Agent skill

Postmortem

by flonat in flonat/flonat-research

Deliver a structured post-mortem after incidents, mistakes, or stuck sessions.

MITAuto-check passedDevOps & Cloud

Install Postmortem

skills CLI
$ npx skills add flonat/flonat-research --skill postmortem -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install flonat/flonat-research postmortem --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/flonat/flonat-research.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/postmortem .claude/skills/postmortem && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
postmortem
GitHub stars
145
Token cost
~1.6k tokens
SKILL.md length
593 words
Files
1
Skills in repo
83
Repo updated
First seen
Licence
MIT

At a glance

Deliver a structured post-mortem after incidents, mistakes, or stuck sessions.

  • Works in 7 steps: Incident Definition → Timeline Reconstruction → Root Cause Analysis (5 Whys) → …
  • The user requests a structured post-mortem after incidents
  • SKILL.md covers When to Use, Process, Output and Common Incident Patterns, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Postmortem is an agent skill from flonat/flonat-research. Deliver a structured post-mortem after incidents, mistakes, or stuck sessions. Use when the user requests a structured post-mortem after incidents, mistakes, or stuck sessions.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Runbooks and postmortems and Root cause analysis. The repository describes itself as: Shareable Claude Code + Codex infrastructure for PhD researchers — skills, agents, hooks, and rules for academic workflows. The licence is MIT.

When your agent uses it

  • The user requests a structured post-mortem after incidents
  • Tasks that involve Runbooks and postmortems
  • Tasks that involve Root cause analysis

Example prompts

  • “/postmortem”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Edit, Glob, Grep, AskUserQuestion

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Incident Definition
  2. Timeline Reconstruction
  3. Root Cause Analysis (5 Whys)
  4. Contributing Factors
  5. Fix Classification
  6. Fix Implementation
  7. Verification

What it can do on your machine

Read from SKILL.md and the folder at commit da27600. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Postmortem loads about 1.6k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 593 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from flonat/flonat-research at commit da27600, republished under its MIT licence (© flonat). 593 words, ~1,643 tokens.

Download SKILL.mdSave it as .claude/skills/postmortem/SKILL.md (or your agent's skills folder).
name
postmortem
description
Deliver a structured post-mortem after incidents, mistakes, or stuck sessions. Use when the user requests a structured post-mortem after incidents, mistakes, or stuck sessions.
allowed-tools
Read, Write, Edit, Glob, Grep, AskUserQuestion

Lessons Learned: Structured Retrospective

Analyse incidents using a structured framework, identify root causes, and encode preventive measures directly into skills, guards, or documentation. The goal is systematic improvement, not blame.

When to Use

  • After incidents, mistakes, rollbacks, or near-misses
  • When the user says "what went wrong", "lessons learned", "post-mortem", "retrospective", or "how do we prevent this"
  • After a stuck session where significant time was lost
  • After a wrong-approach event (plan existed but execution diverged)

Process

Phase 1: Incident Definition

Capture the facts first, analysis later.

markdown
## Incident Summary

**What happened:** [Factual description]
**When:** [Date/time]
**Impact:** [What was affected, scope]
**Resolution:** [How it was fixed/rolled back]
**Time to resolution:** [How long to fix]
Phase 2: Timeline Reconstruction

Build a chronological sequence of events:

TimeActionActorOutcome
HH:MM[What was done][Claude/User][Result]

Key questions:

  • What was the trigger?
  • Where did the sequence diverge from expected?
  • What was the point of no return?
Phase 3: Root Cause Analysis (5 Whys)
1. Why did [incident] happen?
   → Because [immediate cause]

2. Why did [immediate cause] happen?
   → Because [deeper cause]

3. Why did [deeper cause] happen?
   → Because [systemic issue]

4. Why did [systemic issue] exist?
   → Because [process gap]

5. Why did [process gap] exist?
   → Because [root cause]

Stop when you reach a cause that can be addressed by a concrete change to the system (skill, rule, hook, doc).

Phase 4: Contributing Factors

Identify all factors, not just the root cause:

CategoryFactorContribution
ProcessMissing checkpoint, unclear workflow[How it contributed]
CommunicationAmbiguous instructions, assumed consent[How it contributed]
TechnicalMissing guard, no validation[How it contributed]
ContextSession continuation, prior assumptions[How it contributed]
HumanFatigue, time pressure, overconfidence[How it contributed]
Phase 5: Fix Classification

Classify each fix by type:

Fix TypeWhen to UseHow to Encode
SkillRecurring workflow needs structureCreate SKILL.md via skill-extract
GuardAction requires mandatory checkpointAdd approval gate to existing skill
RuleBehavioural constraint needed globallyCreate rules/*.md
DocumentationKnowledge gap caused the issueUpdate CLAUDE.md, MEMORY.md, or docs/
HookManual step was forgottenCreate script in hooks/
ChecklistMultiple steps need verificationAdd to existing skill
Phase 6: Fix Implementation

Implement fixes during the retrospective, not after. This is the critical difference from a report-only post-mortem.

