Security
Incident Security Timeline
Reconstruct a security incident chronology. Uses system, person, time window, request id.
Configure this skill
The page and the file follow your answers.
CRM
Email
Chat
Documents
Calendar
Project tools
6 of 6 systems connected
KeepDirectMissing
Your assistantSKILL.md
Download ↓
When to use it
Reconstruct a security incident chronology.
What it covers
Inputs
Incident ID, interval, timezone.
Result
Timeline of impact, detection, mitigation and recovery with citations and unresolved timing.
What it uses
CalendarEmailDocumentsSlackProject toolsKeep memoryRead only
For developers
Retrieval instructions
Resolve people, accounts and projects by stable identifiers. Use only the sources this task needs. Cite the source and date for each finding. Keep source systems unchanged.
Data sources
Google Workspace, Slack, GitHub, Keep memory.
Procedure
- Call keep_status and report freshness for: Google Workspace, Slack, GitHub, Keep memory. If a required connector for Incident Security Timeline is disconnected or stale, say so up front.
- Resolve inputs for Incident Security Timeline: system, person, time_window, request_id. Default time window: recent access asks and security findings (override if caller provides time_window). Ask only for missing.
- Run keep_search with these skill-specific intents (keep meaning; adjust wording to corpus):