{"id":22218,"plugin_id":"plugins_6ab01c9056c481918eac972df8fb396d","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:17:11.539Z","digest":"249209a52c0e2653ab77777f934723ae3808dae859b276219daf5c64685bc377","against":null,"payload":{"name":"observability-and-incident-response","description":"Review security logging, alerting, audit trails, containment, recovery, and post-incident evidence.","included_files":[],"skill_md_contents":"---\nname: observability-and-incident-response\ndescription: Review security logging, alerting, audit trails, containment, recovery, and post-incident evidence.\n---\n\n# Observability and Incident Response\n\nCheck whether security-relevant events are logged with actor, target, result, request ID, and timestamp without exposing secrets or personal data. Review alert thresholds, retention, tamper resistance, access, key rotation, containment, rollback, recovery, and post-incident learning.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}