Skip to content

Agent Operating Guide

/coach-security-report

Draft a SOC 2 and ISO 27001-aligned security incident report email to AssureSwarm's own security desk, redacted and staged as a Gmail draft you review and send.

Draft a security report email to AssureSwarm’s own security desk: the vendor’s security-incident mailbox. This skill reports TO AssureSwarm: it’s a support and security-reporting channel, not your organization’s incident register. It drives a structured intake aligned to SOC 2 CC7 and ISO 27001 A.5.24–A.5.28, detected-at, severity with a one-line rationale, affected systems, affected data categories, evidence pointers, and any containment actions, auto-gathers tenant context, composes the email, runs it through the canvas-redactor agent, then calls Gmail create_draft. It never sends: the report lands as a draft you review in your email client and send yourself.

For a suspected security event affecting the confidentiality, integrity, or availability of AssureSwarm data: data exposure, a credential or API-key leak, account compromise, unauthorized access, malware, denial-of-service, or social engineering.

  • For a non-security helpdesk issue: a bug, a how-to, a feature request, or an access request not involving suspected compromise: use /coach-ticket-open instead, its non-security sibling.
  • To record and triage the incident as a record in your own Canvas tenant, open an issue item via /coach-item-create and run the grc-incident-management-lifecycle workflow: this skill only notifies the vendor.
Flag Required Notes
--severity critical|high|medium|low|informational No Pre-set the severity; otherwise it’s gathered during intake.
--to <email> No Override the default security-incident@assureswarm.com address.

Everything else is gathered through an interactive, compliance-aligned intake.

/coach-security-report --severity high walks you through the intake, what you observed, when and how, the affected systems and data categories, the evidence you hold, and any containment already taken, auto-gathers tenant context from .coworkcanvas/ config and recent log tails, and composes a [INCIDENT][severity:high] ... email to security-incident@assureswarm.com, cc’ing your own admin address as a record copy. It runs the redaction gate over the body, creates a Gmail draft for you to review and send, and appends the report to .coworkcanvas/incidents/log.md.

  • Drafts only, never sends. You review in your email client and hit send. If you prefer lower attribution, send the resulting draft from a separate account: the plugin tracks no identity beyond the From header on the eventual sent email.
  • Critical and high severity carry a redaction floor. Internal-only fields are always scrubbed, and any uncertain content requires your confirmation before the draft is built.
  • Gmail MCP is required. If it isn’t configured, the skill halts with a clear message: there’s no alternative draft path within this skill.
  • Severity drives routing. The vendor’s Gmail filter routes [severity:critical] and [severity:high] to oncall plus PagerDuty; expect a response within 30 minutes. For those, the skill also reminds you to send now and to notify your own organization’s incident response if you believe an attack is in progress.
  • The local log is your evidence chain under ISO 27001 A.5.28: keep it; don’t delete it. To also track the event in your own tenant’s register, open an issue via /coach-item-create.
  • /coach-ticket-open: the non-security sibling, for helpdesk bugs, how-tos, and access requests.
  • /coach-item-create: open an issue to record the incident in your own tenant’s register.
  • /coach-redact: the standalone form of the redaction gate this skill runs over the draft.