What it does
Tripwire-style intrusion detection for Windows endpoints. Scans the last 7-30 days of Windows Security event log via PowerShell for indicators of compromise - failed-logon clusters (5+ within 10 minut
How it arrives
You don't install skills one by one. ClevskillSetup installs the whole curated pack, wires the safety hooks, and verifies each skill actually runs on your machine. The weekly health scan re-checks it from then on, and repairs route through your approval.
Setup
No setup needed. It works as soon as the pack is installed; no accounts, no API keys, nothing leaves your machine.
Invoke it
In Claude Code or Claude Cowork, just ask in plain language; skills trigger on intent. Things people say that make this skill run:
you: use windows intrusion detector on this claude: [windows-intrusion-detector runs, result returned with full audit log]
Part of the security suite: it runs automatically where it applies, fails closed on errors, and never sends your content anywhere.