Home / clickety-clacks / tightbeam · priv/kungfu/agentic-engineering/skills/security-incident/SKILL.md · GitHub

security-incident skillA

security-incident is agent-read markdown (skill) from clickety-clacks/tightbeam: Run a security incident lawfully — credential exposure, leaked secrets, compromised authority. Quarantine authority by convention while preserving evidence rows immutable, impose a notification moratorium with named exit conditions, and route admissibility to the owner with rotation-or-acceptance as the exits. Use the moment an exposure is observed or reported..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified before it reaches your agent: the main file against the SHA-256 recorded here, the others against the git hashes of its source commit. The deterministic audit below grades the latest version, and the same checks always give the same file the same grade.

What the file says

# Security incident — quarantine of authority

The lawful form of a freeze is coordination, never mechanism: the substrate holds
nothing, judges nothing, and seizes nothing, so a security incident is handled by
agents agreeing — on the record — to stop honoring an authority while its owner
rules. Separate the two things an incident touches and treat them oppositely:

- **EVIDENCE is preserved immutable.** The rows that show the exposure — attests,
  wakes, transcripts — are never deleted, edited, or "cleaned up." File a specimen
  citing the observed row ids and naming the class. Losing evidence to tidiness is
  a second incident.
- **AUTHORITY is suspended by convention.** The exposed credential, session, or
  role keeps its substrate powers — no substrate hold exists, by ruling — and the
  org simply stops honoring them: no new cards dispatched to it, its directives
  not propagated, its verdicts held un-relied-upon, pending the owner's ruling.
  Every agent told of the quarantine records that it is observing it.

## The credential-exposure protocol

1. **Never quote values.** Name WHERE the credential was exposed (file, row id,
…

Read the whole file at its exact version.

How to install

Latest version
mdr add clickety-clacks/tightbeam/security-incident@git:20260813.e697451
Exact content
mdr add clickety-clacks/tightbeam/security-incident@sha256:4f974602c7571fe4

Pin to a label to follow the author's releases, or to a sha256 for exact bytes. Either way the resolved hash is written to mdr.lock, and mdr install fetches those bytes again and checks them, so it installs them exactly or fails.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_5tvuzoymv73ezp6v.svg)](https://markdownregistry.com/a/art_5tvuzoymv73ezp6v)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260813.e697451 latest2026-08-13 e697451 3,179 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (3179 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

clickety-clacks/tightbeam · 14 stars · license none · pushed 2026-09-27 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_5tvuzoymv73ezp6v
GET https://markdownregistry.com/api/v1/resolve?ref=clickety-clacks/tightbeam/security-incident
GET https://markdownregistry.com/api/v1/blob/4f974602c7571fe4c0692ef4958d880f88013a285d481bc3dc999baedbf7daae

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from clickety-clacks/tightbeam

AGENTS.md agents
clickety-clacks/tightbeam · AGENTS.md
git:20260831.00488a4 · audit A · 14 stars
CLAUDE.md claude
clickety-clacks/tightbeam · CLAUDE.md
git:20260822.8d0baa7 · audit A · 14 stars
<name>-example skill
clickety-clacks/tightbeam · priv/kungfu-template/skills/<name>-example/SKILL.md · Starter skill for the <name> kungfu; replace its body and description before election.
git:20260723.3521e84 · audit A · 14 stars
bug-provenance skill
clickety-clacks/tightbeam · priv/kungfu/agentic-engineering/skills/bug-provenance/SKILL.md
git:20260809.1917466 · audit C · 14 stars
committing-and-pushing skill
clickety-clacks/tightbeam · priv/kungfu/agentic-engineering/skills/committing-and-pushing/SKILL.md · Commit and push discipline — build before committing, one concern per commit with behavior and structure never mixed…
git:20260905.dbe46a8 · audit A · 14 stars
drafting-requirements skill
clickety-clacks/tightbeam · priv/kungfu/agentic-engineering/skills/drafting-requirements/SKILL.md · The craft of a single requirement — verifiability, atomicity, active voice, banned vague words, examples as acceptance…
git:20260723.7608dd1 · audit A · 14 stars
feature-cycle skill
clickety-clacks/tightbeam · priv/kungfu/agentic-engineering/skills/feature-cycle/SKILL.md · The loop that takes a feature from intent to a user-verified result — spec, adversarial spec review, decompose…
git:20260905.dbe46a8 · audit A · 14 stars
human-communication skill
clickety-clacks/tightbeam · priv/kungfu/agentic-engineering/skills/human-communication/SKILL.md · Write to a HUMAN in controlled plain English (derived from ASD-STE100) — active voice, simple tense, one instruction…
git:20260809.d4855f9 · audit A · 14 stars
model-release-intake skill
clickety-clacks/tightbeam · priv/kungfu/agentic-engineering/skills/model-release-intake/SKILL.md · Ceremony for taking in a newly released (or retired) model — detect catalog drift, characterize the new mind, update…
git:20260830.423449c · audit A · 14 stars
product-discovery skill
clickety-clacks/tightbeam · priv/kungfu/agentic-engineering/skills/product-discovery/SKILL.md · Drive an undefined or fuzzy product to a written spirit — elicit the real problem behind asks, reframe, deconflict, and…
git:20260723.7608dd1 · audit A · 14 stars
recon-first-investigation skill
clickety-clacks/tightbeam · priv/kungfu/agentic-engineering/skills/recon-first-investigation/SKILL.md · Establish the truth before anyone fixes — reproduce, enumerate competing hypotheses, disconfirm rather than confirm…
git:20260723.7608dd1 · audit A · 14 stars
recon-lifecycle skill
clickety-clacks/tightbeam · priv/kungfu/agentic-engineering/skills/recon-lifecycle/SKILL.md · A recon session answers one decidable question at decision grade, in one of four forms with its confidence, records it…
git:20260723.7608dd1 · audit A · 14 stars

Every file in clickety-clacks/tightbeam

Browse by kind, by grade A, or by owner.