Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: bootstrap-skills-plugin-repo
description: Bootstrap or align a source-first Agent Skills repository with root `skills/`, repo-local discovery mirrors, maintainer docs, and clear Codex plugin-boundary wording. Use when creating a new skills repo or structurally aligning an existing one. Do not use this for narrow README-only, roadmap-only, or host-adapter design work.
description: Bootstrap or align a source-first Agent Skills repository with root `skills/`, discovery mirrors, maintainer docs, and explicit Codex plugin boundaries. Use for new skills repos or structural alignment, not narrow docs or host-adapter work.
metadata:
hermes:
category: agent-portability
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: sync-skills-repo-guidance
description: Audit guidance across AGENTS.md, optional README.md, maintainer docs, and discovery mirrors in an existing Agent Skills or Codex plugin repository. Use when a skills repo may have stale guidance, missing discovery mirrors, outdated OpenAI Codex policy, or unclear boundaries between portable skills and host-specific plugin surfaces. Defer narrow README-only, roadmap-only, or host-adapter design requests to the specialized maintainer skills.
description: Audit Agent Skills or Codex plugin guidance and discovery mirrors. Use for stale policy, missing mirrors, or unclear portable-skill and host-plugin boundaries; defer narrow docs work.
metadata:
hermes:
category: agent-portability
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: analyze-suspicious-script-or-document
description: Decode and analyze suspicious scripts and active documents without triggering them. Use for shell, AppleScript, JavaScript, Python, PowerShell, shortcuts, Office files, PDFs, configuration profiles, encoded commands, macros, embedded objects, external templates, staged downloads, or mixed document-to-script payload chains.
description: Decode and analyze suspicious scripts and active documents without triggering them. Use for shell, AppleScript, JavaScript, Python, PowerShell, shortcuts, Office files, PDFs, profiles, macros, embedded objects, and staged payloads.
---

# Analyze Suspicious Script Or Document
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: assess-and-explain-threat
description: Assess whether suspicious evidence indicates a real threat and explain the result in practical language. Use when a person needs a confidence-calibrated conclusion, immediate protective actions, remaining uncertainty, impact, or understandable advice after artifact, endpoint, vulnerability, identity, or incident evidence has been collected.
description: Assess whether suspicious evidence indicates a real threat and explain it plainly. Use for confidence, protective actions, uncertainty, impact, and advice after artifact, endpoint, identity, or incident evidence.
---

# Assess And Explain Threat
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: assess-exposure-and-impact
description: Prioritize a validated or plausible vulnerability using actual asset exposure and impact. Use when affected versions, deployment reachability, attacker prerequisites, privileges, sensitive data, exploit maturity, CISA KEV status, vendor guidance, mitigations, detection, business criticality, CVSS, and remediation urgency must be combined without relying on a severity score alone.
description: Prioritize a vulnerability using actual asset exposure and impact. Use when versions, reachability, prerequisites, privileges, data, exploit maturity, mitigations, detection, business criticality, and urgency matter beyond CVSS.
---

# Assess Exposure And Impact
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: assess-macos-threat
description: Assess a suspected macOS security threat using exact host, artifact, and platform evidence. Use for suspicious apps, packages, processes, prompts, downloads, profiles, extensions, XProtect or Gatekeeper alerts, account behavior, persistence, privacy access, or unexpected network activity when signing, notarization, quarantine, TCC, SIP, and observed behavior must remain distinct.
description: Assess a suspected macOS threat using exact host and artifact evidence. Use for suspicious apps, processes, downloads, profiles, extensions, alerts, persistence, privacy, or network activity while keeping protections distinct.
---

# Assess macOS Threat
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: author-detection-content
description: Turn validated security behavior into tested detection content. Use for Sigma, osquery, YARA-X routing, endpoint queries, SIEM rules, cloud or application detections, correlation logic, alert enrichment, or regression fixtures when telemetry prerequisites, provenance, expected matches, benign negatives, false-positive controls, performance, severity, response, deployment, and maintenance ownership must be explicit.
description: Turn validated security behavior into tested detection content. Use for Sigma, osquery, YARA-X, endpoint or SIEM queries, cloud detections, correlation, alert enrichment, and fixtures with explicit telemetry and false-positive controls.
---

