Skywatch Reviewing Osprey Rules
Use when validating or reviewing Osprey SML rules. Defines three-layer verification (osprey-cli, proactive checks, convention review) with severity classification. Not triggered on general coding tasks.
Skywatch Reporting Results
Report formats, BLIND structure, data presentation, and output conventions for investigation reports. Use when writing or reviewing investigation reports. Includes templates for memo, cluster deep-dive, cross-cluster, and rule check report types.
Skywatch Accessing Osprey
Understanding the Osprey moderation infrastructure — system architecture, ClickHouse data access, schema reference, and relationship to Ozone labelling. Use when investigating AT Protocol accounts or reviewing rule execution data.
Querying Clickhouse
Query patterns, safety rules, and performance tips for ClickHouse investigation queries against osprey_execution_results. Use when writing or reviewing ClickHouse queries for investigations.
Osprey Sml Reference
Use when writing SML rules for Osprey — syntax questions, type system, naming conventions, labeling patterns, entity extraction, window counting, or label operations
Scanning The Network
>-
Skywatch Investigating Osprey Rules
Systematic investigation methodology for Osprey SML rules projects. Produces structured text reports on project structure, labels, models, UDFs, and execution graphs.
Skywatch Search Incidents
Topic-based incident search with relevance scoring and content classification for AT Protocol investigations. Expands search topics into keyword strategies, classifies results by content type and incident confirmation, and produces geographically grouped output. Use when investigating incidents by topic during Phase 1 (Discovery) or as a standalone search.
Querying Ozone
>-
Classify Cluster
>-
Skywatch Planning Osprey Rules
Use when gathering requirements for a new Osprey SML rule before any code is written. Not triggered on general coding tasks — only when planning what a rule should detect, which labels to apply, and what signals to use.
Skywatch Classify Cluster
Narrative classification of co-sharing clusters on AT Protocol. Analyses cluster member content, identifies dominant narratives, coordination signals, shared sources, and likely origin. Distinguishes information operations from organic coordination. Use when a co-sharing cluster is identified during Phase 3 (Linkage) or Phase 4 (Amplification), or as a standalone cluster assessment.
Skywatch Conducting Investigations
Six-phase investigation methodology for AT Protocol network analysis — from initial discovery through reporting. Covers tool selection, signal identification, evidence standards, and directory conventions. Use when conducting or planning investigations.
Skywatch Labeling Standards
Evidence comment standards and data sourcing for all Ozone label actions. Defines required comment format, citation requirements, tiered evidence thresholds, and ClickHouse-first data sourcing cascade. Loaded by the ozone_label PreToolUse hook when comments fail validation.
Accessing Osprey
Understanding the Osprey moderation infrastructure — system architecture, ClickHouse data access, schema reference, and relationship to Ozone labelling. Use when investigating AT Protocol accounts or reviewing rule execution data.
Fixing Osprey Rules
Use when fixing Osprey SML validation errors or reviewer-identified issues. Contains error categories, fix patterns, and debugging workflow. Not triggered on general coding tasks — only when resolving specific SML errors.
Skywatch Authoring Osprey Rules
Use when writing or modifying Osprey SML rule files from a validated rule specification. Covers model writing, rule writing, effect wiring, and execution graph wiring. Not triggered on general coding tasks.
Skywatch Querying Clickhouse
Query patterns, safety rules, and performance tips for ClickHouse investigation queries against osprey_execution_results. Use when writing or reviewing ClickHouse queries for investigations.
Authoring Osprey Rules
Use when writing or modifying Osprey SML rule files from a validated rule specification. Covers model writing, rule writing, effect wiring, and execution graph wiring. Not triggered on general coding tasks.
Labeling Standards
>-
Triage Rule Hits
>-
Skywatch Triage Rule Hits
Rule hit triage methodology for Osprey rules. Samples recent hits, classifies each as TP/FP/novel/uncertain, and produces aggregate rule health assessment with actionable recommendations. Use when evaluating rule performance during Phase 5 (Rule Validation) or as a standalone rule maintenance check.
Search Incidents
>-
Skywatch Osprey Validate
Validate an Osprey SML rules project by running `uv run osprey-cli push-rules --dry-run` from the osprey-for-atproto repo and reporting the full result without summarising.
Reviewing Osprey Rules
Use when validating or reviewing Osprey SML rules. Defines three-layer verification (osprey-cli, proactive checks, convention review) with severity classification. Not triggered on general coding tasks.
Planning Osprey Rules
Use when gathering requirements for a new Osprey SML rule before any code is written. Not triggered on general coding tasks — only when planning what a rule should detect, which labels to apply, and what signals to use.
Skywatch Working The Queue
OODA-based moderation queue triage — observe reports, orient with context and policy, decide on classification, act on user-confirmed decisions. Supports multiple entry points (reports, appeals, tags, proactive filtering). Use when triaging the Ozone moderation queue or processing moderation reports.
Skywatch Querying Ozone
Reference guide for Ozone MCP tools — query patterns, filter combinations, pagination, write tool conventions, and common recipes. Use when working with the Ozone moderation API via MCP tools. Does not prescribe a workflow, see working-the-queue for queue triage methodology.
Skywatch Scanning The Network
Proactive network-wide threat scanning over a specified time window. Use when looking for emerging threats, incident upticks, anomalous network traffic, coordination patterns, or detection gaps.
Reporting Results
Report formats, BLIND structure, data presentation, and output conventions for investigation reports. Use when writing or reviewing investigation reports. Includes templates for memo, cluster deep-dive, cross-cluster, and rule check report types.
Conducting Investigations
Six-phase investigation methodology for AT Protocol network analysis — from initial discovery through reporting. Covers tool selection, signal identification, evidence standards, and directory conventions. Use when conducting or planning investigations.
Working The Queue
>-
Investigating Osprey Rules
>-
Skywatch Assess Account
Structured account assessment for AT Protocol investigations. Replaces manual account profiling by defining data collection questions, classification schema, and output format. Produces account_type, confidence, signals, and recommendation. Use when profiling an account of interest during Phase 2 (Characterization) or as a standalone quick assessment.
Assess Account
>-