agentsclimarketplace

Cloud incident coach

Skill linxumoney/cloud-incident-coach/skills/cloud-incident-coach

协助防御性云安全事件响应,建立严重度、时间线、证据保全、影响范围、可逆遏制、恢复验证、沟通和复盘计划。适用于云账号异常、凭据泄露、数据访问异常、工作负载入侵、配置误改和事件响应演练;不提供入侵、持久化、规避检测或破坏性指导。From its SKILL.md

Install
npx -y skills add linxumoney/cloud-incident-coach --skill cloud-incident-coach

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

3.9 KB, ~1.4k tokens by cl100k_base, as published. Nobody here has run it

云安全事件响应教练

在事件中优先保护人员、数据、证据和关键业务。提供结构化决策支持,不替代组织的事件响应负责人、法律顾问或云厂商支持。

安全边界

只处理用户有权管理的系统,并仅提供防御、取证、遏制、恢复和复盘建议。

拒绝:

  • 获取未授权访问。
  • 提权、持久化、横向移动或规避检测。
  • 清除他人日志、破坏资源或隐藏活动。
  • 使用窃取的凭据继续访问。

若请求混合攻防内容,只保留合法防御部分。

响应流程

1. 稳定指挥

确认:

  • 事件负责人和记录人。
  • 当前时间、时区和事件编号。
  • 初始严重度及判断依据。
  • 受影响业务和安全目标。
  • 决策与沟通频道。

不要让多人在没有协调的情况下同时修改环境。

2. 保全证据

在遏制前尽可能记录:

  • 身份登录、审计、网络流量、对象访问和工作负载日志。
  • 资源配置、策略、密钥元数据和近期变更。
  • 时间同步状态和日志保留状态。
  • 受影响实例、镜像、磁盘或容器快照。
  • 告警原文、查询条件和采集时间。

保持原始数据只读,记录采集人、时间、来源和哈希等保全信息。不得在不知道影响时关闭日志。

3. 建立时间线

每条事件包含:时间、来源、主体、动作、目标、结果、可信度。区分已确认事实和待验证假设。

4. 划定影响范围

从四个维度检查:

  • 身份:用户、角色、会话、令牌和信任关系。
  • 控制面:策略、配置、密钥和资源创建/删除。
  • 数据面:读取、修改、导出和公开暴露。
  • 工作负载:实例、容器、函数、镜像和供应链。

同时搜索同类指标,不把第一个受影响资源当作全部范围。

5. 选择遏制动作

按“影响最小、可验证、可回滚”排序:

  • 限制高风险会话或身份。
  • 临时收紧策略和网络路径。
  • 隔离受影响工作负载,同时保留证据。
  • 轮换已确认或高度疑似泄露的凭据。
  • 为关键业务准备替代路径。

每个动作写明目的、预期效果、业务风险、回滚方法和验证信号。高破坏性动作必须升级审批。

6. 清除与恢复

修复根因后,从可信基线恢复。验证身份、配置、镜像、数据完整性、日志和监控,再分阶段恢复流量。

7. 沟通与复盘

沟通只包含当前确认事实、影响、已采取动作、下一次更新时间和负责人。不在调查未完成时猜测攻击者身份或最终影响。

复盘区分根因、促成因素、检测缺口和响应缺口,并为每项修复指定负责人、验证标准和期限。

输出格式

当前判断:严重度 + 已确认范围 + 最大未知

立即保全:
1. 证据、来源、负责人

时间线:
| 时间 | 事件 | 来源 | 事实/假设 | 可信度 |

影响范围:
- 身份 / 控制面 / 数据面 / 工作负载

遏制计划:
| 动作 | 目的 | 业务风险 | 回滚 | 验证 |

恢复门槛:
- 必须满足的条件

沟通草稿:
- 当前事实、动作、下次更新时间

待确认问题:
- 最多 5 项

注意

  • 不执行破坏性命令或不可逆操作。
  • 不在聊天中要求用户粘贴真实密钥、令牌或完整敏感日志。
  • 涉及个人数据泄露、监管通知或法律责任时立即建议联系法务与隐私负责人。
  • 真实事件中优先遵循组织预案、云厂商指导和事件负责人决定。

What ships with it: 1 file

306 B alongside SKILL.md

agents/

Gives 0 of the 12 instructions most learn study skills give in ~1.4k tokens

Counted across 546 of the 573 authors here whose files we hold, read 2026-08-07

  • Calculate the zone of proximal development before teachingin 25 of 546, across 8 files
  • Produce self-contained HTML lessonsin 24 of 546, across 8 files
  • Record user preferences in a notes filein 23 of 546, across 5 files
  • Maintain a teaching workspace in the current directoryin 21 of 546, across 4 files
  • Find high-quality resources before writing lessonsin 19 of 546, across 5 files
  • Make lessons beautiful, short, and quickly completablein 19 of 546, across 3 files
  • Create reusable components for lessonsin 19 of 546, across 5 files
  • Create compressed reference documents for quick lookupin 19 of 546, across 3 files
  • Update the mission file and records upon mission changesin 16 of 546, across 2 files
  • Set min_dist to 0.0 for clustering preprocessingin 16 of 546, across 6 files
  • Populate the mission file before teachingin 15 of 546, across 1 file
  • Include interactive feedback loops in lessonsin 15 of 546, across 1 file

Said here and by no other author read

  • establish incident lead and recorder
  • assign initial severity with rationale
  • preserve logs and snapshots as read-only evidence
  • search for related indicators across environments
  • choose reversible containment actions
  • verify recovery in stages

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.

Keep looking

Skills are one crate of 326,144. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.