security-alert-triage

Classifies AWS GuardDuty and CloudTrail alerts and routes urgent ones to Slack/PagerDuty.

1|Updated Feb 26, 2026
One-click install
npx skills add https://github.com/webrix-ai/agent-skills --skill security-alert-triage-webrix-ai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-alert-triage
Source: https://github.com/webrix-ai/agent-skills/tree/main/skills/security-alert-triage
Command: npx skills add https://github.com/webrix-ai/agent-skills --skill security-alert-triage-webrix-ai

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill reduces alert fatigue by turning large volumes of cloud security findings into clear, prioritized incidents with recommended next steps.

Core Features & Use Cases

  • Severity Classification: Sorts AWS GuardDuty, CloudTrail, and similar findings into Critical, High, Medium, and Low/Info levels.
  • Noise Reduction: Correlates repeated or related events and filters known false positives such as pentest activity, dev sandboxes, and maintenance windows.
  • Response Routing: Prepares Slack notifications, PagerDuty incidents, and follow-up actions for security teams.
  • Use Case: A security team receives hundreds of alerts after a busy day and needs a fast summary that identifies the few alerts requiring immediate escalation.

Quick Start

Use the security-alert-triage skill to triage the attached cloud security alerts, classify their severity, remove known false positives, and draft the notifications and escalation actions for critical findings.

Frequently Asked Questions about security-alert-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I reduce false positives in AWS GuardDuty alerts?

Reduce GuardDuty false positives by correlating repeated events and filtering known noise sources like pentest activity, dev sandboxes, and maintenance windows. This triage process normalizes alert data to isolate genuine security incidents requiring escalation.

Can I automatically route cloud security findings to Slack and PagerDuty?

Yes, you can automatically route cloud security findings to Slack and PagerDuty. The triage process classifies alert severity and generates routing guidance to dispatch notifications and escalation actions for critical findings directly to your security team.

What is the best way to triage high-volume CloudTrail alerts during noisy periods?

Triage high-volume CloudTrail alerts by correlating related events and normalizing alert data to cut through noise. This approach summarizes hundreds of findings into prioritized incidents, identifying the few alerts needing immediate response during peak activity.

Does this alert triage approach support multi-account AWS environments?

Yes, this alert triage approach supports multi-account AWS environments. It processes high-volume security findings across multiple accounts, correlating related events and filtering false positives to produce clear, prioritized incident summaries.

How do I classify cloud security alert severity automatically?

Classify cloud security alert severity automatically by sorting findings into Critical, High, Medium, and Low or Info levels. This triage mechanism evaluates AWS GuardDuty, CloudTrail, and similar alerts to prioritize response actions.

Why am I experiencing alert fatigue from cloud security findings?

You experience alert fatigue from cloud security findings when large volumes of unfiltered notifications overwhelm your team. Automated triage reduces this fatigue by turning noisy alerts into clear, prioritized incidents with recommended next steps.