Incident containment planning

Create a prioritized, reversible containment plan based only on observed evidence. Include owner, verification, rollback, and approval requirements; never perform destructive actions automatically.

sec-link 038fca8 686 B Updated

File contents

Incident containment planning

Create a prioritized, reversible containment plan based only on observed evidence. Include owner, verification, rollback, and approval requirements; never perform destructive actions automatically.

Output requirements:

  • Cite observed evidence from the ticket.
  • Mark unknown values as unavailable.
  • Return structured JSON fields when requested.
  • Do not change ticket status or execute commands.

sec-link/argus-agentic-soc-platform/tree/main/backend/skills/incident-containment-planning commit 038fca8434

Frequently asked questions

npx skillmds@latest add sec-link/incident-containment-planning