# Author Detection Content
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: author-yara-x-rules
description: Author, test, tune, and document YARA-X detection rules from validated artifact evidence. Use when malware, suspicious files, scripts, documents, or binary features need local pattern detection with stable discriminators, metadata, positive and negative fixtures, performance checks, false-positive review, rule provenance, and regression testing.
description: Author, test, tune, and document YARA-X rules from validated artifact evidence. Use when suspicious files, scripts, documents, or binary features need local detection with stable patterns, fixtures, performance checks, and regression tests.
---

# Author YARA-X Rules
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: check-artifact-reputation
description: Check local and external reputation for a suspicious artifact, signer, hash, URL, domain, certificate, package, or vendor. Use when provenance and threat-intelligence context could inform triage, while sample-upload privacy, stale intelligence, hash-only misses, false positives, and reputation-versus-behavior limits must remain explicit.
description: Check reputation for a suspicious artifact, signer, hash, URL, domain, certificate, package, or vendor. Use when threat intelligence informs triage while privacy, stale data, false positives, and behavior limits stay explicit.
---

# Check Artifact Reputation
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: contain-and-recover-macos
description: Contain a suspected or confirmed macOS threat and verify recovery. Use when a Mac may need network isolation, process or service containment, account and credential response, persistence removal, artifact quarantine, backup/restore, erase/reinstall, monitoring, or return-to-service decisions while evidence loss, user impact, and platform protections remain explicit.
description: Contain a macOS threat and verify recovery. Use for isolation, process or service containment, credential response, persistence removal, quarantine, restore, erase/reinstall, monitoring, and return-to-service decisions.
---

# Contain And Recover macOS
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: contain-security-incident
description: Contain an active or credible cybersecurity incident across hosts, identities, applications, services, cloud resources, networks, or data. Use when ongoing access, execution, exfiltration, fraud, destruction, lateral movement, unsafe service behavior, or repeated compromise must be interrupted with authorized, reversible actions while evidence, business impact, dependencies, communication, and rollback are tracked.
description: Contain an active or credible incident across hosts, identities, applications, cloud resources, networks, or data. Use when access, execution, exfiltration, fraud, destruction, or repeated compromise needs authorized interruption.
---

# Contain Security Incident
Expand Down
2 changes: 1 addition & 1 deletion plugins/cybersecurity-skills/skills/harden-macos/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: harden-macos
description: Review and improve macOS defensive posture after a threat assessment, incident, or general security request. Use for updates, XProtect/Gatekeeper posture, FileVault, firewall and sharing, remote access, accounts, login/background items, profiles/extensions, browser safety, privacy permissions, backups, credential habits, and monitoring while preserving usability and managed-device policy.
description: Review and improve macOS defensive posture. Use for updates, XProtect and Gatekeeper, FileVault, firewall, remote access, accounts, background items, privacy, backups, credentials, and monitoring after a security assessment or incident.
---

# Harden macOS
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: hunt-security-indicators
description: Hunt scoped systems and telemetry for supplied security indicators or behaviors. Use for hashes, paths, domains, addresses, certificates, accounts, processes, commands, persistence, ATT&CK behaviors, cloud or application events, or incident expansion when data sources, time window, query logic, coverage, false positives, privacy, and follow-up validation must be explicit.
description: Hunt scoped systems and telemetry for supplied indicators or behaviors. Use for hashes, paths, domains, addresses, accounts, processes, persistence, ATT&CK behaviors, cloud events, or incident expansion with explicit scope and validation.
---

# Hunt Security Indicators
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: inspect-macos-persistence
description: Inspect macOS persistence and recurring execution without deleting evidence. Use for suspicious login items, background items, launch agents or daemons, system or network extensions, configuration profiles, shell startup files, scheduled tasks, browser extensions, helper tools, app registrations, or startup behavior that may survive logout, reboot, or application exit.
description: Inspect macOS persistence and recurring execution without deleting evidence. Use for login items, launch agents or daemons, extensions, profiles, shell startup files, scheduled tasks, browser extensions, helpers, and startup behavior.
---

