Incident Response Lifecycle
LeoYeAI/openclaw-master-skills
Incident response process management following the NIST 800-61 lifecycle.
Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…
$ npx skills add trilwu/secskills --skill responding-to-incidents -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills responding-to-incidents --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/responding-to-incidents .claude/skills/responding-to-incidents && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "responding-to-incidents" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/responding-to-incidents into .claude/skills/responding-to-incidents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "responding-to-incidents", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/responding-to-incidentsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill responding-to-incidents -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills responding-to-incidents --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-defense/skills/responding-to-incidents .agents/skills/responding-to-incidents && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "responding-to-incidents" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/responding-to-incidents into .agents/skills/responding-to-incidents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "responding-to-incidents", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill responding-to-incidents -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills responding-to-incidents --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-defense/skills/responding-to-incidents .cursor/skills/responding-to-incidents && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "responding-to-incidents" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/responding-to-incidents into .cursor/skills/responding-to-incidents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "responding-to-incidents", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-defense/skills/responding-to-incidents--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill responding-to-incidents -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills responding-to-incidents --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-defense/skills/responding-to-incidents .gemini/skills/responding-to-incidents && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "responding-to-incidents" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/responding-to-incidents into .gemini/skills/responding-to-incidents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "responding-to-incidents", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills responding-to-incidentsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill responding-to-incidents -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-defense/skills/responding-to-incidents .github/skills/responding-to-incidents && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "responding-to-incidents" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/responding-to-incidents into .github/skills/responding-to-incidents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "responding-to-incidents", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill responding-to-incidents -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills responding-to-incidents --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-defense/skills/responding-to-incidents .opencode/skills/responding-to-incidents && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "responding-to-incidents" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/responding-to-incidents into .opencode/skills/responding-to-incidents/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "responding-to-incidents", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
responding-to-incidentsRun digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…
Responding To Incidents is an agent skill from trilwu/secskills. Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and postmortem. Use during a suspected compromise, when analyzing a disk or memory image, reconstructing an attacker timeline, or answering how far an intrusion spread.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Runbooks and postmortems, Digital forensics and Incident response. It works with Microsoft 365. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
awspython3From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
attack.mitre.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Responding To Incidents loads about 3.9k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 1,367 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo ./avml mem.lime # or LiMEsudo dd if=/dev/sda bs=4M conv=noerror,sync status=progress | tee image.dd | sha256sumsudo ewfacquire /dev/sda # E01 with built-in hashing, preferredsudo mount -o ro,noexec,noload,loop image.dd /mnt/evidenceAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,367 words, ~3,877 tokens.
.claude/skills/responding-to-incidents/SKILL.md (or your agent's skills folder).Two questions drive every incident: how far did they get, and are they still here. Everything else — the malware, the CVE, the root cause — is supporting detail. Answer those two in order and the response follows.
analyzing-malwarehunting-threatstriaging-security-alerts; response begins once triage confirms a true
positiveengineering-detectionsinvestigating-aws-incidents; in Microsoft 365 / Entra — use investigating-m365-entraanalyzing-network-trafficSpecific evidence types have their own procedure skill. This skill sets scope and order; reach for these when a single artifact type becomes the focus.
| Artifact / focus | Skill |
|---|---|
| A RAM capture to work through with Volatility (injected code, in-memory creds, dead-process connections) | analyzing-memory-images |
| A Microsoft 365 / Entra ID compromise: no disk or memory, only cloud logs (UAL, sign-ins, OAuth grants) | investigating-m365-entra |
| Finding how an attacker persisted on a Linux host — the systematic sweep across every init path | analyzing-linux-persistence |
Preparation → Detection & Analysis → Containment → Eradication → Recovery → Lessons Learned
↑__________________|
(re-scope after every new finding)Two rules that are violated constantly and cost the most:
Preserve before you remediate. Rebooting, reimaging, or "just cleaning it up" destroys memory, running process state, and unflushed logs. Once gone, you cannot answer the scoping question, and you will be guessing about whether you got them out.
Do not contain half of it. Partial containment tells the attacker you have noticed and gives them time to re-establish access from the parts you missed. Scope first, then contain everything at once — unless there is active, ongoing damage, in which case stop the damage and accept the trade.
Order of volatility (RFC 3227 §2.1) — collect top to bottom:
registers, cache
routing table, arp cache, process table, kernel statistics, memory
temporary file systems ← tmpfs, /dev/shm: staging lives here
disk
remote logging and monitoring data relevant to the system
physical configuration, network topology
archival mediaNote that the RFC places memory, the process table, and network state in the
same tier rather than ordering them against each other. Modern practice
refines that: capture memory first, because the commands you would run to
enumerate processes and sockets execute on the box and perturb the memory you
have not captured yet. Do not skip the temporary filesystems tier — /dev/shm
and tmpfs are ordinary staging locations and they do not survive the reboot
that someone will inevitably suggest.
