Agent skill

Postmortem

by alirezarezvani in alirezarezvani/claude-skills

/em:postmortem — Honest analysis of what went wrong. An agent skill from alirezarezvani/claude-skills.

MITAuto-check passedDevOps & Cloud

Install Postmortem

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill postmortem -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills postmortem --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/c-level-advisor/executive-mentor/skills/postmortem .claude/skills/postmortem && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
postmortem
GitHub stars
28k
Used in
2 other repos
Token cost
~2k tokens
SKILL.md length
1,027 words
Files
1
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

/em:postmortem — Honest analysis of what went wrong. An agent skill from alirezarezvani/claude-skills.

  • Works in 7 steps: Define the Event Precisely → The 5 Whys — Done Properly → Distinguish Contributing Factors from… → …
  • Tasks that involve Runbooks and postmortems
  • SKILL.md covers Why Most Post-Mortems Fail, The Framework, Post-Mortem Output Format and The Tone of Good Post-Mortems
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Postmortem is an agent skill from alirezarezvani/claude-skills. /em:postmortem — Honest analysis of what went wrong. Use after a failed launch, missed quarter, or bad hire to run a blameless 5-Whys retrospective with a change register — e.g. dissecting why the Q3 release slipped six weeks.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Runbooks and postmortems and Root cause analysis. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • Tasks that involve Runbooks and postmortems
  • Tasks that involve Root cause analysis

Example prompts

  • “/postmortem”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Define the Event Precisely
  2. The 5 Whys — Done Properly
  3. Distinguish Contributing Factors from Root Cause
  4. Identify the Warning Signs That Were Ignored
  5. Distinguish What Was in Control vs. Out of Control
  6. Build the Change Register
  7. Verification Date

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Postmortem loads about 2k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 1,027 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 1,027 words, ~1,989 tokens.

Download SKILL.mdSave it as .claude/skills/postmortem/SKILL.md (or your agent's skills folder).
name
postmortem
description
/em:postmortem — Honest analysis of what went wrong. Use after a failed launch, missed quarter, or bad hire to run a blameless 5-Whys retrospective with a change register — e.g. dissecting why the Q3 release slipped six weeks.

/em:postmortem — Honest Analysis of What Went Wrong

Command: /em:postmortem <event>

Not blame. Understanding. The failed deal, the missed quarter, the feature that flopped, the hire that didn't work out. What actually happened, why, and what changes as a result.


Why Most Post-Mortems Fail

They become one of two things:

The blame session — someone gets scapegoated, defensive walls go up, actual causes don't get examined, and the same problem happens again in a different form.

The whitewash — "We learned a lot, we're going to do better, here are 12 vague action items." Nothing changes. Same problem, different quarter.

A real post-mortem is neither. It's a rigorous investigation into a system failure. Not "whose fault was it" but "what conditions made this outcome predictable in hindsight?"

The purpose: extract the maximum learning value from a failure so you can prevent recurrence and improve the system.


The Framework

Step 1: Define the Event Precisely

Before analysis: describe exactly what happened.

  • What was the expected outcome?
  • What was the actual outcome?
  • When was the gap first visible?
  • What was the impact (financial, operational, reputational)?

Precision matters. "We missed Q3 revenue" is not precise enough. "We closed $420K in new ARR vs $680K target — a $260K miss driven primarily by three deals that slipped to Q4 and one deal that was lost to a competitor" is precise.

Step 2: The 5 Whys — Done Properly

The goal: get from what happened (the symptom) to why it happened (the root cause).

Standard bad 5 Whys:

  • Why did we miss revenue? Because deals slipped.
  • Why did deals slip? Because the sales cycle was longer than expected.
  • Why? Because the customer buying process is complex.
  • Why? Because we're selling to enterprise.
  • Why? That's just how enterprise sales works.

→ Conclusion: Nothing to do. It's just enterprise.

Real 5 Whys:

  • Why did we miss revenue? Three deals slipped out of quarter.
  • Why did those deals slip? None of them had identified a champion with budget authority.
  • Why did we progress deals without a champion? Our qualification criteria didn't require it.
  • Why didn't our qualification criteria require it? When we built the criteria 8 months ago, we were in SMB, not enterprise.
  • Why haven't we updated qualification criteria as ICP shifted? No owner, no process for criteria review.

