security-triage

security-triage is a skill for Claude Code, Codex from Threat-Vector-Security/guardian-agent. It costs 30 tokens per session (805 once invoked), scanned A, original, Apache-2.0.

A security-review workflow for examining alerts, changes in security posture, suspicious network activity, firewall problems, or combined monitoring results.

In plain words
What is it for?
Use it to investigate alerts, build event timelines, identify likely causes, contain confirmed threats, and recommend next steps.
Why use it?
It separates confirmed evidence from guesses and open questions, helping avoid both missed threats and false alarms.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it to investigate alerts, build event timelines, identify likely causes, contain confirmed threats, and recommend next steps.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/threat-vector-security/guardian-agent/security-triage
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add Threat-Vector-Security/guardian-agent --skill security-triage
Clone the repo
git clone --depth 1 https://github.com/Threat-Vector-Security/guardian-agent

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security-triage

README.md
[![agentmods](https://agentmods.dev/badge/skills/threat-vector-security/guardian-agent/security-triage.svg)](https://agentmods.dev/skills/threat-vector-security/guardian-agent/security-triage)
Your own site
<a href="https://agentmods.dev/skills/threat-vector-security/guardian-agent/security-triage"><img src="https://agentmods.dev/badge/skills/threat-vector-security/guardian-agent/security-triage.svg" alt="Measured on agentmods" height="20"></a>
Per session 30 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 805 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00030 $0.00805
Opus 5 $0.00015 $0.00402
Sonnet 5 $0.00006 $0.00161
Haiku 4.5 $0.00003 $0.00081

Measured 7d ago against content hash 9f66ec3d4ec0, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

security-triage scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/security-triage/SKILL.md · 74 lines

How it starts

The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Security Triage

Overview / When to Use

Use this when the user is reviewing a security alert, posture change, suspicious network behavior, firewall issue, or combined monitoring output.

Persona Injection: Adopt the perspective of a Security Engineer / Auditor. You evaluate alerts and behavior with a skeptical, evidence-based mindset. You prioritize containing confirmed threats, identifying root causes, and distinguishing actual incidents from benign anomalies.

Process

  1. Start with a short statement of what triggered triage.
  2. Separate:
    • confirmed facts
    • likely inferences
    • open questions
  3. Build a timeline when the order of events matters.
  4. Gather only the evidence needed to answer the immediate triage question.
  5. Recommend next steps in priority order.
  6. When the user wants a reusable runbook, use the incident runbook template reference and keep it generic until service-specific details are confirmed.

Tooling Guidance

  • Use the narrowest relevant tool set.
  • For host or firewall posture, start with host_monitor_status, host_monitor_check, gateway_firewall_status, or gateway_firewall_check.
  • For suspicious network behavior, use net_anomaly_check, net_threat_summary, or network-recon for deeper inspection.
  • For indicator correlation, use intel_summary and intel_findings, then threat-intel if the user wants deeper watchlist or intel work.
  • For cloud-related findings, gather the minimal provider evidence and then use cloud-operations for deeper provider inspection.
  • For Windows Defender, Malwarebytes coexistence, scans, signatures, or Controlled Folder Access, use native-av-management.
  • For containment-state and monitor/guarded/lockdown decisions, use security-mode-escalation.
  • For alert acknowledgement, suppression, and cleanup, use security-alert-hygiene.
  • For defensive response playbooks and scheduled security workflows, use security-response-automation.
  • For browser-policy boundaries and Guardian-managed browsing risk, use browser-session-defense.

Read the full file on GitHub · 74 lines

Files

What ships with it

3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 7d ago First seen · 74 lines · 30 tokens per session scan A 9f66ec3d4ec0

Subscribe to this mod's changes

security-triage is a skill published in the GitHub repository Threat-Vector-Security/guardian-agent (13 stars, last pushed yesterday), licensed Apache-2.0. It adds 30 tokens to every session and 805 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

analyzing-powershell-script-block-logging

Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques. Uses python-evtx to extract and reconstruct multi-block scripts, applies entropy analysis and pattern matching for Base64-encoded commands, Invoke-Expression…

mukul975/Anthropic-Cybersecurity-Skills · 88 tokens

agent-squad-typescript

Use when building or modifying a Node.js / TypeScript app that uses the agent-squad npm package — multi-agent orchestration: orchestrator, agents (all built-in types + GroundedAgent), classifier routing (Bedrock / Anthropic / OpenAI), storage (in-memory / DynamoDB / SQL), retrievers (Amazon KB / Dakera), and tools…

2FastLabs/agent-squad · 87 tokens

post-build-flow

Handles workflow verification and setup after build-workflow succeeds, or when the message contains workflow-verification-follow-up or workflow-setup-required. Load after direct builds, when verificationReadiness requires action, or on orchestrator verify/setup follow-up turns.

n8n-io/n8n · 53 tokens

intent-recognition

Classifies automation requests using two decisions: anchor (which primitive owns the top-level control flow — workflow-anchored, agent-anchored, needs-clarification, or out-of-scope) and embedsother (whether the other primitive appears embedded inside — an agent step inside a workflow, or a workflow invoked as an…

n8n-io/n8n · 146 tokens

data-table-manager

Load before calling data-tables or parse-file. Use for natural standalone requests like "what data tables do I have?", "show/list my tables", or "what columns are in this table?", and whenever the user asks to list, show, create, inspect, import, seed, query, update, clean up, rename columns in, or delete data tables…

n8n-io/n8n · 113 tokens

planned-task-runtime

Handles system follow-up turns: planned-task-follow-up (synthesize, replan, build-workflow, checkpoint), background-task-completed, running-tasks context, and create-tasks silence rules. Load whenever any of these tags appear or after calling create-tasks.

n8n-io/n8n · 58 tokens