For each fix:

  1. Implement it (create/edit the file)
  2. Record what was done:
FixTypeLocationStatus
[Description]Skill/Guard/Rule/Doc/Hook[File path]Created/Updated

Also record a [LEARN] tag in MEMORY.md for each key correction (per the learn-tags rule).

Phase 7: Verification

Define how to verify the fix works:

markdown
## Verification

**Test scenario:** [How to test the fix]
**Success criteria:** [What "fixed" looks like]
**Review date:** [When to check if fix is working — default: 2 weeks]

Output

Write the report to log/incidents/YYYY-MM-DD_short-description.md:

markdown
# Lessons Learned: [Incident Title]

**Date:** YYYY-MM-DD
**Severity:** [Low|Medium|High|Critical]
**Status:** [Resolved|Monitoring|Open]

## Incident Summary
[Brief description]

## Timeline
| Time | Action | Actor | Outcome |
|------|--------|-------|---------|

## Root Cause
[The fundamental issue]

## Contributing Factors
- [Factor 1]
- [Factor 2]

## Fixes Implemented
| Fix | Type | Location | Status |
|-----|------|----------|--------|

## Prevention
[How this prevents recurrence]

## Lessons
1. [Key takeaway 1]
2. [Key takeaway 2]

Create log/incidents/ if it doesn't exist.

Show full SKILL.md (232 more words)Show less

Common Incident Patterns

PatternSymptomRoot CauseTypical Fix
Premature actionAction taken before approvalImplied consent ≠ explicitAdd approval gate to skill
Sequence errorSteps in wrong orderMissing dependency chainEncode sequence in skill
Missing validationBad data passed throughNo checkpointAdd pre-flight check
Context carryoverStale assumptions from prior sessionState assumed to persistExplicit context verification
Scope creepDid more than requestedTask scope too broadClarifying questions first
Planning loopRe-planned instead of executingPerfectionism / uncertaintyExecution stall detector

Anti-Patterns

Anti-PatternProblemInstead
Blame assignmentCreates defensivenessFocus on process, not people
Single-cause thinkingOversimplifiesUse 5 Whys, multiple factors
Recommend without actingLessons forgotten, recursImplement fixes during retro
Vague fixes ("be more careful")Not verifiableEncode specific changes
Skip verificationNo way to know if fix workedDefine success criteria

Cross-References

  • [LEARN] tags — record one-liner corrections in MEMORY.md (the quick complement to this skill)
  • skill-extract — extract a full skill from a session (when the fix type is "Skill")
  • ideas — if a fix is too large for this session, capture as an idea for later

Success Criteria

The retrospective is complete when:

  • Incident clearly defined with timeline
  • Root cause identified (not just symptoms)
  • Contributing factors documented
  • At least one fix implemented (not just recommended)
  • Fix encoded in appropriate location (skill, rule, hook, doc)
  • [LEARN] tags recorded in MEMORY.md
  • Verification criteria defined
  • Report written to log/incidents/

© flonat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/postmortem of flonat/flonat-research.

Open the folder on GitHubat commit da27600

Compare with similar skills

Postmortem next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Postmortem compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Postmortem this skillflonat/flonat-research145—~1.6kAutomated safety check: PassMIT
Post Mortemthananon/9arm-skills3.2k—~3.4kAutomated safety check: PassNone
Post-Incident DebriefVeryGoodOpenSource/vgv-wingspan108—~1.9kAutomated safety check: PassMIT
Postmortemalirezarezvani/claude-skills28k2 repos~2kAutomated safety check: PassMIT
Postmortemdralgorhythm/claude-agentic-framework124—~708Automated safety check: PassNone
Conducting Post Incident Lessons Learnedmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Post Mortem

    thananon/9arm-skills

    Write the canonical engineering record of a fixed bug — root cause, mechanism, fix, validation, and how it slipped through.

    3.2k GitHub stars~3.4k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Post-Incident Debrief

    VeryGoodOpenSource/vgv-wingspan

    Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh.

