Skills

Skills are short analyst playbooks the Investigation assistant can load when your question matches. They guide how the assistant researches — they never auto-block, push, or enforce actions. You review every recommendation.

Install and manage

  • Open Account → Connections → Skills (or History ▾ → Skills in the Lookup workspace).
  • Install from the catalog, or author a custom skill with a kebab-case name, when-to-use description, and markdown body.
  • Enable or disable per skill. Disabled skills are never matched.

How matching works

  • Type a slash name in the assistant (for example /phishing-triage) to force that skill.
  • Otherwise the assistant scores your question against each enabled skill's description and picks a match when the overlap is clear.
  • A match loads the skill body into that turn only. It does not change inventory, cases, or connectors by itself.

What skills are not

  • Not visual playbooks or drag-and-drop automation.
  • Not a substitute for looking up an indicator — enrich and score still come from Lookup.
  • Not Remote MCP. Skills stay in your Lookup account; remote clients use MCP with a personal token.