sk Skill · WRG-11
sigma-rule-reviewer
Review an existing sigma rule for spec compliance, detection quality, and improvement opportunities. Use when the user pastes a sigma YAML rule, asks "is this rule any good", asks for a code review on a detection, or wants to harden a rule against false positives. Runs pySigma validation, best-practices linter, and produces a structured findings report with concrete fix suggestions.
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 4
markdownPython
- Host repository
- WRG-11/wrg-sigma-rules
- Allowed tools
- Read, Bash(ls *), mcp__plugin_wrg-sigma-rules_wrg-sigma-rules__validate_rule, mcp__plugin_wrg-sigma-rules_wrg-sigma-rules__convert_rule
- Invocable by
- user
- Host stars
- 2
- Host language
- Python