# Memory first, always, on a live suspect host
# Linux
sudo ./avml mem.lime # or LiME
# Windows
DumpIt.exe /OUTPUT mem.raw # or winpmem
# macOS — do NOT reach for osxpmem. Rekall is archived, its last release was
# 2017 and Intel-only, and its kext-based approach is blocked by SIP and
# kext restrictions on Big Sur and later, and on all Apple Silicon. Full-RAM
# capture on a modern Mac realistically needs commercial tooling with the
# required Apple entitlements (e.g. Volexity Surge Collect). If none is
# available, do not stall the response: take process-scoped dumps and a
# comprehensive live-triage collection instead, and record in the incident
# log that full physical memory was not obtainable and why.
# Volatile state before you touch the disk
ps auxwwf; ss -tunap; lsof -n; last -Faiw; w
netstat -anob # Windows
Get-NetTCPConnection | Where State -eq Established
# Disk: image, do not analyze in place
sudo dd if=/dev/sda bs=4M conv=noerror,sync status=progress | tee image.dd | sha256sum
sudo ewfacquire /dev/sda # E01 with built-in hashing, preferred
# Mount read-only, always via a write blocker or loop with `ro`
sudo mount -o ro,noexec,noload,loop image.dd /mnt/evidenceChain of custody is not paperwork you add later. Record at collection time:
Evidence ID | Source host/serial | Collected by | UTC timestamp | Method/tool+version
SHA-256 at acquisition | SHA-256 at each transfer | Custodian at each handoff | Storage locationHash immediately, verify after every copy, and never work on the original. If the incident may become litigation or a regulatory matter, involve legal before collection, not after.
For most incidents, a full disk image per host is too slow. Use targeted collection at scale, then image only the hosts that matter.
# Windows: KAPE with the SANS triage target set
kape.exe --tsource C: --target !SANS_Triage --tdest E:\out --vhdx host01
# Linux/macOS: UAC or a scripted collection
./uac -p full /evidence/host01
# Cloud/EDR: pull the equivalent via API
# - EDR raw telemetry for the window ±7 days
# - Snapshot the volume before terminating any instance
aws ec2 create-snapshot --volume-id vol-xxx --description "IR-<case> preserve"Go to the artifact that answers your question rather than processing everything.
| Question | Windows | Linux | macOS |
|---|---|---|---|
| What executed? | Prefetch, Amcache, ShimCache, SRUM, Sysmon E1 | auditd, shell history, /var/log/*, systemd journal | ExecPolicy DB, /var/db/, unified log |
| Persistence? | Run keys, Services, Scheduled Tasks, WMI subs, startup folder | cron, systemd units, .bashrc, ld.so.preload, init | LaunchAgents/Daemons, login items, profiles |
| Lateral movement? | 4624 type 3/10, 4648, 4672, RDP logs, SMB shares | auth.log, wtmp, .ssh/authorized_keys, known_hosts | Same as Linux plus ARD logs |
| Credential access? | LSASS handles (Sysmon E10), 4688 with procdump | /etc/shadow reads, ptrace, memory of sshd | Keychain access logs |
| Data staged/exfiltrated? | Recycle bin, $MFT timestamps, archive creation, USN journal | find -newermt, large tmp files, tar/zip in history | Same |
| Files accessed? | $MFT, $UsnJrnl, LNK, JumpLists, shellbags | atime (if enabled), auditd | FSEvents |
| Browser/download? | History DBs, Zone.Identifier ADS | Browser profile DBs | Quarantine DB (LSQuarantine) |
# Memory analysis — where "are they still here" usually gets answered
vol -f mem.raw windows.pstree
vol -f mem.raw windows.malfind # injected RWX regions
vol -f mem.raw windows.netscan
vol -f mem.raw windows.cmdline
vol -f mem.raw linux.bash # recovered shell history
# Filesystem timeline
fls -r -m / image.dd > body.txt && mactime -b body.txt -d > timeline.csv
log2timeline.py --storage-file plaso.db image.dd && psort.py -o dynamic plaso.db > super.csvMost modern intrusions run through identity, not malware. Do not stop at the host.
# AWS
aws cloudtrail lookup-events --lookup-attributes AttributeKey=Username,AttributeValue=<user>
# Look for: CreateAccessKey, AttachUserPolicy, AssumeRole chains, ConsoleLogin
# without MFA, GetSecretValue, CreateTrail/StopLogging (anti-forensics)
# Azure / Entra ID
# SigninLogs: impossible travel, legacy auth, unfamiliar device
# AuditLogs: "Add service principal credentials", "Consent to application",
# "Update conditional access policy", role assignments
# Google Workspace / GCP
# Admin audit: OAuth token grants, mail forwarding rules, delegation changesAttacker-created OAuth applications, service principal credentials, and mail forwarding rules are the most-missed persistence in cloud incidents. Enumerate them explicitly during eradication.