# Inspect macOS Persistence
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: inspect-macos-runtime-activity
description: Correlate suspicious macOS process, file, network, permission, and log activity. Use for unexpected processes, child execution, downloads, open files, DNS/connections, privacy prompts, XProtect or Gatekeeper events, file mutations, injected or deleted executables, and Endpoint Security or eslogger evidence when exact permissions and telemetry gaps must remain visible.
description: Correlate suspicious macOS process, file, network, permission, and log activity. Use for unexpected processes, downloads, open files, DNS, privacy prompts, alerts, file mutations, injected executables, and Endpoint Security evidence.
---

# Inspect macOS Runtime Activity
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: map-malware-behavior
description: Map observed or strongly evidenced malicious behavior to current MITRE ATT&CK techniques and platform context. Use when static or dynamic analysis, endpoint telemetry, incident evidence, or a malware report needs a behavior map for detection, response, comparison, or communication without inferring an actor, campaign, family, or complete attack chain from labels alone.
description: Map observed malicious behavior to MITRE ATT&CK techniques. Use when analysis, telemetry, incident evidence, or a report needs a behavior map for detection, response, or communication without inferring an actor or campaign.
---

# Map Malware Behavior
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: operate-agentic-security-tools
description: Operate security tools through an AI agent with explicit authority and evidence boundaries. Use when an agent may invoke local CLIs, GUI apps, browser automation, MCP servers, remote scanners, sandboxes, vulnerability tools, packet tools, or containment actions and permissions, mounts, network, secrets, approvals, logging, output, and cleanup must be constrained.
description: Operate security tools through an AI agent with explicit authority boundaries. Use when an agent may invoke CLIs, GUI apps, browser automation, MCP servers, scanners, sandboxes, or containment actions with constrained approvals and logging.
---

# Operate Agentic Security Tools
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: perform-dynamic-malware-analysis
description: Observe suspicious content in a disposable, instrumented environment. Use when execution, process ancestry, file changes, persistence, network behavior, configuration decryption, child payloads, environment gates, or user interaction must be measured after static analysis and an isolation boundary, authorization, baseline, stop conditions, evidence export, and teardown plan are explicit.
description: Observe suspicious content in a disposable environment. Use when execution, process ancestry, file changes, persistence, network behavior, payloads, or user interaction need measurement after static analysis with isolation and teardown.
---

# Perform Dynamic Malware Analysis
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: perform-static-malware-analysis
description: Analyze a suspicious artifact for capabilities without executing it. Use for binaries, apps, packages, archives, scripts, libraries, extensions, firmware, or embedded payloads when metadata, signatures, imports, strings, resources, configuration, rules, obfuscation, and likely behavior must be inspected and deep binary work may hand off to reverse-engineering-skills.
description: Analyze a suspicious artifact without executing it. Use for binaries, apps, packages, archives, scripts, libraries, extensions, firmware, or payloads when metadata, signatures, imports, strings, resources, and obfuscation need inspection.
---

# Perform Static Malware Analysis
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: preserve-security-evidence
description: Preserve and document security evidence before analysis, containment, or remediation changes it. Use for suspicious artifacts, volatile host state, vulnerability validation, incident records, logs, screenshots, commands, hashes, timelines, transformations, and analyst handoffs that need reproducible provenance without claiming legal-forensics certification.
description: Preserve security evidence before analysis, containment, or remediation changes it. Use for artifacts, volatile host state, vulnerability validation, records, logs, screenshots, commands, hashes, timelines, and reproducible handoffs.
---

# Preserve Security Evidence
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: recover-security-incident
description: Eradicate verified compromise mechanisms, restore trusted service, and monitor after a cybersecurity incident. Use when affected hosts, identities, applications, cloud resources, network controls, or data need rebuild/restore, patching, secret rotation, configuration repair, validation, staged return to service, temporary-control removal, lessons learned, and residual-risk ownership.
description: Recover from an incident by eradicating compromise and restoring service. Use when hosts, identities, applications, cloud resources, network controls, or data need rebuild, patching, rotation, repair, validation, and return to service.
---

