| name | warmup |
| description | The Warmup. A daily intelligence brief for the first coffee. CISO mode delivers a structured cybersecurity digest — active threat actors mapped to MITRE ATT&CK, emerging CVEs with exploitation status, research from CrowdStrike, Palo Alto Unit 42, Elastic Security Labs, and others, plus vendor M&A and regulatory movement. Product Leader mode delivers a product intelligence brief for GMs, PMs, and anyone steering a product — company signal, competitor moves, AI in product, funding and M&A, platform risk, regulatory pressure, analyst sentiment, and a vertical-specific section that adapts to what they build and who they build for. Custom mode lets any user describe their morning interests — stocks, industry news, competitor moves, policy, social signal — and maps them to a curated source suite. Output: a live Iron Log-branded HTML artifact, transparent about every source used, pulled on demand with your first coffee. Trigger phrases: "warmup", "run warmup", "run the warmup", "start my warmup", "give me my warmup", "warmup setup", "set up the warmup", "configure the warmup", "warmup config", "add source to warmup", "remove source from warmup", "show my warmup sources".
|
| license | MIT |
| author | H. Michael Nichols |
| version | 0.3.16 |
| part_of | The Loadout |
The Warmup
Why "The Warmup"
In the gym, a warmup is not optional. You do not walk under the bar cold.
A warmup primes your nervous system, surfaces what is tight, and tells you
whether today's session needs to be adjusted before the work begins. It is
the ten minutes that makes the next ninety honest.
The Warmup does the same thing for your workday. Before you open your inbox,
before you take the first meeting, before you have the conversation that shapes
the next quarter — you know what moved. You know who is active. You know what
the field looks like this morning.
You do not go under the bar cold.
The name comes from Mission Built, where the principle is: prepare like the
result matters, because it does.
When to use this skill
Activate this skill when the user asks you to do any of the following:
- Run their warmup
- Get today's warmup
- Set up the warmup for the first time
- Reconfigure their sources
- Add or remove a source from their brief
- See what sources are in use
Trigger phrases include: "warmup", "run warmup", "run the warmup",
"start my warmup", "give me my warmup", "what's in the brief today",
"warmup setup", "set up the warmup", "configure the warmup",
"warmup config", "add [source] to my warmup", "remove [source] from warmup",
"show my warmup sources", "exclude [source] from warmup".
Philosophy
Signal over noise. Every source labeled. Every claim attributed.
The Warmup has a point of view: authoritative sources first, flagged sources
clearly marked, nothing buried in volume. A brief that forces you to sort
through noise is not a brief — it is a second inbox.
Four principles:
1. Tier before topic. Every item in the brief carries its source's trust
tier visually. A Tier 1 government advisory and a Tier 3 community post are
not the same weight of evidence. The brief treats them differently because
they are different. The user always knows what they are reading.
2. Absence is information. If a source returns nothing today, that is
reported. If a source is unavailable, that is reported. A blank section is
never padded. Silence from a source that usually speaks is itself a signal.
3. The source panel is not optional. Every run of the brief ends with a
full disclosure of every source that was consulted — active, quiet, or
excluded. The user must always be able to audit what their brief was built on.
This is the contract.
4. Recommendations, not mandates. When the skill recommends sources,
it explains why. When it flags a source as lower tier, it says so and says why.
The user decides what goes in their brief. The skill's job is to make sure
those decisions are informed.
Modes
Three modes. Each is triggered by a natural phrase.
| Mode | When | What this skill does |
|---|
| SETUP | First time, or reconfiguring from scratch | Establish the user's profile, build their source suite, save to WARMUP.md, run a test brief |
| RUN | Any time the user wants their brief | Read WARMUP.md, fetch live intelligence from each active source, synthesize sections, render the Iron Log artifact |
| CONFIGURE | Modifying sources without full re-setup | Show active sources, apply changes (add / remove / exclude), update WARMUP.md |
Brief types available at SETUP:
| Brief type | Who it's for | Core focus |
|---|
| CISO | Security executives | Threat actors, CVEs, research, vendor market, regulatory |
| Product Leader | GMs, PMs, anyone steering a product | Company signal, competitors, AI in product, funding, platform risk, vertical-specific |
| Custom | Anyone | User-defined interests, fully flexible source suite |
If no WARMUP.md exists in the project root and the user asks to RUN, prompt
for SETUP first: "No Warmup config found. Run 'warmup setup' to build your
source suite — it takes about two minutes."
