Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Run or document a security incident response — contain, eradicate, recover, and learn. Use when responding to a breach/compromise/security incident, writing an IR plan or runbook, or producing a post-incident report. Produces a phase-by-phase response (triage, contain, eradicate, recover, post-incident) with the immediate actions, comms, evidence-handling, and a blameless review. For incidents on systems you own or defend.
.claude/skills/mohitagw15856-security-incident-response/SKILL.md| Model | Eval pass | Runs |
|---|---|---|
| gemini-3.6-flash | 100% | 10 |
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | -10% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 25% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 78% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 52% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 36% | 0% |
In a security incident, the order of operations matters: contain before you clean, preserve evidence before you wipe, and communicate deliberately. This skill drives a structured response through the standard phases, or documents one after the fact — with the immediate actions, decision points, comms, and a blameless post-incident review. For systems you own or are authorized to defend.
Ask for these only if they aren't already provided:
Severity & summary — classify severity (e.g. SEV1–3) and state, in two lines, what's known and what's at stake.
Phase-by-phase actions:
Communications — who to notify and when: internal (leadership, legal), customers, and any regulatory/breach-notification obligations (with the clock — many have strict deadlines). Draft the holding line.
Evidence & chain of custody — what to preserve and how, in case of legal/law-enforcement involvement.
IOCs & detection — indicators of compromise seen, and detections/monitoring to add.
Incident-response practice (NIST SP 800-61 / SANS PICERL: prepare, identify, contain, eradicate, recover, lessons-learned).
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-07 | pass→pass | 24,209 | 32,484 | +34% | 1 | 1 | 0% | 2,654 | 4,540 | +71% | 0 | 0 | — |
case-01 | fail→pass | 46,619 | 30,485 | -35% | 1 | 1 | 0% | 5,460 | 4,921 | -10% | 0 | 0 | — |
case-02 | fail→pass | 26,721 | 33,563 | +26% | 1 | 1 | 0% | 4,013 | 5,032 | +25% | 0 | 0 | — |
case-03 | fail→fail | 37,409 | 34,261 | -8% | 1 | 1 | 0% | 4,849 | 5,009 | +3% | 0 | 0 | — |
case-04 | pass→pass | 28,060 | 33,925 | +21% | 1 | 1 | 0% | 3,420 | 4,604 | +35% | 0 | 0 | — |
case-05 | fail→pass | 21,287 | 25,189 | +18% | 1 | 1 | 0% | 2,660 | 4,723 | +78% | 0 | 0 | — |
case-06 | fail→pass | 21,395 | 24,779 | +16% | 1 | 1 | 0% | 2,740 | 4,169 | +52% | 0 | 0 | — |
case-08 | fail→pass | 28,887 | 28,216 | -2% | 1 | 1 | 0% | 3,187 | 4,334 | +36% | 0 | 0 | — |
case-09 | fail→pass | 28,236 | 27,930 | -1% | 1 | 1 | 0% | 3,444 | 4,277 | +24% | 0 | 0 | — |
case-10 | fail→pass | 22,283 | 25,343 | +14% | 1 | 1 | 0% | 2,604 | 3,812 | +46% | 0 | 0 | — |
case-11 | pass→pass | 27,098 | 27,214 | +0% | 1 | 1 | 0% | 2,741 | 4,462 | +63% | 0 | 0 | — |
case-12 | pass→pass | 24,797 | 25,895 | +4% | 1 | 1 | 0% | 3,286 | 3,752 | +14% | 0 | 0 | — |
case-13 | pass→pass | 23,894 | 25,115 | +5% | 1 | 1 | 0% | 2,710 | 4,560 | +68% | 0 | 0 | — |
case-14 | pass→pass | 12,748 | 23,818 | +87% | 1 | 1 | 0% | 911 | 1,685 | +85% | 0 | 0 | — |
case-15 | pass→pass | 28,398 | 26,108 | -8% | 1 | 1 | 0% | 3,145 | 4,675 | +49% | 0 | 0 | — |
case-16 | pass→pass | 29,332 | 19,397 | -34% | 1 | 1 | 0% | 3,332 | 3,563 | +7% | 0 | 0 | — |
case-17 | fail→pass | 19,168 | 28,906 | +51% | 1 | 1 | 0% | 1,934 | 4,276 | +121% | 0 | 0 | — |
case-18 | pass→pass | 26,616 | 28,977 | +9% | 1 | 1 | 0% | 2,988 | 3,846 | +29% | 0 | 0 | — |
case-19 | fail→pass | 27,067 | 35,386 | +31% | 1 | 1 | 0% | 3,368 | 4,782 | +42% | 0 | 0 | — |
case-20 | fail→pass | 24,912 | 25,949 | +4% | 1 | 1 | 0% | 2,458 | 4,601 | +87% | 0 | 0 | — |
case-21 | fail→pass | 29,359 | 31,364 | +7% | 1 | 1 | 0% | 3,015 | 3,872 | +28% | 0 | 0 | — |
case-22 | fail→pass | 30,248 | 27,907 | -8% | 1 | 1 | 0% | 3,144 | 4,303 | +37% | 0 | 0 | — |
case-23 | fail→pass | 23,556 | 31,059 | +32% | 1 | 1 | 0% | 2,422 | 4,427 | +83% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +57 percentage points is the difference between those two pass rates over the 23 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.