← Aivana Security InvestigatorCONTENT HISTORY

Update to Aivana Security Investigator

Snapshot Sep 30, 2026 · 23:15 UTC · version 1.1.1

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "investigation",
  "description": "Use when starting or governing an evidence-backed Microsoft security investigation.",
  "included_files": [],
  "skill_md_contents": "---\nname: investigation\ndescription: Use when starting or governing an evidence-backed Microsoft security investigation.\n---\n\nPurpose: create a bounded case, plan safe pivots, and preserve facts, inferences, alternatives and approval boundaries.\n\nPrerequisites: authenticated MCP caller and an explicit entity or case ID.\n\nInputs: entity value, objective, priority, lookback window.\n\nWorkflow: `start_security_investigation` → `run_investigation_plan` or domain hunts → evidence graph/timeline → quality, confidence and closure assessments.\n\nAllowed tools: read-only hunting, local case/evidence/graph/report tools.\n\nSecurity constraints: no external response execution; no raw-result persistence; no verdict from a single signal.\n\nOutput: case ID, reproducible evidence references, next safe action, gaps and stop condition.\n\nFailure modes: unavailable tenant connector, insufficient scope, unknown schema, no safe template, contradictory evidence.\n\nTests: MCP workflow, evidence graph, confidence, closure readiness.\n"
}

SHA-256: e885e520045e49ddbbcf63ec4e51b93a3215f28b199e63d5a5089f604af875f5