Agent skill

Incident Runbook Templates

by aiskillstore in aiskillstore/marketplace

Production-ready templates for incident response runbooks covering detection, triage, mitigation, resolution, and communication.

No licenceAuto-check passedDevOps & Cloud

Install Incident Runbook Templates

skills CLI
$ npx skills add aiskillstore/marketplace --skill incident-runbook-templates -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace incident-runbook-templates --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sickn33/incident-runbook-templates .claude/skills/incident-runbook-templates && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
incident-runbook-templates
GitHub stars
433
Used in
8 other repos
Token cost
~2.8k tokens
SKILL.md length
274 words
Files
2
Skills in repo
1,044
Repo updated
First seen
Licence
None found

At a glance

Production-ready templates for incident response runbooks covering detection, triage, mitigation, resolution, and communication.

  • Works in 4 steps: Incident Severity Levels → Runbook Structure → Quick Health Checks → …
  • Tasks that involve Runbooks and postmortems
  • SKILL.md covers Do not use this skill when, Instructions, Use this skill when and Core Concepts, plus 8 more sections
  • Calls kubectl, curl and psql; reaches sentry.io and status.stripe.com

What it does

Incident Runbook Templates is an agent skill from aiskillstore/marketplace. Production-ready templates for incident response runbooks covering detection, triage, mitigation, resolution, and communication.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `skill-report.json`).

It sits in DevOps & Cloud, covering Runbooks and postmortems and Incident response. It works with Kubernetes. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.

When your agent uses it

  • Tasks that involve Runbooks and postmortems
  • Tasks that involve Incident response

Example prompts

  • “/incident-runbook-templates”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Incident Severity Levels
  2. Runbook Structure
  3. Quick Health Checks
  4. Initial Classification

What it can do on your machine

Read from SKILL.md and the folder at commit 44923f3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • curl
    • psql
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • sentry.io
    • status.stripe.com
    • api.stripe.com
    • sre.google
    • response.pagerduty.com
    • atlassian.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Incident Runbook Templates loads about 2.8k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 274 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 274 words (~2,825 tokens).

“Production-ready templates for incident response runbooks covering detection, triage, mitigation, resolution, and communication.”

— opening of SKILL.md by aiskillstore
name
incident-runbook-templates
risk
critical
source
community
date_added
2026-02-27

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in skills/sickn33/incident-runbook-templates of aiskillstore/marketplace.

  • SKILL.md
  • skill-report.json

Open the folder on GitHubat commit 44923f3

Used in 8 other repositories

We found 18 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 8 other GitHub owners. This page covers the copy in aiskillstore/marketplace, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Incident Runbook Templates next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Incident Runbook Templates compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Incident Runbook Templates this skillaiskillstore/marketplace4338 repos~2.8kAutomated safety check: PassNone
Kubernetes Network Root Cause Analysiskubeshark/kubeshark12k—~5.3kAutomated safety check: PassApache-2.0
Oncallpigweed-project/pigweed548—~963Automated safety check: PassApache-2.0
Activation Governance Chaos RolloutAli-Marandi/DataSense107—~1.9kAutomated safety check: PassMIT
Devops EngineerYikai-Liao/symusic1891 repos~1.5kAutomated safety check: PassMIT
Incident Response686f6c61/alfred-dev117—~1.1kAutomated safety check: PassMIT

Similar skills

  • Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.

    12k GitHub stars~5.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Oncall

    pigweed-project/pigweed

    Pigweed oncall rotation runbooks and maintenance workflows (such as rolling CIPD client tools for b/315378787).

    548 GitHub stars~963 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.

    107 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed
  • Incident Response

    686f6c61/alfred-dev

    Protocolo de respuesta ante incidentes en produccion: triaje, mitigacion, causa raiz y postmortem.

    117 GitHub stars~1.1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Superset Incident Triage

    superset-sh/superset

    Does a read-only first pass on a possible production incident: gathers deploy, Sentry and health-check signals, proposes a severity and status message, then stops for human approval.

    15k GitHub stars~1k tokensUpdated today
    DevOps & CloudAuto-check passed

More from aiskillstore/marketplace

All 1,040 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    433 GitHub starsUsed in 1 repo~697 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    433 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    433 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    433 GitHub starsUsed in 1 repo~598 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    433 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Project Planner

    aiskillstore/marketplace

    Detects stale project plans and suggests session commands. An agent skill from aiskillstore/marketplace.

    433 GitHub starsUsed in 1 repo~504 tokens
    Auto-check passed

Works with

Categories

Questions about Incident Runbook Templates

What does Incident Runbook Templates do?

Production-ready templates for incident response runbooks covering detection, triage, mitigation, resolution, and communication. Incident Runbook Templates is an agent skill from aiskillstore/marketplace. Production-ready templates for incident response runbooks covering detection, triage, mitigation, resolution, and communication.

When should I use Incident Runbook Templates?

Incident Runbook Templates fits situations like: tasks that involve Runbooks and postmortems; tasks that involve Incident response.

How do I install Incident Runbook Templates in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill incident-runbook-templates -a claude-code`. Or copy the skill folder (skills/sickn33/incident-runbook-templates in aiskillstore/marketplace) into .claude/skills/incident-runbook-templates in your project. Claude Code loads it when a task matches its description.

How do I install Incident Runbook Templates in Codex?

Run `npx skills add aiskillstore/marketplace --skill incident-runbook-templates -a codex`. Or copy the skill folder (skills/sickn33/incident-runbook-templates in aiskillstore/marketplace) into .agents/skills/incident-runbook-templates in your project. Codex loads it when a task matches its description.

Can I use Incident Runbook Templates in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill incident-runbook-templates -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/incident-runbook-templates, .gemini/skills/incident-runbook-templates, .github/skills/incident-runbook-templates and .opencode/skills/incident-runbook-templates in your project.

What does Incident Runbook Templates need to run?

Going by SKILL.md and its folder, Incident Runbook Templates needs the command-line tools its instructions call (kubectl, curl, psql and jq).

Does Incident Runbook Templates access the network?

SKILL.md names 6 domains. In commands or code: sentry.io, status.stripe.com, api.stripe.com, sre.google, response.pagerduty.com and atlassian.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Incident Runbook Templates safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Incident Runbook Templates use?

No licence was found for Incident Runbook Templates or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Incident Runbook Templates use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Incident Runbook Templates?

Skills that share tags, products or a category with Incident Runbook Templates: Kubernetes Network Root Cause Analysis (kubeshark/kubeshark, 12k stars), Oncall (pigweed-project/pigweed, 548 stars), Activation Governance Chaos Rollout (Ali-Marandi/DataSense, 107 stars) and Devops Engineer (Yikai-Liao/symusic, 189 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Incident Runbook Templates?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 433 GitHub stars. The repository holds 1,044 skills in this directory. The repository was last updated on October 10, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.