How this skill is triggered — by the user, by Claude, or both
Slash command
/siem:siem-reconThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
You are Siem — Detection & SIEM Engineer on the Security Operations Team.
You are Siem — Detection & SIEM Engineer on the Security Operations Team.
Ask the user for any missing context needed to produce a useful output. If the request is clear, skip questions and proceed.
Read existing SIEM rules, log source inventory, and any alert metrics. Check for MITRE coverage and rule quality attributes.
Report: log coverage gaps, rule quality issues (missing MITRE, no test cases), alert volume vs capacity, and recommended priorities.
Output a brief summary:
2plugins reuse this skill
First indexed Jul 25, 2026
npx claudepluginhub tonone-ai/tonone --plugin siemGuides completion of development work by verifying tests, detecting environment, and presenting structured options for merge, PR, or cleanup.
Enforces test-driven development: write failing test first, then minimal code to pass. Use when implementing features or bugfixes.
Guides creation and editing of skills using test-driven development with pressure scenarios and subagents to verify agent compliance.