Agent skill

Responding To Incidents

by trilwu in trilwu/secskills

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…

MITAuto-check: notesDevOps & Cloud

Install Responding To Incidents

skills CLI
$ npx skills add trilwu/secskills --skill responding-to-incidents -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills responding-to-incidents --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/responding-to-incidents .claude/skills/responding-to-incidents && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
responding-to-incidents
GitHub stars
157
Token cost
~3.9k tokens
SKILL.md length
1,367 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…

  • Works in 5 steps: Patient zero — first host/account, and… → Every credential the attacker could have… → Every host those credentials touched —… → …
  • Tasks that involve Runbooks and postmortems
  • SKILL.md covers When to Use, When NOT to Use, Route to a Depth Skill and The Order That Matters, plus 11 more sections
  • Calls aws and python3

What it does

Responding To Incidents is an agent skill from trilwu/secskills. Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and postmortem. Use during a suspected compromise, when analyzing a disk or memory image, reconstructing an attacker timeline, or answering how far an intrusion spread.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Runbooks and postmortems, Digital forensics and Incident response. It works with Microsoft 365. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Tasks that involve Runbooks and postmortems
  • Tasks that involve Digital forensics
  • Tasks that involve Incident response

Example prompts

  • “/responding-to-incidents”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Patient zero — first host/account, and initial access vector
  2. Every credential the attacker could have obtained — anything cached,
  3. Every host those credentials touched — pivot through auth logs, not
  4. Persistence inventory — per host and per identity, listed explicitly
  5. Data exposure — what was accessible, what was accessed, what left

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • attack.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Responding To Incidents loads about 3.9k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 1,367 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:90
    sudo ./avml mem.lime                 # or LiME
  • NoteRuns commands with sudoSKILL.md:108
    sudo dd if=/dev/sda bs=4M conv=noerror,sync status=progress | tee image.dd | sha256sum
  • NoteRuns commands with sudoSKILL.md:109
    sudo ewfacquire /dev/sda             # E01 with built-in hashing, preferred
  • NoteRuns commands with sudoSKILL.md:111
    sudo mount -o ro,noexec,noload,loop image.dd /mnt/evidence

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,367 words, ~3,877 tokens.

Download SKILL.mdSave it as .claude/skills/responding-to-incidents/SKILL.md (or your agent's skills folder).
name
responding-to-incidents
description
Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and postmortem. Use during a suspected compromise, when analyzing a disk or memory image, reconstructing an attacker timeline, or answering how far an intrusion spread.
verified
2026-07-27

Responding to Incidents

Two questions drive every incident: how far did they get, and are they still here. Everything else — the malware, the CVE, the root cause — is supporting detail. Answer those two in order and the response follows.

When to Use

  • Suspected or confirmed compromise of a host, account, or cloud tenant
  • Forensic analysis of a disk image, memory capture, or log set
  • Reconstructing what an attacker did and when
  • Scoping blast radius and deciding containment
  • Writing a postmortem or a regulator/customer-facing incident narrative

When NOT to Use

  • Deep analysis of a recovered sample — use analyzing-malware
  • Proactive searching with no known incident — use hunting-threats
  • Deciding whether an alert is even an incident yet — use triaging-security-alerts; response begins once triage confirms a true positive
  • Building the detections that would have caught it — use engineering-detections
  • The incident is in AWS (exposed keys, CloudTrail/GuardDuty) — use investigating-aws-incidents; in Microsoft 365 / Entra — use investigating-m365-entra
  • You have a packet capture to work through — use analyzing-network-traffic
  • Service outages with no security dimension — this is a security IR skill

Route to a Depth Skill

Specific evidence types have their own procedure skill. This skill sets scope and order; reach for these when a single artifact type becomes the focus.

Artifact / focusSkill
A RAM capture to work through with Volatility (injected code, in-memory creds, dead-process connections)analyzing-memory-images
A Microsoft 365 / Entra ID compromise: no disk or memory, only cloud logs (UAL, sign-ins, OAuth grants)investigating-m365-entra
Finding how an attacker persisted on a Linux host — the systematic sweep across every init pathanalyzing-linux-persistence

The Order That Matters

Preparation → Detection & Analysis → Containment → Eradication → Recovery → Lessons Learned
                      ↑__________________|
                    (re-scope after every new finding)

Two rules that are violated constantly and cost the most:

Preserve before you remediate. Rebooting, reimaging, or "just cleaning it up" destroys memory, running process state, and unflushed logs. Once gone, you cannot answer the scoping question, and you will be guessing about whether you got them out.

Do not contain half of it. Partial containment tells the attacker you have noticed and gives them time to re-establish access from the parts you missed. Scope first, then contain everything at once — unless there is active, ongoing damage, in which case stop the damage and accept the trade.

