skywatch-bsky
- 36 skills
- 0 followers
- 12 hours ago last updated
- ▌ Skywatch Assess Account · skywatch-bskyStructured account assessment for AT Protocol investigations. Replaces manual account profiling by defining data collection questions, classification schema, and output format. Produces account_type, confidence, signals, and recommendation. Use when profiling an account of interest during Phase 2 (Characterization) or as a standalone quick assessment.
- ▌ Skywatch Querying Ozone · skywatch-bsky bundleThis skill should be used when working with the Ozone moderation API — query patterns, filter combinations, pagination, write tool conventions, and common recipes. Covers both MCP tool access and direct HTTP API access when MCP server is unavailable. Use when querying or writing to Ozone via MCP tools or HTTP. Does not prescribe a workflow, see working-the-queue for queue triage methodology.
- ▌ Skywatch Osprey Validate · skywatch-bskyValidate an Osprey SML rules project by running `uv run osprey-cli push-rules --dry-run` from the skywatch-osprey repo and reporting the full result without summarising.
- ▌ Skywatch Accessing Osprey · skywatch-bsky bundleUnderstanding the Osprey moderation infrastructure — system architecture, ClickHouse data access, schema reference, and relationship to Ozone labelling. Use when investigating AT Protocol accounts or reviewing rule execution data.
- ▌ Skywatch Classify Cluster · skywatch-bskyNarrative classification of co-sharing clusters on AT Protocol. Analyses cluster member content, identifies dominant narratives, coordination signals, shared sources, and likely origin. Distinguishes information operations from organic coordination. Use when a co-sharing cluster is identified during Phase 3 (Linkage) or Phase 4 (Amplification), or as a standalone cluster assessment.
- ▌ Skywatch Search Incidents · skywatch-bskyTopic-based incident search with relevance scoring and content classification for AT Protocol investigations. Expands search topics into keyword strategies, classifies results by content type and incident confirmation, and produces geographically grouped output. Use when investigating incidents by topic during Phase 1 (Discovery) or as a standalone search.
- ▌ Skywatch Triage Rule Hits · skywatch-bskyRule hit triage methodology for Osprey rules. Samples recent hits, classifies each as TP/FP/novel/uncertain, and produces aggregate rule health assessment with actionable recommendations. Use when evaluating rule performance during Phase 5 (Rule Validation) or as a standalone rule maintenance check.
- ▌ Skywatch Reporting Results · skywatch-bsky bundleReport formats, BLIND structure, data presentation, and output conventions for investigation reports. Use when writing or reviewing investigation reports. Includes templates for memo, cluster deep-dive, cross-cluster, and rule check report types.
- ▌ Skywatch Working The Queue · skywatch-bskyOODA-based moderation queue triage — observe reports, orient with context and policy, decide on classification, act on user-confirmed decisions. Supports multiple entry points (reports, appeals, tags, proactive filtering). Use when triaging the Ozone moderation queue or processing moderation reports.
- ▌ Skywatch Labeling Standards · skywatch-bskyEvidence comment standards and data sourcing for all Ozone label actions. Defines required comment format, citation requirements, tiered evidence thresholds, and ClickHouse-first data sourcing cascade. Loaded by the ozone_label PreToolUse hook when comments fail validation.
- ▌ Skywatch Fixing Osprey Rules · skywatch-bskyUse when fixing Osprey SML validation errors or reviewer-identified issues. Contains error categories, fix patterns, and debugging workflow. Not triggered on general coding tasks — only when resolving specific SML errors.
- ▌ Skywatch Querying Clickhouse · skywatch-bsky bundleQuery patterns, safety rules, and performance tips for ClickHouse investigation queries against osprey_execution_results. Use when writing or reviewing ClickHouse queries for investigations.
- ▌ Skywatch Osprey Sml Reference · skywatch-bsky bundleUse when writing SML rules for Osprey — syntax questions, type system, naming conventions, labeling patterns, entity extraction, window counting, or label operations
- ▌ Skywatch Ozone Comment Triage · skywatch-bskyQueue-workflow triage with Ozone-comment output mode. Use when the user asks to review Ozone reports and post evidence/recommendations directly as Ozone comments for later human review, rather than presenting the batch in chat. Covers the full per-subject evidence workflow — ClickHouse rule hits, content context, profile, moderation history, reply threads — with output written as Ozone comments and account escalations instead of in-chat detail blocks.
- ▌ Skywatch Scanning The Network · skywatch-bsky bundleProactive network-wide threat scanning over a specified time window. Use when looking for emerging threats, incident upticks, anomalous network traffic, coordination patterns, or detection gaps.
- ▌ Skywatch Planning Osprey Rules · skywatch-bskyUse when gathering requirements for a new Osprey SML rule before any code is written. Not triggered on general coding tasks — only when planning what a rule should detect, which labels to apply, and what signals to use.
- ▌ Skywatch Authoring Osprey Rules · skywatch-bskyUse when writing or modifying Osprey SML rule files from a validated rule specification. Covers model writing, rule writing, effect wiring, and execution graph wiring. Not triggered on general coding tasks.
