npx claudepluginhub funnywolf/agentic-soc-platform --plugin ASPThis skill uses the workspace's default tool permissions.
当用户要在 ASP 中处理 playbook 自动化时,使用这个 skill。
Manages ASP playbooks: lists definitions, executes on cases/alerts/artifacts with optional user input, inspects run records by target or status.
Designs structured incident response playbooks for cybersecurity incidents using NIST SP 800-61r3 and SANS PICERL frameworks. Covers RACI matrices, escalation, decision trees, SOAR integration.
Designs structured incident response playbooks for specific incident types using NIST SP 800-61r3 and SANS PICERL frameworks. Covers RACI matrices, decision trees, escalation, and SOAR integration.
Share bugs, ideas, or general feedback.
当用户要在 ASP 中处理 playbook 自动化时,使用这个 skill。
list_available_playbook_definitions 只用于查询可运行的 definition。list_playbook_runs 只用于查询运行记录。execute_playbook。user_input 视为该次运行的自然语言补充说明,而不是通用聊天提示。list_available_playbook_definitions。list_playbook_runs(source_id=<target_id>, type=[<target_type>])。execute_playbook。list_available_playbook_definitions。list_playbook_runs。list_available_playbook_definitions。首选回复结构:
| Definition Name | Likely Target | Purpose |
|---|
target_type、target_id 和 playbook definition name。list_available_playbook_definitions。user_input。execute_playbook(type=<target_type>, record_id=<target_id>, name=<definition_name>, user_input=<optional>)。首选回复结构:
Target:类型和 IDPlaybook Definition:选定的名称Run Status:创建时通常为 pending,除非平台返回其他状态User Input:仅在提供时展示Next Useful Step:通常是继续查询相关 playbook runplaybook_id、job_status、type、source_id、limit。source_id。list_playbook_runs。首选回复结构:
| Run ID | Type | Target ID | Job Status | Definition Name | Updated |
|---|
然后在需要时补一句简短解释。
target_type 和 target_id。list_playbook_runs,而不是猜某条具体 run。