Axiom SRE Investigator
openclaw/clawhub
Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.
Production Incident Commander — diagnose and recover from production incidents.
$ npx skills add Houseofmvps/ultraship --skill rescue -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Houseofmvps/ultraship rescue --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/rescue .claude/skills/rescue && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "rescue" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/rescue into .claude/skills/rescue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rescue", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Houseofmvps/ultraship/tree/main/skills/rescueType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Houseofmvps/ultraship --skill rescue -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Houseofmvps/ultraship rescue --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/rescue .agents/skills/rescue && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "rescue" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/rescue into .agents/skills/rescue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rescue", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Houseofmvps/ultraship --skill rescue -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Houseofmvps/ultraship rescue --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/rescue .cursor/skills/rescue && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "rescue" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/rescue into .cursor/skills/rescue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rescue", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Houseofmvps/ultraship.git --path skills/rescue--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Houseofmvps/ultraship --skill rescue -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Houseofmvps/ultraship rescue --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/rescue .gemini/skills/rescue && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "rescue" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/rescue into .gemini/skills/rescue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rescue", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Houseofmvps/ultraship rescueInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Houseofmvps/ultraship --skill rescue -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/rescue .github/skills/rescue && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "rescue" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/rescue into .github/skills/rescue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rescue", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Houseofmvps/ultraship --skill rescue -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Houseofmvps/ultraship rescue --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/rescue .opencode/skills/rescue && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "rescue" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/rescue into .opencode/skills/rescue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rescue", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
rescueProduction Incident Commander — diagnose and recover from production incidents.
Rescue is an agent skill from Houseofmvps/ultraship. Production Incident Commander — diagnose and recover from production incidents. Use when something is broken in production, site is down, errors spiking, or user reports a critical bug.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Incident response. It works with Sentry. The repository describes itself as: "ULTRASHIP" Claude Code plugin — 39 skills, 33 tools, 11 agents for ship-ready workflows: planning, review, pentesting, safety guardrails, canary monitoring, SEO/AI-readiness… The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ed232cb. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
nodegitrailwayFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Rescue loads about 2k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 852 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Houseofmvps/ultraship at commit ed232cb, republished under its MIT licence (© Houseofmvps). 852 words, ~1,961 tokens.
.claude/skills/rescue/SKILL.md (or your agent's skills folder).When production is down, every minute costs trust. This skill runs an incident like a principal SRE — fast triage, clear decision-making, structured recovery, and prevention so it never happens again.
Before doing anything, classify the incident:
| Severity | Definition | Response Time | Example |
|---|---|---|---|
| SEV-1 | Service completely down, all users affected | Immediately | Site returns 500, database unreachable |
| SEV-2 | Major feature broken, many users affected | Within 15 min | Auth broken, payments failing, data loss |
| SEV-3 | Minor feature broken, some users affected | Within 1 hour | One API endpoint slow, email not sending |
| SEV-4 | Cosmetic or edge case | Next business day | UI glitch on one browser, non-critical error log |
Severity determines urgency. SEV-1/2: restore first, investigate later. SEV-3/4: investigate first, then fix.
Ask for:
If the user is panicking, skip questions and use whatever info is available. Speed > completeness for SEV-1.
node ${CLAUDE_PLUGIN_ROOT}/tools/incident-commander.mjs <project-directory> --url=<production-url>Parse the JSON output.
If a Sentry MCP server is connected (check your available tools — search for sentry tools), pull live production errors before guessing at code: list the most recent / most frequent issues since the incident window, read the top stack traces, and map each frame back to a file and line in this repo. A real stack trace from production beats inferring the culprit from recent commits. Use the actual error signature to narrow the suspect commit. If no Sentry server is connected, continue with the static diagnostics above (and mention that connecting Sentry would sharpen this step).
Present findings in order of urgency:
Site Status:
Likely Culprit:
Error Patterns Found:
Resource Issues:
Present in order of speed — for SEV-1/2, always recommend Option 1 first:
Option 1: Rollback (fastest — 2-5 min)
git revert <culprit-hash> --no-edit && git pushThis is almost always the right first move. Restore service, then investigate.
When NOT to rollback:
Option 2: Hot Fix (5-15 min) If the error pattern is clear and the fix is small:
fix: [what was broken] — incident [date]Option 3: Traffic Management (immediate) If the issue is load-related:
Option 4: Investigate Further If the cause isn't clear:
railway logs, Vercel: function logs)After applying a fix:
node ${CLAUDE_PLUGIN_ROOT}/tools/health-check.mjs <production-url>Confirm the site is back to healthy status. Check:
For SEV-1/2, the user needs to communicate with their users:
Status page update template:
[Investigating] We're aware of [issue description] and are actively working on a fix.
[Identified] We've identified the cause and are deploying a fix.