→ Root cause: Qualification criteria outdated, no owner, no review process. → Fix: Update criteria, assign owner, add quarterly review.

The test for a good root cause: Could you prevent recurrence with a specific, concrete change? If yes, you've found something real.

Step 3: Distinguish Contributing Factors from Root Cause

Most events have multiple contributing factors. Not all are root causes.

Contributing factor: Made it worse, but isn't the core reason. If removed, the outcome might have been different — but the same class of problem would recur.

Root cause: The fundamental condition that made the outcome probable. Fix this, and this class of problem doesn't recur.

Example — failed hire:

  • Contributing factors: rushed process, reference checks skipped, team under pressure to staff up
  • Root cause: No defined competency framework, so interview process varied by who happened to conduct interviews

The distinction matters. If you address only contributing factors, you'll have a different-looking but structurally identical failure next time.

Step 4: Identify the Warning Signs That Were Ignored

Every failure has precursors. In hindsight, they're obvious. The value of this step is making them obvious prospectively.

Ask:

  • At what point was the negative outcome predictable?
  • What signals were visible at that point?
  • Who saw them? What happened when they raised them?
  • Why weren't they acted on?

Common patterns:

  • Signal was raised but dismissed by a senior person
  • Signal wasn't raised because nobody felt safe saying it
  • Signal was seen but no one had clear ownership to act on it
  • Data was available but nobody was looking at it
  • The team was too optimistic to take negative signals seriously

This step is particularly important for systemic issues — "we didn't feel safe raising the concern" is a much deeper root cause than "the deal qualification was off."

Show full SKILL.md (360 more words)Show less
Step 5: Distinguish What Was in Control vs. Out of Control

Some failures happen despite correct decisions. Some happen because of incorrect decisions. Knowing the difference prevents both overcorrection and undercorrection.

  • In control: Process, criteria, team capability, resource allocation, decisions made
  • Out of control: Market conditions, customer decisions, competitor actions, macro events

For things out of control: what can be done to be more resilient to similar events? For things in control: what specifically needs to change?

Warning: "It was outside our control" is sometimes used to avoid accountability. Be rigorous.

Step 6: Build the Change Register

Every post-mortem ends with a change register — specific commitments, owned and dated.

Bad action items:

  • "We'll improve our qualification process"
  • "Communication will be better"
  • "We'll be more rigorous about forecasting"

Good action items:

  • "Ravi owns rewriting qualification criteria by March 15 to include champion identification as hard requirement. New criteria reviewed in weekly sales standup starting March 22."
  • "By March 10, Elena adds deal-slippage risk flag to CRM for any open opportunity >60 days without a product demo"
  • "Maria runs a 30-min retrospective with enterprise sales team every 6 weeks starting April 1, reviews win/loss data"

For each action:

  • What exactly is changing?
  • Who owns it?
  • By when?
  • How will you verify it worked?
Step 7: Verification Date

The most commonly skipped step. Post-mortems are useless if nobody checks whether the changes actually happened and actually worked.

Set a verification date: "We'll review whether qualification criteria have been updated and whether deal slippage rate has improved at the June board meeting."

Without this, post-mortems are theater.


Post-Mortem Output Format

EVENT: [Name and date]
EXPECTED: [What was supposed to happen]
ACTUAL: [What happened]
IMPACT: [Quantified]

TIMELINE
[Date]: [What happened or was visible]
[Date]: ...

5 WHYS
1. [Why did X happen?] → Because [Y]
2. [Why did Y happen?] → Because [Z]
3. [Why did Z happen?] → Because [A]
4. [Why did A happen?] → Because [B]
5. [Why did B happen?] → Because [ROOT CAUSE]

ROOT CAUSE: [One clear sentence]

CONTRIBUTING FACTORS
• [Factor] — how it contributed
• [Factor] — how it contributed

WARNING SIGNS MISSED
• [Signal visible at what date] — why it wasn't acted on

WHAT WAS IN CONTROL: [List]
WHAT WASN'T: [List]

CHANGE REGISTER
| Action | Owner | Due Date | Verification |
|--------|-------|----------|-------------|
| [Specific change] | [Name] | [Date] | [How to verify] |

VERIFICATION DATE: [Date of check-in]

The Tone of Good Post-Mortems

Blame is cheap. Understanding is hard.

