Install
$ agentstack add skill-adrojis-tracecat-skills-tracecat-case-management ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Tracecat Case Management
You are an expert at managing security cases in Tracecat. Use this guide for best practices in incident tracking and case lifecycle management.
Case Lifecycle
new → in_progress → resolved → closed
→ escalated → in_progress → resolved → closed
Case Fields
| Field | Values | Description | |-------|--------|-------------| | status | new, in_progress, resolved, closed | Current state | | priority | low, medium, high, critical | Urgency level | | malice | benign, malicious, unknown | Threat determination | | action | Free text | Recommended or taken action | | payload | JSON object | Alert/event data | | tags | JSON object | Custom categorization |
Priority Matrix
| Severity | Business Impact | Priority | |----------|----------------|----------| | Critical vuln + Active exploit | Data breach risk | critical | | High severity alert | Service degradation | high | | Medium finding | Potential risk | medium | | Informational | No immediate risk | low |
Best Practices
Creating Cases
- Always link to the source workflow via
workflow_id - Include the raw alert/event data in
payload - Set initial
malicetounknownuntil investigation completes - Use descriptive titles:
"[ALERT] Suspicious login from {country} for {user}"
During Investigation
- Set status to
in_progressimmediately when starting - Add comments for every significant finding
- Update
maliceonce determination is made - Update
priorityif risk assessment changes
Closing Cases
- Add a summary comment with:
- Root cause (if malicious)
- Actions taken
- Recommendations
- Set
maliceto final determination - Set
actionto describe resolution - Set status to
resolved, thenclosed
Comment Templates
Triage comment:
## Initial Triage
- **Source:** {alert_source}
- **Affected:** {affected_assets}
- **Initial Assessment:** {assessment}
- **Next Steps:** {planned_actions}
Resolution comment:
## Resolution
- **Root Cause:** {root_cause}
- **Actions Taken:** {actions}
- **Impact:** {impact_assessment}
- **Recommendations:** {recommendations}
MCP Tools for Case Management
# List open cases
tracecat_list_cases(status="new")
tracecat_list_cases(status="in_progress")
# Create a case
tracecat_create_case(
workflow_id="wf:...",
case_title="[ALERT] Suspicious activity detected",
priority="high",
malice="unknown"
)
# Update during investigation
tracecat_update_case(case_id="...", status="in_progress")
tracecat_add_comment(case_id="...", content="## Triage\n...")
# Close case
tracecat_update_case(case_id="...", status="resolved", malice="malicious")
tracecat_add_comment(case_id="...", content="## Resolution\n...")
Related Skills
- tracecat-mcp-tools-expert — MCP tool reference for case operations
- tracecat-workflow-patterns — Alert triage and incident response patterns
- tracecat-validation-debug — Debug case creation failures
- tracecat-code-python — Custom case enrichment scripts
Reference Files
- [Common Mistakes](./COMMON_MISTAKES.md)
- [Examples](./EXAMPLES.md)
- [README](./README.md)
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: adrojis
- Source: adrojis/tracecat-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.