基于 SOC 职业分类
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/vstorm-co/agenticos --skill aml-alert-narrative命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
| name | AML alert narrative |
| description | Write the factual narrative behind a monitoring alert for an analyst to decide on. |
| category | security |
The analyst needs the facts assembled, in order, with nothing characterised.
What the rule fired on, in plain language · the transactions that triggered it, with dates, amounts, counterparties and channels · what the customer's expected activity is, from onboarding · how the observed activity differs · what the customer has said about it, if anything · prior alerts on this customer and how they were closed.
"Six transfers of 9,800 over eight days to three new counterparties" is the narrative. "Structuring" is a conclusion, and writing it changes what the file means.
The negative findings — the checks made that found nothing. An analyst needs to know what has already been looked at.
Reach a conclusion, recommend a filing, use typology names as descriptions, or tell the customer that any of this is happening.
Work with messaging-channel bots — Telegram, Slack or Mattermost. Register a bot, route inbound messages through an agent, choose webhook vs polling, handle an @slug mention, or add a new channel adapter. Use when wiring chat into a messaging platform or debugging bot delivery, identity linking or "the bot answered as itself".
Change the agent spec — add or remove a field, rename one, tighten a rule, bump SPEC_VERSION, change publish-time validation, or touch YAML export/import. Use whenever editing app/agents/spec.py or anything that reads a stored spec. Every published agent and every client git repository holds a copy of this format, so a change that only works forwards breaks agents nobody touched.
Work with MCP servers — connect one, add an entry to the server catalog, debug "the agent cannot see my MCP tools" or a failing OAuth flow, or change how connections are probed, prefixed or filtered. Use when the ask involves an external SaaS tool (GitHub, Linear, Notion, Slack, Stripe, Postgres…) and before writing a capability that would just be an API client for one.