[Resolved] The issue has been resolved. [Brief explanation]. We apologize for the disruption.If the user has a status page: help them post the update. If they don't: suggest setting up a simple one (Instatus, Betteruptime, or a static page).
Generate a post-mortem document from the incident-commander output:
# Incident Post-Mortem — [Date]
## Summary
- **What happened:** [One sentence]
- **Severity:** SEV-[N]
- **Duration:** [start time] to [end time] ([N] minutes)
- **Impact:** [Who was affected, what they experienced]
- **Root cause:** [One sentence]
## Timeline
| Time | Event |
|---|---|
| HH:MM | Issue detected (how: monitoring/user report/deploy) |
| HH:MM | Investigation started |
| HH:MM | Root cause identified |
| HH:MM | Fix deployed |
| HH:MM | Service restored |
## Root Cause Analysis
[Detailed explanation of what went wrong and why]
## What Went Well
- [Fast detection, quick recovery, etc.]
## What Went Wrong
- [Missed in review, no test coverage, no monitoring, etc.]
## Action Items
| Action | Priority | Owner | Deadline |
|---|---|---|---|
| Add test for this failure case | High | [user] | This week |
| Add monitoring for [pattern] | High | [user] | This week |
| Add pre-deploy check that would have caught this | Medium | [user] | This sprint |
| [Update runbook/docs] | Low | [user] | This month |Save to docs/incidents/YYYY-MM-DD-incident.md.
Based on the incident, suggest concrete preventive measures:
Immediate (today):
/ship pre-deploy auditThis week:
/health or /api/health)This month:
© Houseofmvps, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/rescue of Houseofmvps/ultraship.
Open the folder on GitHubat commit ed232cb
Rescue next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Rescue this skillHouseofmvps/ultraship | 123 | — | ~2k | Automated safety check: Pass | MIT | |
| Axiom SRE Investigatoropenclaw/clawhub | 9.5k | — | ~7.1k | Automated safety check: Pass | MIT | |
| Superset Incident Triagesuperset-sh/superset | 15k | — | ~1k | Automated safety check: Pass | Custom licence | |
| Sentry Incident Runbookjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~3.7k | Automated safety check: Pass | MIT | |
| Sentry Reliability Patternsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Sentry Alert TunerLeoYeAI/openclaw-master-skills | 2.2k | — | ~7.3k | Automated safety check: Pass | MIT |
openclaw/clawhub
Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.
superset-sh/superset
Does a read-only first pass on a possible production incident: gathers deploy, Sentry and health-check signals, proposes a severity and status message, then stops for human approval.
jeremylongshore/tons-of-skills-marketplace
Execute incident response procedures using Sentry error monitoring.
jeremylongshore/tons-of-skills-marketplace
Build reliable Sentry integrations with graceful degradation, circuit breakers, and offline queuing.
LeoYeAI/openclaw-master-skills
Reduce Sentry alert fatigue by surgically tuning issue grouping, fingerprint rules, severity mapping, sample rates, before-send filters, sourcemap pipelines, and release-health gates.
kubeshark/kubeshark
Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.
Houseofmvps/ultraship
A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions
Houseofmvps/ultraship
Accessibility audit + auto-fix (WCAG 2.2 A/AA). An agent skill from Houseofmvps/ultraship.
Houseofmvps/ultraship
Living Architecture Map — auto-generate Mermaid diagrams of your codebase.
Houseofmvps/ultraship
Learn From the Best — analyze patterns from any codebase and apply them to yours.
Houseofmvps/ultraship
Code review with principal-engineer-level depth. An agent skill from Houseofmvps/ultraship.
Houseofmvps/ultraship
Competitive X-Ray — analyze any competitor URL vs your site.
Works with
Categories
Production Incident Commander — diagnose and recover from production incidents. Rescue is an agent skill from Houseofmvps/ultraship. Production Incident Commander — diagnose and recover from production incidents.
Rescue fits situations like: something is broken in production; user reports a critical bug.
Run `npx skills add Houseofmvps/ultraship --skill rescue -a claude-code`. Or copy the skill folder (skills/rescue in Houseofmvps/ultraship) into .claude/skills/rescue in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Houseofmvps/ultraship --skill rescue -a codex`. Or copy the skill folder (skills/rescue in Houseofmvps/ultraship) into .agents/skills/rescue in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Houseofmvps/ultraship --skill rescue -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rescue, .gemini/skills/rescue, .github/skills/rescue and .opencode/skills/rescue in your project.
Going by SKILL.md and its folder, Rescue needs the command-line tools its instructions call (node, git and railway).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Rescue is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Rescue: Axiom SRE Investigator (openclaw/clawhub, 9.5k stars), Superset Incident Triage (superset-sh/superset, 15k stars), Sentry Incident Runbook (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Sentry Reliability Patterns (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Houseofmvps (a GitHub user) maintains it in Houseofmvps/ultraship, which has 123 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on July 8, 2026.
Source: Houseofmvps/ultraship on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.