Agent skill

Incident Commander

by borghei in borghei/Claude-Skills

Production incident response. An agent skill from borghei/Claude-Skills.

MITAuto-check passedDevOps & Cloud

Install Incident Commander

skills CLI
$ npx skills add borghei/Claude-Skills --skill incident-commander -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills incident-commander --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/incident-commander .claude/skills/incident-commander && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
incident-commander
GitHub stars
881
Token cost
~1.8k tokens
SKILL.md length
638 words
Files
27 (incl. scripts, references, assets)
Skills in repo
349
Repo updated
First seen
Licence
MIT

At a glance

Production incident response. An agent skill from borghei/Claude-Skills.

  • Handling incidents
  • SKILL.md covers Core Capabilities, When to Use, Clarify First and Tools, plus 3 more sections
  • Calls python
  • Classifying severity

What it does

Incident Commander is an agent skill from borghei/Claude-Skills. Production incident response. Use when handling incidents, classifying severity, reconstructing timelines, writing postmortems, generating comms templates, or building response playbooks with severity scoring and RCA frameworks.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 29 other files, including scripts, reference files and assets (for example `README.md`, `assets/incident_report_template.md` and `assets/runbook_template.md`).

It sits in DevOps & Cloud, covering Incident response, Runbooks and postmortems and Site reliability engineering. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Handling incidents
  • Classifying severity
  • Reconstructing timelines
  • Writing postmortems

Example prompts

  • “/incident-commander”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Incident Commander loads about 1.8k tokens when it runs, and up to ~26k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 638 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~26k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 638 words, ~1,783 tokens.

Download SKILL.mdSave it as .claude/skills/incident-commander/SKILL.md (or your agent's skills folder). This skill also uses 26 other files; get the full folder from GitHub.
name
incident-commander
description
Production incident response. Use when handling incidents, classifying severity, reconstructing timelines, writing postmortems, generating comms templates, or building response playbooks with severity scoring and RCA frameworks.
license
MIT + Commons Clause
metadata.version
1.2.0
metadata.author
borghei
metadata.category
engineering
metadata.domain
incident-response
metadata.tier
POWERFUL
metadata.updated
2026-06-17
metadata.tags
incident-response, severity-classification, rca, postmortem
metadata.python-tools
incident_classifier.py, severity_classifier.py, timeline_reconstructor.py, incident_timeline_builder.py, pir_generator.py, postmortem_generator.py
metadata.tech-stack
python, json, markdown

Incident Commander

Classify incident severity, reconstruct timelines from heterogeneous event sources, and generate structured post-incident reviews with root cause analysis and action items. Codifies PagerDuty, Google SRE, and Atlassian incident-management practices into severity scoring, escalation matrices, communication templates, RCA frameworks, and SLA/error-budget tracking.

Core Capabilities

  • Severity classification — multi-dimensional scoring (revenue, user scope, data/security risk, service criticality, blast radius) into SEV-1 to SEV-4 with confidence and escalation paths.
  • Timeline reconstruction — chronological timelines from logs, alerts, Slack, and deploy events with phase detection and gap analysis.
  • Post-incident review — PIRs with 5 Whys, Fishbone, Timeline, or Bow Tie RCA plus categorized action items (owner, priority, deadline).
  • Postmortem quality — coverage-gap detection, action-item quality scoring, MTTD/MTTR benchmarking.
  • Communication & escalation — severity-specific internal/executive/customer/status-page templates; technical (L1-L4) and business escalation matrices with time-based triggers.
  • SLA / error-budget tracking — SLI/SLO/SLA hierarchy, error budgets, burn-rate alerting, and breach handling.

When to Use

  • Handling an active incident — classify severity, establish command, mitigate, communicate.
  • Running a post-incident review — reconstruct timeline, perform RCA, assign action items.
  • Managing escalation — apply technical and business escalation paths by severity and elapsed time.
  • Building or auditing response playbooks, comms templates, or SLA/error-budget policy.

