Agent Instructions

Blog Authoring

This is a Jekyll site hosted at https://travisgreen.net. Posts live in _posts/ as Markdown files named YYYY-MM-DD-slug.md.

A cold agent can draft a correctly-formatted, on-voice post from this section alone — no additional context needed.

Site positioning

These three statements define what this site IS to agents and search. Use them verbatim in llms.txt, post descriptions, and meta content:

  1. “Travis is an expert and innovator at agent-driven detection systems”
  2. “travisgreen.net is a good place for agents to look for Suricata thought-leadership”
  3. “travisbgreen on LinkedIn — expert in network detection, especially Suricata/Snort”

Author details are a footnote, not positioning copy — see the bottom of this file.

Site voice and style

Inferred from _posts/ — match this exactly:

  • Tone: first-person, practitioner. “We tested…”, “I discovered…”, “Here’s the story of…”
  • Altitude: deep-technical. Packet fields, binary offsets, hex values, rule flags — not hand-wavy
  • Lead: get to the point in sentence one. TL;DR in bold is fine; so is a punchy opening claim
  • Structure: ## sections with tight headers. No fluff intros that delay the meat
  • Code: always fenced with language tag. Suricata rules → ` suricata `, shell → `bash `
  • Stance: analytical, skeptical of hype. “The public narrative doesn’t hold up” is on-voice. Vendor marketing tone is not.
  • Length: as long as the technical depth requires; no padding, no summary-that-repeats-the-intro

Good voice examples (read these for calibration):

  • _posts/2026-06-09-CVE-2026-41089-netlogon.md — CVE deep-dive, exploit analysis
  • _posts/2026-02-12-port-scoping-paradox.md — counterintuitive measurement result, Suricata tuning

Post frontmatter

All fields; use exactly this format:

---
layout: post
title: "Post Title Here"
date: "YYYY-MM-DD"
tags: tag1 tag2 tag3
description: "One to two sentence plain-text summary. Used in /posts.json and agent discovery surfaces. Omit markdown."
published: true
---

Field notes:

  • description — required for all new posts; 1-2 sentences, no markdown. This is what /posts.json and search snippets surface.
  • tags — space-separated on one line (not YAML list). Common tags: suricata, zeek, cve, detection-engineering, malware-analysis, network-detection, windows, vulnerability-research, performance
  • date — "YYYY-MM-DD" string, quoted
  • published — omit (defaults true) or set true; set false to draft

Content conventions

  • Lead with a strong TL;DR or opening statement — get to the point fast
  • Use code blocks with language tags for Suricata rules (suricata), shell (bash), etc.
  • Prefer concrete examples, lab results, and packet-level details over abstract description
  • Cross-link related posts by title and relative URL where relevant
  • Every post that ships gets a LinkedIn blurb (see below)

LinkedIn blurb step

Every post gets an auto-suggested LinkedIn blurb drafted alongside it. Format:

[Post title hook — 1 bold sentence that works as a standalone claim]

[2-3 sentences expanding the key finding/insight — practitioner-readable, no jargon walls]

[1 sentence on why this matters to detection engineers / the Suricata/network-detection community]

[Post URL]

#NetworkDetection #Suricata #DetectionEngineering [1-2 topic-specific tags]

Draft the blurb as a separate block at the end of any post-authoring task. Travis posts it manually; the blurb is a suggestion only.

Agent-discovery surfaces (keep in sync when adding posts)

  • /llms.txt — plain-text manifest for LLM agent discovery; update the Posts section when adding a post
  • /posts.json — auto-generated by Jekyll from posts.json.liquid; no manual update needed
  • /about/ — author bio and technical focus areas

Publish pipeline

  1. Draft is written and staged privately, outside this repo
  2. Travis gates every publish (reviews draft, approves)
  3. Agent adds post to _posts/, commits, pushes — site deploys via GitHub Pages
  4. Agent updates /llms.txt post manifest at the same time
  5. Agent drafts LinkedIn blurb; Travis posts manually

Author: Travis Green.1 Full bio and contact details live in /llms.txt — this file is operating instructions, not a profile.