SETUP Mode
Trigger: "warmup setup", "set up the warmup", "configure the warmup for the
first time"
Step 1 — Choose a starting mode
Ask the user: "Three brief types to choose from — which fits you best?
· CISO — cybersecurity executive brief
· Product Leader — GM / PM intelligence brief
· Custom — describe your own interests and I'll build a source suite around them"
- CISO is the flagship configuration. Pre-loaded with an authoritative
source suite curated for security executives. Provide your company name
and sector, region, and peer vendors are looked up automatically — one
confirmation and you're done.
- Product Leader is built for GMs, PMs, and anyone steering a product.
Provide your company name and competitors, vertical, region, and model
are researched automatically. Confirm what's right, answer two quick
follow-ups, and the brief is ready.
- Custom builds a source suite from scratch around the user's described
interests. Takes a few more questions.
- The user can toggle between modes at any time via CONFIGURE.
Step 1b — Get the user's name
Once the mode is chosen, ask: "What's your name? I'll use it in your brief header."
Examples: "Mike", "Sarah", "Alex" — or they can skip with anything like "doesn't matter" or "just leave it blank".
Stored only in the local WARMUP.md, never sent anywhere. Save as name: in the profile. If skipped, leave blank.
Step 2a — If CISO mode
Lead with company name. Auto-fill everything derivable. Ask only what can't be looked up.
Ask: "What's your company name? I'll look up your sector, region, and typical peer vendors automatically. Or say 'skip' and I'll ask instead."
If the user provides a company name:
Call the WebSearch tool with query: "[Company]" company overview industry sector headquarters cybersecurity
From the results, determine:
- Sector — map to one of the Sector Sources table values below (Healthcare, Financial Services, Energy / Utilities, Technology, Government, Manufacturing / OT, Retail, Critical Infrastructure, or the user's own phrasing if it doesn't map cleanly)
- Region — infer from HQ location. Map to: United States, European Union, APAC, Latin America, or Global if multinational
- Peer vendors — based on the company's sector and known competitive landscape, suggest 3–5 security vendors they likely watch (e.g., a healthcare org watches CrowdStrike, Palo Alto, Microsoft Sentinel; a fintech watches Wiz, SentinelOne, Lacework)
Present all findings in a single confirmation message:
"Here's what I found for [Company]:
· Sector: [X]
· Region: [Y]
· Peer vendors to track: [A, B, C]
Does that look right? Edit anything or say 'looks good' to continue."
Accept natural-language edits. Update any field the user corrects. Save company, sector, and region to WARMUP.md.
Then ask these two follow-up questions — do not skip them:
Follow-up 1 — People to follow:
"Anyone in the security world you want to follow closely — executives, CISOs, researchers, threat intel voices? I can suggest a few based on [Company]'s space."
Suggest 2–3 relevant names based on sector and company (e.g., known CISOs at peer companies, prominent threat researchers, security journalists). Present as: "People like [A], [B], [C] are worth following if you're in [sector]. Anyone to add, or skip this?"
Save confirmed names to track_people: in WARMUP.md. If skipped, leave blank.
Follow-up 2 — Personal interests:
"Last one — anything you want at the end of your brief that's not work? Sports, markets, a hobby, a team?"
Save to special_interests: in WARMUP.md. If skipped, omit the section. Accept any answer — "skip", "nothing", or an actual interest. Do not pressure.
If the user skips the company name:
Ask these four questions one at a time:
-
"What industry or sector is your organization in?"
Examples: "Healthcare", "Financial Services", "Energy / Utilities", "Technology", "Government", "Manufacturing / OT", "Retail", "Critical Infrastructure"
Accept open-form. Map to the Sector Sources table below.
-
"What region are you primarily operating in?"
Examples: "United States", "European Union", "APAC", "Latin America", "Global"
-
"Any specific vendors or competitors you want to track?"
Examples: "Palo Alto, CrowdStrike, Wiz", "Microsoft Sentinel, Splunk, SentinelOne", "skip"
-
"Anything you want to stay current on outside of work? Totally optional."
Build the source suite from the CISO Source Suite tables below.
Add sector-specific sources from the Sector Sources table.