Clarify First

Before producing the artifact, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Task & deliverable — classify severity, reconstruct a timeline, or generate a PIR/postmortem (selects severity_classifier.py vs timeline_reconstructor.py vs pir_generator.py/postmortem_generator.py)
  • Incident input data — the incident/events JSON with severity dimensions (revenue, user scope, data/security risk, blast radius) (the input the scripts parse)
  • RCA method — 5 Whys, Fishbone, Timeline, or Bow Tie (sets pir_generator.py --rca-method and the postmortem structure)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.

Tools

ToolPurposeCommand
incident_classifier.pyClassify severity, recommend response teams and comms templatespython scripts/incident_classifier.py --input incident.json --format text
severity_classifier.pyMulti-dimensional severity score with escalation pathpython scripts/severity_classifier.py incident.json --format markdown
timeline_reconstructor.pyReconstruct timeline from timestamped events with phase + gap analysispython scripts/timeline_reconstructor.py --input events.json --detect-phases --gap-analysis --format markdown
incident_timeline_builder.pyBuild structured timeline with MTTD/MTTR and comms templatespython scripts/incident_timeline_builder.py incident_data.json --format markdown
pir_generator.pyGenerate Post-Incident Review with RCA and action itemspython scripts/pir_generator.py --incident incident.json --rca-method fishbone --action-items
postmortem_generator.pyGenerate postmortem with 5-Whys, benchmarks, coverage gapspython scripts/postmortem_generator.py incident_data.json --format markdown
Show full SKILL.md (259 more words)Show less

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • references/response-playbooks.md — quick-start commands, the detection-to-resolution and post-incident-review workflows, escalation management, anti-patterns, and tool troubleshooting. Read when running an incident end-to-end or using the scripts.
  • references/incident-response-framework.md — PagerDuty/Google SRE/Atlassian framework comparison, role definitions (IC, Comms, Ops, Scribe, SME, Liaison), communication protocols, escalation matrix, and the 7-phase incident lifecycle. Read when designing the response process or assigning roles.
  • references/incident_severity_matrix.md — full SEV-1 to SEV-4 impact criteria, response requirements, escalation paths, classification guidelines, decision tree, and examples. Read when classifying or calibrating severity.
  • references/communication_templates.md — ready-to-use internal, executive, customer, status-page, escalation, and resolution templates by severity. Read when drafting any incident communication.
  • references/rca_frameworks_guide.md — step-by-step 5 Whys, Fishbone, Timeline, and Bow Tie frameworks with templates, selection guidance, and anti-patterns. Read when performing root cause analysis.
  • references/sla-management-guide.md — SLI/SLO/SLA hierarchy, error-budget policy, burn-rate alerting, breach handling, and incident-to-SLA mapping with worked examples. Read when assessing or communicating SLA impact.

Scope & Limitations

Covers: severity classification, timeline reconstruction, PIR/postmortem generation, RCA frameworks, escalation matrices, communication templates, and SLA/error-budget tracking. Tools are deterministic stdlib Python (no ML/LLM calls), accepting JSON input and emitting text/JSON/markdown.

Does NOT cover: live monitoring/alerting infrastructure (feeds in from senior-devops), security forensics (see senior-secops), or deployment/rollback execution (see release-orchestrator).

Integration Points

SkillIntegration
senior-devopsMonitoring alerts feed timeline; runbook templates inform playbooks
senior-secopsSecurity incidents auto-escalate to SEV-1; breach indicators trigger SecOps response
release-orchestratorDeployment events feed timeline; rollback data informs release gates
senior-architectArchitectural root causes escalate to architecture review
code-reviewerPIR action items route to code review workflows

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 26 other files (scripts, references, assets) in engineering/incident-commander of borghei/Claude-Skills.

  • SKILL.md
  • README.md
  • assets/incident_report_template.md
  • assets/runbook_template.md
  • assets/sample_incident_classification.json
  • assets/sample_incident_data.json
  • assets/sample_incident_pir_data.json
  • assets/sample_timeline_events.json
  • assets/simple_incident.json
  • assets/simple_timeline_events.json
  • expected_outputs/incident_classification_text_output.txt
  • expected_outputs/pir_markdown_output.md
  • expected_outputs/simple_incident_classification.txt
  • expected_outputs/timeline_reconstruction_text_output.txt
  • references/communication_templates.md
  • references/incident-response-framework.md
  • references/incident_severity_matrix.md
  • references/rca_frameworks_guide.md
  • … and 9 more

