用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/420company/artemis --skill investigate-alerts命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
This skill should be used when the user asks to "call the Spotify Ads API", "create a Spotify ad campaign", "manage Spotify ads", "pull Spotify ad reports", "set up ad sets or ads", "upload ad assets", "target audiences on Spotify", "check campaign status", "get ad account info", "look up API schema or fields", "check what targeting options exist", or asks about Spotify advertising endpoints, request/response formats, enum values, or authentication.
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and infrastructure-as-code (Terraform, Pulumi). Use for any Cloudflare development task. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.
Accessibility audit skill for scanning, fixing, and verifying WCAG 2.2 Level A and AA compliance across React, Next.js, Vue, Angular, Svelte, and plain HTML codebases. Use when auditing accessibility, fixing a11y violations, checking color contrast, generating compliance reports, or integrating accessibility checks into CI/CD pipelines.
基于 SOC 职业分类
正在显示 SKILL.md
| name | investigate-alerts |
| disable-model-invocation | true |
| argument-hint | [since_hours] [severity: all|critical|warning] |
| description | Investigate active and historical ZDX alerts to understand scope, root cause, and impact. |
Investigate alerts: $ARGUMENTS
Extract:
zdx_list_alerts(since=<hours>)
```text
## Step 3: For Each Alert, Investigate
For each active or recent alert:
```text
zdx_get_alert(alert_id="<id>")
```text
Note: alert type, severity, affected application, start time, end time (if resolved).
## Step 4: Check Affected Devices
```text
zdx_list_alert_affected_devices(alert_id="<id>")
```text
Determine scope: one user, one office, one ISP, or organization-wide.
## Step 5: Correlate with Application Metrics
For the affected application:
```text
zdx_get_application_score_trend(app_id="<app_id>", since=<hours>)
zdx_get_application_metric(app_id="<app_id>", metric_name="dns_time", since=<hours>)
```text
Check if metrics degraded around the alert start time.
## Step 6: Present Report
**ALWAYS present data in HTML tables** using `<table>`, `<thead>`, `<tbody>`, `<tr>`, `<th>`, `<td>` tags with inline styling. Use color-coded rows: red (high priority), yellow (medium), green (low/resolved).
Include:
1. **Active alerts summary table** (priority, alert name, application, duration, affected devices, locations, bottleneck metric)
2. **Metric correlation table** per alert (PFT, DNS, availability, root cause indicator)
3. **Detailed analysis** explaining alert severity, scope (isolated vs widespread), and correlation between alerts
4. **Historical pattern analysis** -- is this recurring? What time patterns exist?
5. **Next steps / resolution** per alert:
- High priority: immediate actions (check service health, ISP paths, engage vendor)
- Medium priority: investigate specific bottleneck (DNS, network path)
- Low priority: monitor, check for transient causes (deployments, maintenance)
- Proactive: start a deep trace (`zdx_start_deeptrace`) for recurring alerts to capture detailed network path evidence, then analyze with `zdx_get_deeptrace_webprobe_metrics`, `zdx_get_deeptrace_cloudpath`, and `zdx_get_deeptrace_events`
## Step 7: Generate Downloadable Artifacts — MANDATORY
**You MUST create BOTH files. Do NOT skip the HTML page.**
1. **Word document** (`alert_investigation_report_<date>.docx`): Executive summary, active alerts table, metric correlation per alert, historical pattern analysis, per-alert root cause, prioritized remediation and escalation paths.
2. **Interactive HTML page** (`alert_investigation_report_<date>.html`): Use the complete HTML template from the `zdx-investigate-alerts` skill. The file must be fully functional with working search bar, sortable columns, filter dropdowns, color-coded rows, summary dashboard, and CSV export button. All CSS and JavaScript inline — no external dependencies. Populate the `<tbody>` with one `<tr>` per alert from the collected data.
**Write both files to disk and provide the file paths to the user.**