# Recover Security Incident
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: report-security-assessment
description: Write a reproducible security assessment or penetration-test report from validated evidence. Use when technical findings, negative results, scope, methodology, limitations, exposure, impact, confidence, remediation, retest criteria, evidence handling, and a plain-language executive explanation must be assembled without overstating scanner output or untested coverage.
description: Write a security assessment or penetration-test report from evidence. Use when findings, scope, methodology, limitations, impact, remediation, retest criteria, and an executive explanation need calibrated reporting.
---

# Report Security Assessment
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: route-security-work
description: Route an ambiguous cybersecurity request before tools run. Use for suspicious files, links, messages, host behavior, malware questions, vulnerability reports, authorized pentests, security incidents, threat hunting, detection work, or security advice when the correct workflow and specialist owner are not yet clear.
description: Route an ambiguous cybersecurity request before tools run. Use for suspicious files, links, messages, host behavior, malware, vulnerability reports, authorized pentests, incidents, threat hunting, detection work, or security advice.
---

# Route Security Work
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: scope-authorized-security-test
description: Define and verify authorization, targets, rules of engagement, data handling, safety controls, and stop conditions before active security testing. Use for penetration tests, vulnerability scans, exploit validation, web/API tests, network probing, red-team-like exercises, bug bounty work, or agent-driven testing where ownership and allowed techniques must be explicit.
description: Define authorization, targets, rules, safety controls, and stop conditions before active security testing. Use for penetration tests, scans, exploit validation, web or API tests, network probing, bug bounty, or agent-driven testing.
---

# Scope Authorized Security Test
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: select-analysis-isolation
description: Select and configure an isolation boundary before inspecting or executing untrusted content. Use when choosing among local read-only analysis, a disposable container, Linux VM, macOS VM, remote sandbox, or spare physical device and deciding network, mount, clipboard, credential, device, snapshot, evidence-export, and teardown controls.
description: Select isolation before inspecting or executing untrusted content. Use for local analysis, a container, Linux or macOS VM, remote sandbox, or spare device with defined network, mounts, credentials, snapshots, evidence export, and teardown.
---

# Select Analysis Isolation
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: test-network-services
description: Inventory and test explicitly authorized network services with bounded discovery and protocol-aware validation. Use for approved hosts, address ranges, ports, TLS, banners, service versions, authentication, exposure, segmentation, configuration, packet evidence, or narrowly reviewed vulnerability checks when rate, source, third-party boundaries, and stop conditions are explicit.
description: Test authorized network services with bounded discovery and protocol-aware validation. Use for hosts, ranges, ports, TLS, banners, versions, authentication, exposure, segmentation, configuration, packet evidence, or vulnerability checks.
---

# Test Network Services
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: test-web-and-api-security
description: Test an explicitly authorized web application or API using current OWASP guidance and bounded manual or automated checks. Use for authentication, authorization, session, input, browser, API schema, business logic, file handling, server-side request, configuration, transport, error, and data-exposure tests when accounts, roles, target, rate, evidence, and stop conditions are defined.
description: Test an authorized web application or API using OWASP guidance. Use for authentication, authorization, sessions, input, schemas, business logic, file handling, server-side requests, configuration, transport, errors, and data exposure.
---

# Test Web And API Security
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: triage-security-incident
description: Triage a suspected cybersecurity incident across endpoints, identities, applications, services, cloud resources, networks, or data. Use when an alert, report, compromise indicator, service disruption, unauthorized access, malware event, credential concern, or data exposure needs an incident owner, affected scope, urgency, evidence plan, immediate harm-reduction decision, and communication path.
description: Triage a suspected incident across endpoints, identities, applications, cloud resources, networks, or data. Use when an alert, compromise, disruption, unauthorized access, malware, credential concern, or exposure needs scope and ownership.
---

# Triage Security Incident
Expand Down
Loading