agent build
This commit is contained in:
96
skills/anomaly-detection.md
Normal file
96
skills/anomaly-detection.md
Normal file
@@ -0,0 +1,96 @@
|
||||
---
|
||||
id: anomaly-detection
|
||||
name: Anomaly Detection
|
||||
description: Surface activity that departs from this workspace's own pattern — and stay quiet when nothing does.
|
||||
category: operations
|
||||
pages:
|
||||
- activity
|
||||
- control-center
|
||||
status: active
|
||||
version: 1
|
||||
triggers:
|
||||
- anomaly
|
||||
- anomalies
|
||||
- anomalous
|
||||
- unusual
|
||||
- out of pattern
|
||||
- suspicious
|
||||
owliver:
|
||||
enabled: true
|
||||
suggestions:
|
||||
- label: Is anything unusual?
|
||||
capability: insight
|
||||
- label: Show the signals
|
||||
capability: table
|
||||
capabilities:
|
||||
- summary
|
||||
- insight
|
||||
- list
|
||||
- table
|
||||
- stats
|
||||
responses:
|
||||
summary:
|
||||
title: Activity signals
|
||||
source: activity.signals
|
||||
insight:
|
||||
title: Unusual activity
|
||||
source: activity.signals
|
||||
list:
|
||||
title: Signals
|
||||
source: activity.signals
|
||||
table:
|
||||
title: Signals
|
||||
source: activity.signals
|
||||
stats:
|
||||
title: Activity signals
|
||||
source: activity.signals
|
||||
---
|
||||
|
||||
# Anomaly Detection
|
||||
|
||||
## Purpose
|
||||
|
||||
- Surface activity that departs from this workspace's own baseline.
|
||||
- Explain each signal rather than only naming it.
|
||||
- Report nothing when nothing departs, so a signal keeps its meaning.
|
||||
|
||||
## Capabilities
|
||||
|
||||
- Detect concentration, bursts, off-hours activity, silence and privileged-action share.
|
||||
- Report how many signals are currently raised.
|
||||
- Explain what each one means.
|
||||
|
||||
## Data
|
||||
|
||||
Reads `activity.signals`, which is the same detection the assistant's own
|
||||
greeting counts — one implementation in `lib/activitySignals.js`, so "two
|
||||
unusual patterns" means the same two wherever it is said.
|
||||
|
||||
## Analysis
|
||||
|
||||
Five patterns are checked against this workspace's own history:
|
||||
|
||||
1. **Concentration** — one account is responsible for half or more of events.
|
||||
2. **Burst** — more than three actions from one account inside one hour.
|
||||
3. **Off-hours** — activity before 06:00 or after 22:00.
|
||||
4. **Silent** — a log that has events but nothing in the last 24 hours.
|
||||
5. **Privileged share** — more than 30% of events change who is employed or
|
||||
what is being hired for.
|
||||
|
||||
Only patterns that clear their threshold are reported. A workspace with nothing
|
||||
unusual returns no signals, not a low-severity note.
|
||||
|
||||
## Output
|
||||
|
||||
A count of raised signals, and one row per signal explaining what triggered it
|
||||
with the figure behind it.
|
||||
|
||||
## Limitations
|
||||
|
||||
- **A signal is a deviation from a baseline, not a verdict.** On a live
|
||||
deployment most resolve to an integration, a bulk import or a busy afternoon.
|
||||
Nothing here asserts wrongdoing.
|
||||
- Thresholds are fixed, not learned. A workspace whose normal pattern is one
|
||||
busy account will report concentration every time it is asked.
|
||||
- The baseline is the whole activity log, not a rolling window, so a young
|
||||
workspace has little to compare against.
|
||||
Reference in New Issue
Block a user