Assess and explain threat
Skill gaelic-ghost/socket/plugins/cybersecurity-skills/skills/assess-and-explain-threat
The Source for macOS Agent Workflows
npx -y skills add gaelic-ghost/socket --skill assess-and-explain-threatAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 6 stars6 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Assess whether suspicious evidence indicates a real threat and explain it plainly. Use for confidence, protective actions, uncertainty, impact, and advice after artifact, endpoint, identity, or incident evidence.
SKILL.md
2.1 KB, as published. Nobody here has run it
Assess And Explain Threat
Overview
Turn mixed evidence into a proportionate conclusion and advice the affected person can follow. Do not collapse signatures, reputation, scanner output, or unusual behavior into a binary safe/malicious verdict.
Read references/confidence-and-advice.md for conclusion vocabulary and the explanation shape.
Workflow
-
Restate the decision.
- Identify what the user must decide now and what can wait for more evidence.
-
Grade evidence by directness.
- Separate direct observations, reproducible behaviors, vendor or threat-intelligence claims, weak indicators, absence of findings, and speculation.
- Record contradicting evidence and coverage gaps.
-
Assess behavior and impact.
- State what access, execution, persistence, collection, credential use, network behavior, or data exposure is observed or technically plausible.
- Distinguish capability from intent and artifact presence from successful compromise.
-
Choose a calibrated classification.
- Use one classification from the reference and state confidence separately.
- Name the strongest supporting evidence and what would change the conclusion.
-
Give proportionate advice.
- Put urgent harm-reduction actions first.
- Separate containment, evidence preservation, recovery, credential actions, notification, and long-term hardening.
- Avoid destructive cleanup when evidence is weak and reversible isolation is available.
-
Give a plain-language explanation.
- Answer whether the concern is dangerous, what it appears to do, what is known versus inferred, what to do now, and when to escalate.
- Define specialist terms at first use and avoid fear-amplifying language.
Output
Return the conclusion, confidence, decisive evidence, contradictions/gaps, immediate actions, follow-up analysis, and a short non-specialist explanation.