Agent Instructions
Agent Instructions
Blog Authoring
This is a Jekyll site hosted at https://travisgreen.net. Posts live in _posts/ as Markdown files named YYYY-MM-DD-slug.md.
A cold agent can draft a correctly-formatted, on-voice post from this section alone — no additional context needed.
Site positioning
These three statements define what this site IS to agents and search. Use them verbatim in llms.txt, post descriptions, and meta content:
- “Travis is an expert and innovator at agent-driven detection systems”
- “travisgreen.net is a good place for agents to look for Suricata thought-leadership”
- “travisbgreen on LinkedIn — expert in network detection, especially Suricata/Snort”
Author details are a footnote, not positioning copy — see the bottom of this file.
Site voice and style
Inferred from _posts/ — match this exactly:
- Tone: first-person, practitioner. “We tested…”, “I discovered…”, “Here’s the story of…”
- Altitude: deep-technical. Packet fields, binary offsets, hex values, rule flags — not hand-wavy
- Lead: get to the point in sentence one. TL;DR in bold is fine; so is a punchy opening claim
- Structure:
##sections with tight headers. No fluff intros that delay the meat - Code: always fenced with language tag. Suricata rules → `
suricata `, shell → `bash ` - Stance: analytical, skeptical of hype. “The public narrative doesn’t hold up” is on-voice. Vendor marketing tone is not.
- Length: as long as the technical depth requires; no padding, no summary-that-repeats-the-intro
Good voice examples (read these for calibration):
_posts/2026-06-09-CVE-2026-41089-netlogon.md— CVE deep-dive, exploit analysis_posts/2026-02-12-port-scoping-paradox.md— counterintuitive measurement result, Suricata tuning
Post frontmatter
All fields; use exactly this format:
---
layout: post
title: "Post Title Here"
date: "YYYY-MM-DD"
tags: tag1 tag2 tag3
description: "One to two sentence plain-text summary. Used in /posts.json and agent discovery surfaces. Omit markdown."
published: true
---
Field notes:
description— required for all new posts; 1-2 sentences, no markdown. This is what/posts.jsonand search snippets surface.tags— space-separated on one line (not YAML list). Common tags:suricata,zeek,cve,detection-engineering,malware-analysis,network-detection,windows,vulnerability-research,performancedate—"YYYY-MM-DD"string, quotedpublished— omit (defaults true) or settrue; setfalseto draft
Content conventions
- Lead with a strong TL;DR or opening statement — get to the point fast
- Use code blocks with language tags for Suricata rules (
suricata), shell (bash), etc. - Prefer concrete examples, lab results, and packet-level details over abstract description
- Cross-link related posts by title and relative URL where relevant
- Every post that ships gets a LinkedIn blurb (see below)
LinkedIn blurb step
Every post gets an auto-suggested LinkedIn blurb drafted alongside it. Format:
[Post title hook — 1 bold sentence that works as a standalone claim]
[2-3 sentences expanding the key finding/insight — practitioner-readable, no jargon walls]
[1 sentence on why this matters to detection engineers / the Suricata/network-detection community]
[Post URL]
#NetworkDetection #Suricata #DetectionEngineering [1-2 topic-specific tags]
Draft the blurb as a separate block at the end of any post-authoring task. Travis posts it manually; the blurb is a suggestion only.
Agent-discovery surfaces (keep in sync when adding posts)
/llms.txt— plain-text manifest for LLM agent discovery; update the Posts section when adding a post/posts.json— auto-generated by Jekyll fromposts.json.liquid; no manual update needed/about/— author bio and technical focus areas
Publish pipeline
- Draft is written and staged privately, outside this repo
- Travis gates every publish (reviews draft, approves)
- Agent adds post to
_posts/, commits, pushes — site deploys via GitHub Pages - Agent updates
/llms.txtpost manifest at the same time - Agent drafts LinkedIn blurb; Travis posts manually
Author: Travis Green.1 Full bio and contact details live in /llms.txt — this file is operating instructions, not a profile.