dandyedandyeCommunityยท32 Agent Skills Included

ai-runbooks

Security alert triage, threat hunting, and incident response runbooks

Automates security operations workflows including alert triage, IOC enrichment, threat hunting, and incident response for phishing, malware, ransomware, and compromised accounts. Eliminates manual SIEM queries, repetitive case documentation, and inconsistent triage decisions across analyst tiers. Guides agents through standardized PICERL response phases with role-based personas, so security teams resolve cases faster with consistent, auditable results.
npx skills add dandye/ai-runbooks --all -g -y
Available:

Instructs the agent on the repository's security operations structure, how to activate role-based personas, and how to chain atomic skills into full triage, investigation, and incident response workflows.

All Skills in This Repository (32)

Pure Emerald Level Indicators
๐Ÿ“ฆ In Repo
dandyedandye

respond-compromised-account

Coordinate PICERL-based incident response to detect, contain, eradicate, and recover compromised accounts.

Community
Advanced
๐Ÿ“ฆ In Repo
dandyedandye

pivot-on-ioc

Pivot on an IOC to discover related GTI entities and relationships.

Community
Advanced
๐Ÿ“ฆ In Repo
dandyedandye

close-case-artifact

Close cases or alerts with closure reason, root cause, and justification comment.

Community
Intermediate
๐Ÿ“ฆ In Repo
dandyedandye

design-metadata-schema

Define Dublin Core-aligned metadata schemas for content assets in JSON-schema, XML, or Markdown with validation rules and mappings.

Community
Advanced
๐Ÿ“ฆ In Repo
dandyedandye

enrich-ioc

Enrich IOC indicators with GTI and Chronicle SIEM context to output threat findings and summaries.

Community
Advanced
๐Ÿ“ฆ In Repo
dandyedandye

triage-suspicious-login

Triages suspicious login alerts and outputs LOGIN_VERDICT with risk scores.

Community
Intermediate
๐Ÿ“ฆ In Repo
dandyedandye

respond-phishing

Guide phishing incident response through a PICERL workflow across mail gateways and SIEM.

Community
Advanced
๐Ÿ“ฆ In Repo
dandyedandye

inventory-content

Catalog information assets and extract metadata across a path into JSON, CSV, or Markdown.

Community
Intermediate
๐Ÿ“ฆ In Repo
dandyedandye

confirm-action

Prompts users for confirmation before irreversible automated actions are executed.

Community
Intermediate
๐Ÿ“ฆ In Repo
dandyedandye

generate-taxonomy

Generate a hierarchical taxonomy with facets and a TAXONOMY_DEFINITION document.

Community
Intermediate
๐Ÿ“ฆ In Repo
dandyedandye

generate-sitemap

Generate hierarchical sitemaps from a site path in Mermaid, XML, SVG, or Markdown formats.

Community
Intermediate
๐Ÿ“ฆ In Repo
dandyedandye

audit-content

Audit documentation quality, freshness, and structure into a CONTENT_AUDIT_REPORT markdown.

Community
Intermediate

Frequently Asked Questions

FAQPage Schema
How to install ai-runbooks?โ–ผ

Run `npx skills add dandye/ai-runbooks --all -g -y` in your terminal to install all security runbooks and skills globally.

How to automate SOC alert triage?โ–ผ

Use the full-alert-triage workflow, which checks for duplicate cases, enriches each IOC with threat intelligence and SIEM context, then closes false positives or escalates real threats automatically.

Can it handle phishing and ransomware response?โ–ผ

Yes. Dedicated incident response skills walk the agent through the full PICERL lifecycle for phishing, ransomware, malware, and compromised user accounts, including containment and recovery steps.

Does ai-runbooks work with Chronicle SIEM and SOAR?โ–ผ

Yes. The skills are built around MCP integrations for Chronicle SIEM, SOAR case management, Google Threat Intelligence, and Security Command Center.

Which AI platforms support these runbooks?โ–ผ

The runbooks work with Claude Code, Gemini CLI, and Cline through a shared rules_bank directory, so all platforms use identical security workflows.

Related Repositories in Software Engineering

View All in Software Engineeringโ†’