security-triage

Triage security alerts into evidence, timelines, and recommended next steps.

11|3|Updated Feb 24, 2026
One-click install
npx skills add https://github.com/Threat-Vector-Security/guardian-agent --skill security-triage-threat-vector-security
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/Threat-Vector-Security/guardian-agent/tree/main/skills/security-triage
Command: npx skills add https://github.com/Threat-Vector-Security/guardian-agent --skill security-triage-threat-vector-security

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Triage security alerts and monitoring outputs to produce actionable guidance.

Core Features & Use Cases

  • Prioritized fact gathering: separates confirmed facts, likely inferences, and open questions to drive rapid decision-making.
  • Evidence-based timelines: builds concise event timelines when order of events matters.
  • Runbook guidance: references reusable incident runbooks and standardized reporting templates for consistent handoffs.

Quick Start

Describe the triggering security event and gather the minimal evidence needed to classify and triage it.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage security alerts to produce actionable guidance?

Triage security alerts by gathering minimal evidence to classify the event, separating confirmed facts from open questions, and organizing findings into runbook templates for actionable guidance and handoffs.

What is the best way to build an evidence-based timeline for a security incident?

Build an evidence-based timeline by ordering suspicious network events and firewall findings chronologically, separating confirmed facts from likely inferences to drive rapid incident decision-making.

Can I use this triage process for firewall findings and suspicious network events?

Yes, the triage process applies to firewall findings and suspicious network events by using the narrowest tool sets to classify alerts and organize evidence for incident reviews.

How do I separate confirmed facts from inferences during an incident review?

Separate confirmed facts from likely inferences and open questions during incident reviews to prioritize fact gathering and drive rapid, evidence-based security decision-making.

Does security triage support standardized reporting templates for incident handoffs?

Security triage supports standardized reporting templates and reusable incident runbooks to ensure consistent handoffs and organized evidence separation across monitoring outputs.

What do I need to start triaging a triggering security event?

To start triaging a triggering security event, describe the event and gather the minimal evidence needed to classify it, enabling the organization of timelines and recommended next steps.