| name | u0616-security-failure-root-cause-miner |
| description | Build and operate the "Security Failure Root-Cause Miner" capability for Security and Privacy. Trigger when this exact capability is needed in mission execution. |
Security Failure Root-Cause Miner
Why This Skill Exists
We need this skill because production autonomy must default to least privilege and strong privacy. This specific skill finds recurring break patterns to speed remediation.
When To Use
Use this skill when the request explicitly needs "Security Failure Root-Cause Miner" outcomes in the Security and Privacy domain.
Step-by-Step Implementation Guide
- Define the scope and success metrics for
Security Failure Root-Cause Miner, including at least three measurable KPIs tied to breach, exfiltration, and over-privileged actions.
- Design and version the input/output contract for permissions, sensitive data flows, and threat events, then add schema validation and failure-mode handling.
- Implement the core capability using error pattern mining, and produce root-cause clusters with deterministic scoring.
- Integrate the skill into swarm orchestration: task routing, approval gates, retry strategy, and rollback controls.
- Add unit, integration, and simulation tests that explicitly cover breach, exfiltration, and over-privileged actions, then run regression baselines.
- Deploy behind a feature flag, monitor telemetry/alerts for two release cycles, and iterate thresholds based on observed outcomes.
Required Deliverables
- Capability contract: input schema, deterministic scoring, output schema, and failure modes.
- Runtime profile: general-capability using error pattern mining to produce root-cause clusters.
- Orchestration integration: security-and-privacy:general-capability routing, approval gates, retries, and rollback controls.
- Validation evidence: unit, integration, simulation, regression-baseline suites and rollout telemetry.
Operational Runbook
Preflight
- Confirm the Security Failure Root-Cause Miner request scope, source evidence, and measurable success criteria before execution.
- Verify feature flag skill_0616_security-failure-root-cause-mine, approval gates, and rollback owner before autonomous use.
Execution
- Execute error pattern mining with deterministic scoring and reproducible trace capture.
- Produce root-cause clusters plus scorecard, assumptions, and unresolved-risk notes.
Recovery
- Fail closed when required signals, evidence, or approval gates are missing.
- Rollback to the last stable baseline when posture is critical or validation fails.
Handoff
- Publish root-cause clusters, validation evidence, and telemetry links to downstream owners.
- Queue follow-up tasks for unresolved risks, threshold tuning, or approval review.
Guardrails
- [quality] Require deterministic scoring and validation evidence before promotion.
- [reliability] Preserve retries, rollback controls, and failure-mode evidence for every run.
- [safety] Route critical posture or missing approval gates to human review before autonomous action.