triage-alert
Triage a security alert or case. Use when given an ALERT_ID or CASE_ID to assess if it's a real threat. Enriches IOCs, searches SIEM for context, and determines if the alert should be closed (false po
Also installable via skills CLI
npx skills add dandye/ai-runbooks/skills/triage-alert