Agent skill

Incident Investigation

by fossasia in fossasia/eventyay-interpretation

A skill your agent uses to diagnose and resolve production incidents in VoxBento.

Apache-2.0Auto-check passedBackend & APIs

Install Incident Investigation

skills CLI
$ npx skills add fossasia/eventyay-interpretation --skill incident-investigation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fossasia/eventyay-interpretation incident-investigation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fossasia/eventyay-interpretation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/incident-investigation .claude/skills/incident-investigation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
incident-investigation
GitHub stars
1.6k
Token cost
~1.4k tokens
SKILL.md length
537 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses to diagnose and resolve production incidents in VoxBento.

  • Works in 4 steps: Is the portal up? → Is MediaMTX up? → Portal logs → …
  • Diagnose and resolve production incidents in VoxBento
  • SKILL.md covers Diagnostic Entry Points, Common Incident Types and Emergency Commands
  • Calls docker-compose, curl and uv; needs ADMIN_PASSWORD

What it does

Incident Investigation is an agent skill from fossasia/eventyay-interpretation. Use this skill to diagnose and resolve production incidents in VoxBento.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. The repository describes itself as: A plugin for live interpretation of video streams. The licence is Apache-2.0.

When your agent uses it

  • Diagnose and resolve production incidents in VoxBento

Example prompts

  • “/incident-investigation”

Requirements

  • Python 3
  • Docker

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Is the portal up?
  2. Is MediaMTX up?
  3. Portal logs
  4. Active booth state (no API for this — check portal logs or DB)

What it can do on your machine

Read from SKILL.md and the folder at commit 1ca0139. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker-compose
    • curl
    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl and uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ADMIN_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Incident Investigation loads about 1.4k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 537 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from fossasia/eventyay-interpretation at commit 1ca0139, republished under its Apache-2.0 licence (© fossasia). 537 words, ~1,423 tokens.

Download SKILL.mdSave it as .claude/skills/incident-investigation/SKILL.md (or your agent's skills folder).
name
incident-investigation
description
Use this skill to diagnose and resolve production incidents in VoxBento.

Skill: Incident Investigation

Use this skill to diagnose and resolve production incidents in VoxBento.


Diagnostic Entry Points

1. Is the portal up?
bash
curl http://localhost:8000/healthz
# Expected: {"ok": true, "server": "fastapi", "mediamtx_ok": true}
2. Is MediaMTX up?
bash
curl http://localhost:9997/v3/paths/list
# Expected: 200 with paths array
docker-compose ps mediamtx
docker-compose logs mediamtx --tail=50
3. Portal logs
bash
docker-compose logs portal --tail=100
# Look for: ERROR, WebSocketDisconnect, DB errors, transcription errors
4. Active booth state (no API for this — check portal logs or DB)
bash
# Check live booth count from admin panel: /admin/
# Or query DB directly:
docker-compose exec portal uv run python -c "
import asyncio
from portal.database import get_session, list_events
async def main():
    async with get_session() as s:
        events = await list_events(s)
        for e in events:
            print(e.slug, e.display_name)
asyncio.run(main())
"

Common Incident Types

IC-01: Interpreter cannot "Go Live"

Symptoms: "Go Live" button clicked but WHIP fails or spinner never resolves.

Diagnosis:

  1. Check browser DevTools Network tab for GET /api/events/{slug}/booths/{lang}/whip-url.
    • 403? → Interpreter is not the active interpreter. Check booth:state WS message.
    • 404? → Booth not in memory. Was the WS booth:join message sent successfully?
  2. Check MediaMTX reachability: /healthz → mediamtx_ok.
  3. Check MEDIAMTX_WHIP_BASE is browser-reachable (not Docker-internal URL).
  4. Check WebSocket connection in DevTools → WS tab.

Fix: If not active interpreter: coordinator must reassign via booth:set-active. If MediaMTX down: docker-compose restart mediamtx.


IC-02: Listener hears nothing

Symptoms: Listener page loads but WHEP connection shows "disconnected" or audio is silent.

Diagnosis:

  1. Check interpreter is "Go Live" — ingest_status == 'connected' in booth state.
  2. Check MEDIAMTX_WHIP_BASE in listener page source — must be browser-reachable HTTPS.
  3. Browser DevTools → check RTCPeerConnection state in whep-listener.js.
  4. Check MediaMTX path: GET http://localhost:9997/v3/paths/get/{event_slug}/{language_code}.
  5. Check alwaysAvailable: true on the path — if not set, WHEP fails when no publisher.

Fix: Ensure _ensure_mediamtx_path was called. Manually: PATCH http://mediamtx:9997/v3/config/paths/patch/{path} with {"alwaysAvailable": true}.


IC-03: WebSocket disconnects repeatedly

Symptoms: Interpreters see connection status flickering; participants disappear and reappear.

Diagnosis:

  1. Check portal logs for WebSocketDisconnect.
  2. Check browser DevTools WS tab for close code:
    • 4001: Missing/invalid token.
    • 4003: Token scope mismatch.
    • 1006: Abnormal closure (network issue or portal crash).
  3. Check for asyncio.Lock deadlock in portal/booth_state.py — portal becomes unresponsive.
  4. Check for uncaught exceptions in _handle_* functions (portal logs).

Fix: Restart portal if deadlocked. Fix token scope if 4003 (token was generated for different booth).


Show full SKILL.md (243 more words)Show less
IC-04: Transcription not appearing

Symptoms: Booth is live, transcription enabled, but no captions appear.