The goal isn't to establish that someone made a mistake. The goal is to understand why the system produced that outcome — so the system can be improved.

"The salesperson didn't qualify the deal properly" is blame. "Our qualification framework hadn't been updated when we moved upmarket, and no one owned keeping it current" is understanding.

The first version fires or shames someone. The second version builds a more resilient organization.

Both might be true simultaneously. The distinction is: which one actually prevents recurrence?

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in c-level-advisor/executive-mentor/skills/postmortem of alirezarezvani/claude-skills.

Open the folder on GitHubat commit 19392f7

Used in 2 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in alirezarezvani/claude-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Postmortem next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Postmortem compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Postmortem this skillalirezarezvani/claude-skills28k2 repos~2kAutomated safety check: PassMIT
Post Mortemthananon/9arm-skills3.2k—~3.4kAutomated safety check: PassNone
Post-Incident DebriefVeryGoodOpenSource/vgv-wingspan109—~1.9kAutomated safety check: PassMIT
Postmortemdralgorhythm/claude-agentic-framework125—~708Automated safety check: PassNone
Conducting Post Incident Lessons Learnedmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0
Incident Postmortemgithub/awesome-copilot40k—~1.8kAutomated safety check: PassMIT

Similar skills

  • Post Mortem

    thananon/9arm-skills

    Write the canonical engineering record of a fixed bug — root cause, mechanism, fix, validation, and how it slipped through.

    3.2k GitHub stars~3.4k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Post-Incident Debrief

    VeryGoodOpenSource/vgv-wingspan

    Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh.

    109 GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Postmortem

    dralgorhythm/claude-agentic-framework

    Runs this framework's blameless postmortem workflow — reconstruct the incident timeline from evidence, drive five-whys to a mechanism-level root cause, and produce owner-and-due-date action items…

    125 GitHub stars~708 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Conducting Post Incident Lessons Learned

    mukul975/Anthropic-Cybersecurity-Skills

    Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Postmortem

    github/awesome-copilot

    Official

    A skill your agent uses when an outage, production incident, or significant service degradation has occurred and the team needs to write a structured blameless post-mortem.

    40k GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Quality Postmortem

    petrkindlmann/qa-skills

    Analyze escaped defects and test suite health through blameless postmortems.

    165 GitHub stars~5.9k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Categories

Questions about Postmortem

What does Postmortem do?

/em:postmortem — Honest analysis of what went wrong. An agent skill from alirezarezvani/claude-skills. Postmortem is an agent skill from alirezarezvani/claude-skills. /em:postmortem — Honest analysis of what went wrong.

When should I use Postmortem?

Postmortem fits situations like: tasks that involve Runbooks and postmortems; tasks that involve Root cause analysis.

How do I install Postmortem in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill postmortem -a claude-code`. Or copy the skill folder (c-level-advisor/executive-mentor/skills/postmortem in alirezarezvani/claude-skills) into .claude/skills/postmortem in your project. Claude Code loads it when a task matches its description.

How do I install Postmortem in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill postmortem -a codex`. Or copy the skill folder (c-level-advisor/executive-mentor/skills/postmortem in alirezarezvani/claude-skills) into .agents/skills/postmortem in your project. Codex loads it when a task matches its description.

Can I use Postmortem in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill postmortem -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/postmortem, .gemini/skills/postmortem, .github/skills/postmortem and .opencode/skills/postmortem in your project.

What does Postmortem need to run?

SKILL.md names no scripts, command-line tools or credentials: Postmortem is instructions for the agent only.

Does Postmortem access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Postmortem safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Postmortem use?

Postmortem is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Postmortem use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Postmortem?

Skills that share tags, products or a category with Postmortem: Post Mortem (thananon/9arm-skills, 3.2k stars), Post-Incident Debrief (VeryGoodOpenSource/vgv-wingspan, 109 stars), Postmortem (dralgorhythm/claude-agentic-framework, 125 stars) and Conducting Post Incident Lessons Learned (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Postmortem?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,829 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.