security-digest

Summarize UniFi Protect, Access, and Network events into a prioritized security report.

1|Updated Apr 6, 2025
One-click install
npx skills add https://github.com/david-driscoll/stargate-command-cluster --skill security-digest-david-driscoll
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-digest
Source: https://github.com/david-driscoll/stargate-command-cluster/tree/main/.agents/skills/security-digest
Command: npx skills add https://github.com/david-driscoll/stargate-command-cluster --skill security-digest-david-driscoll

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

The security-digest Skill turns scattered camera, door access, and network firewall events into a single, human-readable overnight (or custom range) security summary.

Core Features & Use Cases

  • Cross-source event correlation: Correlates UniFi Protect detections with UniFi Access and UniFi Network signals using deterministic rules (CORR-01 through CORR-05) to produce merged incidents.
  • Severity classification & prioritization: Applies a time-of-day, location, frequency, and correlation-based severity model to label events as Low/Medium/High (and Critical when applicable).
  • Digest reporting for fast review: Produces an overview, a chronological list of notable events, activity counts per source, and recommendations when action is warranted.

Quick Start

Ask the security-digest assistant: "Generate a security digest for overnight events and highlight anything notable or alert-worthy."

Frequently Asked Questions about security-digest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I summarize overnight UniFi Protect camera events and door access logs into a single report?

You can summarize overnight UniFi Protect camera events and door access logs by correlating detections, access signals, and network alarms into a single prioritized digest report. The security summary applies deterministic correlation rules to merge cross-source incidents for fast review.

What is cross-source event correlation for security incident triage?

Cross-source event correlation for security incident triage is the process of merging UniFi Protect camera detections, UniFi Access door events, and UniFi Network alarms using deterministic rules. This identifies related activities across systems and escalates them into merged, prioritized incidents.

How do I generate a daily security review that prioritizes network alarms and camera detections?

To generate a daily security review, the system applies a severity model driven by time of day, location, frequency, and correlation escalations. It labels events as Low, Medium, High, or Critical and produces an overview with chronological notable events and activity counts.

Can I run an incident triage digest if some UniFi Access or UniFi Network sources are unavailable?

Yes, you can run an incident triage digest when some UniFi Access or UniFi Network sources are unavailable. The system uses graceful degradation to process connected MCP servers and summarize available camera, door, and network alarm events without failing the entire report.

Does the security digest require specific MCP servers to correlate UniFi events?

The security digest requires connected MCP servers to retrieve UniFi Protect, UniFi Access, and UniFi Network data for correlation. It also requires YAML-frontmatter inputs for discovery and applies deterministic correlation rules to generate the prioritized report.

What is the best way to investigate recent UniFi Protect activity across multiple security sources?

The best way to investigate recent UniFi Protect activity is to generate a custom range security digest that correlates camera events with door access and network alarms. This produces a chronological list of notable events, activity counts per source, and actionable recommendations.