{"id":19199,"plugin_id":"plugins_6a9464ad86dc8191bd1a478b38296c88","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:22.696Z","digest":"e885e520045e49ddbbcf63ec4e51b93a3215f28b199e63d5a5089f604af875f5","against":null,"payload":{"name":"investigation","description":"Use when starting or governing an evidence-backed Microsoft security investigation.","included_files":[],"skill_md_contents":"---\nname: investigation\ndescription: Use when starting or governing an evidence-backed Microsoft security investigation.\n---\n\nPurpose: create a bounded case, plan safe pivots, and preserve facts, inferences, alternatives and approval boundaries.\n\nPrerequisites: authenticated MCP caller and an explicit entity or case ID.\n\nInputs: entity value, objective, priority, lookback window.\n\nWorkflow: `start_security_investigation` → `run_investigation_plan` or domain hunts → evidence graph/timeline → quality, confidence and closure assessments.\n\nAllowed tools: read-only hunting, local case/evidence/graph/report tools.\n\nSecurity constraints: no external response execution; no raw-result persistence; no verdict from a single signal.\n\nOutput: case ID, reproducible evidence references, next safe action, gaps and stop condition.\n\nFailure modes: unavailable tenant connector, insufficient scope, unknown schema, no safe template, contradictory evidence.\n\nTests: MCP workflow, evidence graph, confidence, closure readiness.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}