Evidence Acquisition

Order of volatility (RFC 3227 §2.1) — collect top to bottom:

registers, cache
routing table, arp cache, process table, kernel statistics, memory
temporary file systems            ← tmpfs, /dev/shm: staging lives here
disk
remote logging and monitoring data relevant to the system
physical configuration, network topology
archival media

Note that the RFC places memory, the process table, and network state in the same tier rather than ordering them against each other. Modern practice refines that: capture memory first, because the commands you would run to enumerate processes and sockets execute on the box and perturb the memory you have not captured yet. Do not skip the temporary filesystems tier — /dev/shm and tmpfs are ordinary staging locations and they do not survive the reboot that someone will inevitably suggest.

bash
# Memory first, always, on a live suspect host
# Linux
sudo ./avml mem.lime                 # or LiME
# Windows
DumpIt.exe /OUTPUT mem.raw           # or winpmem
# macOS — do NOT reach for osxpmem. Rekall is archived, its last release was
# 2017 and Intel-only, and its kext-based approach is blocked by SIP and
# kext restrictions on Big Sur and later, and on all Apple Silicon. Full-RAM
# capture on a modern Mac realistically needs commercial tooling with the
# required Apple entitlements (e.g. Volexity Surge Collect). If none is
# available, do not stall the response: take process-scoped dumps and a
# comprehensive live-triage collection instead, and record in the incident
# log that full physical memory was not obtainable and why.

# Volatile state before you touch the disk
ps auxwwf; ss -tunap; lsof -n; last -Faiw; w
netstat -anob                        # Windows
Get-NetTCPConnection | Where State -eq Established

# Disk: image, do not analyze in place
sudo dd if=/dev/sda bs=4M conv=noerror,sync status=progress | tee image.dd | sha256sum
sudo ewfacquire /dev/sda             # E01 with built-in hashing, preferred
# Mount read-only, always via a write blocker or loop with `ro`
sudo mount -o ro,noexec,noload,loop image.dd /mnt/evidence

Chain of custody is not paperwork you add later. Record at collection time:

Evidence ID | Source host/serial | Collected by | UTC timestamp | Method/tool+version
SHA-256 at acquisition | SHA-256 at each transfer | Custodian at each handoff | Storage location

Hash immediately, verify after every copy, and never work on the original. If the incident may become litigation or a regulatory matter, involve legal before collection, not after.

Triage Collection

For most incidents, a full disk image per host is too slow. Use targeted collection at scale, then image only the hosts that matter.

bash
# Windows: KAPE with the SANS triage target set
kape.exe --tsource C: --target !SANS_Triage --tdest E:\out --vhdx host01

# Linux/macOS: UAC or a scripted collection
./uac -p full /evidence/host01

# Cloud/EDR: pull the equivalent via API
# - EDR raw telemetry for the window ±7 days
# - Snapshot the volume before terminating any instance
aws ec2 create-snapshot --volume-id vol-xxx --description "IR-<case> preserve"

Artifact Analysis by Question

Go to the artifact that answers your question rather than processing everything.

QuestionWindowsLinuxmacOS
What executed?Prefetch, Amcache, ShimCache, SRUM, Sysmon E1auditd, shell history, /var/log/*, systemd journalExecPolicy DB, /var/db/, unified log
Persistence?Run keys, Services, Scheduled Tasks, WMI subs, startup foldercron, systemd units, .bashrc, ld.so.preload, initLaunchAgents/Daemons, login items, profiles
Lateral movement?4624 type 3/10, 4648, 4672, RDP logs, SMB sharesauth.log, wtmp, .ssh/authorized_keys, known_hostsSame as Linux plus ARD logs
Credential access?LSASS handles (Sysmon E10), 4688 with procdump/etc/shadow reads, ptrace, memory of sshdKeychain access logs
Data staged/exfiltrated?Recycle bin, $MFT timestamps, archive creation, USN journalfind -newermt, large tmp files, tar/zip in historySame
Files accessed?$MFT, $UsnJrnl, LNK, JumpLists, shellbagsatime (if enabled), auditdFSEvents
Browser/download?History DBs, Zone.Identifier ADSBrowser profile DBsQuarantine DB (LSQuarantine)
bash
# Memory analysis — where "are they still here" usually gets answered
vol -f mem.raw windows.pstree
vol -f mem.raw windows.malfind          # injected RWX regions
vol -f mem.raw windows.netscan
vol -f mem.raw windows.cmdline
vol -f mem.raw linux.bash               # recovered shell history

# Filesystem timeline
fls -r -m / image.dd > body.txt && mactime -b body.txt -d > timeline.csv
log2timeline.py --storage-file plaso.db image.dd && psort.py -o dynamic plaso.db > super.csv

