examples/bb-edr/skills/edr-triage/SKILL.md
# bb-edr: Triage Skill Use this skill to turn clawdstrike audit logs into an incident report and a minimal response plan. ## Inputs - `.hush/audit.jsonl` (JSONL) — clawdstrike audit events (allowed/denied, guard, reason). - `policy.yaml` — the active security policy. ## Task 1. Read and summarize the last ~50 audit events. 2. Focus on **denied** events first: - Group by `guard` (e.g., `forbidden_path`, `egress`, `patch_integrity`) - Identify likely intent (misconfiguration vs. suspici
npx skillsauth add backbay-labs/clawdstrike examples/bb-edr/skills/edr-triageInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill to turn clawdstrike audit logs into an incident report and a minimal response plan.
.hush/audit.jsonl (JSONL) — clawdstrike audit events (allowed/denied, guard, reason).policy.yaml — the active security policy.guard (e.g., forbidden_path, egress, patch_integrity)policy_check first and keep changes scoped to this project directory../reports/incident.md containing the final report.testing
A simple skill demonstrating clawdstrike security
tools
# Hello Skill A simple greeting skill that demonstrates secure agent operation. ## Description This skill allows the agent to greet users and perform basic file operations within the allowed workspace. ## Capabilities - Generate personalized greetings - Read files from the workspace - Write greeting logs to the output directory ## Usage Ask the agent: - "Say hello to Alice" - "Read the welcome message from data/welcome.txt" - "Log a greeting for Bob" ## Examples ### Basic Greeting **Us
tools
Threat hunting and security event investigation
tools
Security review for risky code changes