Diagnosis:

  1. Check active_workers state — portal logs should show worker start: Starting {provider} transcription worker for booth {booth_id}.
  2. Check ffmpeg can reach MediaMTX RTSP: docker-compose exec portal ffmpeg -rtsp_transport tcp -i rtsp://mediamtx:8554/{event_slug}/{language_code} -f null - -t 5.
  3. Check API key exists and is valid: portal logs for API key missing or Failed to decrypt.
  4. Check event.transcription_api_enabled is True for external providers.
  5. Check MAX_TOTAL_WORKERS (10) not exceeded: count workers in portal logs.
  6. Check booth DB config: db_booth.transcription_enabled, db_booth.transcription_provider, db_booth.transcription_model.

Fix: Restart transcription worker via admin panel → booth detail → transcription settings (re-save). Or call stop_transcription_worker(booth_id) + start_transcription_worker(...) via debug endpoint if available.


IC-05: Admin login fails

Symptoms: /admin/login with correct password → still shows error.

Diagnosis:

  1. Check ADMIN_PASSWORD env var is set and not empty.
  2. Check admin_token cookie is being set (DevTools → Application → Cookies).
  3. Check JWT secret is consistent (settings.effective_jwt_secret).
  4. Alternative: log in as user with is_admin=True — uses /login + user_token cookie.

IC-06: Database errors

Symptoms: 500 errors on any page involving DB; portal logs show SQLAlchemy errors.

Diagnosis:

  1. Check DB URL: DATABASE_URL env var.
  2. Check migrations are current: uv run alembic current should show head.
  3. If SQLite: check portal-data volume is mounted and has write permission.
  4. If PostgreSQL: check connection string and DB server availability.

Fix: Run uv run alembic upgrade head. If corrupt SQLite: restore from backup volume.


Emergency Commands

bash
# Restart portal only
docker-compose restart portal

# View live logs
docker-compose logs portal -f

# Force-stop all services
docker-compose down

# Full restart
docker-compose up -d

# Apply pending migrations manually
docker-compose exec portal uv run alembic upgrade head

# Check DB migration state
docker-compose exec portal uv run alembic current

© fossasia, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/incident-investigation of fossasia/eventyay-interpretation.

Open the folder on GitHubat commit 1ca0139

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in fossasia/eventyay-interpretation, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Incident Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Incident Investigation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Incident Investigation this skillfossasia/eventyay-interpretation1.6k—~1.4kAutomated safety check: PassApache-2.0
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api44k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    44k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from fossasia/eventyay-interpretation

All 38 skills in this repo
  • Git Guardrails Claude Code

    fossasia/eventyay-interpretation

    Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute.

    1.6k GitHub starsUsed in 12 repos~578 tokens
    Auto-check passed
  • Diagnosing Bugs

    fossasia/eventyay-interpretation

    Diagnosis loop for hard bugs and performance regressions. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 32 repos~2.1k tokens
    Auto-check passed
  • Domain Modeling

    fossasia/eventyay-interpretation

    Build and sharpen a project's domain model. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 30 repos~821 tokens
    Auto-check passed
  • Improve

    fossasia/eventyay-interpretation

    Survey any codebase as a senior advisor and produce prioritized, self-contained implementation plans for OTHER models/agents to execute.

    1.6k GitHub starsUsed in 10 repos~3.7k tokens
    Auto-check: warnings
  • Migrate To Shoehorn

    fossasia/eventyay-interpretation

    Migrate test files from as type assertions to @total-typescript/shoehorn.

    1.6k GitHub starsUsed in 12 repos~698 tokens
    Auto-check passed
  • Setup Pre Commit

    fossasia/eventyay-interpretation

    Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo.

    1.6k GitHub starsUsed in 12 repos~565 tokens
    Auto-check passed

Categories

Questions about Incident Investigation

What does Incident Investigation do?

A skill your agent uses to diagnose and resolve production incidents in VoxBento. Incident Investigation is an agent skill from fossasia/eventyay-interpretation. Use this skill to diagnose and resolve production incidents in VoxBento.

When should I use Incident Investigation?

Incident Investigation fits situations like: diagnose and resolve production incidents in VoxBento.

How do I install Incident Investigation in Claude Code?

Run `npx skills add fossasia/eventyay-interpretation --skill incident-investigation -a claude-code`. Or copy the skill folder (.agents/skills/incident-investigation in fossasia/eventyay-interpretation) into .claude/skills/incident-investigation in your project. Claude Code loads it when a task matches its description.

How do I install Incident Investigation in Codex?

Run `npx skills add fossasia/eventyay-interpretation --skill incident-investigation -a codex`. Or copy the skill folder (.agents/skills/incident-investigation in fossasia/eventyay-interpretation) into .agents/skills/incident-investigation in your project. Codex loads it when a task matches its description.

Can I use Incident Investigation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fossasia/eventyay-interpretation --skill incident-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/incident-investigation, .gemini/skills/incident-investigation, .github/skills/incident-investigation and .opencode/skills/incident-investigation in your project.

What does Incident Investigation need to run?

Going by SKILL.md and its folder, Incident Investigation needs the command-line tools its instructions call (docker-compose, curl and uv) and credentials named ADMIN_PASSWORD. Our summary lists: Python 3; Docker.

Does Incident Investigation access the network?

SKILL.md contains no URLs. Its commands use curl and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Incident Investigation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Incident Investigation use?

Incident Investigation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Incident Investigation use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Incident Investigation?

Skills that share tags, products or a category with Incident Investigation: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Incident Investigation?

fossasia (a GitHub organization) maintains it in fossasia/eventyay-interpretation, which has 1,551 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 5, 2026.

Source: fossasia/eventyay-interpretation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.