Agent Operating Guide
/coach-security-report
Draft a SOC 2 and ISO 27001-aligned security incident report email to AssureSwarm's own security desk, redacted and staged as a Gmail draft you review and send.
Draft a security report email to AssureSwarm’s own security desk: the vendor’s
security-incident mailbox. This skill reports TO AssureSwarm: it’s a support and
security-reporting channel, not your organization’s incident register. It drives a
structured intake aligned to SOC 2 CC7 and ISO 27001 A.5.24–A.5.28, detected-at, severity
with a one-line rationale, affected systems, affected data categories, evidence pointers,
and any containment actions, auto-gathers tenant context, composes the email, runs it
through the canvas-redactor agent, then calls Gmail create_draft. It never sends:
the report lands as a draft you review in your email client and send yourself.
When to use
Section titled “When to use”For a suspected security event affecting the confidentiality, integrity, or availability of AssureSwarm data: data exposure, a credential or API-key leak, account compromise, unauthorized access, malware, denial-of-service, or social engineering.
- For a non-security helpdesk issue: a bug, a how-to, a feature request, or an access request not involving suspected compromise: use /coach-ticket-open instead, its non-security sibling.
- To record and triage the incident as a record in your own Canvas tenant, open an
issueitem via /coach-item-create and run thegrc-incident-management-lifecycleworkflow: this skill only notifies the vendor.
Inputs
Section titled “Inputs”| Flag | Required | Notes |
|---|---|---|
--severity critical|high|medium|low|informational |
No | Pre-set the severity; otherwise it’s gathered during intake. |
--to <email> |
No | Override the default security-incident@assureswarm.com address. |
Everything else is gathered through an interactive, compliance-aligned intake.
Example
Section titled “Example”/coach-security-report --severity high walks you through the intake, what you observed,
when and how, the affected systems and data categories, the evidence you hold, and any
containment already taken, auto-gathers tenant context from .coworkcanvas/ config and
recent log tails, and composes a [INCIDENT][severity:high] ... email to
security-incident@assureswarm.com, cc’ing your own admin address as a record copy. It
runs the redaction gate over the body, creates a Gmail draft for you to review and send,
and appends the report to .coworkcanvas/incidents/log.md.
Good to know
Section titled “Good to know”- Drafts only, never sends. You review in your email client and hit send. If you prefer lower attribution, send the resulting draft from a separate account: the plugin tracks no identity beyond the From header on the eventual sent email.
- Critical and high severity carry a redaction floor. Internal-only fields are always scrubbed, and any uncertain content requires your confirmation before the draft is built.
- Gmail MCP is required. If it isn’t configured, the skill halts with a clear message: there’s no alternative draft path within this skill.
- Severity drives routing. The vendor’s Gmail filter routes
[severity:critical]and[severity:high]to oncall plus PagerDuty; expect a response within 30 minutes. For those, the skill also reminds you to send now and to notify your own organization’s incident response if you believe an attack is in progress. - The local log is your evidence chain under ISO 27001 A.5.28: keep it; don’t delete
it. To also track the event in your own tenant’s register, open an
issuevia /coach-item-create.
Related
Section titled “Related”- /coach-ticket-open: the non-security sibling, for helpdesk bugs, how-tos, and access requests.
- /coach-item-create: open an
issueto record the incident in your own tenant’s register. - /coach-redact: the standalone form of the redaction gate this skill runs over the draft.