{"id":19732,"plugin_id":"plugins_6a9ddbde4d288191b343f998bb82ea5c","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:46.470Z","digest":"75805ae256b9cd40240da493007fcf36518acd5db375ac4ce68c1ae2d33e17d9","against":null,"payload":{"description":"Analyze the public VEDA cyber-resilience demo, including its synthetic portfolio, vulnerabilities, assets, controls, attack paths, and executive signals. Use for VEDA demo questions and briefings; do not use as a source of live vulnerability or production security data.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":208},{"relative_path":"references/demo-evidence.json","size_in_bytes":3468}],"name":"analyze-veda-demo","skill_md_contents":"---\nname: analyze-veda-demo\ndescription: \"Analyze the public VEDA cyber-resilience demo, including its synthetic portfolio, vulnerabilities, assets, controls, attack paths, and executive signals. Use for VEDA demo questions and briefings; do not use as a source of live vulnerability or production security data.\"\n---\n\n# Analyze the VEDA Demo\n\nUse this skill only for the VEDA public demonstration. All evidence is fictional and exists to demonstrate a decision workflow.\n\n## Workflow\n\n1. Read [references/demo-evidence.json](references/demo-evidence.json) when the request depends on specific records, counts, or attack paths.\n2. Answer from the bundled evidence. If the VEDA Site is open and its read-only site tools are available, they may be used to inspect the same demo records.\n3. Distinguish observed demo evidence, inference, and recommended next decision.\n4. Include a short boundary whenever giving a risk score, remediation recommendation, or executive brief: the data is synthetic and the conclusion is not production security advice.\n\n## Supported outcomes\n\n- Summarize the demo portfolio and identify the top modeled priorities.\n- Search or compare the bundled demo vulnerabilities.\n- Explain how an asset's exposure, criticality, controls, and findings contribute to its illustrative risk.\n- Trace a bundled attack path from entry point to business impact.\n- Create a concise executive brief with the evidence, current control state, and next decision.\n\nDo not claim that a CVE, product version, asset, exploit, control, owner, or status is current outside the demonstration. Do not infer real-world exposure from the fictional organization. Do not produce instructions for exploitation. For real security decisions, ask for authoritative inventory and validated evidence.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}