Step 2b — If Product Leader mode
Lead with company name. Auto-fill sector, region, and competitors. Ask only what can't be looked up.
Ask: "What's your company name — and what product or area are you responsible for? I'll look up your sector, region, and top competitors automatically. Or describe it yourself and I'll go from there."
Examples: "Acme Corp, security platform", "Blue Yonder, supply chain", "skip — I'll describe it"
If the user provides a company name:
Call the WebSearch tool with query: "[Company]" product overview market competitors B2B B2C industry
From the results, determine:
- Product focus — what the company primarily builds and sells
- B2B / B2C / platform — infer from business model. Map to:
b2b / b2c / platform / marketplace / hybrid. If ambiguous, note it and ask.
- Vertical / customer industry — who the company sells to. Map to the vertical source options below (Security, Fintech, Healthcare, Enterprise SaaS, Developer tools, E-commerce, Logistics, etc.)
- Region — infer from HQ location
- Top competitors — identify 3–5 direct competitors from search results
Present all findings in a single confirmation message:
"Here's what I found for [Company]:
· Product: [what they build]
· Model: [B2B / B2C / platform]
· Vertical: [customer industry]
· Region: [Y]
· Top competitors: [A, B, C, D]
Does that look right? Edit anything or say 'looks good' to continue."
Accept natural-language edits. If B2B/B2C is still unclear after the search, ask: "One quick one — are you selling to businesses, consumers, or is it a platform other developers build on?"
If the user's vertical doesn't map cleanly, ask: "What does a bad week look like for your business — what external event would most disrupt your roadmap?" Use the answer to infer the right vertical section.
Then ask these three follow-up questions — do not skip them:
Follow-up 1 — AI vendors:
"Which AI vendors or tools matter most to your roadmap? I'd default to OpenAI, Anthropic, Google DeepMind, and Meta AI — plus any tools your team uses (Copilot, Cursor, Mistral). Anything to add or drop?"
Save confirmed list to ai_vendors: in WARMUP.md. If skipped, use the default set.
Follow-up 2 — People to follow:
"Anyone you want to track closely — executives, investors, analysts, journalists, or researchers? I can suggest a few based on [Company]'s space."
Suggest 2–3 relevant names based on vertical and company (e.g., for a security platform: relevant VCs, CISOs at peer companies, prominent analysts). Present: "People like [A], [B], [C] are worth following if you're in [vertical]. Anyone to add, or skip this?"
Save confirmed names to track_people: in WARMUP.md. If skipped, leave blank.
Follow-up 3 — Personal interests:
"Last one — anything you want at the end of your brief that's not work? Sports, markets, a hobby, a team?"
Save to special_interests: in WARMUP.md. If skipped, omit the section. Do not pressure.
If the user skips the company name:
Ask these five questions one at a time:
-
"What are you building and who are you building it for?"
Accept open-form. Infer product focus, B2B/B2C, and vertical from the answer.
-
"What industry or vertical is your customer in — or, if B2C, who is your user?"
Map to the vertical source options below.
-
"Who are your top three to five direct competitors?"
Generate a suggested list based on what they've described. Present: "Based on what you've told me, I'd start with: [A, B, C]. Does that look right?"
-
"Which AI vendors or tools matter most to your roadmap?"
Suggest the standard default set and let them edit.
-
"Any execs or analysts to track personally? Any non-work interests?"
Step 2c — If Custom mode
Ask: "Describe what you want in your warmup. Be specific — topics,
companies, industries, markets, regions, anything that matters to how you start
your day."
From the described interests, map each to one or more recommended sources
using the Custom Mode Source-Building Rules below.
For each mapped source, state:
- What you are recommending and why
- Its trust tier
- A flag if it is Tier 3 or lower: "[Source] is Tier 3 (Community/Unverified).
Items from it will be labeled in the brief. Worth including?"
Recommend any sources the user likely wants but did not mention.
Step 3 — Present the source list for review
Show the full proposed source suite before saving. Format:
Tier 1 — Authoritative
● CISA Alerts & Advisories
● CISA Known Exploited Vulnerabilities (KEV)
● NVD / CVE Database
...
Tier 2 — Research
◉ CrowdStrike Intelligence Blog
◉ Palo Alto Unit 42
...
Tier 3 — News
○ Krebs on Security
...
