# Secops Orchestrator

> Orchestrates security incident response from triage to post-incident improvement.

- Skill: `nahisaho/secops-orchestrator` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add nahisaho/secops-orchestrator`
- Raw SKILL.md: https://api.skillmd.com/api/skills/nahisaho/secops-orchestrator/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: nahisaho (https://skillmd.com/u/nahisaho)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/nahisaho/secops-orchestrator

---


# secops-orchestrator

## Overview
Orchestrates security incident response from triage to post-incident improvement.

## Orchestration Flow
1) secops-alert-triage -> 2) secops-log-correlation -> 3) secops-root-cause-analysis -> 4) secops-containment-plan -> 5) secops-postmortem-writer

## Input Contract
- Alert metadata and environment scope
- Available logs and detection evidence
- Incident response constraints

## Output Contract
- Incident timeline and root-cause hypothesis
- Containment and recovery actions
- Postmortem with corrective/preventive actions

## Quality Gates
- Upstream outputs are complete and parseable before moving to next skill.
- Each step must include assumptions and confidence levels.
- Final response must include recommended next actions.

## Fallback Policy
- If a sub-skill output is insufficient, request clarification and rerun that step.
- If constraints conflict, present at least two viable alternatives.

---

## Verification Loop (v0.2.0)

```
PLAN   → define scope, inputs, expected outputs
EXECUTE → run skill logic
VERIFY  → check outputs against quality gates
REPORT  → structured result for downstream skills
```

### Quality Gates

- [ ] Explicit assumptions and constraints documented
- [ ] Clear decisions and rationale
- [ ] Actionable next steps provided

