malware-response

Correlate malware intelligence with Endor Labs package inventory and classify exposure.

10|2|Updated May 4, 2026
One-click install
npx skills add https://github.com/endorlabs/endor-labs-agent-kit --skill malware-response
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: malware-response
Source: https://github.com/endorlabs/endor-labs-agent-kit/tree/main/gemini/malware-response
Command: npx skills add https://github.com/endorlabs/endor-labs-agent-kit --skill malware-response

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires endorctl, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps AppSec and SOC teams quickly respond to software supply-chain malware incidents by analyzing current malware intelligence and providing remediation guidance.

Core Features & Use Cases

  • Malware Intelligence Analysis: Gathers and correlates current malware intelligence with Endor Labs tenant package inventory.
  • Exposure Classification: Identifies confirmed, possible, or not observed exposure based on evidence.
  • Remediation Guidance: Offers containment suggestions, IOC hunting guidance, and future action contracts.
  • Use Case: If a customer reports a malware campaign affecting a package, this Skill can determine if there's an exposure in the tenant's environment and suggest actions to mitigate the risk.

Quick Start

Run the @malware-response skill to analyze a malware incident in the current namespace.

Frequently Asked Questions about malware-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check if my software supply chain is exposed to a malware campaign?

To check for malware exposure, this Skill correlates external malware intelligence with your Endor Labs tenant package inventory, classifying your exposure as confirmed, possible, or not observed based on evidence.

What remediation steps are needed for a software supply-chain malware incident?

Remediation guidance for a malware incident includes containment suggestions, IOC hunting guidance, and future action contracts to mitigate risk and secure your software supply chain.

Do I need Endor Labs and Gemini CLI to analyze malware exposure?

Yes, analyzing malware exposure requires Endor Labs access and the Gemini CLI with Endor Labs agent support to correlate intelligence with your package inventory.

What is malware exposure classification and how does it work?

Malware exposure classification identifies whether a package in your tenant environment is confirmed, possibly, or not observed to be exposed by correlating external malware intelligence with internal package inventory.

Can I use endorctl for malware intelligence analysis in my current namespace?

Yes, you can run the malware-response Skill with endorctl to analyze a malware incident and correlate current intelligence within your current Endor Labs namespace.

What to do when a package affected by a malware campaign is reported?

When a malware campaign is reported, use this Skill to determine tenant exposure and generate remediation guidance to mitigate the risk in your software supply chain.