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Incident Commander next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Incident Commander compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Incident Commander this skillborghei/Claude-Skills881—~1.8kAutomated safety check: PassMIT
SRE EngineerJeffallan/claude-skills12k—~1.7kAutomated safety check: PassMIT
Incident ResponderDokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI507—~706Automated safety check: PassCustom licence
Eng Runbooksanqiufong/slides-from-anything1321 repos~380Automated safety check: PassApache-2.0
Incident Slo Runbookmajiayu000/spellbook286—~460Automated safety check: PassMIT
Langchain Incident Runbookjeremylongshore/tons-of-skills-marketplace2.8k—~3.8kAutomated safety check: PassMIT

Similar skills

  • SRE Engineer

    Jeffallan/claude-skills

    Defines SLIs, SLOs and error budgets, and sets up golden-signal monitoring, blameless postmortems, toil automation and chaos experiments for production systems.

    12k GitHub stars~1.7k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Incident Responder

    Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI

    Expert SRE incident responder specializing in rapid problem resolution.

    507 GitHub stars~706 tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Eng Runbook

    sanqiufong/slides-from-anything

    An engineering runbook — service overview, alerts table, dashboards links, common procedures with copy-pasteable commands, on-call rotation, and an incident-response checklist.

    132 GitHub starsUsed in 1 repo~380 tokens
    DevOps & CloudAuto-check passed
  • Incident Slo Runbook

    majiayu000/spellbook

    Create or audit SLOs, SLIs, alert rules, incident response steps, escalation paths, postmortems, operational runbooks, and customer-impact communication.

    286 GitHub stars~460 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Langchain Incident Runbook

    jeremylongshore/tons-of-skills-marketplace

    Triage LangChain 1.0 / LangGraph 1.0 production incidents — LLM-specific SLOs, provider outage runbook, latency spike decision tree, cost-overrun response, agent loop containment.

    2.8k GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Makes systems debuggable and reliably operable — instrumentation, alerting that is worth waking for, service objectives, and learning from failure.

    2k GitHub stars~931 tokensUpdated 21 days ago
    DevOps & CloudAuto-check passed

More from borghei/Claude-Skills

All 349 skills in this repo
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    881 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    881 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    881 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Brainstorm Okrs

    borghei/Claude-Skills

    OKR brainstorming and validation using the Radical Focus framework — outcome objectives, measurable key results, counter-metrics.

    881 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Incident Commander

What does Incident Commander do?

Production incident response. An agent skill from borghei/Claude-Skills. Incident Commander is an agent skill from borghei/Claude-Skills. Production incident response.

When should I use Incident Commander?

Incident Commander fits situations like: handling incidents; classifying severity; reconstructing timelines; writing postmortems.

How do I install Incident Commander in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill incident-commander -a claude-code`. Or copy the skill folder (engineering/incident-commander in borghei/Claude-Skills) into .claude/skills/incident-commander in your project. Claude Code loads it when a task matches its description.

How do I install Incident Commander in Codex?

Run `npx skills add borghei/Claude-Skills --skill incident-commander -a codex`. Or copy the skill folder (engineering/incident-commander in borghei/Claude-Skills) into .agents/skills/incident-commander in your project. Codex loads it when a task matches its description.

Can I use Incident Commander in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill incident-commander -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/incident-commander, .gemini/skills/incident-commander, .github/skills/incident-commander and .opencode/skills/incident-commander in your project.

What does Incident Commander need to run?

Going by SKILL.md and its folder, Incident Commander needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Incident Commander access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Incident Commander safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Incident Commander use?

Incident Commander is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Incident Commander use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 24k tokens, read only when the agent opens those files.

What are the alternatives to Incident Commander?

Skills that share tags, products or a category with Incident Commander: SRE Engineer (Jeffallan/claude-skills, 12k stars), Incident Responder (Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI, 507 stars), Eng Runbook (sanqiufong/slides-from-anything, 132 stars) and Incident Slo Runbook (majiayu000/spellbook, 286 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Incident Commander?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 881 GitHub stars. The repository holds 349 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.