Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add gensecaihq/Wazuh-Autopilot --skill action-verificationgit clone --depth 1 https://github.com/gensecaihq/Wazuh-AutopilotWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/gensecaihq/wazuh-autopilot/action-verification)<a href="https://agentmods.dev/skills/gensecaihq/wazuh-autopilot/action-verification"><img src="https://agentmods.dev/badge/skills/gensecaihq/wazuh-autopilot/action-verification/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/gensecaihq/wazuh-autopilot/action-verification"><img src="https://agentmods.dev/badge/skills/gensecaihq/wazuh-autopilot/action-verification.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00042 | $0.01232 |
| Opus 5.5 | $0.00017 | $0.00493 |
| Sonnet 5 | $0.00008 | $0.00246 |
| Haiku 4.5 | $0.00004 | $0.00123 |
Grade A, and why
action-verification scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Action Verification
A successful Wazuh API call means the active-response command was dispatched, not that it worked on the host. The agent may be disconnected, the AR script missing, or the attacker may have re-established access. Verify every executed action.
Procedure
list_actions(case_id)— find actions with statusexecuted(orverified: null).- For each, call the matching check tool with the same target parameters. Know what each check actually looks at. None of them read live host state, so treat a positive as strong evidence, not proof:
| Action type | Check tool | What it inspects (Wazuh MCP Server v4.3.0) | Verified when |
|---|---|---|---|
| block_ip / firewall_drop / host_deny | wazuh_check_blocked_ip(ip_address, agent_id) |
active-response alerts (rule.groups: active_response) with data.srcip = IP in the last 24h, e.g. rule 651 "Host Blocked by firewall-drop Active Response" or rule 653 (host-deny) |
blocked: true (matching_alerts > 0) |
| isolate_host | wazuh_check_agent_isolation(agent_id) |
a recent active-response alert mentioning isolation for the agent. Connection status is not a signal: an isolated host keeps its manager link | isolation_confirmed: true |
| kill_process | wazuh_check_process(agent_id, process_id) |
syscollector process inventory for that PID. Periodic, not live: compare inventory_scan_time to the execution time |
running: false with a scan time after execution |
| disable_user | wazuh_check_user_status(agent_id, username) |
active-response alerts mentioning the user in the last 24h, classified disable/enable. A heuristic, not order-aware | likely_disabled: true |
| quarantine_file | wazuh_check_file_quarantine(agent_id, file_path) |
the latest FIM "deleted" alert (rule 553) for the exact path. Needs the path under FIM monitoring and the Indexer configured | quarantined: true |
| restart_wazuh | check_agent_health(agent_id) |
agent status and last keepalive | agent active with a keepalive after execution |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 74 lines · 42 tokens per session scan A 512ba3abf27b
action-verification is a skill published in the GitHub repository gensecaihq/Wazuh-Autopilot (57 stars, last pushed 2d ago), licensed MIT. It adds 42 tokens to every session and 1,232 once invoked, about $0.0002 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-25.
Other skills, from other repositories
agent-performance-optimizer
Agent skill for performance-optimizer - invoke with $agent-performance-optimizer.
agent-refinement
Agent skill for refinement - invoke with $agent-refinement.
diag-harness
Kernel-version skew check (ADR-027). Reports manifest surface + manifest kernel + installed kernel + verdict (match/patch-diff/minor-diff/major-diff). Exits 1 on minor/major skew with a copy-pasteable npm install @metaharness/[email protected] next step. Exits 2 if no .harness/manifest.json at path.
building-detection-rule-with-splunk-spl
Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
nio-scan
Nio code/skill execution-risk scanner. Use when the user wants to scan a file, repo, directory, or skill for execution risks — e.g. "scan this code for risks", "is this file/plugin dangerous", "check this repo for malicious code", "run nio scan on ". Focused single-purpose skill; for other Nio operations use /nio.
nio-doctor
Nio config validator + connectivity check. Use when the user wants to validate their Nio setup — e.g. "run nio doctor", "is my nio config valid / working", "test my OAuth / external endpoint / LLM connectivity", "why isn't my scorer firing". Focused single-purpose skill; for other Nio operations use /nio.