← all publishers

orcasecurity

@orcasecurity source repo

20 published skills

  1. Orca Investigate · orcasecurity
    CDR-powered incident investigation — traces actor activity, builds session timelines, maps MITRE ATT&CK techniques, and assesses blast radius from cloud audit logs. Use when user asks to investigate activity, trace an actor, or analyze an incident (e.g., "investigate bastion-admin", "trace activity", "what did anika do", "incident investigation").
    0 installs
  2. Orca Alert Triage · orcasecurity
    Analyzes Orca Security alerts with timeline visualization, risk assessment, and progressive disclosure. Use when user asks to triage, analyze, explain, summarize, investigate, or check an Orca alert by ID (e.g., "triage orca-3636513", "what is alert orca-3548863", "check orca-3636513").
    0 installs
  3. Orca Exposure Map · orcasecurity
    External attack surface mapping — internet-facing assets ranked by risk, exposed ports/services, and attacker's-eye view of the environment. Use when user asks about attack surface, exposure, or external view (e.g., "exposure map", "attack surface", "what's exposed", "internet-facing", "external view").
    0 installs
  4. Orca Asset Profile · orcasecurity
    Full 360° security profile of any cloud asset — alerts, attack paths, compliance, permissions, exposure, sensitive data, and CDR activity in one view. Use when user asks about an asset's security posture or profile (e.g., "asset profile for web-bastion-host", "tell me about WEB-PRD", "security posture of", "show me everything about").
    0 installs
  5. Orca Config Origin · orcasecurity
    Traces any Orca alert back to who deployed it, what tool was used, what introduced the issue, and a full timeline of events. Use when user asks about origin, deployment, or ownership of an alert (e.g., "who created this", "where did this come from", "trace back orca-3380725", "who deployed", "what tool was used").
    0 installs
  6. Orca Data Exposure · orcasecurity
    DSPM view — sensitive data at risk across the environment, exposed secrets/PII/credentials, data store security posture, and remediation priorities. Use when user asks about data exposure, sensitive data, or secrets (e.g., "data exposure", "where is our PII", "sensitive data at risk", "exposed secrets", "DSPM view").
    0 installs
  7. Orca Account Health · orcasecurity
    Cloud account coverage and sync-health audit — lists every connected cloud account, sync status, scanner deployment, integration health, and flags blind spots before any audit, investigation, or security review. Use when user asks about coverage, account health, sync status, scanner deployment, "are we monitoring X", or "do we have full coverage" (e.g., "account health", "are all accounts connected", "is everything synced", "coverage audit").
    0 installs
  8. Orca Compliance Gap · orcasecurity
    Deep-dive compliance gap analysis for any framework — failing controls ranked by impact, quick wins, account breakdown, and remediation plan. Use when user asks about compliance gaps, failures, or status (e.g., "compliance gaps", "PCI DSS status", "where are we failing", "SOC 2 compliance", "quick wins").
    0 installs
  9. Orca Identity Review · orcasecurity
    Analyzes any cloud identity for overprivileged access, actual usage patterns, lateral movement risk, and least-privilege recommendations. Use when user asks about identity permissions, overprivileged access, or IAM review (e.g., "identity review for anika", "is this role overprivileged", "review permissions", "IAM analysis").
    0 installs
  10. Orca Impact Analysis · orcasecurity
    Analyzes the full impact of fixing an Orca alert — what closes, what breaks, and what the environment looks like after the fix. Use when user asks about impact, consequences, or blast radius of fixing an alert (e.g., "what's the impact of fixing orca-3380725", "if I fix this what breaks", "what else closes").
    0 installs
  11. Orca Mfa Enforcement · orcasecurity bundle
    Finds users who can sign in without MFA across an account, business unit, or tag, ranks them by identity risk, and drives guided enrollment or gated enforcement. Use for MFA or 2FA gaps, root-account MFA, and MFA coverage evidence for an audit.
    0 installs
  12. Orca Custom Framework · orcasecurity
    Creates custom compliance frameworks from existing frameworks, alert lists, or security themes — organizes controls into sections, maps alerts, and pushes the framework to Orca. Suggests creating custom discovery alerts for gaps not covered by existing rules. Use when user asks to create, build, or generate a custom compliance framework.
    0 installs
  13. Orca Cve Blast Radius · orcasecurity