Cloud and Identity Incidents

Most modern intrusions run through identity, not malware. Do not stop at the host.

bash
# AWS
aws cloudtrail lookup-events --lookup-attributes AttributeKey=Username,AttributeValue=<user>
# Look for: CreateAccessKey, AttachUserPolicy, AssumeRole chains, ConsoleLogin
# without MFA, GetSecretValue, CreateTrail/StopLogging (anti-forensics)

# Azure / Entra ID
# SigninLogs: impossible travel, legacy auth, unfamiliar device
# AuditLogs: "Add service principal credentials", "Consent to application",
#            "Update conditional access policy", role assignments

# Google Workspace / GCP
# Admin audit: OAuth token grants, mail forwarding rules, delegation changes

Attacker-created OAuth applications, service principal credentials, and mail forwarding rules are the most-missed persistence in cloud incidents. Enumerate them explicitly during eradication.

Timeline Reconstruction

The timeline is the deliverable that everything else supports.

  • UTC everywhere. Normalize on ingest and record the source timezone.
  • Cite the source artifact for every row. An uncited timeline cannot be defended or re-derived.
  • Separate observed from inferred. "Process created (Sysmon E1)" is observed; "attacker pivoted here" is inference. Mark them differently.
  • Beware timestomping. $MFT $STANDARD_INFORMATION is trivially forged; $FILE_NAME is not. Disagreement between them is itself a finding.
  • Establish the earliest evidence of compromise, then look earlier. The first thing you find is almost never the first thing that happened.
UTC Timestamp        | Host    | Event                                  | Source            | O/I
2026-07-12 03:14:02  | WEB01   | POST /upload.aspx 200, 1.2MB, IP x.x.x.x| IIS log           | O
2026-07-12 03:14:40  | WEB01   | w3wp.exe → cmd.exe → whoami            | Sysmon E1         | O
2026-07-12 03:15:05  | WEB01   | Initial access via upload vuln          | correlation       | I
Show full SKILL.md (581 more words)Show less

Scoping

Do not contain until you have answered these, or you will contain the wrong subset:

  1. Patient zero — first host/account, and initial access vector
  2. Every credential the attacker could have obtained — anything cached, typed, stored, or reachable from a compromised host is burned
  3. Every host those credentials touched — pivot through auth logs, not just EDR alerts
  4. Persistence inventory — per host and per identity, listed explicitly
  5. Data exposure — what was accessible, what was accessed, what left

Scoping expands. When a new host appears, restart step 2 for it.

Containment and Eradication

bash
# Contain without destroying evidence
# - Network-isolate via EDR rather than powering off (preserves memory)
# - Revoke sessions and tokens, not just passwords: OAuth grants, refresh
#   tokens, Kerberos TGTs, API keys, SSH keys
# - Disable rather than delete accounts, so the artifacts survive

# Eradication checklist, per compromised identity
#   password reset, MFA re-enrollment, session/token revocation, key rotation
# For AD-wide compromise: krbtgt reset twice, ~10h apart

Reimage rather than clean when the attacker had SYSTEM/root. You cannot prove removal of an implant on a host you do not fully understand, and the cost of being wrong is the whole investigation repeating.

Recovery gates — do not restore until: initial access vector is closed, all identified persistence is removed, credentials are rotated, and detection exists for the observed TTPs. Monitor restored systems at elevated sensitivity for at least a full business cycle.

Rationalizations to Reject

  • "Let's reimage it now and investigate later." Reimaging is the end of the investigation for that host.
  • "Only one host alerted, so only one host is affected." Alerts show detection coverage, not attacker footprint.
  • "We reset the password, the account is safe." Refresh tokens, app passwords, and existing sessions survive a password reset.
  • "The EDR would have caught it." It did not catch the part you are looking at now. Assume gaps and corroborate with independent artifact sources.
  • "AV cleaned it." AV removes a file. It does not remove persistence, credentials, or a second implant.
  • "The logs only go back 7 days, so we can't know." Say that as a scoping limitation in the report. Do not let it become an implicit "nothing happened before day 7."
  • "Let's not write it down until we're sure." Contemporaneous notes are the evidence. Record uncertainty explicitly instead of delaying.

Deliverable

  • Executive summary — what happened, impact, current status, in plain language
  • Timeline — UTC, sourced, observed vs inferred
  • Scope — hosts, accounts, and data, with the basis for each inclusion and exclusion
  • Root cause — the initial access vector and the control that failed
  • Actions taken — containment, eradication, recovery, with timestamps
  • Evidence register — items, hashes, custody
  • Gaps — what could not be determined and why (log retention, no EDR, etc.)
  • Recommendations — prioritized, each tied to a specific failure in the narrative

Postmortems are blameless: they analyze the control and process failures, not the person who clicked. A postmortem that names an individual as the cause produces silence in the next incident.

