Preserve Web Incident Skill
CANDIDATE CANDIDATE NEW BOUNDED TASK · Operations Web Function 0.1.0. Capture minimally necessary, reproducible web incident evidence and chain of custody before remediation changes or destroys it. Use for suspected compromise, cloaking, injected spam, rogue redirects, reinfection, unauthorized access, destructive repair requests, or any incident where volatile public responses, logs, files, users, jobs, or host state may be needed to establish cause and persistence.
Canonical owner: operations-web-function:preserve-web-incident · Task registration: TASK_LIBRARY_REGISTRATION_PENDING
Broader definitive hub · Exact Task Library page: TASK_LIBRARY_REGISTRATION_PENDING
Download the complete plugin · Source skill SHA-256: cbdf702d7411d66e25bbcfb593e526425387ed154a1b4d33f628488b209ceb90
Candidate source: dennisyu/blitzmetrics-skills · commit: PENDING_MERGE · path: skills/preserve-web-incident/SKILL.md
Preserve first when changing the system could erase the answer. This skill is evidence collection, not cleanup.
Preservation plan
- Confirm authorization, target, time window, privacy class, and evidence destination.
- Record the source finding and exact reproduction inputs: URL, identity, vantage, headers requested, timestamps, tool version/hash, and control result.
- Capture the smallest sufficient public response set, headers, hashes, screenshots when layout matters, DNS/TLS facts, and search-index evidence.
- When authorized, collect read-only internal corroboration: users, dependencies, must-use extensions, scheduled tasks, relevant file metadata and hashes, logs, database indicators, and host state.
- Hash each artifact and record collector, collection time, source, redaction class, and storage reference.
- Separate untouched originals from redacted working copies.
- State missing evidence and collection failures as
UNKNOWN. - Produce a chain-of-custody receipt and a safe triage summary.
Boundaries
- Do not paste raw payloads, credentials, private paths, account lists, customer data, or exploit details into a task system or public report.
- Do not browse unnecessary private data “just in case.” Collect only what answers the incident questions.
- Do not execute unknown files or probe beyond the authorized target.
- Do not clean, delete, rotate, disable, or publish while operating under a read-only preservation job.
- If a secret appears unexpectedly, stop displaying it, record only that a credential-bearing artifact exists, and route a private rotation/removal action.
Completion
Preservation is complete when a second authorized operator can reproduce the finding or verify why it can no longer be reproduced, artifact hashes and custody are recorded, unknowns are explicit, and remediation can proceed without relying on memory.
Return to $triage-web-incidents for containment and route any change through $change-web-production.
This is a generated candidate implementation page, not automatically a definitive article or accepted Task Library task. It delegates to the named canonical owner until reviewed registration and merge receipts exist.
