用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/backbay-labs/thrunt-god --skill hunt-new-case命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
Show available THRUNT threat hunting commands and artifact layout
Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots
Initialize a threat hunting program with an environment map, tool inventory, huntmap, and empty execution directories
基于 SOC 职业分类
正在显示 SKILL.md
| name | hunt-new-case |
| description | Initialize a threat hunting case from a signal, detection, intel lead, or analyst suspicion |
| argument-hint | [--auto] [--pack <id>] |
| allowed-tools | Read, Bash, Write, Task, AskUserQuestion |
These hunt-native artifacts are the source of truth for the case.
Creates:
.planning/config.json.planning/MISSION.md.planning/HYPOTHESES.md.planning/SUCCESS_CRITERIA.md.planning/HUNTMAP.md.planning/STATE.md.planning/QUERIES/.planning/RECEIPTS/Bootstrap should only scaffold the case. Do not seed sample queries, sample receipts, or completed phases.
Unknown scope details, data sources, operators, and constraints must remain TBD unless the operator confirms them.
Confirmed bootstrap facts such as the case name, mode, opened date, and initial phase/status must be filled immediately.
After this command: Run /hunt-shape-hypothesis or /hunt-plan 1.
<execution_context> @.github/thrunt-god/workflows/hunt-bootstrap.md @.github/thrunt-god/templates/config.json @.github/thrunt-god/templates/mission.md @.github/thrunt-god/templates/hypotheses.md @.github/thrunt-god/templates/success-criteria.md @.github/thrunt-god/templates/huntmap.md @.github/thrunt-god/templates/hunt-state.md </execution_context>
Execute the bootstrap workflow from @.github/thrunt-god/workflows/hunt-bootstrap.md in case mode. Focus on turning the input signal into a scoped case with explicit hypotheses, data sources, and evidence requirements. When `--pack ` is present, use the pack bootstrap output as the default case skeleton and ask only for the missing pack parameters or signal-specific overrides. Create `.planning/QUERIES/` and `.planning/RECEIPTS/` as empty directories only. Do not load query-log or receipt templates during bootstrap; those belong to `/hunt-run` after real execution begins. Default behavior is scaffold-first: write confirmed facts only and leave unknown values as `TBD` instead of inventing sample content. Create `.planning/config.json` during bootstrap if it does not already exist so runtime, settings, and connector commands are immediately usable. Never hand-write `.planning/config.json`; use `thrunt-tools config-new-program` and `thrunt-tools config-set` so the file stays valid THRUNT config. Use built-in connector ids exactly as the runtime registers them, for example `splunk` and `elastic`; do not substitute `elasticsearch`. When writing connector profiles, use `base_url` for the runtime URL field; do not invent or substitute `endpoint`. Only configure connector profiles when auth type and secret ref names are confirmed. Never invent placeholder env vars or placeholder secrets for blocked connectors. When writing `secret_refs`, each confirmed secret must use the THRUNT object shape `{ "type": "env", "value": "ENV_VAR_NAME" }` rather than a raw string. Keep connector narrative, status notes, and access commentary in `ENVIRONMENT.md`, not in ad hoc config keys. Do not leave bootstrap-known fields as `TBD` after writing the files. Write the hunt artifacts directly.