Excluded from this run: (none)
Special Interests (if provided)
○ [Interest 1] — list the 1–3 sources that will cover it
e.g. "Formula 1 → motorsport.com, ESPN F1, AP Sports"
e.g. "SEC football → ESPN, 247Sports, AP Sports"
e.g. "Bourbon releases → Whisky Advocate, BourbonBlog.com"
e.g. "Markets → Reuters Markets, Yahoo Finance"
○ [Interest 2] — same format
If special interests were provided, always list them here. The user deserves to see what sources their brief will pull from — this section is not optional when interests exist.
Ask: "Any sources to add or remove before I save this?"
Step 4 — Ask about the lookback window
Before saving, ask: "Last thing — how far back should I look for your first
brief? The default is 1 day, but since this is your first run I'd recommend
7 days to get up to speed, or 30 days for a full month of context. What works
for you?"
Accept any natural phrasing: "7 days", "go back two weeks", "just today",
"one month". Save the answer as window_override in WARMUP.md if the user
wants a persistent window, or use it only for this run if they say so.
If the user says "default" or "1 day", use adaptive lookback (no override).
Remind them: "You can always override this at run time — just say 'warmup,
go back 2 weeks' and I'll use that window for that run only."
Also ask about search depth:
"One more setting — search depth. By default I cap each search batch to 5 results and 200 words per article. This keeps the brief fast and token-efficient (typically 40–60K tokens for the fetch phase). If you have more token budget, 'deep' mode doubles both — 10 results per batch, 400 words per article — for broader coverage at roughly 2× the fetch cost. Standard is what I'd recommend for daily use. Which do you prefer?"
Save as search_depth: standard or search_depth: deep in WARMUP.md. If the user skips or has no preference, default to standard.
Step 5 — Save WARMUP.md
Save the config file at the project root using the WARMUP.md Config Format
defined below.
Step 6 — Run a test brief
Immediately run a RUN cycle. If any sources return nothing, report:
"[Source] returned no signal in the test run. It may be temporarily
unavailable or the search found nothing recent. I've kept it in your config —
it will be checked each run."
Do not remove sources from config due to a single empty result.
RUN Mode
Trigger: "warmup", "run warmup", "run the warmup", "start my warmup",
"give me my warmup", "what's in the brief today"
Override trigger: The user can specify a custom lookback at run time:
"run the warmup one month back", "run warmup since April 15",
"give me the last two weeks", "warmup — go back 30 days".
If a lookback phrase is detected, use that window instead of the computed
window and note it in the chat summary line.
Step 1 — Read config and compute lookback window
Use the Read file tool (not bash) to read WARMUP.md from the user's project root. If you do not know the project root path, call list_artifacts first — the html_path from the "the-warmup" artifact reveals the workspace folder, and WARMUP.md lives in that same folder. If no artifact exists and no WARMUP.md is found, stop and prompt for SETUP.
Note: mode (CISO or Custom), user profile, active source list, excluded
sources, last_run date, window_override if set.
Compute the lookback window:
today = current date (YYYY-MM-DD)
last_run_date = parsed from WARMUP.md `last_run` field (YYYY-MM-DD)
gap_days = (today - last_run_date) in calendar days
# Override checks — apply first, skip the rest if matched
if user stated a lookback phrase in this run (e.g. "go back 30 days", "since April 15"):
window = user-specified value # note in summary line, skip remaining logic
elif window_override is set in WARMUP.md:
window = window_override
elif last_run is missing or empty:
window = 30 # first run — bootstrap with a month of context
elif gap_days == 1 AND daily_mode: true in WARMUP.md:
window = 2 # daily fast-path: skip re-fetching a full 7-day window
elif gap_days <= 7:
window = 7 # standard — always covers at least a week
else:
window = min(gap_days, 30) # catch-up run, capped at 30 days
# Weekend bridge (run after computing window above)
region = WARMUP.md `region` field (default: Sat+Sun weekend; IL/Israel: Fri+Sat)
if today == first working day after regional weekend AND gap_days <= 2:
window = max(window, gap_days + 2) # cover full weekend
note in summary: "Lookback extended to cover weekend"
if gap_days > 7 AND interval spans a user-declared holiday (Notes: "holiday: YYYY-MM-DD"):
note in summary: "Catch-up run — verify holiday coverage manually if needed"
# Search date parameter