    CVE blast-radius analysis — given a single CVE-ID, find every affected asset across all accounts, rank by real exposure (internet-facing, attack-path participant, crown jewel) instead of static CVSS. Use when user asks about a specific CVE's environmental impact (e.g., "blast radius of CVE-2024-1234", "where are we affected by Log4Shell", "which assets have CVE-2021-44228", "who is exposed to CVE-XXXX").
    0 installs
  14. Orca Morning Briefing · orcasecurity
    Daily security briefing summarizing new critical alerts, attack paths, compliance drift, exposure changes, and aging unactioned alerts from the last 24-72 hours. Use when user asks for a briefing, summary, or overview (e.g., "morning briefing", "what happened", "security summary", "daily report", "what needs attention").
    0 installs
  15. Orca Cloud Cost Optimizer · orcasecurity
    Cloud cost optimization analysis using Orca Security asset data. Discovers all cloud assets (AWS, GCP, Azure) through Orca MCP tools, compares current configurations against cheaper alternatives using live public pricing, and produces a prioritized cost reduction report with exact asset evidence. Use when the user asks about cloud cost optimization, reducing cloud spend, rightsizing instances, saving money on cloud infrastructure, cost reduction opportunities, unused resources, oversized VMs, reserved instances, storage tiering, or wants to know what changes would lower their cloud bill.
    0 installs
  16. Orca Admin Access Grouping · orcasecurity bundle
    Admin access grouping - fetches Orca's pre-computed admin clustering (IAM Policy Optimizer) for AWS, Azure, and GCP, groups every admin identity into a small number of shared least-privilege policies that replace blanket AdministratorAccess / Owner, and drives the swap through a staged, confirmation-gated apply. Use when the user wants to group or tier their admins, cut down how many people hold full admin, replace AdministratorAccess with role-based policies, or see how few policies their admin population actually needs. Scoped to grouping the admin population org-wide into shared policies - it takes no account, business unit, or tag as scope. Right-sizing individual identities within an account, business unit, or tag belongs to orca-overprivileged-identities-rightsizing; a single named identity's permission review belongs to orca-identity-review.
    0 installs
  17. Orca Supply Chain Exposure · orcasecurity
    Supply chain exposure check — given a list of suspect packages (e.g. an MDR advisory like the @antv/* npm campaign), find which versions are deployed across the environment, which match the vulnerable range, and which assets carry them. Use when user asks about supply chain risk, package exposure, IOC package check, malicious package, or "are we running X" (e.g., "are we exposed to the @antv attack", "any assets with left-pad", "check these npm packages", "supply chain check").
    0 installs
  18. Orca K8S Connector Troubleshoot · orcasecurity
    Diagnoses Kubernetes Connector (K8s Tunnel Client / Helm chart `orca-tunnel`) install and connectivity failures from raw customer input — error text, `helm status`, `kubectl describe`, or pod logs — and walks through step-by-step remediation. Use when a user reports the K8s Connector won't install, won't connect, keeps disconnecting, or the cluster shows connected but no scan data appears.
    0 installs
  19. Orca Inactive Identities Cleanup · orcasecurity
    Inactive-identity cleanup - finds inactive identities (users, groups, and non-human identities) across an account, business unit, or tag in every cloud provider Orca supports (AWS, Azure incl. Entra ID, GCP incl. Google Workspace, Alibaba Cloud, OCI, Tencent Cloud), ranks them by identity risk score (highest risk first), and drives remediation through a non-destructive path (disable) or a destructive path (delete) that always requires explicit confirmation. Asks for the inactivity time frame (e.g. last 60 days) when the user hasn't given one. Use when the user wants to clean up inactive or dormant identities, offboard unused users or service accounts, delete stale groups, or shrink the identity attack surface (e.g. "clean up inactive identities", "find dormant users", "disable unused service accounts").
    0 installs
  20. Orca Overprivileged Identities Rightsizing · orcasecurity
    Over-privileged identity right-sizing - finds identities holding more permissions than they use, per Orca's pre-computed PoLP (Principle of Least Privilege) recommendations, across an account, business unit, or tag in AWS, Azure, and GCP. Use when the user wants to right-size over-privileged identities, reduce excess permissions across an account, or apply Orca's PoLP / least-privilege recommendations.
    0 installs