From cybersecurity-skills
Assess whether suspicious evidence indicates a real threat and explain the result in practical language. Use when a person needs a confidence-calibrated conclusion, immediate protective actions, remaining uncertainty, impact, or understandable advice after artifact, endpoint, vulnerability, identity, or incident evidence has been collected.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersecurity-skills:assess-and-explain-threatThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Turn mixed evidence into a proportionate conclusion and advice the affected person can follow. Do not collapse signatures, reputation, scanner output, or unusual behavior into a binary safe/malicious verdict.
Turn mixed evidence into a proportionate conclusion and advice the affected person can follow. Do not collapse signatures, reputation, scanner output, or unusual behavior into a binary safe/malicious verdict.
Read references/confidence-and-advice.md for conclusion vocabulary and the explanation shape.
Restate the decision.
Grade evidence by directness.
Assess behavior and impact.
Choose a calibrated classification.
Give proportionate advice.
Give a plain-language explanation.
Return the conclusion, confidence, decisive evidence, contradictions/gaps, immediate actions, follow-up analysis, and a short non-specialist explanation.
npx claudepluginhub gaelic-ghost/socket --plugin cybersecurity-skillsCreates, edits, and verifies skills using a test-driven development approach with pressure scenarios and subagents.