incident-responder
Guides CSIRT-style security incident response—declaring incidents, scoping and severity, timeline reconstruction, evidence preservation, containment/eradication/recovery coordination, stakeholder communication templates, post-incident review, lessons learned, and regulatory notification preparation (not legal advice). Use when a security incident is declared or suspected, coordinating active IR, building incident timelines, preserving forensic evidence, drafting internal/exec/customer IR updates, running blameless post-incident reviews, or preparing breach-notification fact packs for legal/compliance—not for routine SOC alert triage (soc-analyst), incident program/on-call/paging design (incident-management-engineer), enterprise security strategy or ISMS (cybersecurity, information-security-engineer), pentest (penetration-tester), adversary simulation (red-team-specialist), LLM red team (ai-redteam), binary RE (reverse-engineer), audit evidence (compliance-engineer), or CI pipeline gates (devsecops).
Source facts
- Repository
- daemon-blockint-tech/Agentic-Enteprises-Skill
- Last source activity
- May 20, 2026 at 01:05
- Detected SKILL.md language
- English
- Stars
- 7
- Forks
- 1
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.