Group by guard (e.g., forbidden_path, egress, patch_integrity)
Identify likely intent (misconfiguration vs. suspicious)
Produce a short incident report:
What happened (timeline + key indicators)
Impact assessment (what was attempted, what was blocked)
Recommended response (least-privilege)
If you propose any response action (writing files, changing config), use policy_check first and keep changes scoped to this project directory.
Output
Write ./reports/incident.md containing the final report.
Notes (important)
clawdstrike enforces at the tool boundary. It is not an OS sandbox.
If an operation is denied, treat it as a strong indicator of suspicious behavior or incorrect policy assumptions.
1---2name: edr-triage3description: bb-edr: Triage Skill4---5# bb-edr: Triage Skill67Use this skill to turn clawdstrike audit logs into an incident report and a minimal response plan.89## Inputs1011- `.hush/audit.jsonl` (JSONL) — clawdstrike audit events (allowed/denied, guard, reason).12- `policy.yaml` — the active security policy.1314## Task15161. Read and summarize the last ~50 audit events.172. Focus on **denied** events first:18 - Group by `guard` (e.g., `forbidden_path`, `egress`, `patch_integrity`)19 - Identify likely intent (misconfiguration vs. suspicious)203. Produce a short incident report:21 - What happened (timeline + key indicators)22 - Impact assessment (what was attempted, what was blocked)23 - Recommended response (least-privilege)244. If you propose any response action (writing files, changing config), **use `policy_check` first** and keep changes scoped to this project directory.2526## Output2728- Write `./reports/incident.md` containing the final report.2930## Notes (important)3132- clawdstrike enforces at the **tool boundary**. It is not an OS sandbox.33- If an operation is denied, treat it as a strong indicator of suspicious behavior or incorrect policy assumptions.34
Run npx skillmds@latest add gabrielmoreira/edr-triage in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
bb-edr: Triage Skill It is listed under Coding & Dev Tools on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
gabrielmoreira (@gabrielmoreira) published this skill. Their other Agent Skills are listed on their SkillMD profile.