Skills
Skills are short analyst playbooks the Investigation assistant can load when your question matches. They guide how the assistant researches — they never auto-block, push, or enforce actions. You review every recommendation.
Install and manage
- Open Account → Connections → Skills (or History ▾ → Skills in the Lookup workspace).
- Install from the catalog, or author a custom skill with a kebab-case name, when-to-use description, and markdown body.
- Enable or disable per skill. Disabled skills are never matched.
How matching works
- Type a slash name in the assistant (for example
/phishing-triage) to force that skill. - Otherwise the assistant scores your question against each enabled skill's description and picks a match when the overlap is clear.
- A match loads the skill body into that turn only. It does not change inventory, cases, or connectors by itself.
What skills are not
- Not visual playbooks or drag-and-drop automation.
- Not a substitute for looking up an indicator — enrich and score still come from Lookup.
- Not Remote MCP. Skills stay in your Lookup account; remote clients use MCP with a personal token.