SKILL.md
Generate Report Skill
Save generated report content to a markdown file with standardized naming convention.
Inputs
REPORT_CONTENT- The full markdown content of the reportREPORT_TYPE- Short identifier for the report type:
- alerttriage - Alert triage reports - iocenrichment - IOC enrichment reports - caseinvestigation - Case investigation reports - huntsummary - Threat hunt reports - incident_report - Incident response reports
REPORTNAMESUFFIX- Descriptive suffix (e.g., case ID, IOC value, hunt name)- (Optional)
TARGET_DIRECTORY- Directory to save in (default:./reports/)
Workflow
Step 1: Construct Filename
Generate standardized filename:
{TARGET_DIRECTORY}/{REPORT_TYPE}_{REPORT_NAME_SUFFIX}_{YYYYMMDD_HHMM}.md
Examples:
./reports/alerttriagecase123420250115_1430.md./reports/iocenrichment198.51.100.10202501150900.md./reports/huntsummaryAPT29202501151200.md
Step 2: Write File
Use the Write tool to save REPORT_CONTENT to the constructed path.
Outputs
| Output | Description |
|---|---|
REPORTFILEPATH |
Full path to the saved report file |
WRITE_STATUS |
Success/failure status of the write operation |
Report Template Structure
# [Report Type]: [Subject]
**Generated:** [timestamp]
**Runbook:** [runbook name that generated this]
**Case/Alert ID:** [if applicable]
## Summary
[Brief overview of findings]
## Details
[Detailed findings, enrichment data, etc.]
## Assessment
[Risk assessment, classification]
## Recommendations
[Next steps, actions to take]
## Appendix
[Raw data, tool outputs, diagrams]
Naming Convention
| Report Type | Suffix Example | Full Example |
|---|---|---|
| alert_triage | case_1234 | alerttriagecase123420250115_1430.md |
| ioc_enrichment | evil.com | iocenrichmentevil.com202501150900.md |
| hunt_summary | APT29 | huntsummaryAPT29202501151200.md |