# Coordinate Production Incident Response

Production incidents demand fast, coordinated decisions across technical and business teams. This skill structures triage, mitigation, investigation, communication, recovery, and postmortem work.

## Install

```bash
npx skillstore add sickn33/incident-response-incident-response
```

## Metadata

- Status: approved
- Slug: sickn33-incident-response-incident-response
- Skillstore revision: r2
- Version status: missing
- Tree hash: 501bd2b4e45d3b1a4f830cc8ef67c71b35455f610084cb3dc3abd42dfca494c9
- Author: sickn33
- GitHub username: sickn33
- License: MIT
- Repository: https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/incident-response-incident-response
- Ref: 88a8e9a07f4c54ab105c1c41b6267c287146b07b
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: allowed
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands
- Quality score: 78
- Quality tier: bronze
- Public page: https://skillstore.pages.dev/skills/sickn33-incident-response-incident-response
- Manifest: https://skillstore.pages.dev/api/skills/sickn33-incident-response-incident-response/manifest

## Capabilities

- Classifies incidents from P0 through P3 using impact, outage, security, and data-loss criteria.
- Structures response work across triage, mitigation, investigation, recovery, communication, and prevention phases.
- Creates focused prompts for observability, debugging, security, performance, deployment, and documentation roles.
- Defines incident command responsibilities and communication channels for coordinated decisions.
- Produces guidance for stakeholder updates, customer impact assessments, and status reporting.
- Outlines blameless postmortems, monitoring improvements, and system hardening actions.

## Use Cases

- Direct an active outage: Classify impact, assign response roles, prioritize mitigation, and maintain a clear decision timeline.
- Assess a security incident: Coordinate observability review, exposure analysis, containment planning, and stakeholder communication.
- Lead post-incident learning: Build a blameless timeline, identify contributing factors, assign improvements, and strengthen monitoring.

## Prompt Templates

### Classify an incident

```
Classify this incident using P0 through P3: [alerts and impact]. List affected services, user impact, initial roles, and missing information.
```

### Plan mitigation and updates

```
Build a mitigation and communication plan for [incident]. Include immediate containment, rollback triggers, owners, validation checks, and update audiences.
```

### Investigate root cause

```
Analyze [logs, metrics, traces, and recent changes] for [incident]. Identify the likely root cause, contributing factors, and evidence gaps.
```

### Orchestrate the full response

```
Coordinate an end-to-end response for [incident]. Produce phased actions for triage, mitigation, investigation, deployment, communication, recovery, and a blameless postmortem.
```

## Limitations

- The skill provides guidance only and has no direct monitoring, paging, deployment, or communication integrations.
- Production actions require authorized operators, environment-specific validation, testing, and rollback controls.
- Named subagent types may not exist in every Claude, Codex, or Claude Code environment.
- The referenced implementation playbook is not included in the packaged skill.

## Best Practices

- Confirm incident scope, operator authority, affected services, and success criteria before proposing production changes.
- Maintain a timestamped decision log with owners, evidence, mitigation results, and stakeholder updates.
- Validate every mitigation with health checks, user-impact metrics, and a tested rollback path.

## Anti Patterns

- Do not execute production changes without authorization, staged validation, and rollback readiness.
- Do not declare a root cause when evidence only supports correlation or an untested hypothesis.
- Do not include secrets, personal data, or unnecessary customer details in prompts and incident updates.

## Security Audit

- Audited at: 2026-07-24T01:06:16.046\+00:00
- Summary: All seven static findings are false positives. The backticks delimit a Markdown path, while the other matches are ordinary incident-response prose and telemetry guidance. No prompt injection, exfiltration intent, executable code, or unauthorized reconnaissance was found.

## Stats

- Views: 137
- Downloads: 10
- Favorites: 0
- Popularity score: 0