- ▌ Skywatch Reviewing Osprey Rules · skywatch-bskyUse when validating or reviewing Osprey SML rules. Defines three-layer verification (osprey-cli, proactive checks, convention review) with severity classification. Not triggered on general coding tasks.
- ▌ Skywatch Conducting Investigations · skywatch-bsky bundleSix-phase investigation methodology for AT Protocol network analysis — from initial discovery through reporting. Covers tool selection, signal identification, evidence standards, and directory conventions. Use when conducting or planning investigations.
- ▌ Skywatch Investigating Osprey Rules · skywatch-bsky bundleSystematic investigation methodology for Osprey SML rules projects. Produces structured text reports on project structure, labels, models, UDFs, and execution graphs.
- ▌ Planning Osprey Rules · skywatch-bskyUse when gathering requirements for a new Osprey SML rule before any code is written. Not triggered on general coding tasks — only when planning what a rule should detect, which labels to apply, and what signals to use.
- ▌ Authoring Osprey Rules · skywatch-bskyUse when writing or modifying Osprey SML rule files from a validated rule specification. Covers model writing, rule writing, effect wiring, and execution graph wiring. Not triggered on general coding tasks.
- ▌ Reviewing Osprey Rules · skywatch-bskyUse when validating or reviewing Osprey SML rules. Defines three-layer verification (osprey-cli, proactive checks, convention review) with severity classification. Not triggered on general coding tasks.
- ▌ Assess Account · skywatch-bskyStructured account assessment for AT Protocol investigations. Replaces manual account profiling by defining data collection questions, classification schema, and output format. Produces account_type, confidence, signals, and recommendation. Use when profiling an account of interest during Phase 2 (Characterization) or as a standalone quick assessment.
- ▌ Querying Ozone · skywatch-bskyReference guide for Ozone MCP tools — query patterns, filter combinations, pagination, write tool conventions, and common recipes. Use when working with the Ozone moderation API via MCP tools. Does not prescribe a workflow — see working-the-queue for queue triage methodology.
- ▌ Accessing Osprey · skywatch-bsky bundleUnderstanding the Osprey moderation infrastructure — system architecture, ClickHouse data access, schema reference, and relationship to Ozone labelling. Use when investigating AT Protocol accounts or reviewing rule execution data.
- ▌ Classify Cluster · skywatch-bskyNarrative classification of co-sharing clusters on AT Protocol. Analyses cluster member content, identifies dominant narratives, coordination signals, shared sources, and likely origin. Distinguishes information operations from organic coordination. Use when a co-sharing cluster is identified during Phase 3 (Linkage) or Phase 4 (Amplification), or as a standalone cluster assessment.
- ▌ Search Incidents · skywatch-bskyTopic-based incident search with relevance scoring and content classification for AT Protocol investigations. Expands search topics into keyword strategies, classifies results by content type and incident confirmation, and produces geographically grouped output. Use when investigating incidents by topic during Phase 1 (Discovery) or as a standalone search.
- ▌ Triage Rule Hits · skywatch-bskyRule hit triage methodology for Osprey rules. Samples recent hits, classifies each as TP/FP/novel/uncertain, and produces aggregate rule health assessment with actionable recommendations. Use when evaluating rule performance during Phase 5 (Rule Validation) or as a standalone rule maintenance check.
- ▌ Reporting Results · skywatch-bsky bundleReport formats, BLIND structure, data presentation, and output conventions for investigation reports. Use when writing or reviewing investigation reports. Includes templates for memo, cluster deep-dive, cross-cluster, and rule check report types.
- ▌ Working The Queue · skywatch-bskyOODA-based moderation queue triage — observe reports, orient with context and policy, decide on classification, act on user-confirmed decisions. Supports multiple entry points (reports, appeals, tags, proactive filtering). Use when triaging the Ozone moderation queue or processing moderation reports.
- ▌ Labeling Standards · skywatch-bskyEvidence comment standards and data sourcing for all Ozone label actions. Defines required comment format, citation requirements, tiered evidence thresholds, and ClickHouse-first data sourcing cascade. Loaded by the ozone_label PreToolUse hook when comments fail validation.
- ▌ Querying Clickhouse · skywatch-bsky bundleQuery patterns, safety rules, and performance tips for ClickHouse investigation queries against osprey_execution_results. Use when writing or reviewing ClickHouse queries for investigations.
- ▌ Scanning The Network · skywatch-bskyProactive network-wide threat scanning over a specified time window. Use when looking for emerging threats, incident upticks, anomalous network traffic, coordination patterns, or detection gaps.
- ▌ Conducting Investigations · skywatch-bsky bundleSix-phase investigation methodology for AT Protocol network analysis — from initial discovery through reporting. Covers tool selection, signal identification, evidence standards, and directory conventions. Use when conducting or planning investigations.
- ▌ Investigating Osprey Rules · skywatch-bsky bundleSystematic investigation methodology for Osprey SML rules projects. Produces structured text reports on project structure, labels, models, UDFs, and execution graphs.