What problem does it solve? Security operators waste time navigating multiple Falcon consoles to understand their current risk posture. This Skill correlates detections, cloud risks, vulnerability backlogs, sensor health, and container exposure into a single prioritized brief that leads with what changed and what needs attention today. ## Core Features & Use Cases - Correlated posture assembly: Runs ten targeted Falcon MCP queries covering new high-severity detections, detection clustering by tactic/host/assignee, cloud risks grouped by cloud group and account, confirmed vulnerability backlog, stale sensors, unmanaged assets, and vulnerable container images. - Evidence-based reporting: Reports exact counts from pagination totals, distinguishes confirmed sensor findings from EASM potential findings, and only lists capabilities as "Not checked" when a tool call was refused during the current run. - Active-status awareness: Every surfaced resource states whether it is currently active, since a vulnerability on a stopped instance is a different priority than one on a running workload. - Use Case: Ask for a morning brief and receive a ninety-second summary with a bottom line, ranked action items with suggested next steps, cloud posture grouped by business unit, blind spots from silent hosts, and a follow-through offer to trace the most promising thread. ## Quick Start Ask the assistant to generate a security posture brief summarizing today's detections, vulnerabilities, and sensor health.