agentsclimarketplace

Contain security incident

Skill gaelic-ghost/socket/skills/contain-security-incident

The Source for macOS Agent Workflows

Install
npx -y skills add gaelic-ghost/socket --skill contain-security-incident

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 6 stars6 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Contain an active or credible cybersecurity incident across hosts, identities, applications, services, cloud resources, networks, or data. Use when ongoing access, execution, exfiltration, fraud, destruction, lateral movement, unsafe service behavior, or repeated compromise must be interrupted with authorized, reversible actions while evidence, business impact, dependencies, communication, and rollback are tracked.

SKILL.md

2.3 KB, 347 tokens by cl100k_base, as published. Nobody here has run it

Contain Security Incident

Overview

Interrupt the validated path of harm with the smallest effective action, then verify the containment. Do not confuse a blocked symptom with eradication or recovery.

Read references/containment-plan.md before making disruptive changes.

Workflow

  1. Confirm incident lead, authority, current scope, harm path, critical services, evidence priorities, and emergency contacts.
  2. Model containment choices.
    • Consider host/network isolation, process/service suspension, account disablement, session/token/key revocation, access-policy change, application feature disablement, route/rule changes, or provider controls.
    • Record expected harm reduction, operational impact, volatile evidence loss, dependencies, rollback, and attacker visibility.
  3. Sequence actions.
    • Address active exfiltration/destruction/safety first, then privileged access, propagation, persistence, and re-entry paths.
    • Coordinate simultaneous identity, host, application, and network actions when staggered changes would alert or strand access.
  4. Apply approved changes.
    • Record exact target, operator, time, command/control surface, result, failures, and unexpected effects.
  5. Verify containment.
    • Check that the harmful path stopped, access/session state changed, affected services remain understood, and monitoring still functions.
  6. Expand scope carefully.
    • Hunt for related indicators and access paths; update the incident record before new targets or actions.
  7. Define exit criteria.
    • State what evidence permits eradication/recovery and what temporary controls must remain.

Output

Return containment objective, options/tradeoffs, actions/results, verification, residual access, business impact, temporary controls, rollback, and next-phase criteria.

What ships with it: 2 files

999 B alongside SKILL.md

agents/

references/

Keep looking

Skills are one crate of 327,069. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.