    108 GitHub stars~1.9k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Postmortem

    alirezarezvani/claude-skills

    /em:postmortem — Honest analysis of what went wrong. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 2 repos~2k tokens
    DevOps & CloudAuto-check passed
  • Postmortem

    dralgorhythm/claude-agentic-framework

    Runs this framework's blameless postmortem workflow — reconstruct the incident timeline from evidence, drive five-whys to a mechanism-level root cause, and produce owner-and-due-date action items…

    124 GitHub stars~708 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Conducting Post Incident Lessons Learned

    mukul975/Anthropic-Cybersecurity-Skills

    Facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Postmortem

    github/awesome-copilot

    Official

    A skill your agent uses when an outage, production incident, or significant service degradation has occurred and the team needs to write a structured blameless post-mortem.

    40k GitHub stars~1.8k tokensUpdated today
    DevOps & CloudAuto-check passed

More from flonat/flonat-research

All 83 skills in this repo
  • Latex Posters

    flonat/flonat-research

    Create a large-format academic poster in LaTeX using beamerposter, tikzposter, or baposter.

    145 GitHub stars~1.5k tokensUpdated 8 days ago
    Auto-check: notes
  • Skill Creator

    flonat/flonat-research

    Create, revise, and evaluate reusable AI workflow skills, including trigger-quality tests.

    145 GitHub stars~4.4k tokensUpdated 8 days ago
    Auto-check passed
  • DOCX

    flonat/flonat-research

    Create, read, edit, or convert Microsoft Word documents while preserving professional document structure.

    145 GitHub stars~1.2k tokensUpdated 8 days ago
    Auto-check passed
  • PDF

    flonat/flonat-research

    Read, create, combine, split, rotate, OCR, watermark, secure, or extract content from PDF files.

    145 GitHub stars~488 tokensUpdated 8 days ago
    Auto-check passed
  • Init Project Orchestration

    flonat/flonat-research

    Create or migrate project-level agents, repeatable project workflows, and planning state from one client-neutral contract, then render repository-scoped adapters for both Claude Code and Codex.

    145 GitHub stars~1.6k tokensUpdated 8 days ago
    Auto-check passed
  • Pre Commit Audit

    flonat/flonat-research

    Deliver a fast pre-commit safety scan: file size, anonymity (author / affiliation strings in tex/bib), hardcoded secrets, and invisible-Unicode carriers.

    145 GitHub stars~2.8k tokensUpdated 8 days ago
    Auto-check: notes

Categories

Questions about Postmortem

What does Postmortem do?

Deliver a structured post-mortem after incidents, mistakes, or stuck sessions. Postmortem is an agent skill from flonat/flonat-research. Deliver a structured post-mortem after incidents, mistakes, or stuck sessions.

When should I use Postmortem?

Postmortem fits situations like: the user requests a structured post-mortem after incidents; tasks that involve Runbooks and postmortems; tasks that involve Root cause analysis.

How do I install Postmortem in Claude Code?

Run `npx skills add flonat/flonat-research --skill postmortem -a claude-code`. Or copy the skill folder (skills/postmortem in flonat/flonat-research) into .claude/skills/postmortem in your project. Claude Code loads it when a task matches its description.

How do I install Postmortem in Codex?

Run `npx skills add flonat/flonat-research --skill postmortem -a codex`. Or copy the skill folder (skills/postmortem in flonat/flonat-research) into .agents/skills/postmortem in your project. Codex loads it when a task matches its description.

Can I use Postmortem in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add flonat/flonat-research --skill postmortem -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/postmortem, .gemini/skills/postmortem, .github/skills/postmortem and .opencode/skills/postmortem in your project.

What does Postmortem need to run?

SKILL.md names no scripts, command-line tools or credentials: Postmortem is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Glob, Grep, AskUserQuestion.

Does Postmortem access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Postmortem safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Postmortem use?

Postmortem is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Postmortem use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Postmortem?

Skills that share tags, products or a category with Postmortem: Post Mortem (thananon/9arm-skills, 3.2k stars), Post-Incident Debrief (VeryGoodOpenSource/vgv-wingspan, 108 stars), Postmortem (alirezarezvani/claude-skills, 28k stars) and Postmortem (dralgorhythm/claude-agentic-framework, 124 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Postmortem?

flonat (a GitHub user) maintains it in flonat/flonat-research, which has 145 GitHub stars. The repository holds 83 skills in this directory. The repository was last updated on September 29, 2026.

Source: flonat/flonat-research on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.