基于 SOC 职业分类
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/backbay-labs/thrunt-god --skill thrunt-workstreams命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
Show available THRUNT threat hunting commands and artifact layout
Map available telemetry, query surfaces, tenants, retention windows, and investigation blind spots
Initialize a threat hunting case from a signal, detection, intel lead, or analyst suspicion
| name | thrunt-workstreams |
| description | Manage parallel workstreams — list, create, switch, status, progress, complete, and resume |
Manage parallel workstreams for concurrent milestone work.
/thrunt-workstreams [subcommand] [args]
| Command | Description |
|---|---|
list | List all workstreams with status |
create <name> | Create a new workstream |
status <name> | Detailed status for one workstream |
switch <name> | Set active workstream |
progress | Progress summary across all workstreams |
complete <name> | Archive a completed workstream |
resume <name> | Resume work in a workstream |
Parse the user's input to determine which workstream operation to perform.
If no subcommand given, default to list.
Run: node "$THRUNT_TOOLS" workstream list --raw --cwd "$CWD"
Display the workstreams in a table format showing name, status, current phase, and progress.
Run: node "$THRUNT_TOOLS" workstream create <name> --raw --cwd "$CWD"
After creation, display the new workstream path and suggest next steps:
/hunt-new-program --ws <name> to set up the milestoneRun: node "$THRUNT_TOOLS" workstream status <name> --raw --cwd "$CWD"
Display detailed phase breakdown and state information.
Run: node "$THRUNT_TOOLS" workstream set <name> --raw --cwd "$CWD"
Also set THRUNT_WORKSTREAM env var for the current session.
Run: node "$THRUNT_TOOLS" workstream progress --raw --cwd "$CWD"
Display a progress overview across all workstreams.
Run: node "$THRUNT_TOOLS" workstream complete <name> --raw --cwd "$CWD"
Archive the workstream to milestones/.
Set the workstream as active and suggest /thrunt-resume-work --ws <name>.
Format the JSON output from thrunt-tools into a human-readable display.
Include the ${THRUNT_WS} flag in any routing suggestions.