用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/backbay-labs/thrunt-god --skill hunt-map-environment命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
Show available THRUNT threat hunting commands and artifact layout
Initialize a threat hunting case from a signal, detection, intel lead, or analyst suspicion
Initialize a threat hunting program with an environment map, tool inventory, huntmap, and empty execution directories
基于 SOC 职业分类
正在显示 SKILL.md
| name | hunt-map-environment |
| description | Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots |
| allowed-tools | Read, Bash, Write, AskUserQuestion, Task |
Creates or updates:
.planning/environment/ENVIRONMENT.md.planning/MISSION.md.planning/HYPOTHESES.md.planning/STATE.mdUnknown tenants, tools, retention windows, access paths, and blind spots must remain TBD until the operator confirms them.
Confirmed environment facts should replace existing TBD markers immediately; only unresolved fields should stay TBD.
After this command: Run /hunt-shape-hypothesis or /hunt-plan 1.
<execution_context> @.github/thrunt-god/workflows/hunt-map-environment.md @.github/thrunt-god/templates/environment-map.md </execution_context>
Execute the environment-mapping workflow from @.github/thrunt-god/workflows/hunt-map-environment.md. Prefer concrete environment facts over generic best practices. Preserve existing analyst notes. Default behavior is to preserve confirmed facts and leave unknown values as `TBD` rather than populating simulated environment details. Replace `TBD` only where live workspace evidence or direct operator input confirms the fact.