Skills

Security Alert Triage

verified
Updated May 13, 2026

What this skill does

Automatically triages security alerts from AWS GuardDuty, CloudTrail, and other cloud security services. Classifies each alert by severity and type, correlates related events, filters false positives, suggests response actions, and routes critical alerts to the appropriate team via Slack and PagerDuty.

Example

PROMPT

We have 340 GuardDuty findings from the last 24 hours across 5 AWS accounts. Need help triaging: classify severity, flag false positives (we have known pentest IPs and dev sandbox activity), and route critical/high to our security-oncall Slack channel and PagerDuty.

OUTPUT
Security Alert Triage Summary — Last 24h | Severity | Count | Auto-Resolved | Action Required | |-----------|-------|---------------|-----------------| | Critical | 2 | 0 | 2 | | High | 12 | 1 | 11 | | Medium | 85 | 42 | 43 | | Low/Info | 241 | 198 | 43 | |-----------|-------|---------------|-----------------| | Total | 340 | 241 | 99 | False Positive Rate: ~28% (pentest IPs, known dev sandbox) Routed to Slack: 14 alerts (Critical + High) PagerDuty incidents created: 2 (Critical only) Top Critical Alerts: 1. [GuardDuty] UnauthorizedAccess:EC2/SSHBruteForce — i-0abc123, us-east-1 2. [GuardDuty] Backdoor:EC2/C&CActivity.B!DNS — i-0def456, eu-west-1

Required Tools

SlackSlack
AWSAWS
PagerDutyPagerDuty

Compatible Agents

ClaudeClaude
CursorCursor
WindsurfWindsurf
ChatGPTChatGPT
GitHub CopilotGitHub Copilot
Any MCP-compatible agentAny MCP-compatible agent

Add to your agent

Download Skill

Or install via CLI:

$ npx skills add webrix-ai/agent-skills --skill security-alert-triage

Deploy Org-wide

Provision to teams via RBAC
Identity-aware execution
Signed & verified skills
Full audit trail
Auto-bundled with required MCP servers
Use withwillow

Free for up to 5 users

Your agents are already in the wild.

Give them a Basecamp. Go from AI chaos to AI work, in minutes.

Security Alert Triage | Willow Marketplace