Handle the first hour of a suspected ransomware or malware infection calmly and correctly — contain it, preserve options, and avoid the moves that make it worse. Use when asked what to do about ransomware, my files are encrypted with a ransom note, I think I have malware, or my computer's been hacked. Produces an immediate containment checklist, a preserve-evidence-and-options step, a recovery path (backups, known decryptors, professional help), guidance on the ransom-payment decision, and reporting steps — for personal/small-setup use, not a substitute for professional incident response.
“My files are all encrypted and there's a ransom note — what do I do?”“I think I've got ransomware, help me not make it worse.”“Suspicious pop-up locked my computer demanding payment.”“Should I pay the ransom to get my files back?”“Malware on my work laptop — what's my first move?”
What to give it
▸What you're seeing — ransom note, encrypted/renamed files, pop-ups, or just suspicious behavior
▸The setup — personal device, home network, or a business/multi-device environment
▸Backups — do you have recent offline/cloud backups, and are they disconnected
▸Spread — is it one device or possibly shared drives/other machines
▸Sensitivity — is sensitive/regulated data involved
✅ The bar it holds itself to
Every skill in this library self-verifies — these are this skill's own quality checks, straight from its definition.
✓Containment (disconnect network/drives) is the first action
✓Warns against wiping or paying reflexively; preserve evidence
✓Prioritizes restoring from a verified offline backup
✓Mentions checking for legitimate free decryptors before payment
✓Presents the payment decision honestly as a risky last resort
✓Includes reporting and flags when to get professional IR help
⚠️ What it refuses to do
**Paying immediately** out of panic.
**Reformatting/wiping** before preserving evidence and confirming backups.
**Reconnecting the infected device** and spreading it.
**Restoring from a backup** that was connected during infection.
**Treating a serious business breach** as a DIY job.
Install
npx pm-claude-skills add --agent claude # or codex · cursor · gemini · hermes
# or one-line MCP (every skill, any client):
claude mcp add pm-skills -- npx -y pm-claude-skills-mcp