL.md and its folder, Rsigma needs the command-line tools its instructions call (npx). Our summary lists: Node.js; Docker.

Does Rsigma access the network?

SKILL.md names 2 domains. As links in the text: rsigma.io and github.com. This is read from the text; nothing was executed.

Is Rsigma safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rsigma use?

Rsigma is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rsigma use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.

What are the alternatives to Rsigma?

Skills that share tags, products or a category with Rsigma: Agnix (agent-sh/agnix, 445 stars), Agnix (agent-sh/agnix, 445 stars), Ue Code Authoring (JasonMa0012/MooaToon, 749 stars) and Building Glamorous Tuis (Dicklesworthstone/meta_skill, 205 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rsigma?

timescale (a GitHub organization) maintains it in timescale/rsigma, which has 159 GitHub stars. The repository was last updated on October 6, 2026.

Source: timescale/rsigma on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.