alibabacloud-sas-incident-manageAlibaba Cloud Security Center incident management skill. Query security incidents, threat trends, and incident details. Triggers: "云安全中心", "安全事件", "事件查询", "安...
Install via ClawdBot CLI:
clawdbot install sdk-team/alibabacloud-sas-incident-manageGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses system directories or attempts privilege escalation
sudo mvCalls external URL not in known-safe list
https://ram.console.aliyun.com/AI Analysis
The skill definition shows no evidence of credential harvesting, data exfiltration, or hidden malicious instructions. The external API calls are consistent with the stated Alibaba Cloud Security Center purpose, and the suspicious permissions/URL references appear to be part of documentation or installation guidance rather than active malicious behavior.
Audited Apr 17, 2026 · audit v1.0
Generated Sep 6, 2026
Security analysts use this skill to query and list security incidents from Alibaba Cloud Security Center, enabling rapid triage of alerts. They can filter by threat level and status to prioritize high-severity incidents for immediate investigation.
Security teams can retrieve event counts by threat level to monitor the overall security posture over time. This enables trend analysis and generation of periodic security reports for management or compliance purposes.
After identifying an incident, analysts retrieve full details using the incident UUID to understand the attack pattern, affected resources, and recommended remediation steps. This supports in-depth forensic analysis and response actions.
Organizations can leverage incident query capabilities to maintain audit trails of security events. This helps demonstrate adherence to regulatory requirements by providing detailed records of incident handling.
Integrated into agent-based SOC workflows, this skill enables automated retrieval of incident data for correlation with other threat intelligence sources. It helps streamline the detection and response pipeline.
Managed security service providers can use this skill to efficiently manage security incidents across multiple client cloud environments. It enables them to deliver rapid incident response as a subscription-based service.
Consulting firms can offer security posture assessments and compliance reporting by leveraging trend data from this skill. They turn aggregated incident data into actionable insights for clients.
Large enterprises adopt this skill to improve their internal SOC efficiency, reducing time-to-response and potential losses from security breaches. Savings come from reduced incident impact and operational costs.
💬 Integration Tip
When integrating this skill, ensure you use the 'cloud-siem' product and specify the '--api-version' flag for each command. Set longer read timeouts to avoid timeout issues and always include the '--region' and '--user-agent' parameters.
Scored Sep 6, 2026
Audit a user's current AI tool stack. Score each tool by ROI, identify redundancies, gaps, and upgrade opportunities. Produces a structured report with score...
Manage installed skills lifecycle: suggest by context, track installations, check updates, and cleanup unused.
Document control system management for medical device QMS. Covers document numbering, version control, change management, and 21 CFR Part 11 compliance. Use...
Senior Quality Manager Responsible Person (QMR) for HealthTech and MedTech companies. Provides quality system governance, management review leadership, regul...
ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control imple...
⏰ simple Telegram reminders for OpenClaw. cron, zero dependencies.