Skills incident-response-incident-response
📦

incident-response-incident-response

Content revision r2 Safe ⚙️ External commands

Coordinate Production Incident Response

Production incidents demand fast, coordinated decisions across technical and business teams. This skill structures triage, mitigation, investigation, communication, recovery, and postmortem work.

Supports: Claude Codex Code(CC)
🥉 78 Bronze

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "incident-response-incident-response" from https://skillstore.io/skills/sickn33-incident-response-incident-response.md and its manifest at https://skillstore.io/api/skills/sickn33-incident-response-incident-response/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "incident-response-incident-response". Checkout errors reached 35 percent after a release, but other services remain healthy.

Expected outcome:

  • Severity: P1 because a revenue-critical path has major user impact.
  • Immediate action: pause the rollout, compare healthy and affected instances, and prepare rollback.
  • Validation: track checkout success, latency, error rate, and failed transactions before closing mitigation.

Using "incident-response-incident-response". Prepare a postmortem outline for a 42-minute authentication outage caused by expired certificates.

Expected outcome:

  • Timeline: detection, escalation, certificate diagnosis, replacement, validation, and service recovery.
  • Contributing factors: missing expiry alerts, unclear ownership, and incomplete renewal procedures.
  • Actions: assign certificate inventory, expiry monitoring, renewal testing, and runbook updates with deadlines.

Security Audit

Safe
v5 • 7/24/2026 Open versioned report

All seven static findings are false positives. The backticks delimit a Markdown path, while the other matches are ordinary incident-response prose and telemetry guidance. No prompt injection, exfiltration intent, executable code, or unauthorized reconnaissance was found.

1
Files scanned
177
Lines analyzed
0
Review items
0
False positives ignored

Risk Factors

⚙️ External commands (1)
No confirmed security findings were detected by the latest completed static and semantic audit. This does not prove the skill has no side effects.
Audited by: codex View Audit History →
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/sickn33-incident-response-incident-response/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/sickn33-incident-response-incident-response/security.svg)](https://skillstore.io/skills/sickn33-incident-response-incident-response?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/sickn33-incident-response-incident-response?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-incident-response-incident-response/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/sickn33-incident-response-incident-response.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA · BibTeX · CFF)

APA citation

sickn33. (2026). incident-response-incident-response security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-incident-response-incident-response/audits/5

BibTeX citation

@techreport{sickn33-sickn33-incident-response-incident-response-2026, author = {sickn33}, title = {incident-response-incident-response security audit report (audit version 5)}, institution = {Skillstore}, year = {2026}, number = {5}, url = {https://skillstore.io/skills/sickn33-incident-response-incident-response/audits/5}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "incident-response-incident-response security audit report (audit version 5)" version: "unspecified" type: report authors: - name: "sickn33" date-released: "2026-07-24" url: "https://skillstore.io/skills/sickn33-incident-response-incident-response/audits/5" identifiers: - type: other value: "skillstore:sickn33-incident-response-incident-response:audit:5" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: High
55
Architecture
85
Maintainability
87
Content
69
Community
83
Spec Compliance

What You Can Build

Direct an active outage

Classify impact, assign response roles, prioritize mitigation, and maintain a clear decision timeline.

Assess a security incident

Coordinate observability review, exposure analysis, containment planning, and stakeholder communication.

Lead post-incident learning

Build a blameless timeline, identify contributing factors, assign improvements, and strengthen monitoring.

Try These Prompts

Classify an incident
Classify this incident using P0 through P3: [alerts and impact]. List affected services, user impact, initial roles, and missing information.
Plan mitigation and updates
Build a mitigation and communication plan for [incident]. Include immediate containment, rollback triggers, owners, validation checks, and update audiences.
Investigate root cause
Analyze [logs, metrics, traces, and recent changes] for [incident]. Identify the likely root cause, contributing factors, and evidence gaps.
Orchestrate the full response
Coordinate an end-to-end response for [incident]. Produce phased actions for triage, mitigation, investigation, deployment, communication, recovery, and a blameless postmortem.

Best Practices

  • Confirm incident scope, operator authority, affected services, and success criteria before proposing production changes.
  • Maintain a timestamped decision log with owners, evidence, mitigation results, and stakeholder updates.
  • Validate every mitigation with health checks, user-impact metrics, and a tested rollback path.

Avoid

  • Do not execute production changes without authorization, staged validation, and rollback readiness.
  • Do not declare a root cause when evidence only supports correlation or an untested hypothesis.
  • Do not include secrets, personal data, or unnecessary customer details in prompts and incident updates.

Frequently Asked Questions

Does this skill connect to monitoring or paging tools?
No. It organizes analysis and response prompts but does not provide direct integrations.
Can it execute emergency production changes?
No. Authorized operators must review, approve, execute, and validate every production action.
Which incident severities does it support?
It uses P0 through P3 classifications for critical outages, major degradation, minor degradation, and cosmetic issues.
Does it cover security incidents?
Yes. It guides breach assessment, suspicious activity review, exposure analysis, containment planning, and communication.
What information should I provide?
Provide alerts, user impact, affected services, recent changes, available telemetry, current mitigations, permissions, and response objectives.
Can it create a postmortem?
Yes. It can structure a blameless timeline, contributing factors, lessons, and assigned prevention actions.

Developer Details

Author

sickn33

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

88a8e9a07f4c54ab105c1c41b6267c287146b07b

Maintenance freshness

7/26/2026

Usage

8 downloads · 137 views

File structure

📄 SKILL.md