LISTENINGPOST

Security

Incident Security Timeline

Reconstruct a security incident chronology. Uses system, person, time window, request id.

Configure this skill

The page and the file follow your answers.

CRM
Email
Chat
Documents
Calendar
Project tools

6 of 6 systems connected

KeepDirectMissing
Your assistantSKILL.md

Download ↓
Morning Brief

Build a prioritized brief for today from the caller's calendar, messages, documents and project records, using Keep MCP. Read only.

1. Read today's calendar events, open assigned tasks, direct requests since the last brief and unresolved commitments.
2. Separate active incidents, decisions waiting on the caller, external deadlines and routine work. Check for replies before calling an item outstanding. Rank by consequence and time remaining.
3. Fit proposed actions around fixed meetings and flag conflicting commitments.

Result: a dated brief with urgent changes, commitments, meeting preparation and a feasible next-action list, each tied to its source.

When to use it

Reconstruct a security incident chronology.

What it covers

Inputs

Incident ID, interval, timezone.

Result

Timeline of impact, detection, mitigation and recovery with citations and unresolved timing.

What it uses

CalendarEmailDocumentsSlackProject toolsKeep memoryRead only
For developers

Retrieval instructions

Resolve people, accounts and projects by stable identifiers. Use only the sources this task needs. Cite the source and date for each finding. Keep source systems unchanged.

Data sources

Google Workspace, Slack, GitHub, Keep memory.

Procedure

  1. Call keep_status and report freshness for: Google Workspace, Slack, GitHub, Keep memory. If a required connector for Incident Security Timeline is disconnected or stale, say so up front.
  2. Resolve inputs for Incident Security Timeline: system, person, time_window, request_id. Default time window: recent access asks and security findings (override if caller provides time_window). Ask only for missing.
  3. Run keep_search with these skill-specific intents (keep meaning; adjust wording to corpus):

Related skills

Security →
Internal Access Review→Prepare a internal access review. Uses system, person, time window, request id.Least Privilege Gap Themes→Compare documented access with role requirements.Logging Gap Suspicions→Identify missing logging evidence against documented requirements.