The timeline is the deliverable that everything else supports.
$MFT $STANDARD_INFORMATION is trivially forged;
$FILE_NAME is not. Disagreement between them is itself a finding.UTC Timestamp | Host | Event | Source | O/I
2026-07-12 03:14:02 | WEB01 | POST /upload.aspx 200, 1.2MB, IP x.x.x.x| IIS log | O
2026-07-12 03:14:40 | WEB01 | w3wp.exe → cmd.exe → whoami | Sysmon E1 | O
2026-07-12 03:15:05 | WEB01 | Initial access via upload vuln | correlation | IDo not contain until you have answered these, or you will contain the wrong subset:
Scoping expands. When a new host appears, restart step 2 for it.
# Contain without destroying evidence
# - Network-isolate via EDR rather than powering off (preserves memory)
# - Revoke sessions and tokens, not just passwords: OAuth grants, refresh
# tokens, Kerberos TGTs, API keys, SSH keys
# - Disable rather than delete accounts, so the artifacts survive
# Eradication checklist, per compromised identity
# password reset, MFA re-enrollment, session/token revocation, key rotation
# For AD-wide compromise: krbtgt reset twice, ~10h apartReimage rather than clean when the attacker had SYSTEM/root. You cannot prove removal of an implant on a host you do not fully understand, and the cost of being wrong is the whole investigation repeating.
Recovery gates — do not restore until: initial access vector is closed, all identified persistence is removed, credentials are rotated, and detection exists for the observed TTPs. Monitor restored systems at elevated sensitivity for at least a full business cycle.
Postmortems are blameless: they analyze the control and process failures, not the person who clicked. A postmortem that names an individual as the cause produces silence in the next incident.
<!-- attack:start -->
Generated from secskills-core/ttp-index.json — edit that file, then run
python3 scripts/sync_attack.py --write. Re-verify IDs against the
current ATT&CK release before citing them in a report.
Persistence (TA0003)
exploiting-cloud-platformsDefense Evasion (TA0005)
hunting-threatshunting-threatshunting-threatsCollection (TA0009)
Impact (TA0040)
analyzing-malwarehunting-threatsDetection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.
<!-- attack:end -->
analyzing-malware — sample analysis feeding scoping and IOCshunting-threats — proactive search using the TTPs found hereengineering-detections — closing the detection gap this incident exposed© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-defense/skills/responding-to-incidents of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Responding To Incidents next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Responding To Incidents this skilltrilwu/secskills | 157 | — | ~3.9k | Automated safety check: Notes | MIT | |
| Incident Response LifecycleLeoYeAI/openclaw-master-skills | 2.2k | — | ~5k | Automated safety check: Pass | Apache-2.0 | |
| Extracting Credentials From Memory Dumpmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Performing Ransomware Responsemukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Incident Responsealirezarezvani/claude-skills | 28k | — | ~3.8k | Automated safety check: Pass | MIT | |
| Parsing Artifacts With Eric Zimmerman Toolsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 |
LeoYeAI/openclaw-master-skills
Incident response process management following the NIST 800-61 lifecycle.
mukul975/Anthropic-Cybersecurity-Skills
Extracts cached credentials, password hashes, Kerberos tickets, and authentication tokens from Windows memory dumps using Volatility 3, Mimikatz, and pypykatz.
mukul975/Anthropic-Cybersecurity-Skills
Executes a structured ransomware incident response from detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening, covering ransom negotiation…
alirezarezvani/claude-skills
A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.
mukul975/Anthropic-Cybersecurity-Skills
Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into…
briiirussell/cybersecurity-skills
Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst…
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Works with
Categories
Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…. Responding To Incidents is an agent skill from trilwu/secskills. Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and postmortem.
Responding To Incidents fits situations like: tasks that involve Runbooks and postmortems; tasks that involve Digital forensics; tasks that involve Incident response.
Run `npx skills add trilwu/secskills --skill responding-to-incidents -a claude-code`. Or copy the skill folder (secskills-defense/skills/responding-to-incidents in trilwu/secskills) into .claude/skills/responding-to-incidents in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill responding-to-incidents -a codex`. Or copy the skill folder (secskills-defense/skills/responding-to-incidents in trilwu/secskills) into .agents/skills/responding-to-incidents in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill responding-to-incidents -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/responding-to-incidents, .gemini/skills/responding-to-incidents, .github/skills/responding-to-incidents and .opencode/skills/responding-to-incidents in your project.
Going by SKILL.md and its folder, Responding To Incidents needs the command-line tools its instructions call (aws and python3).
SKILL.md names 1 domain. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Responding To Incidents is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Responding To Incidents: Incident Response Lifecycle (LeoYeAI/openclaw-master-skills, 2.2k stars), Extracting Credentials From Memory Dump (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Ransomware Response (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Incident Response (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.