All skills
simota avatar

/vigil

@35ffd55
by shingo imotasimota/agent-skills85 stars
15

Engineering detection rules (Sigma/YARA), detection coverage mapping, threat hunting hypotheses, Purple Team Blue side, Detection-as-Code CI/CD. Use when defensive verification is needed.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/vigil

This session only. Nothing lands on disk.

referencehandoffs.md

≈776 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Handoff Templates

Purpose: Handoff templates between Vigil and partner agents. Read when: Receiving input from or sending output to partner agents.


Inbound Handoffs

BREACH_TO_VIGIL_HANDOFF

BREACH_TO_VIGIL_HANDOFF:
  attack_findings:
    - id: "[FIND-XXX]"
      technique: "[ATT&CK T-ID]"
      attack_path: "[Step-by-step exploitation]"
      detection_gap: "[What should have been caught]"
  purple_team_scenario:
    red_actions:
      - step: "[Red team action]"
        technique: "[T-ID]"
        expected_detection: "[What blue should see]"
  request:
    scope: "[detection_rule | coverage_mapping | purple_team_blue]"

SENTINEL_TO_VIGIL_HANDOFF

SENTINEL_TO_VIGIL_HANDOFF:
  static_findings:
    - type: "[Finding type]"
      severity: "[Critical/High/Medium/Low]"
      pattern: "[Code pattern detected]"
  request:
    scope: "[runtime_detection | monitoring_rule]"
    priority: "[Which findings need runtime detection]"

TRIAGE_TO_VIGIL_HANDOFF

TRIAGE_TO_VIGIL_HANDOFF:
  incident_pattern:
    type: "[Incident type]"
    root_cause: "[RCA summary]"
    detection_gap: "[How the incident could have been detected earlier]"
  request:
    scope: "[detection_rule | hunting_hypothesis]"

Outbound Handoffs

VIGIL_TO_SENTINEL_HANDOFF

VIGIL_TO_SENTINEL_HANDOFF:
  detection_signatures:
    - pattern: "[Detection pattern for static scanning]"
      technique: "[ATT&CK T-ID]"
      description: "[What to detect in source code]"
      false_positive_guidance: "[Known benign patterns]"

VIGIL_TO_RADAR_HANDOFF

VIGIL_TO_RADAR_HANDOFF:
  detection_regression_tests:
    - test_name: "[Detection rule regression test]"
      rule_ref: "[DET-XXX]"
      test_type: "[true_positive | false_positive]"
      input_data: "[Sample log data]"
      expected: "[match | no_match]"

VIGIL_TO_GEAR_HANDOFF

VIGIL_TO_GEAR_HANDOFF:
  pipeline_config:
    type: "detection-as-code"
    ci_platform: "[github_actions | gitlab_ci | jenkins]"
    steps:
      - name: "lint"
        tool: "sigma-cli check"
      - name: "test"
        tool: "sigma-cli test"
      - name: "convert"
        tool: "sigma convert --target [siem]"
    repo_structure: "[Reference to detection-as-code.md repo layout]"

VIGIL_TO_SCRIBE_HANDOFF

VIGIL_TO_SCRIBE_HANDOFF:
  report_type: "[coverage_report | hunting_report | detection_maturity]"
  content:
    coverage_summary:
      total_techniques: "[X]"
      covered: "[Y]"
      coverage_rate: "[Z%]"
    priority_gaps: "[Top uncovered techniques]"
    rules_created: "[Count and list]"
    hunting_results: "[Hypotheses tested and outcomes]"
  format: "[standalone report | appendix to security doc]"

VIGIL_TO_MEND_HANDOFF

VIGIL_TO_MEND_HANDOFF:
  detection_triggered_runbooks:
    - trigger_rule: "[DET-XXX]"
      technique: "[ATT&CK T-ID]"
      auto_response:
        - "[Isolation step]"
        - "[Evidence collection step]"
        - "[Notification step]"
      escalation: "[When to escalate to Triage]"

Source: SKILL.md on GitHub

No alerts13d4 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The 'vigil' skill is a comprehensive detection engineering assistant designed to create security rules and manage Detection-as-Code pipelines. The analysis shows it adheres to high security standards, such as pinning CI/CD actions to immutable commit SHAs, using least-privilege OIDC for cloud authentication, and enforcing professional data-handling protocols like TLP. No malicious patterns or unauthorized data exfiltration were found.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 35ffd55. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/vigil