PlaygroundCatalog › Ransomware First Response
RF

Ransomware First Response

🔵 Stable🕐 updated 2026-08-05 🔷 SkillSpec L3 pm-digital-safety

Handle the first hour of a suspected ransomware or malware infection calmly and correctly — contain it, preserve options, and avoid the moves that make it worse. Use when asked what to do about ransomware, my files are encrypted with a ransom note, I think I have malware, or my computer's been hacked. Produces an immediate containment checklist, a preserve-evidence-and-options step, a recovery path (backups, known decryptors, professional help), guidance on the ransom-payment decision, and reporting steps — for personal/small-setup use, not a substitute for professional incident response.

▶ Run it free — no key needed 📝 Grade your existing draft View SKILL.md ↗

🗣 Say this to your agent

“My files are all encrypted and there's a ransom note — what do I do?”“I think I've got ransomware, help me not make it worse.”“Suspicious pop-up locked my computer demanding payment.”“Should I pay the ransom to get my files back?”“Malware on my work laptop — what's my first move?”

What to give it

What you're seeing — ransom note, encrypted/renamed files, pop-ups, or just suspicious behavior
The setup — personal device, home network, or a business/multi-device environment
Backups — do you have recent offline/cloud backups, and are they disconnected
Spread — is it one device or possibly shared drives/other machines
Sensitivity — is sensitive/regulated data involved

✅ The bar it holds itself to

Every skill in this library self-verifies — these are this skill's own quality checks, straight from its definition.

Containment (disconnect network/drives) is the first action
Warns against wiping or paying reflexively; preserve evidence
Prioritizes restoring from a verified offline backup
Mentions checking for legitimate free decryptors before payment
Presents the payment decision honestly as a risky last resort
Includes reporting and flags when to get professional IR help

⚠️ What it refuses to do

**Paying immediately** out of panic.
**Reformatting/wiping** before preserving evidence and confirming backups.
**Reconnecting the infected device** and spreading it.
**Restoring from a backup** that was connected during infection.
**Treating a serious business breach** as a DIY job.

Install

npx pm-claude-skills add --agent claude   # or codex · cursor · gemini · hermes
# or one-line MCP (every skill, any client):
claude mcp add pm-skills -- npx -y pm-claude-skills-mcp

Related skills

🔌 Embed this skill

Drop this on your blog, docs, or site — it renders a "Run this skill" card:

<div data-pm-skill="ransomware-first-response"></div>
<script src="https://mohitagw15856.github.io/pm-claude-skills/embed.js" async></script>

💬 Discussion

Ransomware First Response is one of 1078 open-source professional AI agent skills — all SkillSpec L3. Try them all in the browser · ⭐ Star on GitHub · Browse the full catalog