security-agent-repair

Diagnose and repair endpoint security agent failures across EDR/AV platforms.

Updated May 6, 2026
One-click install
npx skills add https://github.com/idemeum/skills --skill security-agent-repair
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-agent-repair
Source: https://github.com/idemeum/skills/tree/main/security-agent-repair
Command: npx skills add https://github.com/idemeum/skills --skill security-agent-repair

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you diagnose and repair endpoint security agent issues so your device stops appearing unprotected or out of compliance.

Core Features & Use Cases

  • Agent liveness and process health checks: Detects whether the endpoint agent is running and whether it is reporting to the management console.
  • Compatibility and integrity verification: Checks SIP/Secure Boot and (macOS) system extension approval status that can prevent agents from functioning.
  • Connectivity, version, and log-driven troubleshooting: Verifies console reachability, evaluates heartbeat freshness, and surfaces recent log errors to determine whether the root cause is connectivity, enrollment/version issues, or tamper/compliance blocks.
  • Guided remediation with safe guardrails: Attempts a controlled restart when appropriate, otherwise escalates with clear IT-ready diagnostics.

Quick Start

Tell the AI: "Run security-agent-repair to diagnose why my CrowdStrike/SentinelOne/Defender agent is unhealthy and fix what it can, then give me an IT-ready summary if escalation is needed."

Frequently Asked Questions about security-agent-repair

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I fix an EDR agent that shows as stopped or reporting a stale heartbeat?

To fix a stale EDR agent heartbeat, you can run a diagnostic sequence that checks agent process health, verifies console connectivity, evaluates heartbeat freshness, and attempts a safe process restart if appropriate.

Why does my macOS endpoint security agent fail to start after installation?

Endpoint security agents on macOS often fail to start due to unapproved system extensions or SIP/Secure Boot integrity issues, which block the agent from loading and reporting compliance posture to the management console.

How do I troubleshoot endpoint compliance posture failures related to FileVault and MDM enrollment?

Troubleshooting endpoint compliance posture involves validating FileVault status and MDM enrollment, checking system extension approval, and reviewing agent logs to determine if tamper protection or insecure boot states are causing the failure.

Can I use an automated workflow to diagnose and repair CrowdStrike or SentinelOne agent connectivity issues?

Yes, an automated workflow can diagnose connectivity issues by checking console reachability, evaluating agent version compatibility, surfacing recent log errors, and applying guided remediation with safe guardrails to restore agent health.

What is the best way to generate an IT-ready diagnostic summary for an unhealthy endpoint protection agent?

The best way to generate an IT-ready diagnostic summary is to run a comprehensive health check that evaluates agent processes, system extensions, connectivity, and logs, then escalates with clear diagnostics if a safe restart is not possible.