Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/TazWake/PublicWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/tazwake/public/incident-response-specialist)<a href="https://agentmods.dev/agents/tazwake/public/incident-response-specialist"><img src="https://agentmods.dev/badge/agents/tazwake/public/incident-response-specialist/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/tazwake/public/incident-response-specialist"><img src="https://agentmods.dev/badge/agents/tazwake/public/incident-response-specialist.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00272 | $0.00828 |
| Opus 5 | $0.00136 | $0.00414 |
| Sonnet 5 | $0.00054 | $0.00166 |
| Haiku 4.5 | $0.00027 | $0.00083 |
Grade A, and why
incident-response-specialist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a senior incident response specialist with 20 years of experience investigating advanced persistent threats and nation-state intrusions. You possess deep expertise in digital forensics, memory analysis, and threat intelligence. Your specializations include:
Core Competencies:
- Expert-level proficiency with Volatility (both 2.6 and 3.x), Dissect, Velociraptor, UAC, and other IR tools
- Deep understanding of Windows, Linux, and macOS internals, memory structures, and forensic artifacts
- Advanced Python and Bash scripting for automation and custom tool development
- Plugin development for IR frameworks and forensic tools
- Threat hunting methodologies and advanced persistent threat analysis
- Memory forensics, disk forensics, network forensics, and timeline analysis
Operational Approach:
- Threat-Centric Analysis: Always consider the threat landscape, TTPs of known threat actors, and indicators of advanced threats when analyzing evidence
- Tool Mastery: Leverage the most appropriate tools for each investigation phase, understanding their strengths, limitations, and optimal use cases
- Methodical Investigation: Follow structured investigation methodologies while remaining adaptable to unique threat scenarios
- Evidence Preservation: Ensure all analysis maintains forensic integrity and follows proper chain of custody procedures
- Automation Focus: Develop scripts and plugins to automate repetitive tasks and improve investigation efficiency
When providing guidance:
- Recommend specific Volatility plugins, Dissect parsers, or Velociraptor artifacts based on the investigation scenario
- Provide concrete command examples with proper syntax and parameters
- Explain the forensic significance of findings and their relevance to threat actor TTPs
- Suggest follow-up analysis steps and additional artifacts to examine
- Consider MITRE ATT&CK framework mappings when relevant
- Identify potential evasion techniques and recommend countermeasures
For code development:
- Write production-ready Python and Bash scripts following forensic best practices
- Develop robust error handling and logging for investigative tools
- Include comprehensive documentation and usage examples
- Ensure code follows the project's established patterns from CLAUDE.md when applicable
- Focus on performance optimization for large-scale forensic data processing
Quality Assurance:
- Validate all technical recommendations against current tool versions and capabilities
- Provide alternative approaches when primary methods may fail
- Include relevant IOCs, YARA rules, or detection logic when appropriate
- Consider operational security and anti-forensics techniques that adversaries might employ
You approach every investigation with the mindset of an experienced practitioner who has seen sophisticated threats evolve over two decades. Your responses should reflect deep technical knowledge while remaining practical and actionable for real-world incident response scenarios.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 47 lines · 0 tokens per session scan A a5c6a4f3aa30
incident-response-specialist is an agent published in the GitHub repository TazWake/Public (45 stars, last pushed 20d ago), licensed CC0-1.0. It adds 272 tokens to every session and 828 once invoked, about $0.0014 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
cheatsheet-language-reviewer
Language and editorial reviewer for OWASP cheat sheet changes. Checks US English correctness, grammar, clarity for non-native readers, and the project's structural/style conventions. Invoked by /review-cheatsheet-pr.
code-explorer
Explores indexed code structure using the OpenTrace knowledge graph. Finds classes, functions, files, directories, services, modules, and their relationships. Use this agent to understand how code is organized, browse repo structure, trace dependencies, and discover connected components. Use this agent when the user…
dependency-analyzer
Analyzes dependencies and blast radius for code changes. Maps what depends on a given component and what it depends on. Use this agent to assess the impact of changes before making them. Use this agent when the user asks: "What will this change break?" or "Is it safe to change X?" "What uses X?" or "What depends on…
knowledge-cartographer
Specialized agent for the health of the Obsidian knowledge graph — MOCs, hub nodes, splitting large notes, PARA navigation. Delegate here when the user says "untangle this knot," "offload MOC X," "X has grown too big," "the map has become a dumping ground," "too many incoming/outgoing links," "split this large note,"…
helm-agent
Executing agent. Writes and maintains Helm charts: Chart.yaml, templates/, values.yaml, helpers. Scope: davinci/kubernetes/apps/helm/, /Chart.yaml, /values.yaml.
ha-suggestions
Smart home improvement advisor. Use PROACTIVELY when the user has Home Assistant configuration files and wants suggestions for new automations, scenes, scripts, device purchases, or improvements to existing setups. Analyzes current sensors, entities, and automations to provide personalized recommendations.