Clarion ships 131 skill templates across 13 domains. Every skill is a self-contained playbook: when to apply it, how to investigate, and what to do about it. Attach one to an agent and it stays synced with the template; edit it and it forks into your own copy.
Cloud
40 skills. The largest domain, and the one with the deepest per-provider coverage.- AWS (10) — a general CloudTrail response procedure plus dedicated playbooks for root-account security, IAM privilege escalation and persistence, credential exposure and access-key compromise, console authentication abuse, compute compromise, network and infrastructure manipulation, data exfiltration and resource exposure, suspicious access activity, and defense evasion or log tampering.
- Azure (10) — security posture triage and Defender for Cloud alert response, then Entra ID identity compromise, RBAC privilege escalation and persistence, Storage and data exposure, Key Vault secret access, network exposure and lateral movement, compute compromise, defense evasion, and Secure Score misconfiguration remediation.
- GCP (7) — Cloud Monitoring incident triage and Security Command Center finding triage, then privilege escalation and anti-forensics, service-account key compromise, unauthorized compute, and SCC-specific IAM and exposure response.
- Wiz (3) — toxic combinations scored on whether their ANDed facets are simultaneously live, threat detections scored on actor and baseline, and resource and identity ownership context.
- Cloudflare (2) — origin and edge availability, certificate and Access lifecycle.
- Vercel and Replit (6) — exposure sweeps and single-site triage for each platform, plus Vercel deployment-failure triage and security and domain monitoring.
- Microsoft Sentinel (1) — Azure and cloud control-plane activity investigation.
- Cross-provider (1) — suspicious shell session.
Identity & Access
26 skills. The broadest attack-pattern coverage of any domain, mirrored across identity providers.- Provider-neutral core (14) — triage and a general response procedure, then impossible travel, brute force and credential attacks, MFA attacks and session hijacking, OAuth and API abuse, admin compromise and privilege escalation, federation and IdP abuse, email and communication exposure, data exfiltration and staging, mobile device and MDM security, security control and policy weakening, government-backed attack warnings, and phishing campaign response.
- Microsoft (6) — Defender XDR variants of impossible travel, MFA and session hijacking, OAuth abuse, and admin compromise; Sentinel identity-compromise investigation and UEBA anomaly investigation.
- 1Password (4) — burst failed sign-ins, user suspension, vault item export, and the vault-access-then-export sequence.
- Huntress ITDR (1) and Wiz entitlement review (1) — identity findings from the detection and posture sides.
Endpoint & Device
16 skills. Every vendor gets a triage entry point; the attack-chain playbooks sit behind it.- CrowdStrike (8) — Falcon and OverWatch triage, then execution (scripts, LOLBins, process-ancestry anomalies), persistence, credential access, defense evasion and sensor tampering, lateral movement, command and control and exfiltration, and ransomware and destructive action.
- SentinelOne (4) — threat triage, investigation and scoping, gated containment and response, and false-positive handling with exclusions.
- Microsoft (2) — Defender endpoint host deep-dive and Sentinel ransomware and mass-impact scoping.
- Huntress (2) — incident investigation and escalation handoff.
SDLC
13 skills. Repository integrity, pipeline integrity, and the governance of what developers connect their tooling to.- GitHub (7) — tag spraying, CI/CD script injection via branch names, force push on a default branch, repository visibility change to public, branch-protection misconfiguration, org-owner addition, and a generic GitHub alert fallback.
- Claude Code / MCP governance (3) — server governance triage, inventory review sweep, and external account triage.
- Apex (2) — triage and remediation, plus a customizable Apex skill.
- Shift-left (1) — assessing new Jira epics for security risk before implementation starts.
DNS & Infrastructure
10 skills. Change detection on the records that define who you are, plus takeover risk. Record change, subdomain change, email-authentication (SPF/DKIM/DMARC) change, new subdomain discovery, DNS hijacking and registrar compromise, DNS tunneling and data exfiltration, DNS DDoS and amplification, Cloudflare DNS and zone integrity, and the dangling-subdomain sweep and triage pair.Operations
7 skills. The playbooks that keep the platform and the program healthy rather than responding to an attack. Outage runbook, health-repair triage for Clarion’s own integrations and monitors, signal-rule refinement, Brain maintenance, Vercel production rollback and recovery, review of newly discovered Vanta vendors, and drafting answers to vendor security questionnaires (DDQ / SIG / VSA).Vulnerability
6 skills. Findings that arrive as a queue rather than an incident, and the evidence trail behind closing them. Dependabot vulnerability remediation and backlog processing, reachability and runtime validation with exposure scoring (shared by Apex and Dependabot), Wiz vulnerability and component exposure, Cantina bug-bounty finding triage, and SOC 2 evidence collection.Security Incidents
5 skills. Cross-product entry points that route to the scenario playbooks in other domains. Microsoft Defender XDR and Microsoft Sentinel incident triage procedures, the Sentinel advanced-hunting pivot, Cloudflare Logpush incident handoff, and credential-harvesting triage.Network
3 skills. Cloudflare Logpush L7 DDoS detection triage, Logpush origin-exposure and DNS-bypass checks, and Cloudflare DDoS and WAF attack response.Web3 & Blockchain
2 skills. Smart contract and on-chain alert response — including emergency pause coordination — and multisig signer monitoring.Application
1 skill. Cloudflare client-side security response, covering injected JavaScript and browser-side supply-chain integrity.Threat Intelligence
1 skill. Threat intel advisory triage and applicability — deciding whether a published advisory, IOC set, or TTP actually touches your environment.Beyond the library
Skill templates are a starting point. The Community Library carries skills written and proven by other security teams running Clarion, alongside full agents. Take a single skill into an agent you already have, or an entire agent with its skills and scheduled jobs.Community Library
Skills and agents shared by teams running Clarion.
Our agents
Every agent template and the skills it bundles.