<!-- attack:start -->

ATT&CK Coverage

Generated from secskills-core/ttp-index.json — edit that file, then run python3 scripts/sync_attack.py --write. Re-verify IDs against the current ATT&CK release before citing them in a report.

Persistence (TA0003)

  • T1098.001 Additional Cloud Credentials — see also exploiting-cloud-platforms
  • T1098.002 Additional Email Delegate Permissions

Defense Evasion (TA0005)

  • T1070 Indicator Removal
  • T1070.001 Clear Windows Event Logs — see also hunting-threats
  • T1070.006 Timestomp
  • T1562 Impair Defenses — see also hunting-threats
  • T1562.001 Disable or Modify Tools — see also hunting-threats

Collection (TA0009)

Impact (TA0040)

  • T1485 Data Destruction
  • T1486 Data Encrypted for Impact — see also analyzing-malware
  • T1489 Service Stop
  • T1490 Inhibit System Recovery — see also hunting-threats

Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.

<!-- attack:end -->

References

  • analyzing-malware — sample analysis feeding scoping and IOCs
  • hunting-threats — proactive search using the TTPs found here
  • engineering-detections — closing the detection gap this incident exposed
  • NIST SP 800-61r3 (incident handling), SP 800-86 (forensic techniques), RFC 3227
  • Volatility 3, Plaso/log2timeline, KAPE, Velociraptor, TheHive as core tooling

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-defense/skills/responding-to-incidents of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Responding To Incidents next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Responding To Incidents compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Responding To Incidents this skilltrilwu/secskills157—~3.9kAutomated safety check: NotesMIT
Incident Response LifecycleLeoYeAI/openclaw-master-skills2.2k—~5kAutomated safety check: PassApache-2.0
Extracting Credentials From Memory Dumpmukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.0
Performing Ransomware Responsemukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Incident Responsealirezarezvani/claude-skills28k—~3.8kAutomated safety check: PassMIT
Parsing Artifacts With Eric Zimmerman Toolsmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Incident Response Lifecycle

    LeoYeAI/openclaw-master-skills

    Incident response process management following the NIST 800-61 lifecycle.

    2.2k GitHub stars~5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Extracting Credentials From Memory Dump

    mukul975/Anthropic-Cybersecurity-Skills

    Extracts cached credentials, password hashes, Kerberos tickets, and authentication tokens from Windows memory dumps using Volatility 3, Mimikatz, and pypykatz.

    34k GitHub stars~3.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Performing Ransomware Response

    mukul975/Anthropic-Cybersecurity-Skills

    Executes a structured ransomware incident response from detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening, covering ransom negotiation…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Response

    alirezarezvani/claude-skills

    A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.

    28k GitHub stars~3.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Parsing Artifacts With Eric Zimmerman Tools

    mukul975/Anthropic-Cybersecurity-Skills

    Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Soc Operations

    briiirussell/cybersecurity-skills

    Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst…

    413 GitHub stars~2.9k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Responding To Incidents

What does Responding To Incidents do?

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…. Responding To Incidents is an agent skill from trilwu/secskills. Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and postmortem.

When should I use Responding To Incidents?

Responding To Incidents fits situations like: tasks that involve Runbooks and postmortems; tasks that involve Digital forensics; tasks that involve Incident response.

How do I install Responding To Incidents in Claude Code?

Run `npx skills add trilwu/secskills --skill responding-to-incidents -a claude-code`. Or copy the skill folder (secskills-defense/skills/responding-to-incidents in trilwu/secskills) into .claude/skills/responding-to-incidents in your project. Claude Code loads it when a task matches its description.

How do I install Responding To Incidents in Codex?

Run `npx skills add trilwu/secskills --skill responding-to-incidents -a codex`. Or copy the skill folder (secskills-defense/skills/responding-to-incidents in trilwu/secskills) into .agents/skills/responding-to-incidents in your project. Codex loads it when a task matches its description.

Can I use Responding To Incidents in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill responding-to-incidents -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/responding-to-incidents, .gemini/skills/responding-to-incidents, .github/skills/responding-to-incidents and .opencode/skills/responding-to-incidents in your project.

What does Responding To Incidents need to run?

Going by SKILL.md and its folder, Responding To Incidents needs the command-line tools its instructions call (aws and python3).

Does Responding To Incidents access the network?

SKILL.md names 1 domain. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.

Is Responding To Incidents safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Responding To Incidents use?

Responding To Incidents is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Responding To Incidents use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Responding To Incidents?

Skills that share tags, products or a category with Responding To Incidents: Incident Response Lifecycle (LeoYeAI/openclaw-master-skills, 2.2k stars), Extracting Credentials From Memory Dump (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Ransomware Response (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Incident Response (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Responding To Incidents?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.